A policy gate, a tamper-evident ledger, and human-in-the-loop approval — sitting between any autonomous agent and the money it can spend. The control plane for agentic spend.
| # | decision | merchant | amount | route | rule fired | ledger hash | stripe receipt |
|---|
The autonomous operator running the revenue workflow that requests each spend.
NVIDIA OpenShell sandbox. The run is Landlock-confined on the local 4090; payment egress reaches Stripe only through an explicit policy.
The agent’s brain — an NVIDIA open model, reasoning via OpenRouter cloud inference.
The payment rail. A real test-mode charge fires only when Cortex returns ALLOW.
An autonomous agent with a payment method is a liability the moment it is unsupervised. Cortex is the enforcement layer between any spending agent and the money.
Per-transaction caps, hard limits, vendor and category allow or deny, rate windows, purpose binding. Every spend is gated before a cent moves.
A hash-chained, append-only ledger. Every decision cross-references its Stripe receipt and sandbox event by one request id. Audit-grade by construction.
Unusual spend escalates and holds. The agent cannot self-approve. A human decides, then the agent resumes. Safe enough for business.