An agent initiates a payment; the mandate bounds amount and destination before execution; approvals can require a human; the evidence shows exactly why it was allowed.
The agent requests the payment with its AgentID — no payment credentials in the agent's hands, ever.
Amount, destination category, time window, and per-entity ceilings check before execution. Outside the rules → LIMIT_EXCEEDED, and nothing has moved. Above the approval threshold → held for the owner.
Guardian holds pattern-breaking payments even when technically permitted; refusals and holds are records, not just log lines.
Each decision is hashed and anchored — the "why was this allowed" question has a verifiable answer per payment.