HANDS.
Docs

Firewall: the policy engine

Every tool that moves money is an intent. The worker, which runs the mind, forwards it to the signer, where packages/policy decides. The engine is pure, deterministic and 100% unit-tested. It re-derives balances from the ledger; it never trusts a number from the model.

Rules (by name)

RuleMeaning
coin.retiredNothing moves after retirement.
coin.not_awakeMoney actions need an awake coin (not sleeping or halted).
run.max_money_actionsAt most 3 money actions per run.
*.min_amountNothing under $1.00.
*.insufficientAmount exceeds spendable treasury.
*.treasury_shareA single buy-back, airdrop, jackpot or program commitment ≤ 50% of spendable.
burn.nothing_heldBurn only from tokens the treasury holds.
program.configProgram config validated per kind (dca, rule, milestone_reward, recurring_reward, jackpot).
card.category_not_allowedCategory must be one the launcher picked at launch.
card.merchant_deniedMerchant domain on the deny list (and subdomains).
card.purpose_requiredPurpose and expected outcome are mandatory.
card.per_tx_cap$25 per purchase ($100 above $5000).
card.daily_cap$50 per day ($250 above $5000).
card.treasury_shareA single spend ≤ 20% of spendable.
card.receipts_overdueOne spend per 24h while a receipt is overdue by more than 48h.
card.window_openOne spending window at a time per coin.
task.reward_cap≤ $20 per task ($50 above $5000).
task.escrow_shareOpen escrow ≤ 20% of treasury.
task.max_open≤ 10 open tasks per coin.
task.deadline_range1 hour to 14 days.
task.claim_not_approvedPayouts only for claims approved by the mind or an admin.
task.bad_wallet / task.worker_bannedClaimant must be a valid, unbanned Solana wallet.
mission.max_activeAt most 3 active missions.

Recipients

The only Solana recipients, ever: the coin's own mint (buyback), the burn, holder wallets from platform-taken snapshots (airdrops and jackpots), task claimants verified by the platform (task payouts), and the platform wallets. Card payments go to merchants through Stripe. No tool can pay an address the mind chose.

Audit

Every intent, verdict and transaction is written to the append-only audit_log with the rule that allowed or blocked it. The coin page shows it under Audit.