Let agents act.
You set the limits.
Control what your AI agents can spend. Set payment policies, delegate budgets, and require human approval when needed. Trellis connects each signed request to an agent identity, delegated authority, and a verifiable decision trail.
Approval infrastructure for the agent era.
Who can act. Under what authority.
signing key verified
→ delegated authority checked
→ spending policy evaluated
→ signed evidence retainedKnow who’s acting.
On whose behalf. Under what authority.
Connect each signed payment request to a signing identity, the organization that granted its authority, and the rules behind the decision.
Which key is acting?
Verify possession of the registered signing key. Attribute requests to a registered agent identity without hosting or managing its agent runtime.
Who granted permission?
Bind the identity to an organization’s policy, delegated budget, and expiry. A valid signature does not grant permission by itself.
Why was it allowed?
Preserve the signed intent, policy decision, and human approval in a signed audit trail. Inspect the authority behind an action.
KYA connects signing keys, organization records, and delegated authority.
Explore the KYA model →Your workflow proposes a payment.
Your rules decide what happens.
Start with a spending policy.
Choose permitted counterparties, per-action limits, and the threshold for human approval. Bind that policy to a signing identity with a budget and expiry.
Explore policies →Check before execution.
Verify the signed request, evaluate spending policy, reserve budget, and require human approval when the policy calls for it.
See authorization decisions →Keep the decision trail.
Export signed audit events and checkpoints. Compare execution records with imported provider observations.
Inspect the evidence model →Agents can make mistakes.
Payment authority needs limits.
Runaway spending
Per-action limits and a shared delegation budget bound exposure. Pending approvals and reserved purchases count toward the budget.
Unexpected counterparties
Counterparty restrictions reject requests outside the policy. The decision binds the exact request to the applicable policy.
Skipped oversight
Requests above the approval threshold wait for a human. Developer keys cannot approve their own requests.
Retries and changed requests
Replaying the same signed nonce returns its original response. Changing the payload under that nonce is rejected; execution binds to the approved intent digest.
Authority that lingers
Short-lived requests and expiring, revocable delegations limit how long permissions remain usable. Revocation cannot undo completed actions.
Missing explanations
Signed audit events capture decisions. Reconciliation makes discrepancies visible rather than treating an accepted request as proof of settlement.
These controls apply to requests routed through Trellis. They do not detect every prompt injection or control credentials and payment paths outside Trellis. Explore their scope in the developer docs.
From intent to an explainable outcome.
Delegate
A human grants an agent a budget, policy, and expiry.
Authorize
The agent signs an exact action. Trellis evaluates the policy and reserves budget.
Execute
After the required human approval, a separate signed request queues the authorized action.
Reconcile
Compare the outcome with provider records. Keep gaps and discrepancies visible.
Your next integration starts with a conversation.
Building agent-operated workflows? Help shape the infrastructure your workflow needs.