AI agents can initiate purchases, renew subscriptions, pay vendors, and manage digital assets, but autonomous execution introduces financial, operational, and security risks. Treasury controls provide the rules and monitoring needed to limit those risks while allowing agents to perform authorized tasks.
Begin with a written policy for each agent. Specify its permitted activities, approved merchants or vendors, supported assets, transaction limits, operating hours, and escalation requirements. Use separate wallets or payment instruments for different functions, such as cloud services, advertising, payroll, and vendor payments. Daily, weekly, and per-transaction caps should be enforced by a system outside the agent’s own instructions. Products such as Oobit Agent Cards illustrate this model by assigning an agent a dedicated programmable payment instrument with server-side controls.
High-risk actions should require additional authorization. Approval thresholds can be based on transaction value, merchant category, destination, asset, or changes to an existing beneficiary. Controls should also prevent duplicate payments, unexpected recurring charges, and transfers to newly added addresses without a cooling-off period. Treasury systems should validate the recipient, network, currency, and final amount before execution. For stablecoin payments, the preview should include exchange rates, network fees, settlement currency, and any applicable conversion costs.
Every request, decision, approval, decline, and settlement should produce an immutable or tamper-evident audit record. Logs should identify the agent, policy version, human approver, wallet or card used, transaction identifier, and reason for the payment. Real-time alerts are useful for unusual frequency, rapid balance depletion, policy violations, failed transactions, and interactions with sanctioned or restricted entities. Reconciliation should compare on-chain activity, card transactions, bank statements, and accounting records.
Treasury controls should include emergency suspension, key rotation, wallet isolation, and recovery procedures. A human operator should be able to disable an agent without relying on the agent itself. Policies require periodic review as vendors, jurisdictions, payment rails, and business objectives change. Testing in a sandbox, using low transaction limits, and gradually expanding permissions reduces the consequences of configuration errors or compromised agent credentials. The objective is controlled autonomy: agents can execute routine financial tasks, while authority, liquidity, and accountability remain governed by explicit rules.