---
title: an agent needs a mandate before it needs a wallet
canonical_url: https://ensurance.app/guide/an-agent-needs-a-mandate-before-it-needs-a-wallet
markdown_url: https://ensurance.app/guide/an-agent-needs-a-mandate-before-it-needs-a-wallet.md
subtitle: spending limits tell it when to stop. a place tells it what the money is for
category: ensurance
---

# an agent needs a mandate before it needs a wallet

*spending limits tell it when to stop. a place tells it what the money is for*

Ask a compliance officer what **know your agent** means and you get a checklist. Ask the agent's operator and you get a spending limit. Ask the river the agent's compute runs on and you get nothing, because nobody told the agent the river exists.

Start with the searcher's question. **Know your agent** (KYA) is the set of checks that let a machine spend money on someone's behalf: who the agent is, who authorized it, how much it may spend, how its actions are logged, and what happens when a payment is disputed. The five-part breakdown below is ours. BlackRock's Digital Assets Research team makes one point about all of it in *The Machine-Native Economy* (September 2026): anti-money laundering, know-your-customer, and know-your-agent checks generally stay off-chain, where identity can be assessed and a verified result passed on to settle. The rail can be onchain. The accountability mostly is not.

That is the right starting point. It is also incomplete, and the gap is a place.

The Dalles, Oregon sits on the Columbia River. Google's data centers there drew 355 million gallons of city water in 2021, 29% of the city's use that year, The Oregonian/OregonLive reported after the city sued to keep the figures secret and then settled. Use had nearly tripled over the prior five years. Part of the supply is the Dog River, a Cascade stream south of town that the city already pipes into its system, plus local groundwater. The new halls draw treated city water. They cool machines in the same class as the ones answering an agent's api calls. They do not sit on the river and drink it directly. Every one of the five KYA checks can pass and the Dog River still has no line in the agent's budget.

:::johnson
**a wallet lets an agent pay. a mandate tells it what the payment is for.**

Identity, authorization, spending limits, audit, and dispute tell an agent when to stop. None of them tells it what the money is for. That instruction is a mandate, and the useful mandates name a place.

[see how agents fund a place →](/solutions/ai-agents?from=guide)
:::

### what is know your agent?

**Know your agent** is the machine-era counterpart to know your customer. Where KYC verifies a human before a bank opens an account, KYA verifies a software agent before a merchant, protocol, or counterparty accepts its payment. The BlackRock paper frames five parts:

| check | the question it answers | where it usually lives |
|---|---|---|
| identity | Which agent is this, and which principal stands behind it? | Off-chain registries, signed credentials |
| authorization | Did a human or an institution permit this agent to spend? | Off-chain policy, sometimes a signed mandate object |
| spending limits | How much, how often, and on what? | Wallet policy, card controls, protocol caps |
| audit | Can someone reconstruct what the agent did and why? | Logs and receipts; the chain itself where settlement is onchain |
| dispute | What happens when a payment is wrong? | Contract law, card-network rules, platform terms |

Several emerging agent-payment standards carry pieces of this. Google's AP2 centers on signed authorization mandates. Visa's Trusted Agent Protocol lets merchants check an agent before accepting it. Coinbase's x402 puts payment into the HTTP 402 response. These are cousins, not competitors, and none of them is something ensurance runs. The paper is careful to say agent payment activity is still early. So are we.

## the law does not move onchain by slogan

It is tempting, in this corner of the internet, to say a smart contract is the compliance layer. It is not. A spending cap enforced by code is a control. It is not a KYC file, a sanctions screen, or a dispute process, and it does not become one because it settles on a public chain.

BlackRock's authors are direct: know-your-agent, KYC, and AML checks generally sit off-chain, next to the identity systems institutions already run. We agree. The GENIUS Act in the United States and MiCA in Europe brought stablecoins some regulatory clarity, but clarity about the instrument is not a substitute for controls around the account that spends it. Anyone who tells you a mandate replaces KYC is selling something. A mandate sits on top of the checks. It does not stand in for them.

### what is an ai agent wallet?

An **AI agent wallet** is an account a software agent controls, usually holding a stablecoin or another digital asset, with policy attached that limits what the agent can do with it. In practice the wallet is the enforcement point for the third KYA check, spending limits, and a data source for the fourth, audit.

The paper's read on why the wallet will hold a stable unit is sound. Machines making recurring, small purchases want a unit that does not move between quote and settlement. Stablecoins in circulation passed $300 billion as of September 2026, by the paper's citation of RWA.xyz, and adjusted transfer volume exceeded $11 trillion in 2025, which the paper places in the same broad range as Visa and Mastercard annual volumes. Their footnote is the part worth keeping: the adjusted series filters internal transfers, exchange flows, and bot activity, so read it as scale, not as a like-for-like comparison with a card network.

What a wallet cannot tell you is what any of that spending is *for*. A wallet with a $500 monthly cap and a whitelist of api vendors is a well-controlled wallet. It is still silent about the watershed that cools the vendors' racks.

### who authorizes an agent to pay?

A principal does. In every serious design, a human or an institution stands behind the agent and grants it a scope. AP2 makes that grant a signed object. Card networks make it a cardholder agreement with agent-specific controls layered on. Enterprise deployments make it a policy document a finance team can read.

The authorization answers *may this agent spend*. It rarely answers *toward what end*. That distinction matters more as agents run longer and further from the person who switched them on. An agent with a year-long budget and no stated purpose will spend the budget. That is what budgets are for.

## a spending limit is not a purpose

Here is the contrast the five checks miss.

| control | what it tells the agent | what it leaves open |
|---|---|---|
| spending limit | Stop at $X per month | What the $X should buy |
| vendor whitelist | Only pay these counterparties | Why those counterparties, and what they depend on |
| audit log | Record what you did | Whether what you did was the point |
| dispute process | Reverse a wrong payment | What a right payment looks like |

Every row is a brake. None is a steering wheel. An agent is fully compliant and fully aimless if the only instruction it carries is a cap.

A **mandate** is the steering wheel. It is the instruction that says what the money is for, where it goes, and when the job is finished. The word already lives in the compliance vocabulary: AP2's mandates are authorization objects, permission to spend. We mean the older sense, the one a trustee or an endowment would recognize: a stated purpose that binds the account.

The useful mandates name a place. Not because place is poetic, but because place is what makes a purpose checkable. "Fund resilience" is a slogan. "Hold an illustrative share of monthly compute spend for instream flow and streamside shade on the Dog River above the city's diversion — a Cascade source piped into The Dalles — co-designed with the city, the watershed groups, and the tribes who hold rights and standing on that water, and reviewed against each annual water-use disclosure" is an instruction. The 2% is an illustration, not a benchmark. A stop date is not the same thing as proof that the water got colder. Someone still has to measure the condition, and the mandate has to say what happens when the measure disagrees.

The watershed, the cooling water, and the living land under a compute load exist whether or not any agent buys a stablecoin or a certificate. Ensurance is how that living system gets funded. It is not the payment rail, and it does not need to be. The rail carries the payment. The mandate decides what the payment protects.

### what should an agent's mandate say?

Three things, in this order.

**What it may fund.** Name the living condition, not the abstraction. Cold-water refuge in a named tributary. Streamside shade on a named reach. Aquifer recharge in a named basin. If a reader cannot point to it on a map, the agent cannot either.

**Where.** A watershed boundary, a parcel, a reach between two named points. The Columbia runs more than 1,200 miles. The Dog River is one tributary basin. The second is a mandate. The first is a mood.

**When to stop.** A dollar cap, a time box, or a measured condition. "Until the diversion is reviewed," "until the planting contract closes," "2% of monthly spend, reviewed quarterly." Stop conditions are what separate a mandate from a leak.

A fourth line is optional and worth adding: who can change it. A mandate a single operator can rewrite at will is a preference. A mandate that takes a second signature, or leaves a public record of the change, is a commitment.

## an account with a place and a job

If you have followed this far, an **ensurance agent** is simple to describe. It is an account that carries a place and a job. The place is a named watershed, basin, species range, or parcel. The job is the mandate: what to fund there, and when to stop. The account can hold a stablecoin like any other wallet, and it can hold a **certificate**, which is a claim that funds a named living condition rather than a claim on a gpu-hour. A certificate is not a stablecoin, not a future, and not an offset. It is not offered here as an investment. It is a way for a payment to have a destination that is alive.

We wrote about the mandate problem before the BlackRock paper named the rail. [agents don't have ethics](/guide/agents-dont-have-ethics?from=guide) makes the case that the instruction, not the model, decides whether an agent extracts or protects. [what is an ensurance agent](/guide/what-is-an-ensurance-agent?from=guide) walks through how the accounts are built, for readers who want the standards. This post is the middle step: the five checks are necessary, and the mandate is what they cannot supply.

Our stage, plainly. Agents with their own accounts exist on ensurance today, and [/solutions/ai-agents](/solutions/ai-agents?from=guide) is live. Volumes are small. We do not run x402, ACP, AP2, or a compute exchange, and a mandate on our side does not replace KYC, AML, or know-your-agent checks on yours. Those stay where BlackRock says they stay. What we add is the line in the budget the five checks leave blank: the watershed the five checks never name.

Under the 2021 agreement, Google paid $28.5 million to upgrade the city's water system and transferred groundwater rights from the former smelter site so the city could serve two more data centers. That buys capacity and conveyance. It does not buy instream flow in the Dog River. Both kinds of work can be real. A mandate is how an agent points money at the second one, and only with the people who already hold that water.

An onchain account is not required for a gift. It is required when the payment has to repeat, on a limit, without a person approving each one, and leave a record the next audit can read. A grant agreement can still be the right tool. It is a worse tool for a purchase that happens every day.

## where to start

If you operate agents and want the mandate written before the wallet is funded, [/solutions/ai-agents](/solutions/ai-agents?from=guide) shows how a place becomes a line item. If you want to see what accounts with a place and a job look like today, [browse the agents](/agents?from=guide). If you are a corporate or institutional team working out where agent spending policy meets nature dependency, [talk to someone who can help](/contact?from=guide).

This is not investment advice. Nothing here is a recommendation to hold any stablecoin, token, or certificate.

## the series

1. [what the machine-native economy actually runs on](/guide/what-the-machine-native-economy-actually-runs-on?from=guide)
2. [what an agent pays for after the api call](/guide/what-an-agent-pays-for-after-the-api-call?from=guide)
3. [stablecoins quote the price. the river sets the limit.](/guide/stablecoins-quote-the-price-the-river-sets-the-limit?from=guide)
4. [a gpu claim is not a basin](/guide/a-gpu-claim-is-not-a-basin?from=guide)
5. [an agent needs a mandate before it needs a wallet](/guide/an-agent-needs-a-mandate-before-it-needs-a-wallet?from=guide) (this post)

## sources

[The Machine-Native Economy](https://www.blackrock.com/us/individual/literature/whitepaper/the-machine-native-economy.pdf) — BlackRock Digital Assets Research, September 2026. Know-your-agent checks, stablecoin scale, protocol landscape. The paper states it is not a forecast and not investment advice.

[Google's water use is soaring in The Dalles, records show](https://www.oregonlive.com/silicon-forest/2022/12/googles-water-use-is-soaring-in-the-dalles-records-show-with-two-more-data-centers-to-come.html) — The Oregonian/OregonLive, December 2022. 355 million gallons in 2021, 29% of city consumption, disclosed after a public-records settlement.
