Runs live against the checkpoint on this page. Nothing is pre-recorded.
Where GaelOne™ sits
The Gate
The Gate is how GaelOne™ draws the checkpoint. It is a picture of the decision, not a component in your stack.
AI agent proposes
Payment system executes
01 · AI agent
02 · GaelOne™
03 · Payment system
Keep your AI.
Put GaelOne™ between them.
Keep your payment system.
It proposes the payment. GaelOne™ does not run your AI and does not decide what it should buy.
It checks the amount, destination account and reference immediately before execution. ALLOW, ASK or STOP.
It moves the money, exactly as it does today — and is only ever asked to once GaelOne™ allows the payment.
GaelOne™ never moves the money. It holds no funds and replaces neither side. It answers one question, immediately before execution: is this still the payment that was approved?
01What GaelOne™ does
It checks the authorized fields, immediately before execution.
Not the agent. Not the session. Not a budget. The amount, the destination account and the reference that are about to be sent — read from the transaction the payment system is about to execute, not from the proposal GaelOne™ was handed, and compared against what a person actually approved.
AI agent proposes
Payment system executes
At rest. Nothing is in flight.
Replay
ALLOW
This exact payment is authorized. The payment call is made.
ASK
This exact payment needs a person. Nothing executes until someone approves it.
STOP
This payment is not authorized. The payment call is not made.
Plate 01 The GaelOne™ Gate
Elevation · 1:1
AApproach railThe transaction the AI proposes, travelling toward execution.
BLeafDraws back to pass, bars to hold, meets to refuse.
CSeamWhere the two leaves meet. Closed, this is the mark.
DExecution railLive only when a valid authorization covers the transaction.
Plate 02 One decision, recorded
Illustrative
Reference
inv_48219
Amount
$2,500.00
Payee
Acme Supply Co.
Approved account
•••• 8472
Destination account
•••• 2291
STOP
The approval covered account •••• 8472. This payment was going to •••• 2291 — same amount, same payee, same reference, a different account. The approval does not cover it, so the payment system is never asked and $0 moves.
The shape of what GaelOne™ emits for one checked transaction. These are the demonstration's own values, not a customer's.
02The proof
Five transactions, run live against the checkpoint.
Press run. Every decision and every dollar below comes back from the checkpoint on this page — nothing here is pre-recorded.
How this demonstration is configuredthree amount bands
Three amount bands, so a proposal has something to be measured against. They are how this demonstration is set up, not what GaelOne™ is: cases 01 and 02 are both refused with the amount sitting perfectly inside its band.
$0.00 – $250.00
ALLOW
Authorized automatically.
$250.01 – $5,000.00
ASK
A person must approve it.
Above $5,000.00
STOP
Not authorized at all.
The case that defines GaelOne™
Case 01
A person approved a payment. The AI changed where it goes.
Same amount. Same payee. Same invoice. A different account. This is what invoice redirection actually looks like, and it is the reason approving an agent is not the same thing as approving a payment.
Case 02
A person approved $2,500.00. The AI tries to send $25,000.00.
Same invoice, same payee, same account. Only the amount moved after the approval was given, and the approval does not stretch to cover it — so the payment system is never asked.
Case 03
A small payment passes without anyone being interrupted.
The AI proposes $25.00 — at or under the $250.00 this demonstration authorizes without a person. Nothing has changed since, so the Gate opens and the money moves.
Case 04
A large payment waits for a person, and nothing executes meanwhile.
The AI proposes $2,500.00, which is above the $250.00 this demonstration authorizes on its own. GaelOne™ asks. The payment system tries to send it anyway and is refused — and then this one waits for you to approve it yourself.
Case 05
Emergency Stop outranks an authorization that is already valid.
A $25.00 payment is authorized and ready to execute. Then Emergency Stop is engaged. A stop that a small enough amount could reason past would not be a stop.
03What GaelOne™ leaves behind
See exactly what GaelOne™ checked.
This is the shape of the record GaelOne™ creates for one decision: the payment it checked, the values it compared, the answer it gave, whether the payment call was permitted, and whether money moved. Durable, exportable, audit-grade record-keeping is not part of this proof — see what it does not include, below.
Plate 03 Authorization records
Illustrative · same invoice, one field apart
REC-01
The approved payment arrived unchanged
Reference
inv_48219
Proposed by
AI agent
Amount
$2,500.00
Payee
Acme Supply Co.
Approved account
•••• 8472
Destination account
•••• 8472
Authorization
Covers this payment
Decision
ALLOW
Payment call
Made
$2,500.00
Money moved
REC-02
A payment to another account arrived
Reference
inv_48219
Proposed by
AI agent
Amount
$2,500.00
Payee
Acme Supply Co.
Approved account
•••• 8472
Destination account
•••• 2291
Authorization
Does not cover this payment
Decision
STOP
Payment call
Not made
$0
Money moved
The same invoice, the same amount and the same payee, twice. One field differs — the account the payment was going to when it reached the checkpoint — and everything after it follows: the approval no longer covers the payment, the decision is STOP, the payment system is never asked, and the ledger reads $0. GaelOne™ records what was decided and whether money moved; it does not move the money.
04The invariant
No valid authorization
No payment call
Nothing moves
An approval covers one exact payment, not the agent that proposed it. Change the amount, the destination account or the reference, and the approval no longer covers what is being sent.
How cases 01 and 02 are stopped
When a person approves, GaelOne™ records the exact payment they approved — the amount, the destination account and the reference. At the execution checkpoint it reads those same three values from the transaction it is about to send, not from the proposal it was handed, and compares them. A changed amount or a changed account is a different payment, so the approval does not match it.
What this proof does not include
In-memory state, one global Emergency Stop, no expiry, no signatures, no multi-tenancy, and a simulated payment system that records what it was asked to move rather than moving it. Those are real simplifications. The check itself is not one — it runs the same implementation GaelOne™ ships to customer-side verifiers.
AI can decide. GaelOne™ decides if the money moves.
Nothing has been asked of the checkpoint in this session yet. Money moved: $0.