Bounded delegation, not blank checks
Giving an agent autonomy should not mean giving it unlimited spending. A spending mandate is a boundary an operator sets that defines exactly what an agent is permitted to pay — for example a maximum amount or a scope of what it may buy. It is bounded delegation: the agent acts on its own, but only within limits a human explicitly authorized.
How a mandate is authorized (device passkey)
Mandates are authorized by the operator using a device passkey, the same kind of hardware-backed credential used for passwordless sign-in. The approval is tied to the operator's device, so a mandate cannot be granted without their deliberate, cryptographic consent. This binds the authority an agent carries back to a real person's action.
Enforcement at transaction time
A mandate is not just a stored setting — it is checked when it matters. Every time an agent attempts to pay, Chosin evaluates the transaction against the active mandate and blocks anything outside the authorized bounds. Enforcement happens at settlement time, so the limits hold even as the agent operates autonomously.
Operator control and revocation
Operators keep control of the mandates they issue. A mandate can be scoped tightly, adjusted, or revoked, and once revoked the agent can no longer spend under it. This gives the human a clear off-switch and an audit of exactly what authority an agent was granted and when.
Ready to Get Started?
Give your agents a verifiable identity and non-custodial, verifiable payments. Get started with Chosin.
Start Free Trial