# How do I stop an AI agent from spending money without approval?

> Put a decision in front of every payment the agent makes, with an amount above which a person must approve. With Immiscible that is one rule ("ask me above £500") and a gate the payment has to pass.

Source: https://immiscible.fly.dev/docs/answers/stop-an-agent-spending

Put a decision in front of every payment the agent makes, and write the rule as an amount above which a person must approve. With Immiscible, the agent (or the card issuer, or the MCP proxy) asks before any money moves, and the answer is `allow` with a signed receipt, `approval_required` while a person decides in the console, by email, in Slack or in Teams, or `deny`.

## How do I set it up?

1. **Connect the agent.** In the project the agent runs from:

```bash
npx immiscible init --purpose pays_invoices
```

   It signs you in through the browser, creates the agent with a payment rule, writes `IMMISCIBLE_URL` and `IMMISCIBLE_AGENT_KEY` to `.env`, and ends with a live test call. See [the CLI](https://immiscible.fly.dev/docs/cli.md#init).

2. **Set the approval line.** In the console, **Agents**, **Agent limits**, edit the payment rule and set **Ask me above** to £500. The rule also carries a per-payment ceiling nobody can talk past (above it is `deny`, not a question) and a monthly total. The JSON is in [ask a person above an amount](https://immiscible.fly.dev/docs/ai-agents.md#ask-a-person-above-an-amount).

3. **Ask before paying.** From code, with the TypeScript SDK:

```ts
import { Immiscible } from '@immiscible/sdk';

const immiscible = new Immiscible().run(); // IMMISCIBLE_URL and IMMISCIBLE_AGENT_KEY from the environment

await immiscible.pay(
  { amount: 42000, currency: 'GBP', merchant: 'northwind.example', summary: 'October invoice', provenance: [{ source: 'user' }] },
  () => payInvoice(), // runs only on allow, after a person approves if one is asked
);
```

   Or from an MCP client, with the `request_payment` tool on [the MCP server](https://immiscible.fly.dev/docs/ai-agents.md#the-mcp-server). Amounts are whole minor units: `42000` is £420.00.

## What stops the agent paying some other way?

Asking is the agent's choice when the only integration is the agent calling the API. Close the other routes:

- **The card rail.** Give the agent a virtual card bound to it, and the issuer asks Immiscible before every authorisation: no receipt, no payment. See [the card rail](https://immiscible.fly.dev/docs/guides/card-rail.md).
- **The MCP proxy.** Put the payment tool behind Immiscible, which holds its credential, so the agent cannot call it directly. See [the MCP proxy](https://immiscible.fly.dev/docs/guides/mcp-proxy.md).
- **The Claude Code hook.** For coding agents, every shell command and web request is checked before it runs, so a `curl` to a payment API the rule does not name is refused or asked about. See [the Claude Code hook](https://immiscible.fly.dev/docs/guides/mcp-proxy.md#the-claude-code-hook).

## How do I set spend limits for an AI agent?

A payment rule (a [mandate](https://immiscible.fly.dev/docs/concepts/mandates.md)) holds the limits: per payment, per day, week or month, which merchants, which categories, and what happens at a new merchant (`approve` or `deny`). On top of the rule, a new agent starts as an intern (unless an owner has set the workspace to start agents as juniors) and a person signs off every payment until it has earned more on evidence; see [autonomy tiers](https://immiscible.fly.dev/docs/concepts/autonomy-tiers.md). With no rule at all the answer is `deny`; there is no default allowance.

## Is it safe to give an AI agent a credit card?

Safer with a card bound to the agent and an issuer that asks before money moves. With [the card rail](https://immiscible.fly.dev/docs/guides/card-rail.md) and Stripe Issuing (or another issuer through signed webhooks), every authorisation is decided against the agent's rule, approved or declined in real time, and recorded. Keep the card's own limits as well: they are the backstop if anything upstream fails.

## What does it not do?

- It never holds money, wallet keys or card numbers, and never signs a transaction; the issuer, wallet or payment API moves the money after an allow.
- It cannot see a payment the agent makes with a credential Immiscible does not stand in front of. Take direct credentials away from the agent.
- A person must answer within the approval's lifetime; an unanswered request does not become an allow.

Next: [the quickstart](https://immiscible.fly.dev/docs/quickstart.md) runs this end to end in five minutes.
