You let an AI shopping agent called ShopBot buy a USD 120 item for you. Before, during and after the payment it runs one workflow each, and every step leaves a receipt.
Show how a chain of receipts lets you prove, after the fact, that the purchase went exactly as you allowed. One agent does all the work in order. It spawns no helper agents, so there is one identity to check and one session receipt at the end.
| Question | Answered by |
|---|---|
| Who is the agent? | art-32 checks its signed agent card and art-04 its delegated authority. |
| Within my money budget? | art-02 compares the price with your daily limit and what was spent today. |
| Within the session budget? | art-36 checks the payment session's cap and terms, and art-02 runs again against that cap. |
| Did I double order? | art-01 checks the approval chain for this cart and flags a second payment against it. |
| Paid what I approved? | art-62 compares the payment receipt with the signed approvals. |
| What else ran? | cry-05 folds every receipt from the session into one root, the held retry included. |
| Within my LLM token budget? | Not covered yet. No AINumbers tool checks model-token spend today. The session budget here is the payment session's cap. |
This walkthrough keeps to one agent on purpose. When an agent hands work to another, each agent needs its own identity check, and each hand-off must narrow the permission it passes on. art-385 checks that a delegated token never widens its parent's limits.
Running the same workflow twice in parallel is the usual way double orders happen: one copy goes stale and retries. A single agent that records every attempt, plus a check that flags a second payment on the same cart, closes that gap.
Workflows agent-identity-trust, tempo-mpp-agent (first three of four steps) and agent-economy-payment-receipt from chaingraph.json. Values are synthetic and the fingerprints are real SHA-256 over the values shown. Inputs and verdict words are illustrative.