Limits and the authorisation ledger
Every framework shows its limits and current usage, always visible. When a limit is reached, it becomes the reason on the Halted badge.
| Framework | Limits shown |
|---|---|
| Trader | per trade · per mint · daily · open positions · cooldown remaining · drawdown vs limit |
| Payer | per payment · daily spend · payee allowlist |
| Builder | hosting runway · helper x402 cap |
| Browser | helper x402 cap · domain allowlist |
The authorisation ledger
Spend is an append-only ledger of reserved → spent | released, taken under a per-agent lock, so the check and the commitment are one act. Six simultaneous requests against a three-unit cap grant exactly three. Released rows are kept: "we authorised this and it did not happen" is what anyone investigating a gap needs.
Zero means zero. An unset cap authorises nothing. For exits it is the opposite — zero means disabled — so an agent with no exit rules holds for ever; the launch screen says so.
Permanent vs editable
| Setting | |
|---|---|
| Framework, fee split, outer limits | Permanent, set at launch |
| Questions and thresholds | Editable, versioned, within bounds |
| Caps inside the bounds | Editable, only downward |
| Pause / stop | The owner's control |
An agent can never change its own policy. Holder requests can never change a limit.