An agent-first setup with an owner checkpoint
An owner creates a restricted connection. The agent reads its bound identity and capabilities, requests an allowance with exact terms, and returns a review link. The owner reviews the policy in the workspace. No shared administrator password is needed by the agent.
A useful first workflow
Choose one recurring financial request with a known counterparty and small test allowance. Have the agent propose it, inspect a refusal outside the policy, approve an allowed request, and follow the evidence. Measure setup effort and investigation time before expanding.
Multiple agents do not imply shared authority
Give agents individual connections. Negotiation and messages from another agent do not grant spending permission. Proposals are bound to the requesting agent and its assigned policy.
Integration requirements
Use the JavaScript client, HTTP API, or local MCP server. The current commerce connection is proposal-only. Evidence reporting is opt-in. A runtime with direct provider credentials can bypass these controls; route the relevant action through the governed integration.