Your agent spends only what your policy signs off on.
Countersign makes each agent wallet a 2-of-3 multisig shared by the agent, its owner and a rotating committee of staked nodes, and the nodes sign only what the owner's published spend policy allows.
- Signers
- Agent, owner, committee
- Needed
- Any two of three
- Rules checked
- Five, in order
Co-sign ledger
Epoch 0reading ledger
checking rule 1 of 5
The ledger did not load
One vendor key stands behind every agent wallet
Agent platforms give their agents spending power through one embedded-wallet provider. That provider holds delegated signing rights over thousands of user wallets, and it signs whatever the platform's agent sends it.
So one bug, one leaked key or one prompt-injected agent can drain every wallet at once. The owners have no independent check. The only limits are the ones the platform and its vendor choose to enforce.
Every payment needs two of three signatures
The agent, the owner and a committee of Countersign nodes each hold one key. The agent can start a payment. It can never finish one alone.
-
The agent proposes
The agent builds a transaction and signs it with its own key. That is one signature of the three.
-
Nodes check the owner's policy
This epoch's three committee nodes run five rules in order: per-transaction cap, allowed programs, allowed tokens, slippage against the oracle price, and the daily spending limit.
-
Two of three sign
If every rule passes, the committee adds its signature and the payment goes out. If one fails, the nodes refuse and record the rule that decided it.
The policy belongs to the owner
The owner publishes the policy. Each version gets a hash, and the nodes check every transaction against that exact version.
The owner can tighten the limits or revoke the agent from any wallet, without asking the platform. Platforms plug in through an SDK that replaces their signer-delegation call with one line.
Published policy
v0reading policy
verifying policy hash
No policy published for this wallet
Publish one from the policy editor and the nodes start checking against it.
Open the policy editorThe policy did not load
signed by its owner,
- Per-transaction cap
- Daily spending limit
- Max slippage vs oracle
- Allowed programs
- Allowed tokens
Send three requests as Atlas Trader's agent
Each button runs the same policy check the app uses. Watch the rules resolve, then find the verdict in the co-sign ledger at the top of this page and on the Wallets page.
Wallet
Active Revokedreading wallet
loading policy
Atlas Trader is not in this ledger
Reset the sample data to bring the wallet back.
The wallet did not load
The owner revoked this agent. The committee refuses every request until the owner restores it.
- Per-transaction cap
- Max slippage vs oracle
- Allowed programs
- Policy version
Agent request
Committee verdictreading Atlas Trader policy
checking rule 1 of 5
No request sent yet
Pick one of the three requests. The committee checks five rules in order, and the first rule that fails decides.
The request did not go through
Stake is the collateral behind every signature
Node operators stake CSIGN to join signing committees. Each epoch, three staked nodes hold the seats and earn a fee for every signature, paid by the platform.
If a node signs a transaction that broke the published policy, the policy hash and the transaction prove it on-chain. The network slashes 20% of that node's stake and repays the owner from it.
A plain payment can't do this. A permissionless network needs collateral it can seize.
- Staked across all nodes
- 0 CSIGN
- Nodes able to take a seat
- 0 of 0
- Committee this epoch
- Minimum stake for a seat
- CSIGN
Stake by node
Stake as a nodereading stake ledger
ranking nodes
No node holds a stake
Stake at least the minimum to take the first committee seat.
Open the stake formThe stake ledger did not load
Teal bars hold a committee seat this epoch. Grey bars wait for their turn in the rotation. The dashed line is the minimum stake.
Sign past a published policy and lose of your stake. The owner is repaid from it. Run the slash on Nodes
signed against 's cap, lost CSIGN of stake, and the owner got back .
Single-vendor delegation next to Countersign
What changes for an agent app that swaps its vendor signer for a co-signing committee. Open a row for the mechanism behind it.
| Question | Single-vendor delegation | Countersign on agent apps |
|---|---|---|
| Who can sign for the agent | One custodial key at the wallet vendor signs for every agent on the platform. | Any two of three keys: the agent, the owner, and this epoch's committee of three staked nodes. |
The agent still proposes every transaction with its own key. A transaction needs a second signature, and the committee only gives one after the five rule checks pass. The owner's key stays with the owner for changes and recovery. | ||
| What a leaked platform key can do | Sign anything from every wallet until someone notices. | Propose transactions. The committee refuses each one that breaks the owner's policy. |
A leaked key only replaces the agent's signature. Caps, allowed programs, allowed tokens, slippage and the daily limit still apply, so the most an attacker can move is what the policy already allowed that day. The Platforms page replays this attack on every wallet with both models side by side. | ||
| Who can change the limits | The platform and its vendor, in their own dashboards. | Only the owner. Every change is a new policy version with its own hash. |
No single company can loosen a limit, the app itself included. Nodes check each transaction against the hash of the latest version the owner published, so an edit nobody published does nothing. | ||
| Stopping a rogue agent | File a request with the platform and wait. | The owner revokes the agent from any wallet. The committee stops signing at once. |
Revoking is an owner action, so it works even when the platform is down or is the problem. Every later request from the agent comes back refused with the reason "agent revoked". | ||
| Moving the agent to another app | Start over with the new app's vendor and the new app's limits. | The policy stays with the wallet. Same version, same limits, no re-approval. |
Moving swaps which platform holds the agent's signing right. The policy, its version and its hash do not change, and the committee keeps checking the same rules on the new platform. | ||
| When a signer breaks the rules | The owner's word against the vendor's logs. | The breach is provable on-chain. The node loses 20% of its stake and the owner is repaid. |
The signed transaction and the policy hash it was checked against sit on-chain together, so anyone can show the rule it broke. The slashed stake repays the owner first. The Nodes page runs this end to end. | ||
Set a limit, then try to break it
The app opens on six agent wallets you own. Tighten a policy, send a payment as the agent, and watch the committee sign or refuse.