Refuse the deployment before the breach.
TGOV is a governance screen for agents that deploy shared treasury capital. You send the market, each desk's mandate and request, and the rules. It returns what every agent is allowed to deploy, and an audit log of why. It does not move money between desks and it does not predict the market.
What it is
A paid decision, not a dashboard. Machine clients pay $0.05 USDC on Base L2 via x402. This page is free. The verdict is the worst agent in the fleet: FREEZE PAUSED ADJUSTED CLEAR. One frozen agent freezes the verdict even if every other desk is fine. A rule that forbids a deployment is refused here, not flagged after the fill.
The decision in one picture
market_state + agents + rules
|
v
severity order: FREEZE, then PAUSE, then CAP
|
v
each agent, first match of that action
|
+-- freeze matches ----------> FROZEN allowed 0
+-- else pause matches ------> PAUSED allowed 0
+-- else one or more caps ---> CAPPED tightest cap_pct of mandate
+-- else --------------------> CLEAR min(request, mandate)
|
v
fleet verdict = worst agent
FREEZE > PAUSED > ADJUSTED > CLEAR
Input example
{
"market_state": {
"volatility_pct": 42,
"liquidity_pct": 55
},
"agents": [
{
"id": "desk-alpha",
"risk_tier": 5,
"mandate_usd": 100000,
"requested_usd": 80000
},
{
"id": "desk-beta",
"risk_tier": 2,
"mandate_usd": 50000,
"requested_usd": 20000
},
{
"id": "desk-gamma",
"risk_tier": 4,
"mandate_usd": 40000,
"requested_usd": 45000
}
]
}
On this example the verdict is PAUSED. Paused: desk-alpha, desk-gamma. Left clear: desk-beta. Allowed 20000 of 145000 requested. The 60 freeze line does not trip at 42, and the 15 cap matches the paused desks but does not reopen them.
curl -s -X POST https://agentpaystore.com/tgov/api/coordinate -H 'Content-Type: application/json' -d '{"market_state":{"volatility_pct":42,"liquidity_pct":55},"agents":[{"id":"desk-alpha","risk_tier":5,"mandate_usd":100000,"requested_usd":80000},{"id":"desk-beta","risk_tier":2,"mandate_usd":50000,"requested_usd":20000},{"id":"desk-gamma","risk_tier":4,"mandate_usd":40000,"requested_usd":45000}]}'
With no payment header that curl is HTTP 402 and the terms. A body that fails validation is a free 422 when a payment header is present. Garbage is not charged. Unknown JSON fields are ignored. A misspelled required field is a validation error.
How it works
- Market state carries volatility_pct from 0 to 100, and optionally liquidity_pct on the same scale. Each agent has a unique id, a risk tier from 1 (safest) to 5, a mandate above zero, and a request of zero or more.
- Rules are optional. Leave them out, or send an empty list, and the default pack is used. It is flagged default_pack true on every rule in the response. v15-cap-high: volatility above 15, cap 50% of mandate, tiers 4 and 5. v30-pause-high: volatility above 30, pause, tiers 4 and 5. v60-freeze-all: volatility above 60, freeze, every tier.
- Above means strictly greater than the threshold. Below means strictly less. A reading sitting exactly on the line does not trip the rule. Tiers are the other way around: a rule applies when the agent's tier is greater than or equal to applies_to_tiers_at_or_above. That field defaults to 4.
- Rules are sorted freeze, then pause, then cap. Inside one action the order you sent is kept. The first matching freeze decides a freeze. The first matching pause decides a pause. Several matching caps keep only the smallest cap percent. They do not multiply. A harsher state is never reopened by a milder one.
- Allowed capital starts at the request, clipped to the mandate. Frozen and paused agents get 0. A capped agent gets the minimum of that amount and the binding cap percent of the mandate. ADJUSTED means somebody was cut below what they asked, and nobody was frozen or paused. CLEAR means every request survived intact. Unused mandate is not given to another agent.
- The audit log has one row per rule that matched an in-scope agent, then one row per agent, then the verdict. Rule rows follow severity and then your order. Agent rows follow your order. Every row in one decision shares one UTC timestamp.
Honest assumptions
- This is a governance screen, not an oracle — outputs are the engine enforcing the rules you gave it, nothing more.
- Rule violation rate is zero by construction because TGOV refuses what the rules forbid rather than flagging it after the fact.
- The latency win comes from refusing instantly at decision time instead of reconciling breaches later.
TGOV will not tell you the volatility is right, that a tier is the right tier, or that a desk can use the capital it is allowed. It will not reallocate a paused desk's mandate to a quieter one. It will not search for a portfolio. Same inputs, same decision. The only field that moves between identical calls is the audit clock.
Try it
The TRY IT form builds the JSON body in the browser and shows the exact curl for it. Run from this page posts that body. A browser on agentpaystore.com is on the gate allow-list and is not charged. The curl, sent with no payment header, returns 402.