- Refund · $450
- ai-customer-support
- acme-corp
- refund_up_to_5000 · 4h · revocable
- issued · consumed
- billing.acme.com/refunds
- 14 May 2026 · 09:41 UTC
Architecture
Bounded Delegation
Caps you can cite.
Accountability Trail
Runs under written limits.
Receiver check
Before the handler runs.
After the ask
Thin ask, thick run.
01Intent
02Expansion
03Attempts
Consequence pressure
Automation needs power. Power needs a ceiling.
What the attempts look like
no mandate
no mandate
no mandate
Mechanism
Intent to receipt. Four beats.
01
Cap
02
Intercept
03
Check
04
Record
By surface
Shrink the blast radius.
Payments & refunds
Code deployments
Data operations
No mandateUnscoped
- Surface
- Exports & bulk
- Ceiling
- None set
- Scope
- Unscoped
- Window
- No TTL
Same substrate
Ship fast. Prove it.
Same rails as proof: limits at the edge, receipts after.
Authorized or refused. Nothing in between.
01
Enforcement
Check authority before your handler.
02
Outcomes
Artifacts reviewers can reopen.
03
Limits
Explicit scope, legible grants.
Three roles