1 · The path in one look
- The agent passes its suite in COLVO Test.
- Connect Stripe with a restricted key.
- Your backend issues a mandate per conversation.
- Observe for a week — nothing changes for customers.
- Enforce with every refund going to a person.
- Raise auto-allow for what reviewers always approve.
2 · Connect Stripe with a restricted key
From the project page → Connections, paste a restricted key and the webhook signing secret. COLVO checks each permission read-only before saving and refuses unrestricted live keys. Only COLVO’s executor ever uses the key.
3 · Observe first
For a week the agent keeps acting as today and reports what it did to POST /v1/observations. COLVO records what it would have decided and checks Stripe. The Observations page shows would-be decisions and replies that disagree with Stripe.
4 · Enforce: one call replaces the Stripe call
Remove the Stripe key from the agent. Where it called Stripe, it proposes to COLVO. Start with auto_allow_up_to_minor: 0: every refund is REVIEW and a person approves it on the Approvals page.
5 · Raise auto-allow
After a week or two, look at what reviewers approve every time — usually small refunds on the customer’s own recent payment — and set auto_allow_up_to_minor to that level. Everything above still goes to a person.
Full code for Node, Python and n8n: Move your agent to Guard.