Glossary

Glossary — Agent Spend Firewall Terminology

Key terms for understanding AI agent spending controls: firewalls, velocity limits, merchant allowlists, and more.

Agent Spend Firewall

A policy engine that sits between an autonomous AI agent and payment APIs, evaluating every spend attempt against config…

Velocity Limit

A rule that limits how many transactions an agent can execute in a time window — the primary defense against runaway-loo…

Merchant Allowlist

A whitelist of approved vendors, APIs, and services an agent is permitted to spend money with. Any transaction to a merc…

Human-in-the-Loop Approval

A spending control pattern where transactions that match certain criteria (over a threshold, to a new merchant, outside …

Runaway Agent Loop

A failure mode where an autonomous agent repeats a paid action indefinitely — due to a reasoning loop, a prompt injectio…

Category-Based Spending Controls

Spending rules that limit or block transactions by category (e.g., 'max $200/month on AI APIs', 'block all advertising s…

Approval Threshold

A dollar amount above which transactions require human approval before execution, even if they pass all other policy rul…

Get started — $99/mo

How Glossary works in practice

Understanding the definition of Glossary is the first step; knowing how it behaves in a production agent environment is what actually protects your budget. In practice, Glossary manifests differently depending on your agent architecture, the payment methods your agent has access to, and whether the control is enforced before or after the transaction executes.

Consider a real example: a research agent with access to a $500/month LLM API budget. Without Glossary, a single retry loop on a complex query can burn through 40% of the monthly budget in 20 minutes — 237 API calls at $0.84 each = $199.08. With Glossary enforced as a velocity cap (10 calls/minute), the agent is blocked at call 11, the total spend is $9.24, and the audit log immediately surfaces the abnormal pattern. The team is alerted within seconds and investigates the retry bug before it recurs.

Common configuration mistakes

How sipi.bot enforces Glossary

sipi.bot evaluates Glossary on every transaction with a deterministic rules check. The agent never sees the payment method directly; it receives a structured JSON decision (APPROVED, BLOCKED, or FLAGGED) and acts accordingly. Every decision is logged with agent ID, merchant, amount, timestamp, and the rule and reason that produced it — so you can always reconstruct why a transaction was allowed or denied. Hosted Team is $99 per month; the same rule engine is MIT-licensed for self-hosting.