Conto
Back to Learn

How to control AI agent spending

Set up spending limits, approvals, and payment records before your agent uses real money.

Published Updated

Check each payment request against your spending rules before the wallet sends the money.

Start with the agent identity

Give each spending agent an owner, a purpose, and access to an approved payment account.

Keep test and production permissions separate. A support agent issuing credits should not inherit the permissions of a procurement agent paying suppliers.

In Conto, each agent has its own identity and can be linked to specific wallets, policies, SDK keys, and approval flows.

Assign administrative permissions

Decide who can register an agent, assign its payment account, and change its spending rules.

Give payment credentials only the permissions needed for the task. Keep policy administration with an authorized owner or administrator.

Record who changes a budget or approval rule so the responsible team can review it later.

Card limits and expense reports can help control employee spending. Agents also need checks on the recipients and repeated purchases they choose during a task. We discuss these needs in The Enterprise is the Biggest Opportunity for Agentic Payments.

Set hard spend limits

Every production agent should have hard limits.

Per transaction

Stops a single oversized payment.

Daily

Limits damage from a bad loop or bad instruction.

Weekly or monthly

Keeps longer-running workflows inside budget.

Service or category

Prevents one vendor, API, or spend type from consuming the whole wallet.

Session

Bounds repeated or streaming usage in one task.

For many teams, the first useful policy is a three-tier rule: routine spend clears, payments above the approval threshold but below the hard limit need approval, and spend above a hard cap is denied. The same structure shows up in Conto's policy engine.

Control who the agent can pay

Choose approved recipients as well as spending limits. A $20 payment to a known provider and a $20 payment to a new wallet may need different decisions.

Review changes to saved payment details. Block excluded recipients and decide whether new recipients need approval.

Use available recipient history and risk information as inputs to your rules. A trust score does not guarantee safety.

Add approvals where judgment matters

Choose which requests need a person’s approval.

The better pattern is approval by exception. Route a payment to review when it crosses an amount threshold, uses a new recipient, falls outside normal hours, fails a trust check, or makes an unusual number of payments in a short time.

Show the amount, recipient, triggering rule, and deadline. Keep the reviewer’s decision with the request.

Example: a support agent issuing credits

A support agent resolves a billing issue and requests a $12 credit for an existing customer.

An example policy allows credits below $25, requires approval from $25 through $100, and blocks amounts above $100. Recipient and payment-frequency rules still apply, even to a small credit.

The record shows which rule applied, who approved the request if needed, and whether the credit completed.

Put wallet controls in the payment path

Choose whether Conto manages payment execution or your own system signs and sends.

With a managed wallet, Conto checks the request before signing and sending. With an external wallet, your payment system must require Conto authorization, send the approved payment, and report the result. Conto cannot stop transfers that bypass that check.

Two wallets, one policy check

Managed wallets and external wallets both pass through policy, approvals, and the final record.

Managed wallet

Conto decides, the wallet sends · Conto holds the rules and the record

01 Request

Agent requests a payment

POST /payments/request
02 Policy check

Conto checks owner policy

approvereviewblock
03 If exception

Owner’s approver decides

Routine spend skips this step.

04 Release

Buyer wallet sends funds

Once the request clears, the managed wallet signs and sends. Conto holds the decision and the record.

POST /payments/:id/execute
05 Record

Logged with full context

tx 0x9f2c… ✓

policy · approval · settled

Agent-controlled wallet

Agent keeps its own keys · Conto authorizes, logs on confirm

01 Request

Agent asks to authorize

POST /payments/approve
02 Policy check

Conto checks owner policy

approvereviewblock
03 If exception

Owner’s approver decides

Routine spend skips this step.

04 Execute

Buyer’s signer sends

Conto returns a 10-minute approval. The agent sends the transaction.

05 Confirm + record

Agent reports the transaction ID

POST /payments/:id/confirm

tx 0x9f2c… ✓

policy · approval · settled

Same payment context, same policy evaluation, same audit trail. Who signs and sends is where the path diverges.

Wallet sendsAgent signsException path

Catch repeated payments and retry loops

A retry loop can repeatedly charge a paid API or request the same payment.

Set limits on payments per minute or hour and spending per service. Use alerts for repeated failures and a freeze rule when the workflow needs to stop.

Monitor pending approvals, new recipients, changed payment details, and rapid budget use while the task is running.

Assign someone who can review alerts and stop the connected payment process.

Keep the audit trail useful

An audit trail should answer a plain question: why did this payment happen?

Keep the request, amount, recipient, rule result, approval, and final payment status together.

Test three paths before production

Test an approved payment, a blocked payment, and a request held for review. Check both the returned decision and what the wallet did. A successful payment alone does not prove blocked requests stay unpaid.

Do this in a sandbox with a real agent, real policy logic, and realistic payment context. The docs walk through the same approach in Testing Payments Safely.

Related Conto resources

Test your spending rules before going live

Run a sandbox agent through one approved payment, one denied payment, and one payment held for approval so the team can see the controls working end to end.

Next guide

x402 and API spend controls for AI agents