Case Study

AgentSafe

Wallet controls for AI agent spending.

In Progress
Project Status
5
Control Layers
Policy-Gated
Primary Model
6
Core Surfaces
AgentSafe logo
AgentSafe
Next.jsReactTypeScriptTailwind CSSNode.js+9 more
AgentSafe
Project Overview

About This Project

AgentSafe is wallet infrastructure for AI agents that need to request payments, transfers, escrows, and settlements without holding open treasury authority. The product includes agent identity, policy-gated execution, smart account controls, segmented vaults, approval routing, incident controls, and audit logs. ChainScore Labs is shaping the product architecture, governance model, screen system, and implementation foundation.

Client

AgentSafe

Timeline

Start
May 2026
Status
In Progress
Duration
In progress since May 2026
Product Thesis and Control Model
System Architecture and Risk Boundaries
Product Surfaces and Operator UX
Implementation Foundation

Technologies

Next.jsReactTypeScriptTailwind CSSNode.jsPostgreSQLRedisWebSocketsSmart AccountsPolicy EngineScoped Session KeysMulti-Sig ApprovalsAudit LoggingRisk Scoring

AI Agents Should Not Hold Unbounded Wallet Authority

AI agents can create useful financial intent. They should not get raw treasury authority. A bad prompt, tool error, compromised workflow, or runaway loop can turn into real loss if the wallet has no policy layer. AgentSafe sits between agents and money. Agents request actions. Policies decide whether to allow, escalate, deny, or freeze. Funds live in segmented vaults. Permissions are scoped and revocable. Every decision becomes an audit event.
AgentSafe hero section introducing policy-controlled wallet infrastructure for AI agents
AgentSafe hero section introducing policy-controlled wallet infrastructure for AI agents
The product turns agent activity into controlled financial workflows

From Autonomous Intent to Governed Execution

The key product decision is to separate intent creation from execution authority. An AI agent may decide that it needs to pay for compute, purchase a service, issue a refund, fund an escrow, or rebalance an operating budget. AgentSafe intercepts that intent and evaluates it against role, vault, amount, asset, chain, counterparty, time window, velocity, and risk rules. That structure creates room for autonomy without giving up control. Low-risk actions can execute automatically. Medium-risk actions can route to a human approval queue. High-risk or unknown actions can be denied, paused, or escalated into incident review.
  • Identity Before Authority: Every agent is registered with a role, status, linked vault, policy profile, and operational scope.
  • Policy Before Execution: Transactions are evaluated as intents first, then routed to allow, review, deny, or freeze states.
  • Vaults Before Treasury Access: Agents operate from limited vaults instead of broad company balances, reducing blast radius.
  • Audit Before Trust: Every registration, policy change, session issuance, approval, denial, and execution produces a traceable event.
AgentSafe features and purpose section explaining policy-controlled agent wallets
AgentSafe features and purpose section explaining policy-controlled agent wallets
Identity, policy, execution, treasury, and audit

The Control Loop

AgentSafe is organized around a deterministic control loop. An agent submits an intent. The policy engine evaluates the request. The system either auto-approves, escalates, or denies it. Approved actions move through the execution layer as wallet operations or connected payment actions. The treasury layer constrains the available funds. The audit layer records every decision and state transition. This keeps intelligence and authority separate. The agent can be useful and active, while the organization keeps spending limits, counterparty constraints, chain restrictions, time windows, and emergency controls in a system that operators can inspect.

01

Identity Layer

Defines each AI agent as a named actor with role, status, linked vault, risk level, and session state.

02

Policy Layer

Stores rules for amount thresholds, asset types, destinations, chains, time windows, velocity, and escalation paths.

03

Execution Layer

Turns approved intents into smart account actions, signed transactions, escrow movements, or connected payment events.

04

Treasury Layer

Segments capital into vaults for refunds, procurement, operations, escrow, sandbox usage, and reserves.

05

Audit Layer

Records intents, policy decisions, approvals, denials, execution traces, pause events, and incident actions.

06

Incident Layer

Supports freeze, pause, revoke, and escalation behavior when policy matching fails or anomaly risk rises.

Setting up a safe environment before agents can move funds

Onboarding as an Operating Charter

The onboarding workspace is intentionally more structured than a normal account setup flow. A team is not just creating a dashboard; it is creating an operating environment for autonomous financial actions. The flow captures workspace details, treasury setup, initial agent roles, approval defaults, and baseline policy settings before agents receive spending authority. The goal is to prevent unsafe defaults. If a policy is missing, a vault is not linked, or approval routing is unclear, the system should fail secure. This framing makes onboarding feel like setting a charter for autonomous finance rather than filling out a marketing form.
  • Workspace Scope: Define organization, team ownership, use case, environment, and default operating assumptions.
  • Treasury Setup: Choose supported assets, vault model, initial budgets, reserve behavior, and chain exposure.
  • Agent Roles: Start with predefined roles such as worker, supervisor, finance assistant, or sandbox agent.
  • Default Controls: Apply baseline spend caps, approval thresholds, allowlists, session expiry, and emergency pause rules.
AgentSafe onboarding workspace for configuring treasury, agents, and baseline policies
AgentSafe onboarding workspace for configuring treasury, agents, and baseline policies
Live situational awareness for autonomous money movement

Command Center Dashboard

The command center is where operators understand system health in seconds. It brings together protected treasury balance, active agents, pending approvals, blocked actions, policy hit rate, anomaly signals, vault utilization, and a live stream of recent intents. This view matters because agent activity can be continuous. Operators need more than a static transaction table; they need a real-time sense of whether the system is behaving as expected. The dashboard is designed to make exceptions obvious and intervention paths immediate.
AgentSafe command center dashboard showing agent activity, approvals, treasury state, and risk signals
AgentSafe command center dashboard showing agent activity, approvals, treasury state, and risk signals
Every autonomous actor becomes inspectable and revocable

Agent Registry

The Agent Registry is the source of truth for non-human actors in the workspace. Each row should make authority visible: agent name, role, status, linked vault, daily spend cap, approval mode, last action, and risk level. The detail view can expose smart account address, allowed actions, counterparties, session keys, policy profile, and escalation history. This turns agents from vague software processes into governed economic entities. Operators can search, filter, pause, revoke, or reconfigure access without touching unrelated workflows.
  • Canonical Identity: Each agent has a stable identity, linked account, owner, role, status, and permission scope.
  • Role-Based Boundaries: Refund agents, procurement agents, research agents, and sandbox agents can each receive different policies.
  • Revocation Controls: Session keys and active permissions can be paused, expired, or revoked when risk appears.
AgentSafe agent registry with status, risk, vault, and policy controls
AgentSafe agent registry with status, risk, vault, and policy controls
Where financial rules become executable constraints

Policy Studio

Policy Studio is the most important surface in AgentSafe. It lets teams define what agents may do using rule templates, structured controls, and natural-language policy inputs. Rules can cover amount thresholds, asset types, destination allowlists, chain restrictions, velocity limits, session expiry, time windows, and escalation conditions. The product goal is to make policy legible to both engineering and finance. A rule should read like operational intent, not hidden infrastructure. Simulation and preview modes help operators understand whether an action would be auto-approved, escalated, denied, or paused before a policy is published.
  • Rule Templates: Start from common workflows such as refunds, procurement, compute spend, escrow release, and sandbox testing.
  • Simulation: Test sample intents against a policy before activating it for live agents.
  • Escalation Paths: Route actions to auto-approve, single approval, dual approval, denial, or emergency freeze.
  • Version History: Track published changes and preserve before/after policy state for review.
AgentSafe policy studio with templates, rules, simulation, and approval logic
AgentSafe policy studio with templates, rules, simulation, and approval logic
Reducing blast radius with segmented capital

Treasury Vaults

Treasury Vaults divide company capital into purpose-specific budgets. Instead of giving an agent access to one large treasury, teams can create vaults for refunds, procurement, operations, escrow, sandbox testing, and reserves. Each vault can define balances, caps, thresholds, linked agents, approval behavior, and freeze state. This is the core financial safety primitive in the product. Even if an agent misbehaves, exposure is limited to the vault and policy scope it was assigned. Operators can rebalance, fund, freeze, or isolate a vault without stopping the entire workspace.
  • Purpose-Built Budgets: Capital is grouped by workflow, team, risk class, or environment instead of one shared balance.
  • Exposure Limits: Vault caps and daily limits define the maximum amount an agent workflow can affect.
  • Containment: Freeze or pause one vault while keeping unrelated workflows operational.
AgentSafe treasury vaults screen with segmented balances, caps, utilization, and linked agents
AgentSafe treasury vaults screen with segmented balances, caps, utilization, and linked agents
A forensic record for every agent decision

Audit Explorer

Any platform that lets AI agents touch money must be explainable after the fact. The Audit Explorer is the forensic layer for AgentSafe: policy updates, agent creation, session issuance, approvals, denials, vault funding, execution traces, pause events, and incident actions all become searchable events. The audit model is designed for enterprise trust. Each record should include timestamp, actor, object, policy decision, severity, reference ID, and before/after state where applicable. That gives security, finance, and compliance teams a shared source of truth when reviewing agent behavior.
  • Decision Trace: Show why an action was approved, escalated, denied, or paused.
  • State Changes: Capture before/after details for policies, vaults, sessions, and agent permissions.
  • Review and Export: Support filtering, detail inspection, export, and downstream compliance workflows.
AgentSafe audit explorer showing policy events, agent actions, approvals, and execution traces
AgentSafe audit explorer showing policy events, agent actions, approvals, and execution traces
Metrics

Current Progress

AgentSafe is presented as an active build, not a completed public launch. The case study avoids fabricated usage metrics and focuses on the system definition already in place: agent identity, policy enforcement, treasury segmentation, command-center monitoring, incident controls, and auditability. The next implementation workstream is to harden the policy schema and intent lifecycle around real agent workflows: request creation, rule matching, approval routing, smart account execution, vault state updates, and audit log generation.

May 2026
Started
Product strategy, control architecture, and screen system work began in May 2026.
In Build
Status
Policy model, dashboard flows, vault controls, and audit structure are in progress.
5
System Layers
Identity, policy, execution, treasury, and audit.
Pending
Metrics
No production usage metrics are included until real product data exists.
Project Gallery

Visual showcase

Gallery image 1
1 / 8
AgentSafe - ChainScore Labs | ChainScore Labs