ACTION TYPE · MOVE MONEY

Payments that leave before anyone checks the total.

Wires, internal transfers, refunds, payouts. An agent that can call the payment API can move money at the speed of the API, and the rule that should have stopped it is usually a sentence in a policy document.

Who runs it today: Treasury agents, payout scripts, refund bots, reconciliation jobs.

The rules that usually govern it

  • A ceiling per payment, often lifted by a second signature
  • A cumulative cap per day, per account or per counterparty
  • A cooling-off period after a new or changed beneficiary
  • A limit on how often the beneficiary itself can change

Typical rule shapes, not a claim about any one organisation. A pilot starts from yours.

Where rules like these break

  1. The ceiling was conditional all along.

    “No payment above X without a second signature” caps unsigned payments only. A signed one of any size passes, and nobody notices until a solver is asked.

  2. Split it, and every part is legal.

    A per-payment rule cannot see a total. Several payments under the ceiling move more than the ceiling, one compliant request at a time.

What the gate does

  1. 01

    Checks each request against the proven policy before it executes. What fails never reaches the system.

  2. 02

    Refuses when a window or population the rule depends on is missing or does not reconcile, instead of guessing.

  3. 03

    Seals every decision, allow or block, so it can be re-checked without us.

What you can check today

PUBLIC

A sealed evidence pack for a real payment control, verifiable in your browser, and a lab where you can attack the same policy.