Pocket Heron

Agent permissions / Local policy lab

Give every request
a boundary.

A small workbench for an agent’s spending power.
Set the rules. Run the requests. See exactly where they stop.

01 / Policy workbench

Start with a merchant and a spending boundary. Everything runs in this browser.

Policy clauses

USD

One exact merchant ID per line. Empty means deny all.

$
$

Local midnight to midnight, including daylight saving changes.

Active policy

Edits take effect after Apply policy and rewind the simulation.

Authorization timeline

Your scenario · no events yet

0 EVENTS
0 / 0
⌜ · ⌝

No requests, no assumptions.

Add a request below, or load a clearly marked synthetic example.

Compose an event +

Same timestamp = concurrent requests, serialized in input order. Completion and release reference an existing request ID.

02 / Budget ledgerNo budget activity
Authorization dateReservedCompletedAvailableAllowance used

Available = daily allowance − active reservations − completed requests. Values are simulated USD, never wallet balances.

A policy you can carry.

Export the active policy and request sequence. Import it to reproduce every decision.

03 / Accounting notes

A hold is a promise.
A failure gives it back.

01

Reserve → complete

Reserving reduces available allowance. Completion moves that exact amount from reserved to completed, without counting it twice.

02

Fail or cancel → release

Only an active hold can be released. A repeated event or second terminal action is rejected, with no ledger change.

03

The original day keeps it

Completion after midnight belongs to the reservation’s original local date. New-day spending has its own allowance. Holds do not expire automatically.

04

A portable policy layer

A proposed application token would support access to shared policy libraries and contribution records across cooperating apps. Local simulation is free of token requirements. No token has been issued.

Shared policy library

SOON

Your local policy is ready to export. Publishing to a team library needs a shared account service and access controls that are not connected.

No wallet, signature or payment is requested. Your work stays here.