null) wallet or relationship limit means no cap. A limit of 0 blocks every payment. A
positive value is the cap.
Policy scope
Every policy has one explicit scope:- Organization: a mandatory baseline applied automatically to every payment in the organization.
- Assigned: applies only through an explicit agent, wallet, or card assignment. An unassigned policy is a draft control and is not enforced.
Evaluation order
- Pre-checks: the agent must be ACTIVE with linked wallets
DEVandSTAGINGagents can use only known testnet wallets. Mainnet and unclassified chains are denied.
- Geographic and sanctions: address sanctions screening on every payment, plus an OFAC country check when the request includes
context.recipientCountry(no policy needed) - Counterparty trust: pre-fetch trust level and network trust score for use in policy rules
- Wallet policies: spend limits, wallet-level time windows (timezone-aware), and other configured policy rules
- Identity allow rules evaluate environment, risk tier, owner role, tags, and attestation mode. Missing identity context denies the payment.
- Counterparty rules: block list, trust requirements, network intelligence
- Relationship controls: per-agent payee limits, category allowlists, approval requirements, and temporary access expiry
- Final decision: any denial denies. Otherwise a rule or workflow that requires approval holds the payment. Otherwise it is approved. See outcomes.
Address sanctions screening is active by default and uses maintained compliance data. A sanctions
match can deny a payment even when every configured policy would otherwise allow it.
Counterparty lifecycle and agent controls
Counterparty lifecycle state and per-agent relationship controls are evaluated independently:- A counterparty can move through
DISCOVERED,PENDING_REVIEW,APPROVED,TRUSTED,MONITORED,QUARANTINED, andBLOCKED. PENDING_REVIEW,MONITORED, andQUARANTINEDroute payments to approval.DISCOVEREDroutes a production agent’s payments to approval. Development and staging agents, which can only use testnet wallets, are not held for payee discovery.BLOCKEDdenies the payment.- Each agent-to-counterparty relationship can add stricter per-payment, daily, and monthly limits, require approval, restrict categories, or expire at a specific time.
Evaluation semantics
Policy rules use simple AND logic. Every active organization policy and every active policy assigned to the selected agent, wallet, or card is evaluated once, and every rule inside those policies must pass unless it is aDENY or REQUIRE_APPROVAL trigger that does not match.
When the request leaves out a field
Many rules read a field from the payment request, such ascategory, context.recipientCountry,
targetContractAddress, or the x402 or MPP service.
- If the request does not include the field an
ALLOWrule checks, the payment is denied. - If the request does not include the field a
DENYorREQUIRE_APPROVALrule checks, that rule does not apply. ABLOCKED_CATEGORIESrule blocks nothing when the agent sends nocategory.
category when you use category rules.
When a list must hold even if the agent leaves the field out, write it as an ALLOW list.
Wallet balance and custody
Evaluation checks the wallet balance only for wallets Conto custodies. For those, the recorded balance is a ledger Conto maintains as it executes each payment, so a payment that would overdraw the wallet is denied withINSUFFICIENT_BALANCE.
External wallets are not checked this way on the external-wallet approval flow
(POST /api/sdk/payments/approve). Conto does not hold the keys and never sees the transfers the agent
signs, so the balance it records is a point-in-time reading rather than a running total.
Enforcing it would block funded wallets while still clearing drained ones. Spend limits, policy
rules, counterparty controls, budgets, and approval workflows apply to external wallets exactly as
they do to custodied ones, and an underfunded transfer reverts onchain rather than settling.
For a hands-on walkthrough, test allow, review, and deny.
Related
Policies
Create, assign, and simulate a policy
Policy rule reference
Every rule type, operator, and value format