
AgentSafe
Wallet controls for AI agent spending.

About This Project
AgentSafe is wallet infrastructure for AI agents that need to request payments, transfers, escrows, and settlements without holding open treasury authority. The product includes agent identity, policy-gated execution, smart account controls, segmented vaults, approval routing, incident controls, and audit logs. ChainScore Labs is shaping the product architecture, governance model, screen system, and implementation foundation.
Client
Timeline
Technologies
AI Agents Should Not Hold Unbounded Wallet Authority

From Autonomous Intent to Governed Execution
- Identity Before Authority: Every agent is registered with a role, status, linked vault, policy profile, and operational scope.
- Policy Before Execution: Transactions are evaluated as intents first, then routed to allow, review, deny, or freeze states.
- Vaults Before Treasury Access: Agents operate from limited vaults instead of broad company balances, reducing blast radius.
- Audit Before Trust: Every registration, policy change, session issuance, approval, denial, and execution produces a traceable event.

The Control Loop
AgentSafe is organized around a deterministic control loop. An agent submits an intent. The policy engine evaluates the request. The system either auto-approves, escalates, or denies it. Approved actions move through the execution layer as wallet operations or connected payment actions. The treasury layer constrains the available funds. The audit layer records every decision and state transition. This keeps intelligence and authority separate. The agent can be useful and active, while the organization keeps spending limits, counterparty constraints, chain restrictions, time windows, and emergency controls in a system that operators can inspect.
Identity Layer
Defines each AI agent as a named actor with role, status, linked vault, risk level, and session state.
Policy Layer
Stores rules for amount thresholds, asset types, destinations, chains, time windows, velocity, and escalation paths.
Execution Layer
Turns approved intents into smart account actions, signed transactions, escrow movements, or connected payment events.
Treasury Layer
Segments capital into vaults for refunds, procurement, operations, escrow, sandbox usage, and reserves.
Audit Layer
Records intents, policy decisions, approvals, denials, execution traces, pause events, and incident actions.
Incident Layer
Supports freeze, pause, revoke, and escalation behavior when policy matching fails or anomaly risk rises.
Onboarding as an Operating Charter
- Workspace Scope: Define organization, team ownership, use case, environment, and default operating assumptions.
- Treasury Setup: Choose supported assets, vault model, initial budgets, reserve behavior, and chain exposure.
- Agent Roles: Start with predefined roles such as worker, supervisor, finance assistant, or sandbox agent.
- Default Controls: Apply baseline spend caps, approval thresholds, allowlists, session expiry, and emergency pause rules.

Command Center Dashboard

Agent Registry
- Canonical Identity: Each agent has a stable identity, linked account, owner, role, status, and permission scope.
- Role-Based Boundaries: Refund agents, procurement agents, research agents, and sandbox agents can each receive different policies.
- Revocation Controls: Session keys and active permissions can be paused, expired, or revoked when risk appears.

Policy Studio
- Rule Templates: Start from common workflows such as refunds, procurement, compute spend, escrow release, and sandbox testing.
- Simulation: Test sample intents against a policy before activating it for live agents.
- Escalation Paths: Route actions to auto-approve, single approval, dual approval, denial, or emergency freeze.
- Version History: Track published changes and preserve before/after policy state for review.

Treasury Vaults
- Purpose-Built Budgets: Capital is grouped by workflow, team, risk class, or environment instead of one shared balance.
- Exposure Limits: Vault caps and daily limits define the maximum amount an agent workflow can affect.
- Containment: Freeze or pause one vault while keeping unrelated workflows operational.

Audit Explorer
- Decision Trace: Show why an action was approved, escalated, denied, or paused.
- State Changes: Capture before/after details for policies, vaults, sessions, and agent permissions.
- Review and Export: Support filtering, detail inspection, export, and downstream compliance workflows.

Current Progress
AgentSafe is presented as an active build, not a completed public launch. The case study avoids fabricated usage metrics and focuses on the system definition already in place: agent identity, policy enforcement, treasury segmentation, command-center monitoring, incident controls, and auditability. The next implementation workstream is to harden the policy schema and intent lifecycle around real agent workflows: request creation, rule matching, approval routing, smart account execution, vault state updates, and audit log generation.
Visual showcase
