These are the roles organizations hand to agents first, because they are the ones with the clearest instructions and the most repetition. Each one commits money or moves it. What separates them is not how much they spend — it is what is left of your recovery once the instruction has gone out, and that is a property of the action and the rail rather than of the amount.
The colour on each card is the tier its decisive action sits at — amber for hold-before-commit, red for nothing reverses it.
An agent drafts a purchase order and the draft is freely reversible — delete it, nothing happened. Issue it and you can still withdraw it, so long as the supplier has not acted. The moment they accept, the same document becomes an accepted purchase order: a commitment whose cancellation is now a negotiation, not a mechanism. Nothing about the amount changed. Counterparty reliance did.
What Reddix does: classifies at issue, not at acceptance, so the hold lands while withdrawal is still yours to make. Above your threshold the order is held for a second person before it is released to the supplier.
Approving an invoice for payment is the obvious exposure. The quieter one is a vendor bank-detail change: it moves nothing on the day it happens, clears no approval aimed at payments, and silently redirects every payment to that vendor from then on. It sits at the same tier as the wire it will eventually divert, because that is what it is worth to an attacker.
What Reddix does: treats the master-data change as a financial action in its own right and holds it for maker-checker, rather than tiering only the payments that follow it.
“Send $40,000 to this counterparty” is one instruction with several endings. On an ACH inside the return window there is a real mechanism to pull it back. On a wire or an instant rail there is not — recovery depends on the receiving side agreeing to help. Settled on-chain, no recovery primitive exists at all. Same sentence, three different amounts of protection.
What Reddix does: tiers by the rail actually used, so an instruction that would be logged and allowed on one rail is held before release on another. Where nothing reverses, it says so instead of promising an undo.
A card refund is compensable and a pre-capture void costs nothing at all. Held to one action at a time, this is the least alarming column on the page. The failure here is not severity but velocity: an agent in a retry loop, or one that has learned refunding closes tickets fastest, issues thousands of individually defensible refunds before anybody looks at the total.
What Reddix does: raises effective materiality on velocity and first-time-payee signals without changing the tier, so a run of small actions can cross a threshold that no single one of them would.
One question decides the control in every case, and it is not the one most approval systems ask.
The agent belongs to one team. The consequence lands on three.
You are being asked to attest that spend initiated by software is controlled to the same standard as spend initiated by a person — usually without a list of what the agents actually did.
Maker-checker is testable when a person is the maker. When the maker is an agent, the question is whether the evidence exists at all: who initiated, on what basis, who released it, and when.
Exposure here is governed volume, tier distribution and held-action counts. Without those, agent spend is priced as an unknown, which is rarely priced generously.
Stated here rather than discovered later.
Start with the exposure report: thirty days in shadow mode, read-only, nothing in your payment path. At the end you have your own governed volume, your own tier distribution, and a count of the actions that would have been held — against the four roles above rather than against a benchmark.