Deterministic Off-Chain, Provable On-Chain: Governing Autonomous Agents on Distributed Ledgers

Updated: 1 day ago

Distributed ledgers were designed to remove the need for trust between parties. Autonomous agents introduce a new need for it.
When an AI agent holds the ability to initiate transactions on a ledger, three questions arise that the ledger itself can't answer. Was this agent authorized to make this transaction? Under which limits and conditions? And can anyone prove it, afterward, without relying on the word of the agent or its operator?
A blockchain can prove that a transaction happened and that it was signed by a valid key. It can't prove that the transaction should have happened. That is a decision, and decisions need their own infrastructure.
This article describes an architecture for governing agentic payments on distributed ledgers, built on four principles: delegated authority by mandate, deterministic decisions off-chain, verifiable proof on-chain, and execution by the client's own custodian.
The problem with putting agents directly on-chain
The simplest way to let an agent transact is to give it a key. It is also the most dangerous.
A key is total authority. Whoever holds it can sign any transaction, of any amount, to any address. A ledger has no concept of "this key may pay suppliers up to a daily limit." Whatever limits exist must be enforced somewhere else.
Smart contracts help, but only partly. On-chain logic can enforce some constraints, such as amounts or approved addresses. But many conditions that matter for institutional decisions depend on off-chain evidence: an invoice, a customer's status, a compliance check, a policy that changes over time. Bringing all of that on-chain is expensive, slow and often undesirable for privacy reasons.
Errors are hard to undo. Ledger transactions are designed to be final. An unauthorized or mistaken transaction executed by an agent may be impossible to reverse.
Accountability is invisible. The ledger shows which key signed. It doesn't show which human authorized the agent, under which mandate, or why this specific transaction was allowed.
The architecture: four principles
1. Delegated authority by mandate
A human, or an institution, defines a mandate for the agent: what it may do, up to which limits, with which counterparties, under which conditions, until when. The mandate is explicit, versioned and revocable. The agent never receives more authority than the mandate grants.
From that point, the agent operates on its own, inside the mandate. The human doesn't approve each transaction. The human approved the boundaries.
2. Deterministic decision off-chain
Every transaction the agent wants to make is first submitted to a decision layer that sits off-chain. The decision layer:
checks the transaction against the mandate in force;
verifies the evidence each condition requires;
applies the institution's policy;
produces a typed outcome: execute, condition, escalate or block.
The decision is deterministic: the same request, evidence and mandate version always produce the same outcome. Because it runs off-chain, it is fast, inexpensive and can use evidence that should never be placed on a public ledger.
3. Verifiable proof on-chain
When a transaction is approved, the decision layer issues a decision certificate: a signed record of the decision, including the mandate version, the evidence checked, the policy applied and the outcome.
The certificate itself stays off-chain, where privacy can be protected. Its cryptographic fingerprint, a hash, is anchored in the transaction itself. That links the on-chain action to the off-chain authorization in a way that anyone can verify:
the transaction on the ledger carries the hash;
the holder of the certificate can show that its hash matches;
the signature on the certificate proves who issued the decision;
any alteration to the certificate breaks the match.
The ledger now proves not only that a transaction happened, but that it was authorized, by whom, under what terms, without revealing those terms publicly.
4. Execution by the client's custodian
The decision layer never holds keys and never signs transactions. Once a transaction is approved, it is sent unsigned to the custodian the client has chosen. The custodian applies its own controls, signs with the client's key in its secure environment, and broadcasts the transaction to the network.
This separation is deliberate:
The decision layer can authorize but can't move funds. Compromising it doesn't give access to assets.
The custodian can move funds but only acts on authorized decisions. A transaction without a valid decision ID is an anomaly.
The client keeps full custody. Assets and keys remain under the client's control at all times.
The architecture can work with different custodians and different ledgers, through an adapter layer that translates one decision model into each custodian's interface. The decision layer stays the same; only the execution adapter changes.
Walking through a transaction
An illustrative flow.
A company's treasury agent needs to pay a foreign supplier and proposes a transaction on a distributed ledger.
The decision layer checks the mandate: the supplier is approved, the amount is within the daily limit, and the matching invoice is present.
The decision is execute. A decision certificate is issued and signed. Its hash is prepared for inclusion in the transaction.
The unsigned transaction, carrying the hash, goes to the company's custodian.
The custodian applies its own policy checks, signs with the company's key and broadcasts.
The transaction settles. The decision record is updated with the execution status and the on-chain transaction reference.
If the supplier hadn't been approved, the decision would have been escalate, and no transaction would have reached the custodian. If the invoice had been missing, the decision would have been block, with the reason recorded. Either way, the record shows exactly why.
What this architecture makes possible
Full agent autonomy within explicit limits. Agents can operate continuously without human approval of each action, because every action is checked against boundaries a human defined.
Proof without exposure. Counterparties, auditors and regulators can verify that a transaction was authorized without access to the private details of the mandate or the evidence.
Accountability that survives disputes. When a transaction is contested, the decision certificate shows what was authorized, under which mandate version, at which moment.
Speed and cost efficiency. Decision logic runs off-chain, where it is fast and inexpensive. Only a compact fingerprint goes on-chain.
Non-custodial by design. The organization governing the decisions never takes custody of assets or keys, which simplifies its regulatory position and reduces systemic risk.
Beyond a single ledger
The same principles apply wherever agents act on financial rails: on public or permissioned ledgers, on instant payment systems, and across Open Finance connections. What changes is where the proof is anchored and who executes. What doesn't change is the core sequence:
Mandate → Decision → Certificate → Execution → Proof
As agents begin to transact with each other, across institutions and networks, that sequence becomes the basis for something the agentic economy will need badly: a way for one party to trust another party's agent, not because it trusts the agent, but because it can verify the authority behind every action.
Authority delegated by mandate. Decisions made deterministically off-chain. Proof anchored on-chain. Execution always by the client's custodian.
Want to explore governed agentic payments on distributed ledgers? Talk to our team →

Comments