Use Cases
August 26, 2026

Four Things an Agent Needs Before It Can Move Money

Space and Time Foundation

The Space and Time Foundation is an independent organization dedicated to the advancement and adoption of Space and Time.

Ask someone building agent infrastructure what still stands between today's systems and real autonomy over money, and the answer usually arrives as a list with verification somewhere near the bottom, one more capability to ship after identity, authorization, and settlement. The ordering is right and the framing is a trap, because the last item does not belong on the same list as the first three. It is a different kind of problem, and building as though it were the next increment of the same work is how institutions end up with agents they cannot actually trust.

Start with why the first three yielded so quickly. Each was solved by giving the agent, or something the agent controls, a new capability it could carry with it. Identity came from letting an agent register and present a verifiable credential that a counterparty could look up before dealing with it. Authorization came from binding the agent's actions to a cryptographically signed mandate that spells out its scope, its limits, and the conditions it may act under. Settlement came from embedding payment directly into the agent's request, so a transaction completes in the same exchange that asked for the resource. In each case the answer lived on the agent's side of the interaction, and the agent could produce its own proof on demand: here is my identity, here is my authority, here is my payment.

The fourth requirement lives somewhere the agent cannot reach

Verification breaks that pattern because of where the thing being proven actually sits. Identity, authority, and payment are all facts about the agent, and the agent is a competent witness to facts about itself. The accuracy of the data an agent acts on is a fact about the world, originating in sources the agent does not own, passing through systems it does not control, and arriving through a process whose trustworthiness is precisely what a counterparty is trying to establish. An agent asked to prove it was authorized can hold up its mandate. An agent asked to prove the price it acted on was real has nothing of its own to hold up, because the answer was never its to give.

This is the structural reason the agent-side attempts at verification keep collapsing when you lean on them. An agent that signs its own outputs has attested to nothing beyond its own assertion, which is the very thing in question. A detailed log of everything the agent read is the agent testifying on its own behalf, persuasive only to someone already inclined to believe it. Reputation, genuinely useful for deciding whom to transact with, describes how an agent has behaved across its history and stays silent on whether the specific figure in front of it at this moment is correct. Every one of these answers lives on the agent's side of the line, and the fact that needs establishing lives on the other side, which is why none of them satisfies a counterparty who has real capital at stake and no reason for faith.

Why this matters more as the other three succeed

There is an uncomfortable consequence to how well identity, authorization, and settlement now work. The better those three become, the more completely they remove the human from the loop, and the human was the one quietly performing verification all along. A person approving an agent's action was, among other things, glancing at the numbers and applying judgment about whether they looked right before anything irreversible happened. Automate identity, authority, and settlement to the point where no person is left in the sequence, and that informal check vanishes with them, leaving an agent that can prove everything about itself and nothing about what it read.

The requirement that remains, then, has to be met somewhere the agent cannot simply add a capability to itself: at the data layer, by the system that serves the data rather than the one consuming it, because only the source side can speak to whether a query ran correctly over data that was never altered. What an agent ultimately needs is to ask a question of a dataset and receive back an answer that carries proof of its own correctness, evidence generated outside the agent that a counterparty can check without extending the agent any trust at all.

Space and Time is built to be that layer as the data blockchain securing onchain finance. A query to SXT returns its result alongside cryptographic proof that the computation executed correctly against tamperproof data, which places the proof exactly where the agent could never put it: on the far side of the line, where the data lives. Identity, authorization, and settlement let an agent vouch for itself. This is the piece that lets something else vouch for what the agent saw, which is the only kind of assurance a counterparty was ever going to accept before letting an autonomous system move real money.

The three solved problems were solved the same way, and their success trained the ecosystem to look to the agent for every answer. The fourth is the reminder that some of what an agent needs can only come from elsewhere. What it read, and whether that reading was true, is the one question its own word was never going to settle.

Space and Time Foundation

The Space and Time Foundation is an independent organization dedicated to the advancement and adoption of Space and Time.