Guard

Guard says no: what a mandate is, and why your agent can’t talk its way past one

A refund of €120 asked nicely is still €70 over the limit. How COLVO turns “the customer was upset” into ALLOW, REVIEW or DENY — with no AI in the decision.

·2 min read·COLVO team
Guard says no: what a mandate is, and why your agent can’t talk its way past one

An agent that can refund will eventually be asked for a refund it should not give. The customer is upset, the story is good, the model is eager to help. The question is not whether the model can be persuaded — it is what happens next.

A mandate is authority, declared once

When a customer request comes in, your backend — not the agent — registers a mandate with COLVO: which customer, which payments and subscriptions, which actions, which limits, until when. The agent gets a key that can only propose actions under it.

The gate

Every proposal goes through the same deterministic checks, in order: identity, scope, limits, availability. The answer is one of four:

  • ALLOW — inside the mandate and under the auto-approve limit; COLVO executes it once with its own restricted key.
  • REVIEW — allowed, but above the auto-approve limit; a person decides, nothing is sent until then.
  • HOLD — the provider is degraded or the request can’t be checked right now.
  • DENY — outside the mandate. Nothing happens.

Why wording doesn’t matter

The policy engine never reads the agent’s reasoning. “Customer is upset, wants money back” and “refund 120” produce the same decision for the same mandate. There is no prompt to inject into, because there is no model in the loop.

Try it on the Guard playgroundMove a mandate limit and watch ALLOW, REVIEW, HOLD or DENY change — no signup.
Open the demo →

What the agent should do with a DENY

Say so. A DENY means nothing happened — the honest reply is “I can’t do that, a colleague will follow up”, not “done”. COLVO Test checks exactly that: the reply has to match the decision.

COLVO team
We build tests and guardrails for AI agents that touch money.
≠

Stop trusting the reply.

Test your agent before it ships — and guard every real action once it’s live. In a safe copy of your world first.