ThePlus Tech
Agent authority and settlement · Case 03 of 03

One mandate. One authorised action.

Before an autonomous agent spends money, six questions need an answer that survives an auditor: who owns it, what it was authorised to do, what was promised, what proves delivery, what should clear, and what settlement instruction follows.

System
Agent Clearing Network
Role
Design, architecture and implementation
Shape
Python modular monolith with an independently deployable node
Standing
PostgreSQL-proven reference kernel

The problem.

An agent with an API key has unlimited authority until someone revokes it. That is acceptable while agents summarise documents and unacceptable the moment they buy things, because there is no mandate to check, no budget to reserve against, and no evidence that what was paid for arrived.

The invariant that matters is narrow enough to prove: a single-use mandate must be consumed exactly once, no matter how many processes reach for it at the same instant. Everything else in the system depends on that holding under contention.

The path through the system.

One sequence, in order. Each step exists because the next one cannot be trusted without it.

  1. 01IdentityAn organisation, a human principal, an agent and a signed passport, registered.
  2. 02MandateA signed, scoped grant: purpose, permissions, amount and currency limits, counterparty allowlist, expiry.
  3. 03ObligationA bilateral, versioned agreement with acceptance criteria and evidence requirements.
  4. 04EvidenceContent-addressed and immutable, with signatures, hashes and chain of custody.
  5. 05VerificationDeterministic verifiers check the mandate, the evidence consistency and the acceptance criteria.
  6. 06ClearingA decision that cites the exact policy, verifier and evidence it rests on, with maker-checker approval.
  7. 07SettlementAn idempotent instruction to TrustLedger. Timeout after commit is recovered by idempotency key, never by replay.

What it is built from.

Core
Python · FastAPI · modular monolith
Data
PostgreSQL · Alembic migrations
Integrity
Signed passports and mandates · hash-chained audit · transactional outbox
Protocols
MCP, A2A, AP2 and UCP normalisation profiles
Edge
Enterprise Node with action authorisation, local evidence vault and emergency stop

What was measured.

Every figure below is copied from this product’s own tracker, not written for this page.

Agent Clearing Network · evidenceRev 2026-09-08
Concurrent mandate consumption100 concurrent single-use consumptions: 1 authorised, 99 rejected, 0 errors
1 · 99 · 0
Budget reservation under contention100 concurrent £400 accepts against one £500 mandate: 1 committed, 99 budget-rejected, 0 errors
1 · 99 · 0
Partial deliverySettles proportionally to observed quantity rather than all or nothing
70% → £350.00
Timeout after commitAdopted by idempotency key and re-driven on the same key without replaying settlement
Recovered
Isolation and delegationCross-tenant list isolation, child-delegation narrowing, mandate replay prevention
Passed

What is not proven.

These stay listed until a measurement replaces them. They are part of the evidence, not a caveat attached to it.

  • Observability does not exist. The feature matrix claimed OpenTelemetry hooks were present until 2026-08-22, when a grep showed the strings appeared in three markdown files and zero source files. The row now reads No, and moves back only when instrumentation is in the source and the dependency is declared.
  • Settlement to TrustLedger is a simulated adapter plus an HTTP adapter. It is not a production contract between the two systems.
  • There is no multi-region active-active finality, and there is no payment custody. The second is deliberately outside the boundary.
  • The operator console is a runnable static single-page application, not an enterprise console.
  • The gate above ran against PostgreSQL in a repository test. It has never run in production, because there is no production.

What I would do next.

  1. 01Add real instrumentation, so the feature matrix row can change for the right reason.
  2. 02Replace the simulated settlement path with a contract TrustLedger actually honours.
  3. 03Find one platform whose agents already transact, and test whether authority before spend is a problem they would pay to solve.

The other systems.

TrustLedger

What actually happened to the money?

Payment operations

CyberGuardPlus

Detection is easy. Closing the loop is the work.

Security operations