Dev.to AI 🤖 Ai 👁 0 📖 2 min read

"The boss said yes" is not an approval

"The boss said yes" is not an approval. When an AI agent wants to spend money through Verax, the call is held. The agent cannot approve it by itself; there is no auto-approve path. A person approves it, on the machine w

"The boss said yes" is not an approval.

When an AI agent wants to spend money through Verax, the call is held. The agent cannot approve it by itself; there is no auto-approve path. A person approves it, on the machine where the body runs.

What gets held

spend is capped by payee, amount, currency and a daily limit, and even inside those caps it always defers. Any other call is held when your policy marks its rule for approval. The agent's token can read and write memory through the gate; it cannot approve.

Who resolves it

A held call is resolved with verax approve on that machine. There is no remote approver. When four approvals of the same request arrive at once, one allow is recorded and the others answer already-resolved.

A spend approval also re-checks the daily budget at the moment it is approved, against what has already been approved today, so approvals that are each fine on their own cannot add up past the limit.

The name in the record

The approval is not just a click. The approver's operator id is bound into the signed record, so a week later "who approved this?" has an answer you can check, not one you have to remember.

Since 0.4.2 an approval sent over HTTP needs a passkey assertion when an operator is registered, and verax verify checks that signature against the operator's public key without asking the body. The panel that sends it opens through verax desktop, which is not released yet, so on a released install the approval is verax approve, and a CLI approval stays unsigned: the operator id is in the record the body signs.

What it doesn't do: approving is not paying. Verax records an authorization; a person or another system moves the money. The operator id is the id Verax knows that operator by, not a verified identity from your company directory. Since 0.4.3 a checkpoint can be registered with a transparency log someone else runs; without that, the same system keeps the record and signs it. No independent audit has been done.

Episode 4 of the series, animated in three.js and voiced with ElevenLabs.

Source (Apache-2.0): https://github.com/verax-ai/verax

📰 Read the original article on Dev.to AI

Originally published by Dev.to AI. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.