On this page
Coordinate agents, businesses, and decisions.

A funded ceiling for autonomous work

Paxeer X budgets give an owner a bounded way to fund delegated work. A budget binds an account, asset, purpose, funding amount, period allowance and expiry. Delegates receive spending authority within that ceiling. The owner can change policy, remove delegates or close the budget as the assignment changes.

A budget is a funded ceiling over spending. Account balances, capability permissions, approval holds and budget allowances remain distinct controls. An agent must satisfy every applicable control before its action proceeds.

Choose the enforcement boundary

ControlEnforcementUse
ProtocolBudgetNative protocol validation.Funded spending ceilings and delegated authority checked during execution.
DaemonLimitThe agent daemon.Local automation limits for activity routed through that daemon.
CapabilityScoped agent authorization.Activity, asset, counterparty, amount, rate, purpose and expiry restrictions.
Approval holdThe daemon preparation workflow.Human review of a particular disclosed activity before release.

Route all relevant traffic through the daemon when relying on a daemon limit or approval hold: bypassing that daemon bypasses those controls. Approval releases a prepared action and grants no additional protocol authority.

Configure a budget

FieldMeaning
budget_id, budget_account32-byte budget identity and account binding.
asset_id, purpose_hashThe funded asset and committed purpose reference.
amountInitial funding amount.
per_period_limitMaximum permitted spend in a budget period.
period_length, period_startPeriod duration and initial period boundary.
rollover_policy, carry_capNo rollover, or capped carry-forward of allowance.
expiry, revocation_sequenceLifetime and revocation generation.
source_account, source_sequenceVersion 2 funding source and its replay-protected debit sequence.

Amounts and limits use unsigned 128-bit values at the protocol boundary. Agent API amounts, sequences, limits and timestamps travel as decimal strings, preserving exact values across clients. Native budgets support up to 16 delegates. The rollover constants are LX_BUDGET_ROLLOVER_NONE = 1 and LX_BUDGET_ROLLOVER_CAPPED = 2.

Example policy

Consider a procurement agent with 1,000 asset units funded, a 200-unit period ceiling, no rollover and a fixed expiry. A 60-unit purchase consumes both funding and current-period allowance. Adding funding increases available funds; it does not remove the period ceiling. A second delegate shares the budget ceiling rather than receiving an independent copy of it.

Choose asset-unit scaling before encoding values. With six decimal places, 60 units encodes as 60000000. The example describes policy values; obtain the asset precision from its registered metadata.

Native budget activities

Budget is module 3. Its activity types occupy 0x0003xxxx. Canonical payloads begin with a big-endian two-byte version prefix.

ActivityTypePurpose
LX_BUDGET_CREATE0x00030001Create a funded budget and its period policy.
LX_BUDGET_FUND0x00030002Add funds, preserving policy limits.
LX_BUDGET_AMEND0x00030003Amend period limit, carry cap, expiry and rollover.
LX_BUDGET_DELEGATE_ADD0x00030004Add a permitted delegate.
LX_BUDGET_DELEGATE_REMOVE0x00030005Remove a delegate.
LX_BUDGET_SPEND0x00030006Transfer the specified amount to a recipient within the budget.
LX_BUDGET_CLOSE0x00030007Close using the required revocation sequence.

Canonical spend payload

version:u16be = 1
budget_id:bytes32
recipient:bytes32
amount:u128be

Total: 82 bytes

Create supports version 1 at 211 bytes and version 2 at 251 bytes. Fund supports version 1 at 50 bytes and version 2 at 58 bytes. Version 2 create appends the source account and source sequence; version 2 fund appends the source sequence. Period maintenance uses the protocol batch timestamp to roll due periods.

Agent API workflow

  1. Use budget.create with the intended enforcement mode and establish the permitted agent capability.
  2. Use budget.fund to allocate funds; inspect budget.list and budget.reconciliation before scheduling new spending.
  3. Prepare the action with actor, authority, account sequence, timestamp bound, idempotency key, fee limit, payload and payload hash.
  4. Review the returned disclosure, then sign and submit the exact preparation.
  5. Track the submission and reconcile its verified receipt with the budget and account state.
  6. Use budget.revoke and capability revocation when the assignment ends.

Protocol spending uses the native budget activity and protocol validation. Daemon budget objects carry their enforcement mode explicitly. Keep receipt evidence attached to reconciled spending so local scheduling decisions follow committed results.

Approve the exact action

An approval record contains approval_id, tenant, the held structured activity disclosure, canonical bytes digest, hold reason, creation time, expiry and state. Review actor, authority, counterparties, amounts, asset, fee limit, expiry and idempotency key alongside the canonical digest.

OperationBehavior
approval.listFind approval records in the authorized scope.
approval.getInspect one held action and its disclosure.
approval.approveRelease the exact preparation bound to the reviewed digest.
approval.rejectReject the held action.

Decision operations carry an idempotency_key. Approval states are Held, Granted, Rejected, Expired and Defective; all except Held are terminal. A modified activity requires its own preparation and review. Approval does not override a missing delegate grant, expired capability or exhausted budget.

Reconcile before retrying

A submission progresses through Prepared, Signed, Queued, Submitted and Acknowledged before its final result. Unknown is a pending state requiring reconciliation. An Executed result carries a receipt reference and Paxeer settlement domain. Use track or wait to inspect evidence and the actual verification level before making a new economic attempt.

Common refusals

RefusalResponse
LXP_ERR_BUDGET_PERIOD_CAP, LXP_ERR_BUDGET_ALLOWANCE_EXCEEDEDInspect period policy and remaining allowance; amend only with owner authority.
LXP_ERR_INSUFFICIENT_BUDGET_FUNDSReconcile funds and fund the budget if appropriate.
LXP_ERR_UNAUTHORIZED_DELEGATE, LXP_ERR_UNAUTHORIZED_DEBITCheck delegate, owner and funding-source bindings.
LXP_ERR_BUDGET_REVOKED, LXP_ERR_EXPIREDStop spending under that authority.
LXP_ERR_STALE_REVOCATION, LXP_ERR_SEQUENCE_REUSED, LXP_ERR_SEQUENCE_GAPRefresh verified revocation and sequence state before preparing again.
Technical references: include/layerx/lx_budget.h; src/modules/budget/; agent/schema/agent-api/ budget, write, identity and approval contracts.

See identity and delegated credentials for owner authority, session revocation and recovery.

Paxeer X · System documentationBack to top ↑

Ask Paxeer X Docs

Answers from the documentation.

What would you like to know?

Ask a question, find a guide, or get help with your next step.

Enter to send · Shift+Enter for a new line