Know Your Agent · Agent Mandate Certificate
Know your agent.
Check its authority.
When an AI agent books, buys or pays on someone’s behalf, identity is only the beginning. Make the company, the mandate and its limits independently inspectable.
No card. Sandbox records are clearly marked. Use fictional data.
AGENT MANDATEIllustration
Sample Trading Firm · enquiry & quote agent
Authority, made visible.
- Principal brand
- Alpine Gate · sample
- Allowed actions
- Quote only
- Spending authority
- None · no booking or payment
- Financial actions
- Outside this mandate
- Validity
- 1 Nov 2026 – 30 Apr 2027
- Record version
- v1 · proposed schema
Illustrative record, not issued. These values do not confer authority or indicate verified company status.
More than an identity check
Who stands behind it.
What it may do. Whether it still holds.
01 / PRINCIPALWho is behind it
Link the agent to its principal and the evidence supporting that relationship. Company identity and authority are distinct checks.
02 / MANDATEWhat it may do
Named actions, counterparties, assets and limits. A principal signs the mandate; the record states what was checked.
03 / LIFECYCLEWhether it still holds
Inspect the record’s current status and validity, not just a screenshot from the day it was issued.
One mandate. Two sides.
Built for agents.
Readable by counterparties.
For companies running agents
- Establish the principal and register its signing key.
-
Define the agent’s action, scope, session and validity.
- Sign the mandate and issue an authorization record.
-
Share the verification link with your counterparty.
Explore current mandate verification ↗
For merchants and platforms
Inspect the evidence, mandate and current record status before relying on an agent’s claim.
The authenticated per-action API returns a signed decision: allow,
deny
or needs human approval. Execution remains the receiving platform’s responsibility. Human approval is a stop signal, not a completed co-approval workflow.
Discuss a merchant pilot ↗
Illustration · not a live mandate
Same agent. Two different decisions.
An example company signs a mandate allowing its agent to purchase from one approved supplier, up to $200 per action. Assume the signatures, validity, session and remaining period allowance all pass.
AllowA $150 purchase
The action and supplier are permitted, and the amount is within the mandate. The API returns a signed allow receipt and reserves $150 against any configured period allowance.
DenyA $250 purchase
The same agent requests more than the $200 per-action limit. The API returns a signed deny receipt. The receiving platform must stop the purchase.
Neither response executes a purchase or payment. A configured human-approval threshold can instead produce a needs-human stop signal; human co-approval execution is not included. New authenticated signed decisions are metered, including denials.
Clear scope, visible evidence
The record is the beginning.
The check is the next layer.
Existing foundationSigned mandate records
Principal-key registration, signed mandate validation, authorization records and public verification links form the current foundation.
Read the developer guide ↗
Phase one · APIPer-action policy checks
Agent key challenges, allowed counterparty organization IDs, per-action and period limits, session binding and signed decision receipts. Live checks require enrollment in KYA billing. Human co-approval execution and continuous KYA monitoring are not included in phase one.
Public status lookup remains free and separate from authenticated checks that reserve mandate allowance. A successful check does not execute or prove a payment.
Explore the proposed certificate fields
Agent and principal
Stable agent ID, name, operator, public-key fingerprint and optional endpoint. Principal company certificate, legal identity, jurisdiction, relevant licence and authorising signatory.
Mandate and validity
Actions, counterparties, per-action and period limits, assets, human-approval threshold, session binding, valid-from and expiry dates, evidence level, status, version and issuer signature.
Four evidence levels, no hidden assurance
- Self-reported
-
The issuer states the claim. It is not independently verified.
- Source checked
-
The record identifies the source or signature actually checked. It does not imply that every company or signatory claim has been verified.
- Evidence reviewed
-
Human review of authority documents and the signatory’s authority is scoped separately.
- Continuously monitored
-
The proposed KYA programme adds scheduled company and licence checks, status changes and subscribed alerts. Not yet available for KYA.
Built for delegated business
Where authority matters.
Merchants & booking platforms
Understand the authority behind concierge and shopping-agent requests.
Trading & payout platforms
Keep evidence of the mandate behind automated orders and payout requests.
Payment & treasury teams
Make delegated permissions inspectable without handing Proof Rail custody of funds.
Alpine Gate is the intended first integration for Sample Trading Firm. Its sample above is illustrative, not a live issued mandate or evidence of customer adoption.
One platform, not another contract
Start with a mandate.
Automate when ready.
Certificates use Proof Rail’s current record pricing. The optional KYA add-on includes 20 checks per included record in your selected plan, per KYA billing month. Additional checks cost $0.002 each—1,000 additional checks cost $2. No additional base fee. Sandbox checks and public status lookups are free.
Enable the add-on in your customer dashboard after activating your certificate plan. Every new authenticated signed decision counts, including allow, deny and needs-human; identical retries count once. The issuing company pays. The add-on has its own billing period. Plan changes require the KYA allowance to be updated before live checks resume. Specialist reviews are quoted separately.
Is this KYC for bots?
No. Identity, delegated authority and transaction acceptance are different questions. A mandate records authority; it does not replace a bank’s or regulated firm’s own checks.
Can I verify without an integration?
Public records can be inspected through a verification link or QR code. Signed per-action checks require the API; a no-code interactive check form is not included in phase one.
Does this execute payments or guarantee behaviour?
No. Proof Rail does not hold funds, execute payments or act as a licence. A record states what was checked and when; it does not guarantee how an agent will behave. Payment-method neutrality does not imply an integration with every payment provider.
What happens after revocation?
New signed checks deny revoked or expired mandates. An identical retry returns its original historical receipt, not a fresh approval. Revocation cannot undo a completed action. KYA-specific subscribed alerts remain planned.
Know Your Agent
Let agents act.
Know who they act for.