Delegated Treasury
Issue agent spend authority as an on-chain spend-control attestation rather than a soft prompt, so spending limits are verifiable on the other side and you can safely delegate payments to the agent.
For finance and governance teams
Prove an agent stayed within authority even when prompt injection hits — replacing soft prompt-based spend caps with a cryptographic attestation.
-
CFOs, treasurers, and controllers at enterprises rolling out AI agents
-
Heads of SaaS procurement and purchasing ops who have agents in the loop
-
Audit and compliance teams building agent-spend trails under SOX, J-SOX, and equivalent internal-control regimes
Hand over the source, or just the facts?
Nothing changes on the floor. Everything changes for the receiver.
① Your team just saves, as always.
- The usual step
- Fill in the record and save
- On save
- A proof is attached (API, behind the scenes)
- The document itself
- never sent
② They just open a link.
- Proven fact
- the spend happened inside authorized controls
- the treasury's internal rules
- not shown
- Login / keys
- not needed
- The document stays private — the record itself is never sent or disclosed.
- Independent verification — the receiver just opens a link. No account, no keys.
- Edits are detected — even a one-character edit fails verification.
Lemma issues the spend authority you delegate to an AI agent as an on-chain spend-control attestation — not as a soft prompt. Each attestation carries, signed by the issuing organization, the spend limit, the eligible category scope, the validity window, and a revocation endpoint.
Counterparties — sellers, payment facilitators — verify the attestation independently before accepting payment. No platform trust required. Because it crosses as a ZK proof, only the constraint conditions cross to the verifier; your internal budget structure and approval policy stay inside. At audit, every transaction is paired with cryptographic evidence of the delegation that authorized it.
Where the spend-control attestation slots into your AI agent operations and treasury controls is what we map out in a first conversation.
Why the usual methods fall short.
Only work that needs all three at once — pass without exposing, independent verification, tamper-evidence — is Lemma's domain.
| Method | Pass without exposing | Independent verification | Tamper-evident | What happens |
|---|---|---|---|---|
| Access control / permissions | △ | ✗ | ✗ | “Someone inside could have edited it” remains possible |
| Masking / redacted copies | △ | ✗ | ✗ | Redaction work grows; the original is still unproven |
| Encrypt and store / send | ✓ | ✗ | ✗ | To verify, the receiver needs it disclosed after all |
| Lemma (ZK proof)the only one with all 3 | ✓ | ✓ | ✓ | The receiver just opens a link |
How it works — and how to start.
We help design disclosure scope and retention, run the PoC, and support production.
Start with a 30-minute call.
Tell us one workflow where you want to delegate spend to an agent but cannot prove it, in the first 30 minutes. No disclosure of internal budget structure or approval policy required.
Related Use Cases
Find the case that matches your industry and problem
Browse all 36 use cases →TRY LEMMA
Run it yourself.
No sales call needed — start hands-on with Lemma's products.