runs in your browser · pure functionmeasure, never moveApache-2.0 · zero-dep

Can the agent sign for this?

A System of Record (SAP, Oracle, a custom ERP) holds the signing limits; EcoCloud is the System of Action that an agent operates through. Before an agent commits a value-bearing mutation, this kernel measures the amount against policy and returns allow, escrow (trip the circuit breaker, hand to a human — do not execute), or deny. EcoCloud never moves money or runs the transaction — it governs whether the agent may proceed. Vendor-neutral: the value can be an SAP PO, an invoice, or a refund.

Proposed action & policykernel source →
per-action ceiling
actor's own cap (tighter wins)
aggregate for the period
already spent this period
Verdict (live)

Honest scope. This is a deterministic, signable governance primitive in the same family as the consensus and reputation kernels — same verdict in browser, edge, and Node. escrow means "route to a human approval gate," never "pay" — EcoCloud has no money-movement path and this kernel adds none. It is the value-threshold complement to EcoCloud's existing count/confidence-based conditional delegation gates. Not yet wired into live task execution: EcoCloud tasks don't carry transaction values today — feeding this real amounts needs a System-of-Record connector (the next step). Whether SAP exposes its objects over MCP / OData / RFC is a property of your SAP landscape, not something this kernel assumes. Source: flowdesk-escrow-kernel.js.