Holds, mandates and spend limits: how a business keeps control of an automated payment.
A mandate only says what an AI agent was allowed to try. What protects a business is what happens on its own side of the transaction: the hold it places, the ceiling it enforces, and the mandate scope it insists on before a booking or order is allowed to proceed.
6 min read
Why the business's own rules still matter
A signed mandate is only half of what keeps an automated payment under control. The other half is entirely up to the business.
A mandate is the customer's side of the guarantee: proof they approved the spend. It isn't a substitute for a business's own acceptance rules. A business that requires 48 hours' notice, or a deposit on large group bookings, still applies that rule to an agent-initiated request exactly as it would to a person calling directly. The mandate doesn't override it.
The three controls a business has
A pre-authorisation hold rather than immediate capture, so a business can confirm details before money moves. A hard ceiling on transaction size, independent of whatever the mandate claims to allow, as a second check rather than relying on the mandate alone. And mandate scope checking: refusing a request if the mandate covers something broader or vaguer than the specific booking or order on the table, on top of whatever AP2's own coverage check already confirmed at checkout.
A worked example
A family's assistant has a standing mandate to shop for home essentials, up to £300. It places an order with a retailer that holds the charge until a backordered item is confirmed back in stock and ready to ship. The mandate confirms the spend is authorised; the retailer's own rule about holding payment until the item is genuinely ready still applies independently, checked and enforced at the business's end, not assumed away because a mandate exists.
Configured once, applied automatically
These controls are configured once, as part of setting up a business's structured, agent-readable identity with Selfe: the hold behaviour, the ceiling, the scope rules that matter for that business specifically. From then on, every agent-initiated request is checked against them automatically, the same way every time.
Does a mandate override a business's own deposit or hold policy?
No. Both apply independently; an authorised mandate still has to clear the business's own rules.
Can these controls be different for different kinds of booking?
Yes, they're configured per business, so a large-group rule can differ from a standard one.
AP2 and agent payments: how an agent proves it's allowed to spend on someone's behalf.
A credential proves an AI agent is who it says it is. AP2 (Agent Payments Protocol) proves something narrower and more specific: that a real person authorised this exact spend, up to this exact limit, and a business can verify that before it charges anything.
UCP and the checkout handoff: what changes when a purchase completes inside the conversation.
Every other protocol in this hub gets a purchase ready. UCP is the one that completes it: the point where a business hands back a confirmed order without sending the customer off to finish the job on a website.
What a checkout API call looks like from the other side.
Strip away the protocol names and an AI agent completing a purchase is, from a business's own system, just another API request arriving with a specific, checkable shape. Here's roughly what lands, and what a business's system has to do with it.