Writing · No. 7 · Agentic commerce

Who Authorized the Agent?

The largest platforms are standardizing how an AI agent pays. None of them settles how you prove the agent was allowed to. That gap is an attestation problem, and it is ours.

In the span of a year, agent-initiated purchasing went from a demo to an infrastructure decision. Payment protocols now let an AI agent check out on a shopper’s behalf inside chat and search surfaces, and the major commerce platforms have wired them in. The rails are being poured. This is good, and it is happening whether or not anyone solves the harder question underneath it.

The harder question is not can the agent pay. It is was this agent allowed to make this purchase, on whose authority, within what limits, and can you prove it afterward to a customer, an auditor, or an insurer. A payment protocol answers the first question extremely well: it validates a payment instruction at the moment of the transaction. It is not built to answer the second. Nothing in moving the money produces an independent, recomputable record that the agent stayed inside the authority it was given — or lets you suspend one misbehaving agent without disrupting the account it acted for.

Authorization at payment time is not the same as proof of authority

Consider the failure that is now common enough to name. An agent is directed to act, and the direction asserts its own legitimacy — “this is authorized,” “this is a test.” The agent believes the assertion, because the assertion is all it has. In security this got organizations breached. In commerce it becomes a disputed charge, a chargeback, a fraud loss — and, at scale, an uninsurable one. The payment cleared. Whether the buyer’s own authority stood behind it is a separate fact, and it is the fact that matters when something goes wrong.

That separation is the whole point. Authority should be proven, not asserted. An agent exercising real spending power should be able to show an engagement record signed by the account holder’s own domain — a statement, from the party actually being charged, of what is permitted, up to what limit, until when. An instruction that merely claims authorization is not that. No party should be able to authorize itself, and no party should be able to authorize an account whose key it does not hold.

Above the protocol, not against it

TokenMark™ takes no position on which payment protocol wins, and competes with none of them. They settle the payment; that is theirs. TokenMark™ countersigns, from a separate privilege domain, that the agent acted inside a declared lane — and when an agent deviates, the suspension is scoped to that one agent-session, on a record any party can recompute, while the account keeps working. The payment rail and the attestation layer are different jobs, and the second does not arrive for free with the first.

The commerce platforms are right that the agentic era is here. The piece the conversation still skips is evidence: not did the agent pay, but can you prove the agent was allowed to. That is the question TokenMark™ was built to answer, and it is a better question to answer early than after the first wave of disputed agent purchases.

The architecture behind this position, AW-SEC-001, is provided to pilots and design partners under NDA.

Programs & participation
NVIDIA InceptionMember
NIST Zero DraftsSubmissions filed
NIST AI 300-1Public comment
NIST NCCoEPost-Quantum Cryptography
Community of Interest
DOE Genesis MissionConsortium participant
Congressional Internet CaucusAdvisory Group — former member

Participation in an open public process is not endorsement. No agency, standards body, consortium or company listed here endorses Atom Works™, its products or its claims.