Spend Policy Engine
A parent account controls each of its agents through a spend policy. The policy is what makes it reasonable to give software real purchasing power: the agent receives actual authority, while your own stays fully intact.
Available rules
| Rule | What it does |
|---|---|
| Daily limit | Caps total USDG spent over any rolling 24-hour period |
| Per-transaction limit | Caps the size of a single payment |
| Allowed recipients | Lists the addresses, handles or domains (for x402) the agent is permitted to pay |
| Asset restrictions | Sets which assets the agent can spend. The default is USDG only, and bridged USDC and ETH can be enabled |
| Time windows | Restricts the hours or days during which the agent can transact |
| Approval threshold | Sets an amount above which a person has to explicitly approve the payment before it runs |
Creating a policy
Set policies in the parent dashboard at Agents → [agent name] → Spend Policy, or use the API (see Agent and Policy Endpoints).
You can edit a policy at any time. New rules apply to transactions from that moment on and have no effect on anything that has already settled.
Enforcement
Here Cyphron differs from typical spend controls. Checks happen before a signature exists, not in a review afterward. During signing, the agent tests the proposed payment against the policy currently in force. If any rule fails, no transaction is built and nothing is submitted. An agent never tries an out-of-policy payment only to have it silently bounced later on, because that payment is never signed in the first place.
Approvals
When a payment exceeds the threshold you set, the agent prepares the transaction, holds it, and alerts the parent account. A person reviews the amount, the recipient and any accompanying context, and then approves or declines.
- Approved: the payment is signed and sent right away
- Declined: the payment is dropped, so nothing is submitted and no funds move
- No response: the request lapses after a configurable period (24 hours unless changed) and counts as declined
Think of the threshold as a slider between independence and supervision. A value of zero means you review every payment the agent makes. A high value suits an agent you trust to run routine, low-value tasks without you.
Example policy
{
"daily_limit_usdg": 500.00,
"per_transaction_limit_usdg": 50.00,
"allowed_recipients": ["api.market", "*.anthropic.com", "@yourname"],
"assets": ["USDG"],
"active_hours": "00:00-23:59",
"hitl_threshold_usdg": 25.00
}
With this policy, the agent can pay api.market and anthropic.com domains freely, as long as each payment is $25 or less. Anything over $25, or any payment to a recipient not on the list, either waits for human approval or gets blocked.