Skip to main content
Tythe underwrites agents, not only the principals behind them. Every agent is assessed continuously on how it behaves, and that assessment is what decides how much of a principal’s grant it can actually use. This page comes before mandates for a reason. A principal writing a mandate is deciding how much authority to put on the table. What the agent can use from that table is decided here. Read this first, then Mandates.

The Conduct Rating

The assessment is called the Conduct Rating: a bounded measure of how an agent behaves against the mandates it has been given. It is built entirely from what the agent does on Tythe, it moves continuously in both directions, and it is the only thing that moves an agent’s authority inside the limits a principal set.

What it decides

A mandate grants a ceiling on every numeric field: the most the principal is willing to allow. The Conduct Rating sets the effective value inside that ceiling, and the effective value is what the account actually enforces. It never sets anything above the ceiling, and no single adjustment moves a field more than a registered step. Those are properties of the contracts, not promises from the engine.

What is measured

Every action an agent takes produces a receipt, and the receipts are the input. The agent’s ERC-8004 reputation from other counterparties is read as a weak additional signal. Another principal’s data is never used to judge it.

What raises it

  • Long runs of actions that fit the mandate on the first attempt.
  • A stable counterparty set, and payments that look like the agent’s own history.
  • Escalations that the operator approves, which show the threshold is set where judgement is actually wanted.
  • Sub-agents that behave.
  • Loans drawn and serviced on schedule.
  • Venue allocations that perform in line with published expectations.
  • Time. Consistency over weeks counts for more than a clean day.

What lowers it

  • Spend velocity far above the agent’s own baseline.
  • Bursts of payments to counterparties it has never used.
  • Rejected actions, especially repeated ones. An agent that probes its limits looks like a compromised one.
  • Escalations the operator rejects.
  • Actions outside the mandate’s time window.
  • Sub-agents that misbehave.
  • Missed capture on Loans the agent drew.

Automatic responses

A revocation reaches the chain as soon as anyone relays it, not only when Tythe does. It cannot be delayed by a stalled service.

Recovering after a tighten

1

Read the signal

Your current Conduct Rating and the signals behind the last change are readable through the developer surface. The console shows the principal the same thing.
2

Stop probing

Repeated rejected actions are themselves a negative signal. Read the effective value and act inside it rather than testing where the line now is.
3

Return to known counterparties

Novelty is what most anomaly bands are built around. Routine payments to an established set are the fastest way back.
4

Operate consistently

Recovery is gradual by construction: one bounded step per re-evaluation, on sustained clean conduct. There is no appeal that skips it.
If the tighten came from a misconfigured mandate rather than the agent’s behaviour, that is a conversation with the principal, who can narrow or reissue the mandate to fit what the agent actually does.

What it is not

  • Not creditworthiness. The principal is underwritten for credit. An agent’s rating measures behaviour.
  • Not portable authority. A high rating does not grant scope; it only moves the effective value inside a ceiling a principal set.
  • Not private. A bounded summary is published to the ERC-8004 reputation registry so other counterparties can see it, unless the principal turns publication off. Raw signals are never published.
  • Not permanent. It moves in both directions, continuously.

Mandates

How an action is checked, and what a rejection tells you.

Accountability

What is published, and who answers for what.