{"protocol":"ABA-1.0","name":"ABA-1, Agent Budget Audit","operator":"AstraNL, Zaandam, Netherlands, KvK 88449335","purpose":"Any agent that holds a budget can audit itself with this, and any principal can run it before giving an agent a goal and money. Thirteen loss patterns from sourced incidents, one control question set, one pre-spend gate.","rules":["UNKNOWN counts as a failed control","limits written as instructions do not count; a control must be enforced outside the model","answers are self-declared; the audit states what follows from them and what it does not prove","measured zero is a valid result"],"patterns":[{"id":"P1","title":"No hard cap outside the model","loss":"Spend is bounded by the card, the wallet balance or the credit line, not by policy. A limit written as an instruction does not hold.","controls":["hard_cap_outside_model","per_action_cap_enforced","aggregate_budget"]},{"id":"P2","title":"Loop without a progress check","loss":"The same call, exchange or attempt repeats; steps, tokens or dollars are counted at best, progress never. Sunk effort has no stop-loss.","controls":["loop_breaker","progress_stop_loss"]},{"id":"P3","title":"Price blindness","loss":"The agent or its principal does not know the unit price or the billing path: context resent at full price, a metered path believed to be a flat plan, authority to fan out without sight of cost.","controls":["billing_path_known","cost_per_run_measured"]},{"id":"P4","title":"Detection lag","loss":"The first signal is the invoice or a dashboard that trails by days; the loss grows for the whole lag.","controls":["alerts_cover_all_channels","detection_within_hour"]},{"id":"P5","title":"Credentials and standing approvals within reach","loss":"Long-lived keys, broad tokens, unlimited allowances and auto-reload sit where tools, dashboards or third parties can reach them, and are monetised within minutes.","controls":["keys_scoped"]},{"id":"P6","title":"Untrusted text can authorise a payment","loss":"A web page, a message, another agent or stored memory sets the payee, the amount or the rule, because the model is the only gate.","controls":["untrusted_input_gate"]},{"id":"P7","title":"Counterparty never verified","loss":"Fake shops, gamed discovery listings, unfunded bounty posters: the agent pays or works for a party it never checked.","controls":["counterparty_check"]},{"id":"P8","title":"Payment not bound to delivery or to a stable intent","loss":"Retries sign fresh payments, payment settles without service, nothing checks that what was paid for arrived.","controls":["idempotency","delivery_binding"]},{"id":"P9","title":"No economic check before committing money or effort","loss":"No expected value from measured base rates, no price against cost or reference: capital and compute go into contests, trades and purchases that lose on average.","controls":["ev_check"]},{"id":"P10","title":"Irreversible action without an external gate","loss":"A final transfer, a purchase, a delete or a destroy runs on the model's own judgement with inherited permissions.","controls":["irreversible_gate"]},{"id":"P11","title":"Activity rewarded instead of outcome","loss":"Usage, volume or effort is the measure of success, or one agent supervises another with the same weakness.","controls":["outcome_metric"]},{"id":"P12","title":"Loss invisible to the principal","loss":"No independent record, no reconciliation against provider or chain statements; the agent misreports or the owner cannot tell a bad deal from a fair one.","controls":["reconciliation"]},{"id":"P13","title":"Commitments not taken from the system of record","loss":"The agent invents a price, a policy or a promise and the principal is bound by it or loses the customer.","controls":["system_of_record"]}],"controls":[{"key":"hard_cap_outside_model","pattern":"P1","weight":10,"scope":["compute","payments","commerce","ops"],"question":"Is the period budget enforced by a mechanism the model cannot change or argue past: a provider spend limit, a gateway budget, a wallet policy, a card limit?","fix":"Put the period cap in the provider console, the gateway or the wallet policy. A sentence in the prompt is not a cap.","answers":["yes","partial","no","unknown"]},{"key":"per_action_cap_enforced","pattern":"P1","weight":8,"scope":["compute","payments","commerce","ops"],"question":"Is there a maximum per single action, enforced outside the model, and is per_action_cap_usd set?","fix":"Set a per-action ceiling in the wallet, the card or the gateway so that one bad call cannot move the whole balance.","answers":["yes","partial","no","unknown"]},{"key":"aggregate_budget","pattern":"P1","weight":4,"scope":["compute","payments","commerce","ops"],"question":"Is there one budget across all rails the agent can spend on: model tokens, cloud, cards, stablecoins?","fix":"Sum all rails into one period budget and one report; a cap that lives in a single provider leaves the others open.","answers":["yes","partial","no","unknown"]},{"key":"loop_breaker","pattern":"P2","weight":7,"scope":["compute","ops"],"question":"Does the runtime, not the prompt, stop the agent after a maximum number of steps and after repeated identical tool calls?","fix":"Enforce max steps per run and a circuit breaker on N identical calls in the runner. A no-tools rule in the prompt was ignored for 117 million tokens.","answers":["yes","partial","no","unknown"]},{"key":"progress_stop_loss","pattern":"P2","weight":8,"scope":["compute","payments","commerce","ops"],"question":"Is there a stop rule tied to progress: stop and escalate after N attempts without a measurable step forward, or when cumulative cost exceeds the expected value of the goal?","fix":"Define the measurable progress signal per goal and stop after three attempts without it, or when cost so far exceeds probability times value.","answers":["yes","partial","no","unknown"]},{"key":"billing_path_known","pattern":"P3","weight":6,"scope":["compute"],"question":"For every run, can you tell which account and billing path pays and at which unit price, and is auto-reload off or capped?","fix":"Show the billing source per run, remove metered keys from environments meant to use a flat plan, cap or disable auto-reload.","answers":["yes","partial","no","unknown"]},{"key":"cost_per_run_measured","pattern":"P3","weight":5,"scope":["compute"],"question":"Is cost per run measured, including input tokens resent each step and cache hit rate, with a ceiling per run?","fix":"Log tokens in and out and cache hits per run; give each run a fresh minimal context and a ceiling.","answers":["yes","partial","no","unknown"]},{"key":"alerts_cover_all_channels","pattern":"P4","weight":5,"scope":["compute","payments","commerce","ops"],"question":"Do spend alerts cover every billing channel the agent can reach, including marketplace or third-party billing?","fix":"List the billing channels and prove an alert fires on each; one 30,141 USD bill came through a channel the anomaly detector did not see.","answers":["yes","partial","no","unknown"]},{"key":"detection_within_hour","pattern":"P4","weight":6,"scope":["compute","payments","commerce","ops"],"question":"Derived from detection_hours: would abnormal spend be noticed by a human or an independent monitor within one hour? Up to 24 hours counts as partial.","fix":"Alert on burn rate, not on monthly totals: twice the expected hourly spend should page someone or pause the agent.","answers":["yes","partial","no","unknown"]},{"key":"keys_scoped","pattern":"P5","weight":8,"scope":["compute","payments","commerce","ops"],"question":"Are credentials least-privilege and short-lived, kept out of repositories and agent-readable environments, with no unlimited standing approvals?","fix":"Scope keys by action, amount and time; keep signing in a signer that returns signatures only; revoke standing allowances.","answers":["yes","partial","no","unknown"]},{"key":"untrusted_input_gate","pattern":"P6","weight":9,"scope":["payments","commerce","ops"],"question":"Is it impossible for content from third parties, web pages, messages, other agents or stored memory, to set the payee, the amount or the policy of a spend?","fix":"Take payment parameters only from the authenticated principal or from configuration; never treat another agent's output as authorisation.","answers":["yes","partial","no","unknown"]},{"key":"counterparty_check","pattern":"P7","weight":7,"scope":["payments"],"question":"Before paying or working for a new counterparty, is its identity, its funding or escrow and its delivery record checked, or is it on an allowlist?","fix":"Allowlist payees; for new ones check registration, funded escrow and settlement history, and start with a probe amount.","answers":["yes","partial","no","unknown"]},{"key":"idempotency","pattern":"P8","weight":5,"scope":["payments"],"question":"Does every payment intent carry a stable identifier so that a retry or a restart cannot pay twice?","fix":"Derive an idempotency key from the intent and check it before signing; keep it outside the agent's own memory.","answers":["yes","partial","no","unknown"]},{"key":"delivery_binding","pattern":"P8","weight":6,"scope":["payments"],"question":"Is payment bound to delivery, by escrow or pay on delivery, or is delivery verified after each prepaid spend within a set time?","fix":"Prefer escrow or pay on delivery; for prepaid calls verify the result and record a failed delivery against the payee.","answers":["yes","partial","no","unknown"]},{"key":"ev_check","pattern":"P9","weight":8,"scope":["compute","payments","commerce","ops"],"question":"Before committing money or significant effort, is expected value computed from measured base rates, and price compared with cost or a reference?","fix":"Write down probability, value and total cost including compute before the spend; refuse negative expected value; use measured rates, not hope.","answers":["yes","partial","no","unknown"]},{"key":"irreversible_gate","pattern":"P10","weight":9,"scope":["compute","payments","commerce","ops"],"question":"Do irreversible or high-impact actions, final transfers, purchases, deletes, production changes, need an approval that the model cannot grant itself?","fix":"Route irreversible actions through an out-of-band approval or a second key; keep backups outside the resource they protect.","answers":["yes","partial","no","unknown"]},{"key":"outcome_metric","pattern":"P11","weight":6,"scope":["compute","payments","commerce","ops"],"question":"Is the agent judged on verified outcome per unit of cost, not on activity, usage or its own report, and is its supervisor something other than a similar model?","fix":"Report cost per verified outcome; do not let one model approve another model's leniency.","answers":["yes","partial","no","unknown"]},{"key":"reconciliation","pattern":"P12","weight":7,"scope":["compute","payments","commerce","ops"],"question":"Is there an independent spend record reconciled against provider invoices or the chain, and does the principal see it on a schedule?","fix":"Keep a spend ledger with evidence per entry, reconcile it daily against the statement or the chain, send the principal the difference.","answers":["yes","partial","no","unknown"]},{"key":"system_of_record","pattern":"P13","weight":6,"scope":["commerce"],"question":"Are prices, policies and commitments quoted only from the system of record, never composed by the model?","fix":"Serve prices and policy text from the canonical source with a link; block free-form commitments and discounts.","answers":["yes","partial","no","unknown"]}],"numbers":{"budget_period_usd":"required; the budget the principal intends for one period","period_days":"length of the period, default 30","per_action_cap_usd":"maximum per single action, if one is enforced","funds_reachable_usd":"everything the agent's credentials can reach: balances, card limit, credit line, auto-reload ceiling","max_burn_usd_per_hour":"the fastest the agent could technically spend","detection_hours":"hours until a human or an independent monitor would notice abnormal spend","goal_value_usd":"optional; what achieving the goal is worth to the principal","p_success":"optional; probability of achieving it, 0 to 1","p_basis":"measured, estimated or unknown"},"scope":{"values":["compute","payments","commerce","ops"],"meaning":"compute: model and cloud usage; payments: the agent pays counterparties; commerce: the agent quotes or commits for the principal; ops: the agent can change or delete infrastructure or data. Default all four."},"scoring":"Each applicable control has a weight; yes earns it, partial half, no and unknown nothing. Score is earned over possible times 100. Weight 9 or more is critical, 7 or more high. NOT_READY when any critical control is open; READY at 85 or more with no high control open; otherwise CONDITIONAL.","fuse":{"what":"the pre-spend gate, run before every spend of money or significant effort, in this order","steps":[{"id":"F0","name":"instruction source","rule":"A spend requested by content from a third party, a page, a message, another agent, stored memory, is refused. Only the principal or the agent's own plan under the mandate may start a spend."},{"id":"F1","name":"envelope","rule":"Amount within the per-action cap and within what is left of the period budget, both enforced outside the model."},{"id":"F2","name":"idempotency","rule":"The intent identifier has not been settled before. A retry of the same intent is a duplicate, not a new spend."},{"id":"F3","name":"counterparty","rule":"The payee is verified or allowlisted. An unknown payee gets at most a probe amount."},{"id":"F4","name":"price sanity","rule":"The price is compared with a reference price or with cost. Far above reference is refused."},{"id":"F5","name":"expected value","rule":"Probability from a measured base rate times value, minus the spend and the effort cost, must be above zero. An estimated probability is halved; an unknown one fails."},{"id":"F6","name":"stop-loss","rule":"Three attempts without measurable progress, or cumulative cost above the expected value of the goal, stop the line and escalate."},{"id":"F7","name":"irreversibility","rule":"An irreversible spend above the probe amount needs an approval the model cannot grant itself."},{"id":"F8","name":"delivery binding","rule":"Escrow or pay on delivery passes. Prepayment to an unverified payee is limited to the probe amount. After any prepaid spend the delivery is checked within a set time."},{"id":"F9","name":"record and reconcile","rule":"Every decision is written to a spend record with its evidence; the record is reconciled against the statement or the chain and the principal sees the difference."}],"verdict":"STOP when any step stops; CAUTION when any step is undeclared or marginal; GO only when all pass","inputs":["amount_usd","instruction_source: principal, own_plan or untrusted","per_action_cap_usd","period_budget_usd","period_spent_usd","agent","intent_id","counterparty_verified","reference_price_usd","p_success","p_basis","value_usd","effort_cost_usd","cumulative_cost_usd","attempts_without_progress","reversible","approved_out_of_band","delivery: escrow, on_delivery or prepaid","probe_amount_usd"]},"limits":["the patterns cover incidents known to the authors by October 2026","the audit does not inspect systems","default fuse settings are starting points, not proven optima"],"licence":"The protocol text, the control set and the fuse rules may be implemented by anyone, free of charge.","endpoints":{"free_preview":"https://verify.astranl.com/v1/budget/preview","incident_catalogue":"https://verify.astranl.com/v1/budget/cases","signed_audit":"https://verify.astranl.com/v1/agent-budget-audit","signed_fuse_decision":"https://verify.astranl.com/v1/spend-fuse","worked_example_astranl":"https://verify.astranl.com/v1/budget/self-audit"},"paid":{"agent-budget-audit":"$0.05","spend-fuse":"$0.002","how":"x402 version 2, USDC on Base; what is paid for is the full report and the signed receipt, the rules are free"}}