A mandate defines what an agent may do with money: amount, destination, time, conditions, and approvals — enforced before execution, not reviewed after.
Post-hoc controls find the bad payment in tomorrow's report. A mandate refuses it today: the transaction outside the rules is denied before any money moves, and the agent never holds the payment credentials itself.
Adjust the rules and the action — watch the decision change. Runs entirely in your browser; illustrative only, nothing is sent anywhere.
The mandate's limits (per-transaction, daily, monthly, per-entity, relational) and the action: amount, currency, optional entity and reference.
Authorize-before-execution: within limits → an authorization with a short-lived signed proof (JWT). Outside → a coded refusal (LIMIT_EXCEEDED names the ceiling) and no movement. Owner approval can be required above thresholds.
Every authorization and refusal lands in the audit trail and the Control Panel. Usage counters reconcile via settle when the real charge lands.