An agent authorises a ceiling it cannot exceed. The seller charges only the actual. Every number lands on Hedera, where anyone can check it.
npm run agent:auto runs unattended — six purchases in a row, each one audited, with no human in the loop.A raw allowance isn’t single-use, never expires and binds no recipient — so a contract has to enforce those. The rails were already here: HIP-336 grants an allowance to a contract, HIP-376 lets it spend transferFrom.
The contract has no owner and no upgrade path — it enforces the four in consensus, or it reverts.
The seller signs the price before the work and the meter reading after, both anchored to HCS. So it can’t show one price to you and another to an auditor.
Anyone re-derives the verdict from the public Mirror Node:captured ≠ units × signed price ⇒ fraud.
✓ signer resolves to a Hedera account key
✓ four artifacts, one key — undeniable
✓ the settlement exists on-chain
✓ terms on HCS match what the buyer signed
✗ charge equals units × the signed price
186 × 50 = 9,300, but 27,900 was taken
VERDICT ⛔ arithmetic_fraud
The seller signed these numbers.The seller counts the tokens — a consistent liar could inflate them. What changes is that the count is now signed, timestamped and bound to what was delivered. The buyer can recount and then holds the seller’s signature on a false number. That is the difference between a dispute and a complaint.