On-chain, the mistake is final.
No chargeback, no reversal, nobody to call. A control that runs after the transfer is a report. Digital assets and crypto get the widest pack we ship: the eight rule areas below.
What is in the pack
| Rule | What it stops |
|---|---|
| Sanctions screening | a transfer to a listed address, against the lists you subscribe to |
| KYC tiers | a wallet doing more than its verification level allows |
| Daily volume caps and cooldown | a wallet drained by many small transfers, each under the single-transfer limit, with a 24-hour cooldown after a breach |
| First-time destination | the first send to an address nobody has seen, held for review |
| New-wallet drain | a freshly created wallet emptying itself |
| Bridge whitelist and token security | funds leaving through a bridge you never approved |
| Geo restriction | activity from a jurisdiction you do not serve |
| Recovery | the flow attackers actually target, because it is designed to work when the user has lost everything |
These are declarations you read and edit. Change a tier limit and it goes through candidate, backtest and promote like any other rule.
When an agent is the one signing
The signed transaction reaches your node through a gateway. It decodes the asset, the recipient and the amount out of the signed bytes and decides before the transaction reaches the network. Your signing key stays where you keep it.
An agent moves faster than a person, acts on text it read somewhere, and will repeat the same wrong thing until something stops it. Two controls matter more than the rest.
Authorization, including the case where each action is permitted and the sequence is not. And a counter with a stop, because the loop is what turns one bad decision into an incident.
The instruction can also arrive inside the data. Injection detection reads what came in and what a tool sent back, because a tool's answer can carry an instruction of its own.
This one has been done
Sanctions and KYC screening, transaction caps with state, human review and the audit trail have run embedded in another product, under that product's brand, on its own infrastructure: the case.