iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
An FX treasury agent can remember approved context, analyze currency exposure, and prepare recommendations without receiving authority to execute trades or payments. The separation has to exist in its tools, credentials, authorization checks, and execution path—not just in its prompt. This article sets out a build pattern for that boundary; it does not claim that any particular implementation or deployment has been independently verified.
What the agent can do—and what it must not be able to do
An agent is more than a model that answers questions. It may call tools, use an identity with delegated privileges, retain state, and take multiple steps. That creates a path from incorrect output to real-world side effects unless authority is deliberately limited. A useful design separates analysis from execution:
- Analysis: gather permitted data, identify exposures or cash-flow needs, explain uncertainty, and compare options.
- Recommendation: prepare a proposed action with its supporting data, assumptions, limits, and alternatives.
- Authorization and execution: a separate control plane checks policy and permissions; an accountable human or existing treasury system retains execution authority.
This boundary is consistent with Microsoft’s agent shared-responsibility and autonomous-agent risk guidance, and with financial-sector control recommendations. It is a design pattern, not evidence that a particular agent has been configured this way. To substantiate a claim that an agent never touches money, inspect its registered tools, credentials, policy controls, and execution-path records.
Draw the trust boundaries before wiring up tools
Map the components and the identities they use before connecting the model to treasury data. A representative flow is:
#1 Best Overall
- Memory store: provides approved, scoped context to the run.
- Model and orchestrator: interpret the request and decide which permitted read operations to call.
- Read-only data connectors: retrieve only the market, exposure, or workflow data the use case needs.
- Recommendation output: presents a proposed action and its basis without initiating it.
- Policy and authorization service: independently evaluates any request to cross into a sensitive action.
- Approval interface and treasury execution system: keep accountable approval and execution outside the agent’s authority.
For a genuinely non-executing agent, do not register payment or trade execution tools to it. Its credentials should be read-only or limited to necessary non-execution operations. It should not be able to change its own permissions, policy, or credentials. Any later handoff to a treasury action should require a separate authorized service and the appropriate approval.
A prompt that says “never trade” is not an authorization boundary. Apply least privilege to each tool and enforce authorization deterministically at the action boundary. A policy check should evaluate the actual requested operation and its parameters, not merely rely on the model’s explanation of what it intends to do.
Make memory useful without treating it as authority
Persistent memory can influence later runs, so it belongs inside the security boundary. It is not automatically reliable because it is stored in a database or retrieved as a vector. Define what the agent may remember, where entries come from, who can read or change them, and how long they remain available.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #2
Decide what is retained
Depending on the use case, memory could hold approved preferences, relevant prior exposure context, or workflow state. Keep credentials, payment instructions, and untrusted instructions out of it. Treat any retained financial context as information for analysis—not permission to act.
Record provenance and scope
Scope entries to the appropriate user or tenant, control access, and track their source and age. Keep imported invoices, emails, ERP records, market feeds, and remembered messages—if the system uses them—as data to evaluate, not instructions that override system policy. Separate instructions from retrieved content and validate tool parameters independently.
Provide correction, expiry, and deletion
Set retention rules and give authorized users a way to inspect, correct, expire, or delete stored entries. Decide how stale or conflicting context is handled. Isolation, encryption, access control, provenance, and defenses against memory poisoning are complementary controls; a memory technology alone does not provide them.
Rank #3
Put a legible approval gate in front of sensitive actions
Human review only works when the reviewer can understand what is being proposed. Before any sensitive action is handed off, present the reason for the recommendation, the data and timestamps used, relevant limits, uncertainty, and plausible alternatives. Make clear what approval would authorize and what system would act afterward.
Keep the approval decision separate from the agent’s natural-language claim that an action is safe. Apply the organization’s authorization rules to the action itself, including its parameters and the identity requesting it. High-impact or irreversible actions should require an appropriate human gate rather than relying on a model’s confidence.
Make the workflow observable and interruptible
Record enough information to reconstruct what happened: the identity involved, tool calls and parameters, results, rationale, approval decisions, and outcomes. Show users the intended action and its status. Provide a dependable pause, suspension, or override path so an operator can stop the workflow if its behavior or inputs look wrong.
Rank #4
Testing and production should be separated, with permissions and controls appropriate to each. The IMF’s April 2026 technology note discusses human approval for final actions, explicit permission boundaries, separation of testing from production, suspension or override, and logging for audits and incident reviews. These are governance recommendations, not proof that a particular agent meets them.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Use financial-services guidance as a governance input, not a compliance badge
On February 19, 2026, the U.S. Treasury announced a Financial Services AI Risk Management Framework and a shared AI Lexicon. Treasury described the framework as adapting NIST’s AI Risk Management Framework to financial-services operational, regulatory, and consumer-protection considerations, and as a way to evaluate use cases and manage risk across the AI lifecycle. Its existence does not establish that a particular design is compliant, approved, or safe to deploy.
J.P. Morgan’s June 25, 2026 corporate-treasury article offers an illustrative scenario in which an agent identifies a supplier-currency shift, proposes a rolling hedge, compares counterparty quotes, and queues a trade for human approval. It is an industry example, not evidence of results from a particular implementation. The transferable idea is the division of labor: an agent can do groundwork while a separate authority retains the decision to execute.
Best Value
What would prove that the agent never touches the money?
The claim should be supported by implementation evidence, not inferred from a conversational promise. A reviewer would need to see, at minimum, which tools are registered, what permissions and credentials they use, where deterministic authorization runs, and what logs show about attempted and completed actions. The architecture should demonstrate that the agent cannot directly invoke trade or payment execution, alter its own controls, or bypass the separate approval and execution path.
Microsoft’s rule of thumb is that “Autonomy never reduces accountability.” For an FX treasury workflow, that means the organization operating the system remains responsible for defining the agent’s authority, reviewing its actions, and retaining evidence of how decisions were made.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problems

