Assemble the cart, present a per-order authorisation carrying the all-in total and the limits the shopper set, and place nothing until the shopper has authorised that exact order.
Gather candidate products, live prices and merchant terms from supported commerce and agent-protocol sources.
02
Rank the candidates, and mark which merchants permit automated purchasing at all.
Reason
03
Price the all-in total — item, shipping, tax and every mandatory fee — before anything is shown.
04
Draw the mandate the shopper set: scope, price ceiling, category limits, ship-to and expiry.
05
Bind the cart to that mandate, and mark where the cart falls outside it.
Decide
06
Name any commercial relationship that influenced the selection.
07
Present the order to the shopper for a per-order authorisation, and wait there.
Out
08
Keep the mandate, the cart, the totals and the authorisation against the order.
09
Execute write actions only inside the approval boundaries agreed during implementation.
→Product statement
The agent proposes the order; the shopper authorises it — and whether a wrong purchase counts as unauthorised is unsettled, which is why the authorisation record matters.
Example workflow
One order, intent to authorisation
AgentHuman
1Shopping intent receivedA stated request, a reorder, or a standing shopping list
2Mandate assembledProducts, live prices, merchant terms, agent permissions and an all-in total for each
3Cart built and heldThe exact item, quantity, merchant, all-in total, ship-to, tender and confidence
4Mandate checks runMandate checks, ceiling and expiry checks, merchant-permission checks and confidence threshold
No human action required
Stages 1 to 4 run unaided and no order exists yet — the cart sits un-submitted, and the shopper's lane opens at the confidence gate.
5DecisionSplits on the mandate limit
Inside the mandate
Goes to the shopper to authorise.
Outside the mandate
Adds a mandate re-check first.
Shopper authorisation
The cart is held with its mandate, its all-in total and the protections disclosure.
Authorise · Amend · Cancel
Authorised — order placed▼
6Merchant accepts or declinesThe merchant stays the seller of record throughout
7Order evaluatedMandate conformance, total drift, cancellation-window use and orders the shopper later disowned
Cancellations
Every amendment the shopper makes is counted in the evaluation.
What should not run autonomously
Human approval stays in control
Outside the boundary — human approval required8 items
Buying age-restricted, prescription or otherwise regulated goods.
Accepting merchant terms, arbitration clauses or warranty disclaimers.
Enrolling in a subscription, auto-renewal or free-to-pay conversion.
Buying where the merchant's terms bar agents, or access was revoked.
Automation boundaryAgent acts unaided
✓Search, compare and rank candidates with each all-in total itemised.
✓Build a cart and hold it un-submitted at a merchant.
✓Present the authorisation record.
✓Cancel an in-flight order and revoke the delegated token behind it.
Any write happens inside the boundaries agreed at implementation, never ahead of the shopper's authorisation.
Disguising the agent, spoofing a session or passing a bot control.
Shipping to an unverified address, or using a new payment instrument.
Exceeding the per-order maximum charge, or the authorisation's expiry.
Filing or arguing a bank or card dispute on the shopper's behalf.
Example output
One authorisation record, annotated
What the shopper authorises is the exact order the agent is permitted to place.
Authorisation record · single orderIllustrative example
Order
What will be bought
Total shown
Mandate
Confidence
Protections
Reorder, same item
One unit of the exact item bought before, from the same merchant
Item, shipping, tax
Per-order, with expiry
88%
Caps may not apply
As receivedTaken from the merchant's live listing and the shopper's own mandate — nothing on this side is assumed.
Mandate terms usedMaximum charge amountMerchant and category limitsVerified ship-to address
Why this disclosureThe shopper authorised the agent and a person still decides.
ActionAuthoriseAmendCancel
What the score decidesBelow the configured threshold the cart is re-checked against the mandate.
Value
Where AI adds value
The same four claims, placed at the point in the workflow where each one applies.
Where the value landsValue 01 – 04
Every orderFrom the shopper's mandate
03Assembly
Build against the mandate
Work inside the scope, the ceiling, the category limits and the expiry the shopper set.
01Approved path
Buy only what was authorised
Reorders and tightly stated intents arrive as a cart ready to authorise.
02Human review
Stop where the mandate runs out
Anything past the scope, the ceiling or the merchant's own agent terms stops and waits for the shopper.
04Build an evidence trail
The mandate, the cart and the authorisation stay attached to the order.
Integrations
Typical integrations
Five system groups connect to the same agent. Which of them are in scope is decided in discovery.
Agent-commerce protocolsAgentic Commerce Protocol Visa Trusted Agent Protocol
Unintended purchases are counted per order and read as a lift on the all-order baseline. Funding type Nestack reports it by slice rather than in aggregate The cohorts that carry it are named, not averaged away..
Slice performance — reported separately, not only in aggregateIllustrative example
Slice
Failure rate
Lift
Lift vs. threshold
Status
Debit, anti-agent terms, final sale
9.0%
2.9×
Review
Open-ended comparison intents
6.8%
2.2×
Review
Credit, protocol-integrated
5.6%
1.8×
Watch
Reorder under a per-order mandate
2.8%
0.9×
Normal
Bar: unintended-purchase lift vs. the all-order baseline · scale 0–4.0× · tick marks the 2.0× review threshold2 of 4 slices over threshold
Evidence-linked improvement
No cycle here closes on agreement
The cycle closes on a test, not a write-up — one the next release has to pass That suite is what the following detection is measured against..
Improvement cycle · five stagesSwitchback — the path turns at Improve and returns at Learn
01Detect
Disowned orders cluster in one intent type.
02Diagnose
The authorisation records are replayed against the carts until one cause is left.
03Improve
The change is stamped to a version, with the orders that produced it attached.
04Verify
Re-run the affected cases; a fail holds the release.
05Learn
A standing test, plus a change to the authorisation rules.
Learn → DetectThe return edge. Each detection meets more standing cases than the one before.
Typical build scope
Twelve workstreams across six weeks
The build scope read against the delivery timeline. Week structure follows the six-week plan — discovery, sources, cart workflow, evaluation, integration, then production validation and handover.
WorkstreamWeek 1Week 2Week 3Week 4Week 5Week 6
01Purchasing workflow discovery and boundary definition.
02Merchant and payment-source assessment.
03Mandate, ceiling and merchant-terms mapping.
04Catalogue and price ingestion with all-in totals.
05Cart assembly and mandate binding.
06Confidence scoring and authorisation routing.
07Shopper authorisation workflow.
08Wallet, token and merchant integration.
09Mandate regression cases.
10Guardrails and spend controls.
11Mandate-trail instrumentation.
12Deployment, documentation and Agent Care handover.
12 workstreams · 6 weeks · bar shows the weeks a workstream is active — several run in parallelFinal scope and sequence confirmed in discovery
Engagement tiers
What each tier includes
Rows are the capabilities named in each tier's scope. Higher tiers include everything below them.
Capability✓ in scope · — not at this tierPilotOne merchant, one mandateProductionProduction order volumeAdvancedMultiple merchants / tenders
Introduced at Pilot
Carts built to your mandate✓✓✓
Shopper authorisation✓✓✓
Mandate-conformance baseline✓✓✓
Introduced at Production
Reporting by merchant—✓✓
Authorisation workflow in your app—✓✓
Approved order placement—✓✓
Wallet and network integration—✓✓
Introduced at Advanced
Multi-merchant mandate sets——✓
Multi-party authorisation——✓
High order volume——✓
Enterprise mandate controls——✓
Build priceFrom $5,000From $8,000Custom quote
Final build priceConfirmed after discovery based on integrations, workflow complexity, transaction volume, approval controls and deployment requirements.
Separate from buildBuild pricing is separate from recurring Agent Care, which covers managed monitoring, evaluations, incidents and verified improvements after launch.
What we need from you
What you bring, and what we build with it
Each input maps to a piece of build scope and a week in the delivery timeline.
You bringWe build with it
01The merchants you buy from and their agent terms→Merchant-terms and agent-permission mappingWeek 1
02Representative past orders→Cart-assembly baseline, ranking and all-in totalsWeek 2
03Your ceilings, category limits and ship-to list→Mandate and ceiling mapping, and the automation boundaryWeek 1
04Access to relevant APIs, feeds or exports→Merchant, protocol and payment assessment, then integration setupWeek 2
05Orders the shopper did not want→Mandate cases and the evaluation suiteWeek 4
06The mandate limits the shopper actually set→Mandate limits, spend routing and authorisation controlsWeek 3
07The shopper's own authorisation record→Shopper authorisation workflow, then pilot and production validationWeeks 5–6
Nothing else is requiredDeployment, documentation and Agent Care handover are ours.
Delivery timeline
Four phases across six weeks
Each band spans the weeks its work is named in, and week 5 carries two because both genuinely run.
PhaseW1W2W3W4W5W6
DiscoveryW1
BuildW2 – W3
EvaluateW4 – W5
Pilot & LaunchW5 – W6
Week focusW1Purchasing workflow discovery, mandate mapping and the automation boundaryW2Merchant and wallet connections establishedW3Mandate binding, confidence logic and authorisation controlsW4Mandate cases and spend guardrailsW5Token and wallet integration, pilot orders and targeted correctionsW6One mandate run end to end under the shopper's authorisation
Reading the bandNo week is padded. The fifth carries evaluation and pilot together.
At the end of W6Hand-over happens against a verified mandate run, not a demo.
DurationSix-week plan shown · typical delivery 4–6 weeks depending on scope confirmed in discovery.
Next step · Retail AI agent
Build a buy-for-me agent around a mandate you can produce later.
Show us what your shoppers ask for, which merchants you buy from and the limits they set. Nobody has yet decided whether a wrong purchase is unauthorised, so we build the record that will have to answer for it.