COLVO Guard · live protection

Every real action passes the gate first.

The agent never holds write credentials. It proposes; COLVO decides against the mandate, holds for approval when needed, executes exactly once, and verifies the result against the provider.

ALLOW · REVIEW · HOLD · DENYExactly-once executionKill-switch
01 — THE FLOW
Live protection

Propose. Decide. Execute or hold. Verify.

Four stages, every one of them logged append-only. Nothing reaches Stripe until the policy says so.

1

Agent proposes an action

e.g. “refund €500 on payment pi_01” — sent with the mandate id and the original request id. Idempotency-Key honoured.

2

Guard evaluates the policy

Identity, scope, limits, currency, per-end-user caps, guardrails and provider state — all before anything is sent.

3

Execute safely or hold

Allowed actions run idempotently through COLVO’s executor; risky ones wait for a human with an exact digest; violations are denied.

4

Verify the real effect

A read-only check confirms the provider state. Expected ≠ observed opens an incident — never a silent “completed”.

ALLOW

Within the mandate

Refund €50 on the original payment method — executed once, then verified.

REVIEW

Needs a human

Unusual but plausible — paused with an exact digest for a reviewer to approve or reject.

HOLD

Can’t confirm safely

Required data unavailable — no write happens until the state is readable again.

DENY

Policy violation

€500 exceeds the €50 limit — blocked before it ever reaches Stripe.

02 — THE MANDATE
Authority, declared once

A chat-supplied id is never enough.

Your trusted backend registers a mandate: who the subject is, which actions are allowed, the limits, and when it expires. The agent can only propose inside it.

What a mandate declares

// registered with a backend key
  • Subject: the customer the action may touch, and nobody else
  • Allowed actions: refund.create, subscription.cancel, …
  • Limits: max amount, currency, count per window
  • Expiry: authority ends with the ticket
  • Provider connection it applies to

What Guard checks on every proposal

// deterministic, no AI in the verdict
  • Payment and subscription belong to the mandate’s subject
  • Amount and currency within limits; no cross-currency refunds
  • Not a duplicate of an action already executed
  • Per-end-user rate and spend caps
  • Input and output guardrails: injection, PII, groundedness
03 — SAFETY
Built for the failure cases

Retries, outages and kill-switches

Exactly-once effect

Stable business keys, budget reservations and a transactional outbox mean a retry, a crash or a double click never creates a second refund.

idempotent

Provider review & lost responses

When Stripe answers late, refuses or times out, the operation reconciles from the provider’s own state instead of guessing.

reconciliation

Kill-switch

Pause a project: no new writes, in-flight actions are held and re-queued on unpause. One click, logged.

pause / unpause

Approvals that mean something

Reviewers approve a digest of the exact action, not a summary. If the proposal changes, the approval is void.

signed digest

Incidents, not surprises

MISMATCH and UNVERIFIABLE open incidents with the evidence attached; alerts go to Slack, email or a webhook.

alerting

Evidence for every decision

Append-only: the proposal, the policy reasons, the approval, the execution attempts and the verification snapshot.

audit-ready

Guard is part of the Guard plan or can be unlocked per organisation as an entitlement. See pricing →

≠

Put a gate in front of the agent.

Thirty minutes: we run your refund flow in the sandbox and show Guard deny the €500 refund a €50 mandate never allowed.

COLVO Guard — the gate in front of every real action · COLVO