Issue AgentIDs for customer-facing agents and apply account-specific controls — every customer's agent runs inside that customer's limits, and you can prove it.
Each customer-facing agent gets its own AgentID bound to that account — incidents attribute to an agent and an accountable context, not to your platform key.
Limits per customer, not per platform: per-transaction and daily ceilings, per-entity sub-budgets ("at most N per merchant per month"), approval thresholds the customer controls.
When a customer disputes an agent action, the trail is per-customer and independently verifiable — support answers with proof, not "our logs say".
Integration is API-first: the REST reference covers issuing agents and mandates programmatically per account.