OPEN PMAS VERIFIER

Authority can move. It must not grow.

The PMAS verifier proves that authority cannot grow as it moves between machines. Compare what a parent agent holds with what it proposes to delegate downstream.

AUTHORIZES ACTIONSNo
EXECUTES RAILSNo
PERSISTS DOCUMENTSNo
WHAT THIS PROVES

An agent may delegate less authority. It may never invent more.

For developers, this prevents privilege escalation between autonomous agents. For enterprises, it creates a simple governance invariant: downstream machines cannot silently increase spend limits, add merchants, switch environments, add rails, extend validity, increase usage, or enable powers their parent never had.

HOW TO USE THIS VERIFIER

Four steps from delegated authority to proof.

You do not need to be a PMAS expert to understand the result. The JSON is the technical artifact; the verifier translates it into a clear delegation comparison.

1

Parent Authority

Paste the authority the first agent currently holds. This is the maximum boundary available to delegate.

2

Proposed Child Authority

Paste the authority the downstream agent would receive. It may stay equal or become narrower.

3

Verify Delegation

Paylogee compares scope, amounts, merchants, environments, rails, currencies, validity, state, usage and subdelegation.

4

Read the result

PASS means no authority grew. REJECTED means the child gained authority it was never entitled to receive.

BUSINESS-LANGUAGE EXAMPLE

A procurement agent cannot create a bigger spending authority for its child.

The example below is intentionally simplified for business users. The JSON editors later on show the portable PMAS representation.

Parent Agent

Spend limit$1,000
MerchantAcme Software
Railx402
EnvironmentSandbox
Uses3
delegates to proposed child

Child Agent

Spend limit$1,500 - VIOLATION
MerchantAcme Software
Railx402
EnvironmentSandbox
Uses3
Delegation rejected. The child per-transaction ceiling is $500 higher than the parent authority. This verifier result is evidence, not a Gateway decision.
WHY THIS MATTERS OPERATIONALLY

One invariant, different value for every team.

DevelopersPrevent privilege escalation between autonomous agents and services.
SecurityEnforce least privilege across machine-to-machine delegation chains.
FinanceStop downstream agents from increasing spend ceilings or changing commercial boundaries.
ComplianceProve what authority was delegated and whether it stayed inside the original boundary.
ExecutivesAllow autonomous operation without allowing machines to manufacture new authority.
HOW PAYLOGEE FITS TOGETHER

From identity to accountable execution.

Each layer answers a different enterprise question. The verifier focuses only on whether delegated authority grew.

IdentityWHO is this agent?

Machine identity and subject.

KYAIS it the expected agent?

Identity, principal and runtime posture.

Machine AuthorityWHAT may it do?

Bounded operational power.

PMASHOW is authority represented?

Portable authority contract.

No AmplificationCAN delegation become broader?

This verifier answers no.

Paylogee RuntimeSHOULD this action happen now?

Canonical governance and decision path.

Commerce ReceiptWHAT happened and why?

Post-action evidence.

TECHNICAL VERIFICATION

Compare two PMAS Authority Envelopes.

Use the canonical examples or paste your own documents. The left side is the authority being delegated from; the right side is the authority proposed for the child.

Authority Envelope: a portable JSON document describing the principal, agent subject, allowed actions and resources, merchants/counterparties, environment, rails, currencies, spend ceilings, usage, validity, state and subdelegation.
Delegation input Parent = authority being delegated from. Child = authority the downstream agent would receive.
Amplification example loaded The child exceeds the parent's per-transaction amount ceiling. Verification should reject the delegation.
maximum authority available to delegate

Paste the PMAS Authority Envelope JSON that represents the authority the parent currently holds.

authority the child would receive

Paste the proposed child envelope. It may equal or narrow the parent, but it must never gain additional authority.

PMAS No Authority Amplification checks principal · scope · resource · merchant · amount · environment · rail · currency · validity · state · usage · subdelegation