Refund Guard

Stop an AI agent from issuing a refund above an amount you set. Refund Guard denies the tool call before the refund function runs, with optional human approval for a middle band.

Real-Time(Preventive)Checked before the call runs, so it can stop it

A support agent can call issue_refund, and the model fills in the amount. Refund Guard looks at that amount before the function runs. Above your cutoff, the function does not run.

Runs On
The SDK only
You Set
The refund tool names, a currency, and a Deny Above cutoff in that currency.
Your Agent Sends
The refund amount in the tool arguments

What Happens

With a $50 cutoff and Block on:

Refund amountResult
$20, or exactly $50The refund function runs.
$80The call is denied. The function body never runs, and the agent gets an error for that call.
No amount on the callThe rule is skipped and the function still runs. The match is recorded as a warning.

Observe records the match and lets the call through. Warn does the same and marks what would have happened. Only Block denies the call. The trace is saved either way.

Set It Up

  1. In the app, open Policies and click Create Policy.
  2. Choose Refund Guard.
  3. Leave Named Tools selected and type the real function name, such as issue_refund.
  4. Choose a Currency. USD is the default. Set Deny Above in that currency.
  5. Leave Amount Field as amount, or enter the field your tool uses.
  6. Set the mode to Block, then click Activate Policy.
  7. Wrap the agent with govern() and mark the refund function as a tool.

A bare number such as 40 uses the policy currency. With Ask For Approval off, a currency code on the call is not treated as a separate reason to deny.

Named Tools Or Detect Automatically

Named Tools is the accurate choice. Only the functions you type are capped. Detect Automatically guesses from the function name, looking for words like refund. A lookup that merely has an amount field is not treated as a refund.

Optionally Ask A Person First

Some refunds are too big to run on their own but too common to deny. Turn on Ask For Approval and set a lower limit. Refunds at or below it run. Refunds between it and Deny Above wait for a person in the Approvals inbox. Refunds above Deny Above are still denied. Approving does not run the refund for you. Your own server does that. Your agent needs Python SDK 0.1.32 or TypeScript SDK 0.1.18 or later. Read the approval guide.

Good To Know

  • Traccia never moves money, calls a card network, or undoes a refund that already happened.
  • This policy needs the SDK and a tool span. It does not apply on the Gateway.
  • It is not Spend Cap. Spend Cap limits what the model call costs. Refund Guard limits money the agent moves through a tool.

For a full example with a small agent, see Cap Refunds And Purchases.

Next Steps

© 2026 Traccia.