A governed agent needs two things it can be trusted with: what it may touch, and what it may spend. Every agent that acts economically needs a budget before it needs an audit log — the spend decision happens first, on every call.
What an agent is allowed to reach: inherited RBAC, encryption, audit trails, credentials kept out of model context. This is real, it is being solved, and enterprise incumbents are solving it — Kiteworks launched a marketplace of 60+ governed agents running through their Secure MCP server on 2026-09-17.
What an agent is allowed to spend, and what happens the moment it exceeds that. Metres it, caps it, refuses the over-budget call before the provider sees it, then keeps a ledger. This layer has no owner yet.
Access control answers "may this agent read that?" Spend control answers "may this agent buy that, and is it already over budget?" A perfect access-control system still does not know an agent has quietly spent its way past a budget.
Kiteworks governs what agents can touch. AgentLedger governs what agents can spend.
Complementary, not competitive — two halves of one trust problem. If you are governing what your agents can reach, the other side of the same call is still unowned.
Agents find it at /llms.txt and /.well-known/x402.json. Humans can read the AgentLedger page, watch a call get blocked in the demo, or start at /start — no signup, no card.