5分で読める

The Fifth Capability

If you are scoping an agent payments build this quarter, you already have a list. Identity for the agent. Authorization rules and spending limits. A settlement rail, probably more than one. A line near the bottom for monitoring.

The Fifth Capability

If you are scoping an agent payments build this quarter, you already have a list. Identity for the agent. Authorization rules and spending limits. A settlement rail, probably more than one. A line near the bottom for monitoring.

Now look for the line covering a durable record of what the agent did, written at the moment it did it, that survives someone with subpoena power asking you to prove it.

Most build plans don't carry that line. The reason isn't carelessness. The platforms selling into these builds don't scope it either.

Mastercard shipped the hard part

On June 10, Mastercard launched Agent Pay for Machines, a service for payments between agents and machines that settles across cards, accounts and stablecoins. The announcement is careful and specific. It names four foundational capabilities: credentialing, permissioning, transacting and settling.

Those four solve the hardest part of machine payments: making them work. Credentialing establishes that the agent is who it says it is. Permissioning bounds what it may spend. Transacting moves the instruction. Settling delivers the money and guarantees it arrives.

That's a complete account of how a machine payment gets authorized and how funds land. What the industry has not yet standardized is what you hold afterward.

The distinction matters. Transparency while a workflow runs is a different asset from evidence once it has run. The first tells your team what is happening. The second is what you produce 18 months later when somebody disputes it.

The launch partners are already naming the fifth

The quote sheet is where it surfaces.

Mastercard listed 31 initial participants, and several of them describe the same next layer. t54 Labs says its contribution creates "a clear evidence layer" for agent authorization, chargebacks, dispute resolution, and liability review. RippleX lists a full audit trail among the capabilities enterprises need before letting agents transact at machine speed. Catena describes applying auditability wherever money moves. Turnkey states plainly that machine payments only work when agent actions are secure, auditable, and policy-controlled.

Mastercard built the payment rails. The partners closest to the build are already naming the record that rides on top of them.

Sapiom, another partner, put the underlying condition bluntly. Most agent projects stall before production, because the infrastructure was never built for them.

An auditor already has a rule for this

Finance leaders tend to assume logs will cover it. Every system writes logs, right? The vendor dashboard exports them, and somebody can pull the records.

Auditors have been thinking about this problem for longer than agents have existed. They landed somewhere uncomfortable. PCAOB standards hold that the reliability of information a company generates internally rises when the controls over that information are effective. The AICPA's audit evidence standard says much the same. Tested controls are what establish reliability. A file existing proves only that a file exists, not what the file contains.

Apply that to an agent stack. The account of what the agent did comes from the software that did it, sits in a system your own team can edit, and gets offered as proof of the conduct under review. Nobody outside the workflow ever saw it happen. An auditor is being asked to accept the defendant's diary.

The regulatory clock is running on the same question. Under the EU AI Act, high-risk systems must technically allow automatic recording of events across the system's lifetime, and those obligations apply from August 2, 2026. The Financial Stability Board's June consultation went further, warning that supervisors may be unable to reconstruct the decision pathways agents take. Nobody is asking whether agents should move money. They're asking what you can produce afterward to show that money movement was verifiable.

A record written at execution is a different artifact

When the proof gets written as the payment executes, checked by something with no stake in the outcome, nobody reconstructs anything later. The evidence is already sitting there when the question arrives.

That's the layer W3.io builds. Each step in a workflow carries its own independent confirmation, and those confirmations assemble into a single readable document we call a Workflow Attestation. Audie Sheridan, our CTO, has the technical walkthrough, and the mechanics are his to describe.

The claim here is deliberately small.

A verified record settles what happened. It says nothing about whether the agent should have acted, and it leaves the liability question exactly where the law currently leaves it: unresolved. It removes the argument about the facts, leaving only the one worth having. For a CFO certifying controls over decisions no employee ever watched happen, that's the difference between exposure and oversight. A trust layer for money that moves itself starts there.

Adding it later is the expensive path

This isn't an argument for slowing down. The rails for agent-powered financial workflows are arriving whether or not any single company is ready for them.

The argument is about sequence, and the cost of getting the sequence wrong is now measurable. Gartner predicted in June 2025 that more than 40% of agentic AI projects will be canceled by the end of 2027, naming escalating costs, unclear business value, and inadequate risk controls. Deloitte surveyed 3,235 leaders across 24 countries and found that only 21% have a mature governance model for autonomous agents. Roughly 80% lack the basics, including audit trails that cover the full chain of agent actions. Three-quarters of those same organizations expect to be using agents at least moderately within two years.

The pattern in those numbers is clear. Companies build an agent that ships, works, then stops at a gate it was never designed to clear. The controls get added afterward, against a system already in production, on somebody else's timeline. That's the expensive order, and it's the one most teams are on right now.

The cheaper order doesn't require rebuilding anything. Composing the record into the workflow at the start costs a day of scoping. Retrofitting it costs a quarter and a production freeze, which is the whole practical argument for an operating system for autonomous finance rather than a stack of parts assembled after the fact.

Credentialing, permissioning, transacting, and settling describe a payment that works. A fifth capability would describe one you can still account for a year later. It belongs on the same page as the other four, and on most pages it isn't there yet.

The Fifth Capability — W3.io Blog