## TL;DR

An agent posting bills can create real liabilities, so writes need layered guardrails: validation (matched, coded, within tolerance), limits (amount caps, daily totals), and reversibility (draft status first, post after approval). Start agents in draft-creation mode and graduate to posting with human approval, then to auto-posting for low-risk patterns only.

## Steps

1. Require validation gates before any bill create: match status, coding, tolerance.
   Expected: Only clean bills reach the ERP.
2. Create bills as drafts, not posted.
   Expected: Reversibility by default.
3. Enforce amount caps and daily totals per agent.
   Expected: Blast-radius limits.
4. Graduate: drafts, then approved posting, then auto-post low-risk.
   Expected: Earned autonomy.
5. Alert on guardrail trips in real time.
   Expected: Immediate awareness.

## When to use

- Enabling agent bill posting
- AP automation go-live
- Write-access security reviews

## When not to use

- Read-only extraction agents
- Human bill entry
- Payment execution

## Compatibility

ERP-agnostic; enforced in the agent orchestration layer.

## Variant phrasings

### agent posting vendor bills safely

### AP agent write guardrails

### safe autonomous bill creation

## Root cause

A bill posted is a liability recognized. Without guardrails, a bug or prompt issue can post thousands of bad bills before anyone notices.

## Edge cases

- Draft status differs by ERP; confirm the draft concept exists
- Caps need periodic review as volumes grow
- Emergency bypass needs break-glass logging

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_nErck9ZW9DRylcxclIo7YQ
