A limit that the model can reason about is a limit the model can reason around. That single sentence explains why, in agentic finance, policy belongs below the model rather than inside it. The model is good at generating intent — deciding what to do next. It should not be the thing that decides whether that intent is allowed. Those two jobs need to sit in different places, and only one of them should be persuasive.
Where policy should sit
Above the model there is language: prompts, tools, context. Below the model there is arithmetic: limits, allowlists, thresholds. A mandate placed below the model is applied by the surrounding system, not by the agent. The agent proposes an operation; the layer beneath it accepts or refuses. There is no negotiation, because there is nothing to negotiate with.
Why it has to be strict
A policy layer that can be swayed is not a control. If an agent can explain, persuade or reframe its way past a limit — through a clever prompt, an injected instruction or a plausible story — the limit was never really there. A mandate below the model is deliberately narrow: it checks amounts against limits, counterparties against approvals, and everything against policy version. It does not improvise.
What this gives you
The practical result is a set of controls that hold regardless of what the model decides:
- limits the agent cannot exceed;
- approved counterparties it cannot add to;
- approval thresholds that route larger operations to a human;
- a captured policy version, so every decision is traceable.
When an operation crosses a limit, it does not vanish into a rejection. It becomes an approval request, with context attached — and the decision, once made, joins the same record.
In short
- Policy belongs below the model, not inside it.
- The layer beneath should be narrow, strict and unpersuadable.
- Limits, allowlists and thresholds hold regardless of model behaviour.
- Over-limit operations escalate instead of disappearing.
Learn how mandates and limits are expressed on the agent layer.