Shared card
One card number. No way to say which agent may spend what, or with whom.
Ostrel is pre-launch. Mandates for AI agents, built on the Canton Network. Request access
Permission slips for AI agentsChecked before settlement
Ostrel issues on-ledger mandates for AI agents. Spend limits, approved counterparties, an expiry date and a kill switch, all checked before a transaction settles.
Pre-launch. We’ll only write when there’s something to show you.
Incoming request
Presents mandate
Checking before settlement
Result
Shared card
One card number. No way to say which agent may spend what, or with whom.
API key
A key can pay anyone, any amount, until somebody remembers to rotate it.
Approval queue
Or every purchase waits for a person, and the agent stops being useful.
Month-end
Either way, you learn what the agent did after the money has moved.
Drag to change the daily limit and see which queued requests still fit.
After that, every check fails. Nobody has to remember to switch it off.
The agent can transact inside its limits.
A mandate is a contract on the ledger between your company and your agent. This is its whole life.
You write the limits, name the counterparties and set an expiry. Your company signs. The mandate now exists on the ledger.
When the agent wants to pay or sign, it attaches the mandate to the transaction it proposes. No card number, no shared key.
The mandate’s rules run inside the same transaction as the payment. If any rule fails, the whole transaction is rejected.
Archive the mandate whenever you like. The agent’s authority ends with its very next transaction, not at the next key rotation.
The console shows what each agent may do and what it tried to do. This one is a working demo on illustrative data. Send a transaction, then revoke the mandate and send another.
Mandates / M-0142
Your agent keeps its framework and its tools. It gains a mandate ID to present when it transacts. The rules live in a contract, so nothing depends on the agent behaving.
import { Ostrel } from "@ostrel/sdk";
const ostrel = new Ostrel({ apiKey: process.env.OSTREL_API_KEY });
const mandate = await ostrel.mandates.issue({
agent: "procurement-agent-01",
limit: { amount: "5000.00", currency: "USD", period: "day" },
perTransaction: "1500.00",
counterparties: ["northfield-supply", "alder-compute"],
expiresAt: "2026-12-31T23:59:59Z",
});
// The agent presents mandate.id with each transaction.
// When you want it to stop:
await ostrel.mandates.revoke(mandate.id);
curl "$OSTREL_API/v1/mandates" \
-H "Authorization: Bearer $OSTREL_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"agent": "procurement-agent-01",
"limit": { "amount": "5000.00", "currency": "USD", "period": "day" },
"per_transaction": "1500.00",
"counterparties": ["northfield-supply", "alder-compute"],
"expires_at": "2026-12-31T23:59:59Z"
}'
# Revoke
curl -X POST "$OSTREL_API/v1/mandates/M-0142/revoke" \
-H "Authorization: Bearer $OSTREL_API_KEY"
template Mandate
with
principal : Party
agent : Party
perTransaction : Decimal
counterparties : [Party]
expiresAt : Time
where
signatory principal
observer agent
nonconsuming choice Authorise : ()
with payee : Party; amount : Decimal
controller agent
do
now <- getTime
assertMsg "Mandate expired" (now < expiresAt)
assertMsg "Over per-transaction cap" (amount <= perTransaction)
assertMsg "Counterparty not on mandate" (payee `elem` counterparties)
choice Revoke : ()
controller principal
do pure ()
Simplified for the page. Names and shapes may change before launch.
Why on-ledgerCanton Network
Ostrel runs on the Canton Network, a public ledger built for finance with privacy designed in. The mandate check and the payment sit in one transaction. Both happen, or neither does.
One transaction
Mandate
DeclinedA $2,300 order from a new supplier. Over the cap and not on the list.
Something else on your mind? Leave your email and ask us directly.
Request accessA contract on the ledger that says what one agent may do for your company: how much it may spend, with whom, until when. Your company signs it. The agent presents it. Think of a corporate card and a power of attorney, written for software.
A card limit is enforced by the issuer and you see the result on a statement. A mandate is enforced inside the transaction itself, names the counterparties, covers actions other than card payments, and can be revoked without cancelling anything else.
The mandate contract is archived. The agent’s next transaction that relies on it is rejected before anything settles. Transactions that already settled are unaffected.
The parties to them. On Canton, a contract is shared with its stakeholders and not broadcast to the rest of the network. Your limits and your counterparties are not public.
Two reasons. Privacy: parties see only the contracts they are a stakeholder in. Atomic settlement: a transaction that spans several applications settles as a whole or not at all, so the mandate check cannot be skipped or run late.
It needs to present its mandate when it proposes a transaction. The limits are not in the prompt or in the agent’s code, so a confused or compromised agent still cannot exceed them.
Not yet. Ostrel is pre-launch. The screens on this page are a demo with illustrative data. Request access and we’ll write to you when there is something to try.
Pre-launch. We’ll only write when there’s something to show you.