{
  "_about": "AI agent payment policy template published by Flominzo (https://flominzo.com/resources/ai-agent-payment-policy-template). Vendor-neutral starting point. Every value is an EXAMPLE: replace it with your own. Not legal or compliance advice; review with your risk, finance and compliance owners. The agent never holds spending authority in its prompt: the payment layer enforces this policy outside the model and denies when in doubt.",
  "policy": {
    "id": "pol-supplier-payments-001",
    "version": 3,
    "status": "active",
    "description": "Pay approved supplier invoices from the operating account",
    "owner": "head-of-finance@example.com",
    "approvers": ["controller@example.com", "cfo@example.com"]
  },
  "agent": {
    "id": "agent-ap-assistant",
    "operated_by": "finance-operations",
    "environment": "production",
    "can_change_this_policy": false
  },
  "scope": {
    "purposes": ["supplier_invoice"],
    "categories_blocked": ["payroll", "refund", "crypto"],
    "rails_allowed": ["bank_transfer"],
    "currencies_allowed": ["GBP", "EUR"],
    "source_accounts": ["operating-account-gbp"]
  },
  "counterparties": {
    "mode": "allow_list",
    "new_payee_cooling_period_hours": 48,
    "allow_list": [
      { "name": "Example Textiles Ltd", "account_reference": "GB00EXMP00000000000001", "max_per_payment": 5000 },
      { "name": "Example Logistics GmbH", "account_reference": "DE00EXMP0000000000000002", "max_per_payment": 2500 }
    ]
  },
  "limits": {
    "currency": "GBP",
    "per_payment_max": 5000,
    "daily_max": 20000,
    "monthly_max": 150000,
    "max_payments_per_day": 25,
    "budget_reservation": "atomic"
  },
  "approvals": {
    "by_amount": [
      { "up_to": 1000, "approval": "none" },
      { "up_to": 5000, "approval": "one_approver" },
      { "above": 5000, "approval": "denied" }
    ],
    "by_reversibility": {
      "irreversible_rails_require_approval": true,
      "new_payee_requires_approval": true
    },
    "approval_timeout_hours": 24
  },
  "validity": {
    "valid_from": "2026-10-01T00:00:00Z",
    "expires_at": "2027-03-31T23:59:59Z",
    "allowed_hours_utc": "07:00-19:00"
  },
  "revocation": {
    "who_can_revoke": ["head-of-finance@example.com", "security-oncall@example.com"],
    "procedure": "Suspend the policy; pending intents are cancelled where the provider allows, and in-flight ones are tracked to a final outcome.",
    "target_time_minutes": 5
  },
  "failure_behaviour": {
    "on_check_error": "deny",
    "on_check_timeout": "deny",
    "on_policy_missing_or_expired": "deny",
    "alert_to": "finance-ops-alerts@example.com"
  },
  "idempotency": {
    "one_key_per_intent": true,
    "retry_rule": "status_query_before_retry",
    "unknown_outcome": "investigate"
  },
  "audit": {
    "record_fields": [
      "policy_id",
      "policy_version",
      "agent_id",
      "task_or_request_id",
      "payee",
      "amount_and_currency",
      "decision",
      "approver_and_time",
      "idempotency_key",
      "provider_reference",
      "final_outcome"
    ],
    "retention_years": 7
  },
  "reconciliation": {
    "required": true,
    "match_against": ["provider_status", "settlement_file", "bank_statement"],
    "unexplained_difference": "open_exception_with_owner"
  },
  "review": {
    "cadence": "monthly",
    "reviewers": ["head-of-finance@example.com", "risk@example.com"],
    "last_reviewed": "2026-09-29"
  }
}
