Answers
How do I stop an AI agent from spending money without approval?
Put a decision in front of every payment the agent makes, with an amount above which a person must approve. With Immiscible that is one rule ("ask me above £500") and a gate the payment has to pass.
Put a decision in front of every payment the agent makes, and write the rule as an amount above which a person must approve. With Immiscible, the agent (or the card issuer, or the MCP proxy) asks before any money moves, and the answer is allow with a signed receipt, approval_required while a person decides in the console, by email, in Slack or in Teams, or deny.
#How do I set it up?
- Connect the agent. In the project the agent runs from:
npx immiscible init --purpose pays_invoicesIt signs you in through the browser, creates the agent with a payment rule, writes IMMISCIBLE_URL and IMMISCIBLE_AGENT_KEY to .env, and ends with a live test call. See the CLI.
Set the approval line. In the console, Agents, Agent limits, edit the payment rule and set Ask me above to £500. The rule also carries a per-payment ceiling nobody can talk past (above it is
deny, not a question) and a monthly total. The JSON is in ask a person above an amount.Ask before paying. From code, with the TypeScript SDK:
import { Immiscible } from '@immiscible/sdk';
const immiscible = new Immiscible().run(); // IMMISCIBLE_URL and IMMISCIBLE_AGENT_KEY from the environment
await immiscible.pay(
{ amount: 42000, currency: 'GBP', merchant: 'northwind.example', summary: 'October invoice', provenance: [{ source: 'user' }] },
() => payInvoice(), // runs only on allow, after a person approves if one is asked
);Or from an MCP client, with the request_payment tool on the MCP server. Amounts are whole minor units: 42000 is £420.00.
#What stops the agent paying some other way?
Asking is the agent’s choice when the only integration is the agent calling the API. Close the other routes:
- The card rail. Give the agent a virtual card bound to it, and the issuer asks Immiscible before every authorisation: no receipt, no payment. See the card rail.
- The MCP proxy. Put the payment tool behind Immiscible, which holds its credential, so the agent cannot call it directly. See the MCP proxy.
- The Claude Code hook. For coding agents, every shell command and web request is checked before it runs, so a
curlto a payment API the rule does not name is refused or asked about. See the Claude Code hook.
#How do I set spend limits for an AI agent?
A payment rule (a mandate) holds the limits: per payment, per day, week or month, which merchants, which categories, and what happens at a new merchant (approve or deny). On top of the rule, a new agent starts as an intern (unless an owner has set the workspace to start agents as juniors) and a person signs off every payment until it has earned more on evidence; see autonomy tiers. With no rule at all the answer is deny; there is no default allowance.
#Is it safe to give an AI agent a credit card?
Safer with a card bound to the agent and an issuer that asks before money moves. With the card rail and Stripe Issuing (or another issuer through signed webhooks), every authorisation is decided against the agent’s rule, approved or declined in real time, and recorded. Keep the card’s own limits as well: they are the backstop if anything upstream fails.
#What does it not do?
- It never holds money, wallet keys or card numbers, and never signs a transaction; the issuer, wallet or payment API moves the money after an allow.
- It cannot see a payment the agent makes with a credential Immiscible does not stand in front of. Take direct credentials away from the agent.
- A person must answer within the approval’s lifetime; an unanswered request does not become an allow.
Next: the quickstart runs this end to end in five minutes.