Sequence Diagram · Commerce
Agentic Commerce — AI Buys on Your Behalf
A sequence showing how an AI agent discovers offers, operates under delegated authority, requests human approval when required, executes payment and completes fulfillment.
A new local copy, ready to customize. No signup required.
When an AI agent clicks Buy, whose decision is it? Explore how delegated authority, human approval and payment authorization turn a travel plan into a controlled transaction.
- Technologies
- Large Language Models (LLMs), AI Agent Orchestration, Policy Engines, Delegated Authorization, Identity Verification, Fraud Detection, Payment Gateways, Payment Tokenization, Idempotent Transaction Processing
- Tags
- Agentic AI, AI Agents, Agentic Commerce, Payments, Delegated Authority, Human-in-the-Loop, Trust, Risk, AI Governance, Autonomous Systems, Travel, Retail, Advanced
When an AI agent clicks Buy, whose decision is it?
Today, software can recommend a flight. The more difficult architecture begins when the software can actually buy it.
Who authorized the agent? What exactly could it buy, and how much could it spend? How does a merchant verify the request? When must a human return to the loop? This example follows the boundary between a useful recommendation and a legitimate commercial action.
The scenario: four nights in Tokyo
“Book me a four-night trip to Tokyo. Total budget: $1,500. Direct flights only. Hotel rating must be at least 4.3. Do not make any individual purchase above $500 without asking me first.”
- Total trip budget: $1,500, enforced across purchases and outstanding reservations.
- Direct round-trip flights only.
- Four hotel nights; minimum rating 4.3.
- Individual purchases up to $500 may proceed within the delegation.
- Above $500, obtain explicit approval for the exact merchant, price and travel dates.
Illustrative travel dates are 10–14 June 2027. A $480 direct round-trip flight and a $620 hotel rated 4.5 total $1,100, including quoted taxes and fees. The remaining $400 is unspent budget, not a promise that other trip costs are covered. These are fictional offers, not current travel prices.
Why architects should care
- Representation: how is delegation recorded, scoped, expired and tied to the agent and customer?
- Merchant trust: what evidence proves the actual offer and amount were authorized?
- Enforcement: which service owns atomic budget reservations, per-purchase limits and concurrent requests?
- Consent and disputes: what records explain who approved what? Which contracts allocate liability among customer, merchant, agent platform and payment provider?
- Prompt manipulation: how do untrusted offers stay outside the financial authority boundary?
- Changing markets: what happens when prices or availability change between discovery and checkout?
- Duplicate purchases: how are retries, timeouts and partial completion reconciled?
- Revocation and audit: how quickly can withdrawal stop new actions, and which material decisions can be reconstructed?
Architecture at a glance
- Customer — defines the goal, grants bounded authority and reviews exceptions.
- Personal AI Agent — plans, compares offers and proposes actions; it does not own unlimited authority.
- Consent / Delegation Service and Spending Policy Engine — retain consent, enforce deterministic constraints and record transaction-specific approval.
- Travel Marketplace, Airline and Hotel Provider — expose expiring offers and eligible non-charging holds; providers deliver bookings.
- Agent Identity / Intent Verification and Risk / Fraud Decision — verify represented identity, transaction intent and merchant context before acceptance.
- Merchant Checkout — validates evidence and coordinates execution using scoped permits and idempotency keys.
- Payment Provider and Issuing Bank — separately authorize and execute payment using protected payment references.
Six tinted participant groups mark responsibility boundaries. Participants retain one identity across phases; groups are not repeated copies of an actor. The overview links to six detail sequences: delegation, discovery, trust, human approval, payment and fulfillment.
Intent ≠ Authority ≠ Payment
A $620 hotel can be a good recommendation, exceed the agent’s $500 purchase limit, gain explicit customer approval and still be declined by the issuing bank. An API token identifies a caller; it does not establish that the customer authorized this purchase.
Human-in-the-loop without making the agent useless
The $480 flight fits the individual limit. The $620 hotel triggers an exception: the customer reviews the hotel, final price, merchant and four-night dates. Approval binds those terms and expires; it does not raise the total budget or unlock every future hotel purchase.
Bounded autonomy handles routine actions within a clear envelope and escalates consequential exceptions. Unrestricted spending removes customer control; approval for every minor action removes the agent’s practical value. A denied or withdrawn approval stops the hotel transaction. Changed terms return to policy and, where required, the customer.
Failure and abuse cases
- Prompt injection or out-of-scope intent — treat merchant content as untrusted data; enforce action scope outside the model.
- Changed price or unavailable offer — pause checkout, re-plan within the total budget and refresh any approval tied to the changed terms. Never silently increase spend.
- Duplicate transaction or uncertain response — reconcile the original idempotency key; do not create a fresh charge because a response timed out.
- Compromised agent or malicious merchant — verify identity and transaction intent independently; risk denial or verification failure stops execution.
- Expired delegation, revoked consent or customer withdrawal — check authoritative status again at the execution boundary. Define revocation latency and the point beyond which cancellation becomes a refund process.
- Payment decline or incorrect retry — record the outcome, release unused budget reservations and stop remaining purchases; report an earlier successful purchase accurately. An allowed alternative is a new policy evaluation.
- Paid but unconfirmed booking — reconcile provider state and receipts; do not promise fulfillment or buy a duplicate. Partial trips need an explicit cancellation/refund policy.
Design decisions and trade-offs
- Separate financial authority from LLM reasoning; keep payment credentials in the payment boundary and expose only protected references to the workflow.
- Use deterministic scope and budget policies, with atomic reservations; added coordination protects against concurrent overspending.
- Require human approval above $500, bound to merchant, quote, dates and expiry; this adds friction precisely where delegated authority ends.
- Audit every material action with consent, policy, risk, approval, payment and booking references; retain the minimum evidence needed for review under a defined privacy and retention policy.
- Make delegation scoped, time-limited and revocable; execution-time checks improve control but require available authority services and a documented cancellation boundary.
- Let merchants validate represented identity and customer intent; this creates an integration and trust-governance obligation rather than relying on possession of an API token.
Questions for the architect
- Would you let an AI agent spend $20 without approval? $200? $2,000?
- Who should define limits: the customer, bank, merchant or agent platform?
- How should a merchant verify that an agent legitimately represents a customer?
- What evidence should exist when a transaction is disputed?
- Should an AI agent ever directly possess payment credentials?
- How quickly should authority be revocable, including an in-flight transaction?
- How would you defend this workflow from prompt injection?
- At what point does “AI assistant” become a legally meaningful actor, and which jurisdiction and contracts govern that question?
Explore and adapt the sequence
- Inspect the overview, then open the numbered detail sequences to follow the trust and authorization flow.
- Examine “4 · Human approval — $620 hotel” and the approved, declined and within-limit branches.
- Use Open presentation for more room, or Show all to inspect the complete hierarchy.
- After publication, use Remix this architecture to open your own editable copy in the Designer.
- Adapt the policies and fulfillment roles for retail purchases, business procurement or another industry. Keep intent, authority and payment separate.
Architecture source
aal sequence "0.1" dictionary "0.1.0"
interaction AgenticCommerce "Agentic Commerce — AI Buys on Your Behalf" {
participant Customer "Customer" { type actor }
participant Consent "Consent / Delegation" { type service }
participant Agent "Personal AI Agent" { type service }
participant Search "Travel Marketplace" { type system }
participant Identity "Agent Identity / Intent" { type service }
participant Risk "Risk / Fraud Decision" { type service }
participant Policy "Spending Policy Engine" { type service }
participant Checkout "Merchant Checkout" { type api }
participant Payments "Payment Provider" { type service }
participant Bank "Issuing Bank" { type system }
participant Airline "Airline" { type system }
participant Hotel "Hotel Provider" { type system }
// Groups own participant identity; the same actor is reused across phases.
group DelegationGroup "Customer & Delegation" { participants [Customer, Consent] type "Human authority" }
group PlanningGroup "Planning & Discovery" { participants [Agent, Search] type "Intelligence" }
group TrustGroup "Trust & Authorization" { participants [Identity, Risk] type "Verified intent" }
group ApprovalGroup "Human Approval & Policy" { participants [Policy] type "Spending guardrails" }
group PaymentGroup "Checkout & Payment" { participants [Checkout, Payments, Bank] type "Financial execution" }
group FulfillmentGroup "Travel Fulfillment" { participants [Airline, Hotel] type "Bookings" }
sequence Journey "Tokyo trip — controlled purchase" {
participants [Customer, Agent, Policy, Checkout]
message TripRequest Customer -> Agent sync "1 · Book four nights in Tokyo" { detail Delegation }
message PlanTrip Agent -> Agent sync "2 · Compare eligible offers" { detail Discovery }
message VerifyPurchase Agent -> Checkout sync "3 · Verify delegated intent" { detail Trust }
message CheckoutQuote Checkout -> Agent return "Current total: $1,100 incl. fees"
fragment PriceChanged break "Price changed before checkout" {
branch QuoteChanged "either quote differs" {
message RepricePolicy Agent -> Policy sync "Recheck total and approval threshold"
message RevisedOptions Agent -> Customer async "Pause; reconsider revised offers"
}
}
message EvaluatePurchase Agent -> Policy sync "4 · Check $620 hotel approval" { detail Approval }
fragment ApprovalRejected break "Human approval denied / withdrawn" {
branch MissingApproval "hotel has no matching approval" {
message NoAuthority Policy -> Agent return "Stop; no hotel payment authority"
}
}
message PurchasePermitted Policy -> Agent return "Flight allowed; hotel approved"
message ExecutePurchases Agent -> Checkout sync "5 · Execute bounded purchases" { detail Payment }
fragment PurchaseResult alt "Payment outcome" {
branch AllPaid "both purchases paid" {
message Paid Checkout -> Agent return "Payment receipts; spend $1,100"
message GetBookings Agent -> Checkout sync "6 · Collect confirmed bookings" { detail Fulfillment }
message FinalItinerary Agent -> Customer async "Tickets + hotel reference; $400 unspent"
}
else Declined {
message DeclineResult Checkout -> Agent return "Declined / partial outcome recorded"
message FailureNotice Agent -> Customer async "Report exact result; no blind retry"
}
}
}
sequence Delegation "1 · Customer & delegation" {
participants [Customer, Agent, Consent, Policy]
message CaptureIntent Agent -> Consent sync "Record trip intent and spending constraints"
message ConfirmConsent Consent -> Customer sync "Review scope, expiry and revocation"
message GrantConsent Customer -> Consent return "Delegate bounded travel authority"
message CreatePolicy Consent -> Policy sync "Create deterministic policy; budget $1,500"
note Guardrails over [Agent, Policy] "Direct flights; rating >= 4.3; ask above $500"
message DelegationReference Consent -> Agent return "Scoped delegation reference, not card data"
}
sequence Discovery "2 · Planning & discovery" {
participants [Agent, Search, Airline, Hotel]
message SearchTrip Agent -> Search sync "Tokyo, 10–14 Jun 2027; direct; rating >= 4.3"
fragment FindOffers par "Independent offer discovery" {
branch Flights "flight offers" {
message FlightSearch Search -> Airline sync "Direct round trip; all-in price"
message FlightOffer Airline -> Search return "$480; available; quote expires"
}
branch Hotels "hotel offers" {
message HotelSearch Search -> Hotel sync "Four nights; rating >= 4.3"
message HotelOffer Hotel -> Search return "$620; rating 4.5; available"
}
}
message CandidateOffers Search -> Agent return "Candidates $1,100; $400 budget buffer"
message HoldOffers Agent -> Search sync "Reserve eligible non-charging holds"
note HoldLimit over [Agent, Search] "Hold expiry is not permission to pay"
}
sequence Trust "3 · Trust & transaction authorization" {
participants [Agent, Checkout, Identity, Risk, Consent, Policy]
message PresentEvidence Agent -> Checkout sync "Delegation ref + exact merchant / offer / intent"
message VerifyIdentity Checkout -> Identity sync "Verify agent, represented customer and intent"
message ReadConsent Identity -> Consent sync "Validate scope, expiry and current revocation"
message CurrentConsent Consent -> Identity return "Verified consent and delegation evidence"
message IdentityEvidence Identity -> Checkout return "Bound identity + transaction intent"
message RiskDecision Checkout -> Risk sync "Assess merchant and transaction context"
message RiskResult Risk -> Checkout return "Accept or deny; retain decision reference"
fragment TrustDenied break "Identity or risk rejected" {
branch InvalidEvidence "invalid identity / intent or risk denied" {
message TrustFailure Checkout -> Agent return "Stop; no commercial execution"
}
}
message CheckAuthority Checkout -> Policy sync "Evaluate exact quotes against delegation"
message AuthorityResult Policy -> Checkout return "Flight eligible; hotel requires approval"
note TokenNotAuthority over [Agent, Checkout] "An API token alone grants no spending authority"
}
sequence Approval "4 · Human approval — $620 hotel" {
participants [Agent, Policy, Customer, Consent]
message EvaluateQuotes Agent -> Policy sync "Flight $480; hotel $620; total $1,100"
fragment PerPurchaseLimit alt "Individual purchase limit: $500" {
branch OverLimit "hotel $620 > $500" {
message ApprovalRequired Policy -> Agent return "Explicit approval required"
message ApprovalPrompt Agent -> Customer sync "Review hotel, $620, merchant, 10–14 Jun"
fragment CustomerDecision alt "Customer decides" {
branch Approves "customer approves this exact hotel quote" {
message ApproveHotel Customer -> Consent sync "Approve $620 for this merchant and dates"
message BindApproval Consent -> Policy sync "Bind approval to offer, amount, dates and expiry"
message ApprovedHotel Policy -> Agent return "Hotel permitted; total cap still $1,500"
}
else Rejects {
message RejectHotel Customer -> Agent return "Decline / withdraw authority"
fragment ApprovalStop break "Approval denied" {
branch NoConsent "no matching approval" {
message AbortHotel Agent -> Customer async "Stop; release holds; no hotel charge"
}
}
}
}
}
else WithinLimit {
message RoutineAllowed Policy -> Agent return "Flight $480 within delegated limits"
}
}
note ApprovalScope over [Agent, Policy] "Approval covers one quote; price changes need re-evaluation"
}
sequence Payment "5 · Payment — one bounded attempt per purchase" {
participants [Agent, Consent, Policy, Checkout, Payments, Bank]
fragment EachPurchase loop "Flight $480, then hotel $620" {
branch RemainingPurchase "next eligible purchase; stop after a decline" {
message PaymentIntent Agent -> Checkout sync "Payment intent + evidence + idempotency key"
message FinalConsent Checkout -> Consent sync "Recheck current consent at execution boundary"
fragment RevocationStop break "Expired or revoked delegation" {
branch Revoked "current authority invalid" {
message AuthorityDenied Consent -> Checkout return "Deny; do not submit payment"
}
}
fragment ChangedAtPayment break "Quote changed since approval" {
branch ChangedQuote "exact quote no longer matches" {
message PausePayment Checkout -> Agent return "Reconsider; no payment submitted"
}
}
message ReserveBudget Checkout -> Policy sync "Atomically reserve budget + consume scoped permit"
fragment PolicyStop break "Policy denies transaction" {
branch OutsideEnvelope "scope / approval / remaining budget invalid" {
message PolicyDenied Policy -> Checkout return "Stop; no payment authority"
}
}
message SubmitPayment Checkout -> Payments sync "Tokenized payment ref + bound authority context"
message BankAuthorization Payments -> Bank sync "Authorize exact merchant and amount"
fragment BankResult alt "Payment authorization" {
branch Authorized "approved by issuer" {
message BankApproved Bank -> Payments return "Authorized"
message PaymentSuccess Payments -> Checkout return "Payment completed; receipt reference"
message CommitSpend Checkout -> Policy sync "Commit spend; record outcome against same key"
}
else BankDeclined {
message BankFailure Bank -> Payments return "Declined"
message PaymentFailure Payments -> Checkout return "Failure; no automatic new charge"
message ReleaseBudget Checkout -> Policy sync "Release reservation; record declined attempt"
fragment PaymentStop break "Stop remaining purchases" {
branch StopAfterDecline "payment failed" {
message ReportDecline Checkout -> Agent return "Report failure / any earlier payment"
}
}
}
}
}
}
note RetrySafety over [Checkout, Payments] "Unknown result: reconcile same key before any retry"
}
sequence Fulfillment "6 · Fulfillment & confirmations" {
participants [Checkout, Airline, Hotel, Agent, Customer]
fragment ConfirmBookings par "Fulfill paid purchases" {
branch IssueTicket "flight paid" {
message TicketRequest Checkout -> Airline sync "Issue ticket for paid reservation; same booking key"
message TicketReference Airline -> Checkout return "Confirmed ticket + booking reference"
}
branch ConfirmHotel "hotel paid" {
message HotelRequest Checkout -> Hotel sync "Confirm paid four-night reservation"
message HotelReference Hotel -> Checkout return "Confirmed hotel + booking reference"
}
}
message BookingReferences Checkout -> Agent return "Confirmed bookings + payment receipts"
message Consolidate Agent -> Agent sync "Consolidate itinerary and actual spend"
message NotifyCustomer Agent -> Customer async "Tokyo itinerary; $1,100 spent; $400 remaining"
note FulfillmentLimit over [Checkout, Agent] "Paid but unconfirmed: reconcile; never claim a booking exists"
}
}