Allow
No rule fires. The action may continue. If the pilot scope includes it, a record of the decision context is kept.
The normal case.Agent Rules are the selling conditions you choose for AI-assisted purchases. Before a sensitive action, Trusteed can allow it, ask for human review, or block it based on the limits you configured. It always explains the reason for the decision.
No rule is fully operational across all five platforms equally: each card shows its real availability.
A rule doesn't return a number: it returns a decision with its reason. That's what lets an agent retry usefully, and lets you defend the block if someone asks.
No rule fires. The action may continue. If the pilot scope includes it, a record of the decision context is kept.
The normal case.A rule flags the operation without closing it. Human confirmation is required before executing, per the threshold you configured.
Not yes or no: not yet.The action never reaches the backend. The response includes the rule code, the threshold that was missed, and what it would take to pass.
Always with a reason.Each platform carries two numbers: autonomous / supported. The first counts rules that platform decides on its own with the full signal locally; the second also counts rules that work when another component supplies the signal. WooCommerce at "0 / 29" does not mean it does nothing: it means none of the 29 it supports resolves without that signal. The filter selects on the first number.
If a robot or assistant wants to buy in your store it must show its 'digital ID'. No identification, no purchase. That simple.
Example: An anonymous bot tries to add 3 shirts to the cart → Trusteed stops it before payment.
The agent's digital ID has a cryptographic 'signature' that proves it is real. If someone tries to use a fake or tampered ID, the purchase is stopped instantly.
Example: An attacker tampers with the agent token → invalid signature → blocked.
When a user lets an assistant buy for them, they set a limit — a maximum amount ('no more than €100') and/or which product categories are allowed (chosen from a dropdown, e.g. 'sneakers only'). If the cart goes over the amount or includes a category outside the mandate, the purchase is stopped.
Example: User authorised up to €100 and the cart reaches €250 → blocked.
If the agent's 'digital ID' was created very recently, an extra check is added. Brand-new keys are a warning sign.
Example: Agent uses a key created just moments ago → extra check before payment.
If Trusteed has cancelled an agent's access — for abuse, fraud or any other reason — that agent cannot buy in any connected store.
Example: An agent marked as fraudulent tries to buy → blocked immediately.
Not all systems that 'verify' agents are equally reliable. If the verification source has low confidence, the purchase is stopped.
Example: Agent verified by a low-confidence system → blocked.
If an agent has recently been blocked across several Trusteed stores, your store blocks it too. Shared protection between merchants.
Example: A bot blocked in 3 clothing stores → also blocked in your shoe store.
The user gives the assistant specific permissions ('search only', 'add to cart only'). If the assistant tries to do something more — like pay without permission — it is stopped.
Example: Assistant with 'search' permission tries to process payment → blocked.
On automated payment routes, the agent must always identify itself. No exceptions at checkout.
Example: Agentic checkout with no agent token → blocked before processing.
Agents that have never bought in your store go through an extra check. Like asking for references the first time.
Example: New agent with no history in your store → review before approving.
If an agent racks up several failed payment attempts in a short time, something is wrong. Could be an error, could be an attack. Stopped for investigation.
Example: Several failed payment attempts in a short window → temporarily blocked.
Some products (gift cards, expensive electronics, etc.) have higher fraud risk. The merchant picks the categories to flag from a dropdown — no typing — and the order is held for review when one is in the cart.
Example: Agent tries to buy 10 gift cards → blocked (flagged category).
If you sell non-returnable products (digital items, unique sizes) and the agent has not confirmed it understands, the purchase is stopped to avoid disputes.
Example: Agent buys a digital course without confirming it has no return → blocked.
Blocks deliveries to restricted countries (North Korea, Iran, Syria, Cuba) and agents that cancel too many orders after shipping.
Example: Order with shipping to Iran → blocked automatically by legal restrictions.
If a product's price changed significantly since the agent found it, the purchase is stopped. The agent would be buying something different from what the user authorised.
Example: Product cost €50 when the agent found it, now costs €58 → extra check.
If the product has very low or uncertain stock, the purchase is stopped to avoid selling something that may not be available.
Example: Last pair of trainers in stock, warehouse not confirmed → extra check.
If an agent makes excessive use of discount codes in a row, it is running a brute-force attack to find valid coupons. Stopped immediately.
Example: Bot rapidly tries many discount codes in a row → blocked.
If the cart is far larger than your store's average order, something does not add up. Could be an error, could be fraud. Reviewed before processing.
Example: Store with a modest average order receives a far larger cart → review triggered.
The merchant can restrict which countries they sell to. If an order comes from an unauthorised country, it is blocked automatically.
Example: Store that only sells in Spain receives an order billed in Mexico → blocked.
Some merchants — especially B2B — only accept agent orders during working hours. If an agent tries to buy at 3 AM it is paused until the next business day.
Example: B2B store only accepts orders 9–18h and one arrives at 23h → paused.
Even if the agent is well-known in other stores, its first purchase with you always goes through an extra check. First time — reasonable to verify.
Example: Veteran agent with 500 global purchases, but first time in your store → review.
The merchant can decide which payment methods to accept for agent purchases. If the agent tries to pay with an unauthorised method, it is stopped.
Example: Merchant does not accept BNPL for agents and assistant tries to pay with Klarna → blocked.
If an agent returns a disproportionate share of everything it buys, there is an abnormal pattern. It may be testing products at the merchant's expense.
Example: Agent that returns most of its recent orders → blocked.
Chargebacks cost the merchant money. If an agent has opened several disputes recently, it is blocked to protect the merchant.
Example: Agent with several recent chargebacks → blocked.
PO boxes and freight forwarders are signs of package re-routing — a common pattern in fraud. The merchant can block these addresses.
Example: Delivery to 'Package Forwarder LLC, Miami' → re-routing signal → review.
Agents cannot subscribe the user to recurring payments without the user explicitly approving it. No written consent, no subscription.
Example: Assistant tries to activate annual subscription without user confirmation → blocked.
Gift cards are hard to trace and widely used in fraud. By default, agents cannot buy them unless the merchant explicitly allows it.
Example: Agent tries to buy €500 in gift cards → blocked by default.
In business-to-business sales there must always be an official purchase order. If the agent places a B2B order without one, it is stopped.
Example: Company buys office supplies through agent with no PO number → blocked.
The merchant chooses their security level: Open, Balanced, Strict or Regulated. Each level requires different evidence. Without the right evidence, the purchase is stopped.
Example: Merchant in Regulated mode: agent without regulatory evidence → blocked.
The merchant can set simple rules: maximum order amount, allowed countries. The easiest rules to configure and the ones most small stores use.
Example: Merchant sets max €100 per agent order; cart of €180 → blocked.