# Agents that pay for what they use, with a receipt for every dollar

URL: https://www.orla.finance/en/for/ai-teams
Markdown twin of that page. Append `.md` to any Orla page URL to get one.

Lantern Automation builds and runs agents for its clients, six people and three machines.

#### Every dollar a machine moved, with a receipt

The research agent paid Serper and Firecrawl overnight and the runner wants to pay Modal. Whose money was it, how much, and who decided?

- Every dollar an agent moved has a receipt: which agent, whose it is, how much, to whom, by which channel, and who decided it in words ("the agent alone, inside its policy", "proposed by the agent, signed by Anna"), with the daily cap and what was left of it at that moment. Raising the cap later does not rewrite an old receipt.
- Watch mode by default. An agent pays alone only from its own wallet and within your limits. Anything from your accounts is a proposal a person signs.
- A refusal at the perimeter leaves a trail: no right, an account out of scope, the call ceiling, the amount ceiling. What a leaked key tried now has an answer, and a refused call counts as a use of the key.
- Ask the assistant what the machines did this week: figures per agent and per channel, the three most expensive payees, the refusals by reason, and how many decisions wait for a person. It can show a run of refusals, and changing the fence stays a press of the owner's.
- A connected agent can run the assistant's reports over MCP: the cash forecast, what is owed both ways, the week of payments and the signing queue, VAT and the tax year, balances and their history. Bank details arrive masked unless the connection was approved to see them, an agent narrowed to some accounts is refused a report that only makes sense for the whole space, and reports never list the team or what each person spent.
- Your own endpoints can charge other machines the same way: your server names a price and the payer's agent pays it (x402). That seller side is on for listed books while it is new.

#### A fence per agent, and a ceiling that stops

What can the research agent spend today, where may it pay, and when the runner burns through its month at three in the morning, does anything stop it or does somebody only get told?

- A fence per agent: a term, the x402 hosts it may pay with a ceiling per request, and a daily cap on what it spends in that space. It pays from its own wallet, so the worst case is the deposit it was given.
- Spend guard: a monthly ceiling in USD on one agent or on one supplier that stops the spending where the other rules only tell. Over it the agent is frozen together with its card. Only a person unfreezes, and what was unfrozen works until next month. When a supplier's ceiling is crossed and no agent card is fenced to that supplier, the notice says nothing was stopped.
- The agent can read its own fence: the daily cap, what was spent today, what is left, the ceiling per request, the hosts, and whether it is still observing. It plans a batch of purchases instead of finding the ceiling by hitting it.
- A host gets onto the list by a person's press. Find a service searches the catalogues and an agent may search too; allowing a host is always a human press, because a catalogue row is a document somebody else wrote. The list takes hostnames only, and a name outside Latin is shown in punycode, so a lookalike does not read as the name you know.
- The first x402 payment pins the address a host is paid at. A later quote with another address is refused until the owner confirms the change by hand, against the host's own documentation and not against the request.
- The owner hears before the fence says no: once a day at eighty percent of the daily cap, when the wallet's stablecoins fall under the level named in the policy, and at once when an observing agent parks a proposal.
- Freeze an agent and even its reads refuse; its rights are recomputed on every call.
- A preset per agent: analyst reads, bookkeeper proposes while it observes, treasurer pays inside its ceiling; a rule written for one space never travels to another.

#### A card for an agent, fenced by its balance

Modal and Firecrawl want a card, not a wallet. Can the agent hold one that cannot spend more than you loaded?

- Cards for agents, fenced by balance: the card holds exactly what you moved onto it from the pool, so a wrong charge can take at most that. Start it from a supplier limit and the balance is the limit.
- New agent cards carry no per-payment or daily limit and no merchant rules at the issuer. Orla refuses to save merchant, category, channel or amount rules for such a card rather than show rules nobody enforces, and the card says so: load only what this agent may spend.
- By default the agent never sees the number. On the card's policy you may allow the numbers, once: the agent reads the number, expiry and CVV one time, and may ask again only after you save that form again. One-time codes are not rationed. What it already took cannot be taken back, short of blocking the card.
- An agent whose access carries a daily cap is not given such a card, and the cap cannot be added while the card is open. Take the agent out of the space and the card is frozen at the issuer at once.
- One prepaid balance, topped up in USDT or USDC; the person who owns the agent answers for the card at the issuer.
- The issuer's history is checked against what you allocated, so a stray charge shows up the same day; freeze the agent and the card freezes with it.

#### Client work invoiced in dollars or USDC

Cedar Health pays by transfer, Bluefin pays a milestone in USDC, Orrin paid on the day. Who still owes what, and into which account does it land?

- Four figures as filters: owed, overdue, received this month, paid without an invoice; each one opens its own list.
- Paid by card via your Stripe, by transfer or in stablecoins; the invoice marks itself paid when the money lands, and a reminder goes out when it does not.
- Recurring invoices and reminders; a quote becomes the invoice.

#### The treasury, and what the machines really used

Compute is billed in USDC, the office in dollars, and the OpenAI credits were bought in one go. What is the treasury's shape this quarter, and how much of those credits is already used?

- What the machines spend at OpenAI or Anthropic is read from the vendor, not guessed from the card: paste the organisation's admin key under Connections and Orla reads the vendor's cost report once a night, per day and per model. A limit on that supplier then shows what the card was charged, what the vendor says was used, and the gap between them: paid for and not yet used, or used and not yet billed. Nothing is booked from these readings, and the connection is still being rolled out.
- Wallets on EVM chains by address beside the bank by feed; balances and their history per account, each one priced at the day's rate, for a quarter or a year at a time, on one screen.
- Suppliers and contractors are paid from your own bank. From Mercury a payment is a request in Mercury's approval queue, under a token that cannot send money; Slash has no drafts, so there a person presses Send via Slash in Orla after the quorum. Both are being rolled out.
- An agent can spend from a Safe allowance instead of its own float: the owners sign the setup in Safe{Wallet}, and the chain itself holds the limit. This is being rolled out gradually.
- A low balance rule can look ahead: it reads the cash forecast for the account the machines are funded from and warns on the day the line will cross the threshold, a week before rather than the morning after.
- A transfer between your own accounts is never income, and a top-up to the card pool is a move between them, not a line of cost in the month.
- Idle USDC can earn on Aave v3 without anyone holding a key; Orla never holds a key.

#### Who can move money, and what holds them

Six people and three machines share one treasury. Who can sign, who can only prepare, and what does the accountant read?

- Roles: owner, admin, member, viewer, accountant. An agent's rights come from its own grant and its preset, never from the seat of the person who happens to own it.
- Signing rules: a threshold, the number of signatures, address book only, a monthly allowance per person counted across every door.
- A payment above the threshold waits for a quorum, whoever proposed it.

#### The month to the accountant, machines included

Two wallets, a bank, a card pool and three agents. What does the accountant get, and can they see what a machine did?

- A closing checklist with a door into each list: rows without a category, without an account code, without paper, unpaid invoices, payments still waiting for a signature.
- A zip archive, a journal CSV, and each account's feed for QuickBooks Online and Xero; an agent's spend is a row like any other, and the machines' receipts leave with the month as a CSV of their own.
- Review, Close, Reopen with a reason; what changed after the export is visible, and an accountant seat reads the closed period without changing it.

#### Six people, three machines, different rights

- Founder: Owns the agents, sets each fence and its spend guard, unfreezes what the guard stopped, and signs what crosses the threshold.
- Finance lead: Reads the receipts and the vendors' own usage figures, tops up the card pool, prepares the contractor batch, and closes the month.
- Team member: Runs an agent in observation until its proposals look right, then switches it to active.
- Accountant: Finds every machine's row in the month's files, and reads the closed period as it was closed.

#### Ask it what the agents did this week

The composer reads the receipts the agents left and tells you what ran on rules and what still waits for a person.

- How much runs on rules: Which rows the rules sorted this week and which you sorted by hand, and the five merchants worth a rule.
- A brief before you sign: For a payment on your signature: who they are, what you paid them before, their risk, and how far this amount is from usual.
- A threshold on the forecast: USD Main runs below 5,000 on the 23rd, said a week before rather than the morning after.

#### Agents sign in over MCP, or use a key

Agents sign in over MCP, or use a revocable key for a script or an n8n flow, each under a grant per space. Wallets by address, the bank by feed.

#### Before a machine spends a dollar

- Watch mode: A new agent spends nothing on its own and only proposes. A person accepts each proposal until the team switches it to active, and not before.
- The fence: A term, the hosts it may pay, a daily cap on its wallet and a monthly spend guard that freezes it. On a card the balance is the whole limit, and the deposit is the worst case.
- Receipts: Every dollar a machine moved names the agent, whose money it was, and who decided.
- Freeze: Freeze an agent and even its reads refuse; its card freezes with it, and every right it holds is recomputed on each call it makes.

#### Questions

##### Does an agent ever hold our private key?

No. An agent that pays on chain has its own wallet, and its key is made inside a managed key service and never lands on Orla's servers: they only ask it for a signature the fence already allowed. It is funded from the treasury with what you decide to deposit; the treasury's key stays where it was. The worst case is the deposit, never the treasury it was funded from.

##### What stops an agent from paying the wrong host or merchant?

Its fence. The x402 hosts it may pay are a list a person keeps, with a ceiling per request and per day, and the address a host is paid at is pinned by the first payment, so a changed address waits for the owner. A new agent card has no merchant rules to lean on: it holds only what you moved onto it, so a wrong merchant gets at most the card's balance. A refusal at the perimeter is written to the trail, and a rule for one space never applies in another.

##### Can a ceiling stop an agent, or does it only tell us?

The spend guard stops. It is a monthly ceiling in USD on one agent or on one supplier: over it the agent is frozen together with its card, and the approvers are told with the month's figures. Only a person unfreezes, and what was unfrozen keeps working until next month.

##### Does the agent ever see the card number?

Not by default. You can allow the numbers, once, on the card's policy: the agent reads the number, expiry and CVV one time and may ask again only after you save that form again. What it took cannot be taken back except by blocking the card, so keep on that card only what this agent may spend.

##### Can the accountant tell a machine's row from a person's?

Yes. Every row an agent booked or paid carries the agent's name and its receipt: which agent, whose money, how much, to whom, and who decided. It goes out with the month's files like any other row, with its receipt attached.
