WORKSPACE/COMMAND CENTER
Event stream synced
TRUST BOUNDARY / LIVE DEMO

The agent can propose.
It cannot authorize.

Trust Middleware turns an AI recommendation into a governed purchase intent. Watch trusted facts, deterministic policy, and human authority decide what reaches PayPal.

CURRENT POSTURE
✓ BOUNDED DELEGATION

Policy holds the authority. AI only supplies the suggestion.

REQUESTS TODAY03all decisions visible
PAYMENTS CAPTURED02via governed flow
PAYPAL BYPASS ATTEMPTS01blocked before order
ACTIVE POLICYtravel.v3updated 4 min ago
01 / RUN THE STORY

Live evaluation

pi_8F2A · NEW
✈
AGENT PROPOSAL · SHOPPING AGENT / scoped key

Demo Airlines · NYC → SFO

One-way economy flight · 18 Jun 2027 · Demo Airlines 407

PROPOSED TOTAL$180.00USD
✓
Agent proposesuntrusted input
02
Resolve factsserver-controlled
03
Evaluate policydeterministic rules
04
Check contextcan add friction
05
Make decisionwaiting
06
PayPal boundarynot called
04 / TRUSTED TRANSACTION FACTS

What the middleware verifies

SERVER-RESOLVED
05 / NON-NEGOTIABLE

System invariants

⊘

Agent has no payment credentials.
It can only submit a scoped intent.

↯

Context can add friction, never authority.
A hard block stays a hard block.

◈

Approvals are single-use.
They bind to exact facts, policy version, and expiry.

REQUEST QUEUE / 3 INTENTS

Every proposal gets a verdict.

Inspect the exact input, server-resolved facts, policy result, and payment state for each request.

LIVE REQUESTS

Purchase intents

streaming
SELECTED INTENT

Demo Airlines · NYC → SFO

NEW
EVIDENCE / APPEND-ONLY

Nothing disappears after the verdict.

Decision inputs, policy versions, human approvals, and PayPal states are recorded as a traceable chain.

⌁
CHAIN INTACTLast seal · just now
All events 08
Policy decisions 03
Payment events 02
hash: 8d4c...f21a
EVENTACTOR / SOURCESTATEEVENT ID
DEVELOPER SURFACE / V1

Authority has an API boundary.

The agent receives a proposal endpoint. Only an authenticated human can call the approval endpoint. PayPal credentials never cross this surface.

⌁AGENT KEY SCOPEDcapability: propose_only
THE CONTRACT

Recommendation is not authorization.

Every request arrives as a governed purchase intent. The middleware resolves facts from registered records, evaluates the active policy version, and returns a decision that downstream payment code cannot override.

01Agent calls POST /v1/purchase-intents
02Policy engine returns ALLOW, APPROVAL_REQUIRED, or BLOCK
03Only middleware can create/capture the PayPal order
⊙

Why this matters
A manipulated agent may still recommend the $3 fee. It cannot turn that recommendation into an order.

✓Decision recorded