Docs
Firewall: the policy engine
Every tool that moves money is an intent. The worker, which runs the mind, forwards it to the signer, where packages/policy decides. The engine is pure, deterministic and 100% unit-tested. It re-derives balances from the ledger; it never trusts a number from the model.
Rules (by name)
| Rule | Meaning |
|---|---|
coin.retired | Nothing moves after retirement. |
coin.not_awake | Money actions need an awake coin (not sleeping or halted). |
run.max_money_actions | At most 3 money actions per run. |
*.min_amount | Nothing under $1.00. |
*.insufficient | Amount exceeds spendable treasury. |
*.treasury_share | A single buy-back, airdrop, jackpot or program commitment ≤ 50% of spendable. |
burn.nothing_held | Burn only from tokens the treasury holds. |
program.config | Program config validated per kind (dca, rule, milestone_reward, recurring_reward, jackpot). |
card.category_not_allowed | Category must be one the launcher picked at launch. |
card.merchant_denied | Merchant domain on the deny list (and subdomains). |
card.purpose_required | Purpose and expected outcome are mandatory. |
card.per_tx_cap | $25 per purchase ($100 above $5000). |
card.daily_cap | $50 per day ($250 above $5000). |
card.treasury_share | A single spend ≤ 20% of spendable. |
card.receipts_overdue | One spend per 24h while a receipt is overdue by more than 48h. |
card.window_open | One spending window at a time per coin. |
task.reward_cap | ≤ $20 per task ($50 above $5000). |
task.escrow_share | Open escrow ≤ 20% of treasury. |
task.max_open | ≤ 10 open tasks per coin. |
task.deadline_range | 1 hour to 14 days. |
task.claim_not_approved | Payouts only for claims approved by the mind or an admin. |
task.bad_wallet / task.worker_banned | Claimant must be a valid, unbanned Solana wallet. |
mission.max_active | At most 3 active missions. |
Recipients
The only Solana recipients, ever: the coin's own mint (buyback), the burn, holder wallets from platform-taken snapshots (airdrops and jackpots), task claimants verified by the platform (task payouts), and the platform wallets. Card payments go to merchants through Stripe. No tool can pay an address the mind chose.
Audit
Every intent, verdict and transaction is written to the append-only audit_log with the rule that allowed or blocked it. The coin page shows it under Audit.
