{"id":"https://mandateshield.com/evidence/v1/control-matrix.json","canonical":"https://mandateshield.com/evidence/payment-authority-control-matrix","version":"1.0.0","standard_version":"2.1.0","reviewed_on":"2026-07-24","title":"AI Payment Authority Control Matrix","description":"Machine-readable evidence map for MandateShield deterministic, advisory and external AI-agent payment-authority controls.","status":"vendor-published-evidence-map","certification":false,"deployment_attestation":false,"methodology":{"review_date":"2026-07-24","evidence_policy":"Claims are mapped to public product contracts, current vendor-profile conformance vectors and primary official protocol sources. A vector is cited only when its current canonical ID directly exercises the stated behavior.","classification_rules":{"deterministic":"A normalized fact, cryptographic binding or durable state transition produces a reproducible fail-closed outcome.","advisory":"A contextual or heuristic signal may require REVIEW but is not proof of compromise and cannot create authority.","external":"The control is a required integration responsibility outside the boundary MandateShield can enforce."},"claim_boundary":"This is a vendor-published evidence map, not independent certification, a deployment attestation or proof of payment settlement."},"sources":[{"id":"mandateshield-standard","title":"Mandate Execution Boundary Specification v2.1.0","publisher":"MandateShield","url":"https://mandateshield.com/standard","kind":"product-contract"},{"id":"mandateshield-security","title":"MandateShield security architecture","publisher":"MandateShield","url":"https://mandateshield.com/security","kind":"product-contract"},{"id":"mandateshield-methodology","title":"MandateShield methodology and evidence","publisher":"MandateShield","url":"https://mandateshield.com/methodology","kind":"product-contract"},{"id":"mandateshield-conformance","title":"MandateShield Conformance Profile v1","publisher":"MandateShield","url":"https://mandateshield.com/conformance/v1/vectors.json","kind":"test-profile"},{"id":"mandateshield-openapi","title":"MandateShield OpenAPI contract","publisher":"MandateShield","url":"https://mandateshield.com/openapi.json","kind":"product-contract"},{"id":"ap2","title":"Agent Payments Protocol specification","publisher":"Agent Payments Protocol","url":"https://ap2-protocol.org/ap2/specification/","kind":"official-specification"},{"id":"ucp","title":"Universal Commerce Protocol official specification","publisher":"Universal Commerce Protocol","url":"https://ucp.dev/2026-04-08/specification/overview/","kind":"official-specification"},{"id":"tap","title":"Trusted Agent Protocol specifications","publisher":"Visa","url":"https://developer.visa.com/capabilities/trusted-agent-protocol/trusted-agent-protocol-specifications/","kind":"official-specification"},{"id":"x402","title":"x402 documentation","publisher":"Coinbase Developer Platform","url":"https://docs.cdp.coinbase.com/x402/welcome","kind":"official-specification"},{"id":"acp","title":"Agentic Commerce Protocol documentation","publisher":"Stripe","url":"https://docs.stripe.com/agentic-commerce/protocol","kind":"official-specification"},{"id":"mpp","title":"Machine Payments Protocol","publisher":"Tempo and Stripe","url":"https://mpp.dev/","kind":"official-specification"},{"id":"rfc7515","title":"RFC 7515: JSON Web Signature","publisher":"RFC Editor","url":"https://www.rfc-editor.org/rfc/rfc7515","kind":"official-specification"},{"id":"rfc7638","title":"RFC 7638: JSON Web Key Thumbprint","publisher":"RFC Editor","url":"https://www.rfc-editor.org/rfc/rfc7638","kind":"official-specification"},{"id":"rfc9421","title":"RFC 9421: HTTP Message Signatures","publisher":"RFC Editor","url":"https://www.rfc-editor.org/rfc/rfc9421","kind":"official-specification"},{"id":"rfc9901","title":"RFC 9901: Selective Disclosure for JWTs","publisher":"RFC Editor","url":"https://www.rfc-editor.org/rfc/rfc9901","kind":"official-specification"}],"controls":[{"id":"registered-mandate","name":"Registered mandate authority","classification":"deterministic","outcome":"BLOCK","summary":"Live verification loads immutable account-registered limits instead of trusting policy supplied by the agent.","production_behavior":"Strict v2 withholds an executable reservation when no matching active registered mandate exists.","reason_codes":["REGISTERED_MANDATE_REQUIRED"],"conformance_vector_ids":[],"evidence_basis":"The production invariant and public API contract require an active mandate version before authority can be established.","limitations":["The customer remains responsible for obtaining lawful user authority and registering the correct mandate.","Registration does not establish payment credential validity or settlement."],"source_ids":["mandateshield-standard","mandateshield-security","mandateshield-openapi"]},{"id":"exact-fiat-amount","name":"Exact fiat amount representation","classification":"deterministic","outcome":"BLOCK","summary":"Currency-aware integer minor units prevent silent rounding and contradictory major/minor representations.","production_behavior":"Malformed, non-representable or conflicting fiat amounts fail closed before an execution reservation can be created.","reason_codes":["INVALID_AMOUNT","AMOUNT_PRECISION_INVALID"],"conformance_vector_ids":["fiat-usd-exact-minor-units","fiat-conflicting-minor-units","fiat-jpy-fractional-major-unit"],"evidence_basis":"Executable offline vectors exercise valid USD cents, contradictory representations and a fractional zero-decimal currency.","limitations":["Currency exponent handling does not perform foreign-exchange conversion.","Taxes, fees and shipping must already be reflected in the normalized final amount."],"source_ids":["mandateshield-conformance","mandateshield-standard"]},{"id":"fiat-scope","name":"Fiat amount, currency and merchant scope","classification":"deterministic","outcome":"BLOCK","summary":"The final amount, ISO currency and stable merchant identifier must remain inside the registered mandate.","production_behavior":"A missing ceiling or scope, overspend, currency switch or merchant substitution blocks the request.","reason_codes":["MISSING_SPEND_CAP","SPEND_CAP_EXCEEDED","NO_CURRENCY_SCOPE","CURRENCY_OUT_OF_SCOPE","NO_MERCHANT_SCOPE","MERCHANT_OUT_OF_SCOPE"],"conformance_vector_ids":[],"evidence_basis":"These are deterministic policy branches in the published reason-code and execution-boundary contracts.","limitations":["Merchant identifiers must be normalized consistently by the integrator.","This control does not verify merchant solvency, sanctions status or fulfillment."],"source_ids":["mandateshield-standard","mandateshield-security","mandateshield-openapi"]},{"id":"atomic-asset-scope","name":"Exact atomic-asset scope","classification":"deterministic","outcome":"BLOCK","summary":"Atomic units, decimal exponent, asset, network and paid resource are compared exactly.","production_behavior":"One unit above the cap or a substituted asset, network, exponent or resource fails closed.","reason_codes":["INVALID_ATOMIC_AMOUNT","MISSING_ATOMIC_SPEND_CAP","ATOMIC_DECIMALS_MISMATCH","ATOMIC_SPEND_CAP_EXCEEDED","ASSET_OUT_OF_SCOPE","NETWORK_OUT_OF_SCOPE","RESOURCE_OUT_OF_SCOPE"],"conformance_vector_ids":["x402-exact-beyond-safe-integer","x402-one-unit-over-cap","x402-resource-substitution"],"evidence_basis":"Executable vectors distinguish adjacent integers beyond JavaScript Number precision and reject resource substitution.","limitations":["MandateShield does not parse an HTTP 402 challenge, construct a payment credential or call a facilitator.","Asset and network identifiers must be normalized by the integration."],"source_ids":["mandateshield-conformance","mandateshield-standard","x402"]},{"id":"consent-and-expiry","name":"Consent and authority expiry","classification":"deterministic","outcome":"BLOCK","summary":"Explicit consent and a finite, current authority window are required for production.","production_behavior":"Missing consent, missing expiry or expired authority blocks; an overly long analysis window can produce REVIEW.","reason_codes":["MISSING_EXPIRY","MANDATE_EXPIRED","CONSENT_NOT_PROVEN","LONG_EXPIRY_WINDOW"],"conformance_vector_ids":[],"evidence_basis":"Consent and expiry are explicit branches in the public decision contract; production signed evidence also requires freshness.","limitations":["The verifier checks recorded facts, not the quality of a user-interface consent flow.","Consumer-law disclosure and revocation processes remain the operator's responsibility."],"source_ids":["mandateshield-standard","mandateshield-security","mandateshield-methodology"]},{"id":"signature-and-key-trust","name":"Signature and account-pinned key trust","classification":"deterministic","outcome":"BLOCK","summary":"Signature math is combined with an account-pinned RFC 7638 thumbprint, issuer, audience and protocol match.","production_behavior":"Invalid signatures, unsafe keys, caller-selected trust or registered issuer/audience mismatches cannot establish execution authority.","reason_codes":["CRYPTOGRAPHIC_SIGNATURE_INVALID","CRYPTOGRAPHIC_KEY_UNSAFE","UNTRUSTED_VERIFICATION_KEY","TRUSTED_ISSUER_MISMATCH","TRUSTED_AUDIENCE_MISMATCH"],"conformance_vector_ids":[],"evidence_basis":"The strict execution invariant requires ACCOUNT_PINNED key trust in addition to valid supported signatures.","limitations":["The account operator is responsible for onboarding and rotating the correct issuer key.","The wider protocol trust registry is not replaced by a local key pin."],"source_ids":["mandateshield-standard","mandateshield-security","rfc7515","rfc7638"]},{"id":"signed-purchase-binding","name":"Signed final-purchase binding","classification":"deterministic","outcome":"BLOCK","summary":"Signed authority must bind the canonical final purchase digest or the required TAP content digest.","production_behavior":"Changing the merchant or another bound purchase fact after signing rejects the evidence.","reason_codes":["SIGNED_INPUT_BINDING_MISSING","SIGNED_INPUT_BINDING_MISMATCH","TAP_CONTENT_DIGEST_MISMATCH"],"conformance_vector_ids":["jws-final-envelope-substitution"],"evidence_basis":"The cryptographic integration vector preserves a valid JWS while substituting the evaluated merchant and expects rejection.","limitations":["Only facts included in the normalized envelope can be bound.","The integrator must ensure the envelope represents the final checkout rather than an earlier draft."],"source_ids":["mandateshield-conformance","mandateshield-standard","rfc7515","rfc9421"]},{"id":"challenge-and-freshness","name":"One-time challenge and signed freshness","classification":"deterministic","outcome":"BLOCK","summary":"Production evidence is bound to a server-issued, five-minute, consume-once challenge and signed time window.","production_behavior":"Missing, expired, future-dated or mismatched nonce and freshness evidence fails closed.","reason_codes":["CRYPTOGRAPHIC_EVIDENCE_EXPIRED","CRYPTOGRAPHIC_EVIDENCE_NOT_YET_VALID","CRYPTOGRAPHIC_EVIDENCE_FUTURE_IAT","PRODUCTION_EVIDENCE_FRESHNESS_REQUIRED","CRYPTOGRAPHIC_NONCE_MISMATCH","VERIFICATION_CHALLENGE_INVALID"],"conformance_vector_ids":[],"evidence_basis":"Challenge consumption and bounded signed freshness are normative strict-v2 requirements.","limitations":["Clock synchronization and correct challenge handling remain integration dependencies.","Fresh evidence does not by itself prove lawful authority."],"source_ids":["mandateshield-standard","mandateshield-security","mandateshield-openapi"]},{"id":"protocol-evidence-profiles","name":"AP2 and TAP evidence-profile checks","classification":"deterministic","outcome":"BLOCK","summary":"Supported AP2 SD-JWT+KB and normalized TAP HTTP-signature projections have protocol-specific binding requirements.","production_behavior":"Missing AP2 holder proof or omitted TAP signed components rejects the evidence.","reason_codes":["SD_JWT_KEY_BINDING_REQUIRED","AP2_PAYMENT_AMOUNT_MISMATCH","AP2_PAYEE_MISMATCH","AP2_TRANSACTION_BINDING_MISMATCH","TAP_REQUIRED_COMPONENT_NOT_SIGNED","TAP_AUTHORITY_MISMATCH","TAP_SIGNATURE_INVALID"],"conformance_vector_ids":["ap2-holder-proof-required","tap-required-component-omitted"],"evidence_basis":"Portable cryptographic integration vectors cover AP2 holder binding and TAP required signed components.","limitations":["Full AP2 checkout/delegate-chain and issuer-registry processing remains external.","Raw Visa structured-field and Visa trust-store processing remains external."],"source_ids":["mandateshield-conformance","ap2","tap","rfc9421","rfc9901"]},{"id":"replay-and-persistence","name":"Account-wide replay and persistence","classification":"deterministic","outcome":"BLOCK","summary":"A durable account-wide idempotency tombstone coordinates retries, concurrency and API-key rotation.","production_behavior":"Exact retries recover the committed result; conflicting or concurrent reuse fails closed.","reason_codes":["REPLAY_GUARD_MISSING","REPLAY_GUARD_INVALID","REPLAY_DETECTED","CONCURRENT_REPLAY_DETECTED","REPLAY_RECORD_UNAVAILABLE","PERSISTENCE_UNAVAILABLE"],"conformance_vector_ids":["replay-key-invalid-characters","strict-account-wide-replay-recovery"],"evidence_basis":"One executable offline vector rejects an unsafe key; one stateful contract vector specifies account-wide recovery and conflicting reuse.","limitations":["The stateful vector is an integration target, not an independent deployment attestation.","A customer gateway must use stable identifiers consistently across its own retries."],"source_ids":["mandateshield-conformance","mandateshield-standard","mandateshield-security"]},{"id":"budget-and-execution-state","name":"Cumulative budget and execution state","classification":"deterministic","outcome":"BLOCK","summary":"Qualifying ALLOW decisions atomically reserve configured lifetime, UTC-day and UTC-month headroom.","production_behavior":"Only a live, persisted, account-pinned ALLOW can create RESERVED state; PROCESSOR credentials alone may CONSUME, COMMIT or RELEASE it.","reason_codes":["EXECUTION_AUTHORITY_NOT_ESTABLISHED"],"conformance_vector_ids":[],"evidence_basis":"The public standard defines the eight-field execution invariant, role-separated credentials and legal state transitions.","limitations":["MandateShield never submits a provider payment.","A gateway that bypasses the required CONSUME transition is outside the enforceable boundary.","A processor_result is an authenticated customer-adapter assertion, not provider-signed settlement proof."],"source_ids":["mandateshield-standard","mandateshield-security","mandateshield-methodology","mandateshield-openapi"]},{"id":"signed-receipt-consistency","name":"Signed receipt consistency","classification":"deterministic","outcome":"BLOCK","summary":"Receipt verification binds the decision core, canonical digest and top-level execution claims.","production_behavior":"A changed decision core or contradictory top-level decision is rejected even when other receipt fields are self-consistent.","reason_codes":[],"conformance_vector_ids":["receipt-decision-core-digest-tamper","receipt-top-level-decision-contradiction"],"evidence_basis":"Portable receipt-integration vectors specify the two negative verification outcomes.","limitations":["Passing a receipt verifier proves receipt consistency, not payment settlement.","The published profile is vendor-authored and is not independent certification."],"source_ids":["mandateshield-conformance","mandateshield-standard"]},{"id":"unknown-constraint-fail-closed","name":"Unknown strict constraint handling","classification":"deterministic","outcome":"BLOCK","summary":"Strict production refuses to approve a constraint field that the active verifier does not evaluate.","production_behavior":"An unsupported strict constraint blocks instead of being silently ignored.","reason_codes":["UNSUPPORTED_CONSTRAINT_FIELD"],"conformance_vector_ids":["strict-unknown-constraint-field"],"evidence_basis":"An executable offline vector adds an unsupported allowed_items constraint and expects BLOCK.","limitations":["Integrators must adopt an explicit versioned adapter before relying on a new constraint."],"source_ids":["mandateshield-conformance","mandateshield-standard"]},{"id":"prompt-injection-signal","name":"Prompt-injection pattern signal","classification":"advisory","outcome":"REVIEW","summary":"Pattern matches can flag possible instruction override language but are not treated as proof of compromise.","production_behavior":"The signal can require REVIEW; deterministic authority checks remain decisive.","reason_codes":["PROMPT_INJECTION_SIGNAL"],"conformance_vector_ids":[],"evidence_basis":"The public methodology and security architecture explicitly classify this control as heuristic.","limitations":["Pattern detection can produce false positives and false negatives.","It is not a complete prompt-injection detector and never creates authority."],"source_ids":["mandateshield-security","mandateshield-methodology"]},{"id":"community-threat-signal","name":"Privacy-thresholded community signal","classification":"advisory","outcome":"REVIEW","summary":"Cross-account observations provide contextual threat evidence only after the published privacy threshold.","production_behavior":"A qualifying signal can require REVIEW but does not create an automatic community block.","reason_codes":["COMMUNITY_THREAT_SIGNAL"],"conformance_vector_ids":[],"evidence_basis":"The public methodology identifies cross-account observations as contextual rather than deterministic authority.","limitations":["Absence of a signal does not establish safety.","The signal is not sanctions screening, fraud scoring or an identity registry."],"source_ids":["mandateshield-security","mandateshield-methodology"]},{"id":"processor-gateway-enforcement","name":"Processor-gateway enforcement","classification":"external","outcome":"EXTERNAL","summary":"The customer's trusted gateway must make CONSUME a hard precondition for its one provider submission.","production_behavior":"MandateShield exposes role-separated state transitions but cannot prevent an external merchant system from bypassing them.","reason_codes":[],"conformance_vector_ids":[],"evidence_basis":"The standard and methodology define this as a mandatory integration responsibility outside the hosted verification boundary.","limitations":["No payment is submitted, processed or settled by MandateShield.","Correct gateway wiring requires customer-side implementation and testing."],"source_ids":["mandateshield-standard","mandateshield-security","mandateshield-methodology"]}]}