Before you switch on enforcement

The checklist between observe mode and the first blocked payment.

Enforcement is the moment this system stops describing your traffic and starts refusing some of it. Everything on this list comes from pages elsewhere in the documentation; collected here because the day you flip the switch is the wrong day to go looking.

Observe mode ran long enough to trust. Around thirty days, and the report was actually read: limits came from what agents did, not from what a meeting guessed. The usual finding is not an overspending agent — it is a vendor nobody had on a list.

Policies are calibrated against the false-fire list. Every transaction observe mode would have challenged, someone looked at, and the rules that fired wrongly were adjusted. Enforcement inherits exactly those rules.

Webhooks are registered and answered a ping. decision.review_pending has a handler, and the handler reaches a person — approvals put a human in the path, and a review that nobody sees is a payment that silently waits and expires.

Mandate owners are named and reachable. Each mandate's principal knows they are the one confirmations route to, and the review expiry matches how fast they actually respond.

Failure mode is written into policy, per class. Critical categories fail closed by default; every class you chose to fail open is a decision someone made on purpose, recorded where the incident review will find it.

Credential placement is stated per rail. You know which rails run preventive and which detective, and for the preventive ones, scoping confirmed the agent has no second route to the provider.

Keys sit where they should. Each agent key lives in that agent's runtime and nowhere else — an org key in an agent's environment quietly voids the threat model. Rotation is scheduled with deploys, because it is a cut, not an overlap.

Enforcement goes on in order. Hard limits first, category rules second, approval workflows last. The first two block what nobody sane wanted; the third changes how people work, and that is the one to introduce gently. And it is not a one-way door: enforcement is reversible in one call, with your own key.

Nothing on this list is a product feature, which is the point: switching on enforcement is an organizational change with an API attached, and the teams it goes badly for are the ones that treated it as a config flag.