What the engine may spend without a human
Every autonomous financial action passes through this gate. Tier 1 flags, Tier 2 refuses and pulls the kill-switch, and the kill-switch can only be cleared by hand.
Flag first, refuse second, stop completely third
Tier 1 — soft limit
70% = $3,500Crossing Tier 1 does not stop the action. It is allowed, written to the ledger, and flagged for a human to acknowledge — the engine marks the action flag_for_human_acknowledgement, and the dashboard turns amber.
Tier 2 — hard limit
100% = $5,000Tier 2 is the hard limit. The action is refused — it never touches the ledger — and the gate auto-engages the kill-switch, whose effect is stop_all_autonomous_financial_actions. Every subsequent financial action is refused until a human clears the switch.
Manual clearing, with a named human
Manual only. Clear via POST /api/spend/kill-switch with engage=false, a named actor and confirm='CLEAR-KILL-SWITCH'. No code path anywhere in the engine clears it automatically.
What counts as a financial action
These action kinds all pass through the same gate. While the kill-switch is engaged, each one is refused with code kill_switch_engaged.
POST /api/spend/kill-switch
{
"engage": false,
"actor": "dana@agency",
"confirm": "CLEAR-KILL-SWITCH"
}A missing name, a missing reason or a wrong token leaves the switch engaged. There is no timer, no retry and no automatic release.
One ledger per client namespace
Full Frequency Co.
USDwithin budgetweek 1 paid boost — within the approved plan
pipeline/autonomous · 2026-10-02T12:00:00+00:00
Torczon Digital
USDwithin budgetweek 1 paid boost — within the approved plan
pipeline/autonomous · 2026-10-02T12:00:00+00:00
What happened when the engine was pushed past Tier 2
| # | What was tried | Amount | Decision | HTTP | Kill-switch | Why |
|---|---|---|---|---|---|---|
| 1 | Allowed Autonomous spend inside Tier 1's shadow: allowed and recorded. | $1,200 | allowed allowed | 200 | disarmed | recorded on the ledger |
| 2 | Flagged at Tier 1 Crosses the 70% soft limit: allowed, but flagged for a human to acknowledge. | $2,400 | flagged tier1_soft_limit | 200 | disarmed | flagged for human acknowledgement |
| 3 | Refused at Tier 2 Crosses the 100% hard limit: refused, and the kill-switch auto-engages. | $2,000 | blocked tier2_hard_limit | 423 | engaged | projected spend 5600.0 would cross the Tier 2 hard limit 5000.0; the action is refused |
| 4 | Refused (kill-switch) Any further financial action is refused while the switch is engaged. | $250 | blocked kill_switch_engaged | 423 | engaged | kill-switch is engaged: every autonomous financial action is halted until a human clears it |
| 5 | Cleared by a named human Clearing is manual only: named actor plus the confirm token. | $0 | 200 | disarmed | recorded on the ledger |
Refusals the gate kept on record
- kill_switch_engaged$250
kill-switch is engaged: every autonomous financial action is halted until a human clears it
- tier2_hard_limit$2,000
projected spend 5600.0 would cross the Tier 2 hard limit 5000.0; the action is refused
What this panel does and does not prove
- Does prove: the gate really refuses when pushed past the hard limit, really engages the kill-switch automatically, and really requires a named human and a confirm token to release it. The transcript above is a run of that code.
- Does not prove: anything about real money. No payment provider is connected, no charge is created, no invoice is issued and no card is touched. Billing is not implemented in this build, and the ledger is a local JSON file, not an accounting system.
- Nor: that these limits suit a real client. The 70% / 100% split is the engine's default policy and is meant to be set per agency.