Architecture
Where GaelOne™ sits between an AI agent and the payment system, what reaches the checkpoint, and what does not.
Where GaelOne™ sits
GaelOne™ sits between an AI agent and the payment system that would execute what it proposes. It is not in the path of anything else — it does not proxy your traffic, host your agent, sit in front of your systems generally, or move money itself.
- 01Your AI. proposes one payment to your payment system.
- 02GaelOne™ checks it. and answers ALLOW, ASK or STOP. The decision is recorded.
- 03A person approves. only when the answer was ASK. The approval is recorded against that exact payment.
- 04GaelOne™ checks again. immediately before execution — the amount, the destination account and the reference, read from the payment that is about to be sent, inside the same transaction that records the result.
- 05A release is issued. only if that second check still allows it, and it covers one payment, one payment system, one window, and one use.
- 06Your payment system. verifies the release before it sends. Without a valid release it does not send the payment.
- 07The record is written. the decision, the reason and the outcome go to append-only records.
Why the recheck is separate from the decision
An approval covers one exact payment. An answer given when an AI proposed a payment is not evidence about the payment it finally sends — the amount, the destination account or the reference can change in between, and an authorization no longer covers values it was never issued for.
So the final recheck is a second, independent reading, performed inside the same transaction that records the execution. An approval given before that moment does not override it.
Can an agent bypass GaelOne™?
Yes, if the payment never reaches GaelOne™. GaelOne™ checks payments routed through its interfaces. A payment that takes a different path is not checked, and no claim on this site should be read as saying otherwise.
This is why integration is real work rather than a switch. Placing an agent’s payments on this path is the substance of the work, and it is scoped to one agent and one payment system precisely because doing it properly for one is more valuable than doing it loosely for many. Evaluate GaelOne™ on the payment workflow you would start with.
How an AI integrates
An AI declares what it can attempt: the payments it may propose, the system it proposes them to, and the interfaces it speaks. It never declares whether it is permitted. What is authorized, and whether a person approved it, are read from GaelOne™’s own records — at the decision, and again immediately before execution.
A declaration that tries to state its own authority, its own approval, its own organization or its own outcome is refused rather than ignored, so an integrator finds out while integrating instead of during an incident.
What happens if GaelOne™ is unavailable
The path fails closed. A payment that cannot get an answer from GaelOne™ does not proceed on the assumption that it would have been allowed.
GaelOne™ currently runs as a single deployment against one PostgreSQL database. There is no multi-region deployment, no published availability target, and no formal service level commitment today. An evaluator should treat availability as something to discuss rather than something already engineered.
What GaelOne™ receives
For each proposed payment: which AI, which payment system, the payment itself, and the plain-language reason the AI gave. Plus the identity of the people who review, approve and activate.
GaelOne™ does not receive the contents of the systems your AI acts on, and it is not a data pipeline. If a payment would require GaelOne™ to hold data of that kind, that is a conversation to have before an engagement rather than a detail to discover during one.
How decisions are authenticated
Every route resolves identity from a server-side session, and every permission is re-read from durable storage inside the transaction that acts on it. Reaching a route proves nothing; a request cannot supply its own organization, its own actor, or its own permission.
Tenant boundaries are enforced on every read and every write. A record belonging to another organization returns not found rather than not authorized, so the existence of another tenant’s data is not disclosed by the shape of a refusal.
Which integrations are verified today
One reference integration, built by us, whose supported payments are the ones GaelOne™ can check end to end today.
There are no verified third-party AI-platform integrations. Anyone claiming otherwise on our behalf is mistaken, and this page is the record of what is actually true.
GaelOne™ and related marks are proprietary to GaelOne™.
Questions about this page? Write to hello@gaelone.com, or use the contact form.