Two halves of one problem. Only one has an owner.

A governed agent needs two things it can be trusted with: what it may touch, and what it may spend. Every agent that acts economically needs a budget before it needs an audit log — the spend decision happens first, on every call.

Access governance

What an agent is allowed to reach: inherited RBAC, encryption, audit trails, credentials kept out of model context. This is real, it is being solved, and enterprise incumbents are solving it — Kiteworks launched a marketplace of 60+ governed agents running through their Secure MCP server on 2026-09-17.

Spend governance

What an agent is allowed to spend, and what happens the moment it exceeds that. Metres it, caps it, refuses the over-budget call before the provider sees it, then keeps a ledger. This layer has no owner yet.

Why they are different products

Access control answers "may this agent read that?" Spend control answers "may this agent buy that, and is it already over budget?" A perfect access-control system still does not know an agent has quietly spent its way past a budget.

The line

Kiteworks governs what agents can touch. AgentLedger governs what agents can spend.

Complementary, not competitive — two halves of one trust problem. If you are governing what your agents can reach, the other side of the same call is still unowned.

What we claim, and what we don't

  • Claimed: an agent can buy 24 hours of AgentLedger Pro for $0.01 USDC over x402 on Base mainnet, no human in the loop. It settled on mainnet.
  • Claimed: a call that would exceed a set budget returns 402 and is refused before it reaches the provider — not logged afterwards.
  • Not claimed: that this is a governance suite, that we hold enterprise certifications, or that we replace anything you run for access control. We are the spend half.
  • Not claimed: traction. We are early, and you can check the live surfaces yourself rather than take a metric on faith.

Check it rather than believe it

Agents find it at /llms.txt and /.well-known/x402.json. Humans can read the AgentLedger page, watch a call get blocked in the demo, or start at /start — no signup, no card.