Deadlatch, done for you
The audit tells you what is open. This closes it.
You ran the Agent Payment Security Audit, or you are about to. The readout ends with a shortest path. This is that path, built into your stack by the person who wrote the engine, in days. Fixed scope and a fixed quote per step, in the order the audit gave.
What gets built
Five steps. The audit picks which ones you need.
Each step closes named dimensions in the readout. Most teams need the first one. Some need all five. The audit decides, not the sales page.
01The boundary
A payment-governance layer between the agent and the rail. The credential moves behind it, the agent submits intents, and the layer is the only path that can pay. Purse enforcement mode, deployed as the public broker image against your own Postgres, mock rail first, real rail when you are ready.
Bound grants, caps that bite first
Every grant tied to an exact payee and amount. Per-spend and per-day caps enforced before the spend, and budget reserved the moment a grant is minted, so parallel small spends cannot outrun the day's limit.
A person the agent cannot impersonate
Spends above your threshold wait for an approval given out of band, on a channel the agent cannot reach. The admin port is separate from the agent port and needs a token the agent never sees.
A record no one can quietly edit
Every decision and the settled amount in a hash-chained receipt store anyone can verify with plain SHA-256, exported into your telemetry with a Grafana dashboard included. Verifiable outside the tool, including outside me.
The re-check
Tripwire run against your tool set with an alarm on drift, so a new tool, MCP server, or dependency cannot reopen a money path unnoticed. The practice is handed over so it stays yours.
Everything installed is public and inspectable before you buy. The packages are on npm, the broker image is on GHCR, the engine behind the audit is open. Nothing here depends on trusting me.
How it runs
Audit. Scope. Build. Verify by running the audit again.
Run the free audit and send the readout. Nothing else is needed to begin. One call scopes it, and you get a fixed quote per step in the order the readout gave. The build happens in your environment, in days, from the same public images and packages anyone can inspect.
Done means the audit is run again on the finished setup and the dimensions the step promised come back Closed. If they do not, the step is not done and it is not invoiced.
Why this operator
The person who wrote the engine installs it.
Purse, blackbox, Tripwire, the receipt engine, and the audit itself are all mine and all public. The broker runs in production on a reference deployment you can hit. The final review of the audit found the one way its shortest path could name a breach and hand over a path that never closed it, and that got fixed before the release. That is the standard the install is held to.
Start
Send the readout.
Attach the audit's markdown or paste the terminal output. You get back which steps I would build, in what order, and what each costs. If the honest answer is that you only need the first step, that is the answer you get.