THE “THIRD” MAN BETWEEN YOU AND THE BUYER
Let AI agents buy from you without letting them spend freely. Every money action carries a cap, a reason, and a log entry.
A refusal is a feature.
When an agent asks for more than it is allowed, the answer is no — in a full sentence, naming the bound that applied, written to the audit log before anything moves.
One request, every bound
Seven checks.
In order.
Every purchase — from a chat widget, an MCP tool call, or the recovery pipeline — walks the same list before a rupee is reserved. Scroll to step through it.
- ··purchase:createGranted to this key. Refunds and payouts are not in the enum at all.
- 02guardian statenormal — 4 buys/hr against a 14-day p95 of 11.
- 03AP2 mandateES256 signature verified, cart hash matches, not yet redeemed.
- 04razorpay connectedMerchant keys resolved and decrypted for this tenant.
- 05stock available3 of 12 reserved atomically in the same UPDATE.
- 06catalogue price match₹1,400.00 asserted, ₹1,400.00 on file. Exact, in paise.
- 07spend cap balance₹4,200.00 requested against ₹1,180.00 remaining.
One backend, one audit log
Four surfaces.
The same gate.
Headless, gated, no UI
An external buyer's agent gets fourteen tools over Streamable HTTP and the same cap check a human checkout hits.
MERCHANT DASHBOARDEvery decision, with its reason
Caps per agent, a live SSE decision stream, the recovery pipeline, returns, and a kill switch.
BUYER CHATA storefront that answers back
Discover, build a cart, negotiate inside a merchant-set floor, redeem coins, pay. One script tag on any domain.
REVENUE RECOVERYRetries that stop themselves
A failed payment gets a real Payment Link and a bounded schedule. The stopping rule is arithmetic, not a model call.
Where we chose not to use AI
AI decides judgement.
Code decides limits.
A language model never gets asked whether a transaction fits its cap. That is subtraction, and subtraction does not hallucinate. If the gate cannot evaluate a request — model down, database unreachable, state ambiguous — it denies, and logs why.
- 01Spend caps and remaining balance
- 02Retry counts and stopping rules
- 03Escalation and ROI thresholds
- 04Whether a bound was breached
- 05Negotiation floors and concessions
- 06Every arithmetic operation on money
- 01Classifying an ambiguous decline reason
- 02Conversational product discovery
- 03Ranking a pre-filtered set of bundles
- 04Phrasing an already-decided counter
- 05Conducting a return conversation
- 06Explaining a decision in plain language
Twenty-seven layers, not four
Past the gate,
there is a lot more.
An adversarial agent, a supervised returns desk, five ways onto a merchant's own store, and a control layer for the merchant who wants to watch before they trust it.
Gemini and Google ADK, actually adversarial
A standalone Google ADK agent on Gemini 3.5 Flash, holding nothing but a real key, buying against this product the same way a stranger's agent would. No shared code with the gate it's trying to get past.
RETURNS DESKThe model recommends. It never approves.
An AI runs the whole return conversation and checks it against the merchant's own policy. The refund still needs a human, every single time — proven by a test the model can't get around.
STORE ONBOARDINGA CLI, a Shopify app, a plugin, an audit page
One shared readiness engine, five front doors: an npx CLI, a public no-install audit, a VS Code extension, a real Shopify sync, and a generated WooCommerce plugin.
CONTROL LAYERGuardian, a kill switch, a trust score that can't cheat
Anomalous agents get throttled automatically. One button freezes every agent at once. A trust score can inform a merchant — it is never imported by the gate.
One merchant's numbers, illustrative — every merchant sees only their own