Spending rules · Vault program · Solana

Give your agent a wallet.
Keep it at heel.

Heel is a vault your AI agent spends from. You say which programs it may call, how much and until when. The program refuses everything else.

The rope

What you gave the agent. Change a rule and the counters start over, like in the program.

day 0, 00:00
The policy, in words

Or send the dog on an errand.

Drag the dog to a shop, or pick an errand. The instruction, the verdict and the reason show up here.
This session

    The rulebook, knotted on the rope

    Seven rules. That is all the rope is made of.

    How it is wired

    A vault with a rulebook bolted on.

    On Solana a wallet cannot run someone else's code, so Heel works the other way round. You open a vault: an account only the Heel program can sign for. You put the allowance in it. The agent gets its own key, and can only act through the rules. Your savings never go in.

    1

    Open a vault

    One transaction creates your vault, an address derived from your wallet. Only the Heel program can sign for it. You fund it with the allowance, in SOL and tokens, and nothing more:

    seeds = [ "heel", ... ]

    Take the funds back any time: you are the vault's owner.

    2

    Set a policy

    You send the program the agent, the limits and the call list. This is the real instruction data of the policy on the left, discriminator first, then the arguments:

    ...
    3

    The agent works

    The agent signs a transaction with its own key, for the Heel program, carrying the instructions it wants. Each one is checked against the policy first, then made by the vault. One refusal fails the whole transaction.

    // agent -> Heel program
    execute([ { program, accounts, data }, ... ])
    Why you can believe the screen above

    The bytes are the real ones.

    23tests that pass on the rules and on the bytes
    8kinds of instruction rebuilt byte for byte against @solana/web3.js and spl-token, for both token programs
    8programs and mints read from mainnet-beta, plus a real SOL transfer from a recent block rebuilt exactly
    0admin keys, upgrade rights or fees in the design

    Status: the rules engine and the wire format are written and tested. The Solana program is specified, not written. Not audited, not deployed. The page above runs the engine the program will have to match. The button in the session reads the real addresses from the cluster.

    Straight talk

    What it guarantees, and what it does not.

    The rope holds

    • An agent can only call the programs and instructions the policy lists, spend only what the limits allow, and pay only who you named.
    • An agent can never make the vault call the Heel program itself: the admin instructions stay yours.
    • Instructions that hand the vault's accounts away are refused even when listed.
    • A refused instruction fails the whole transaction. Nothing half-happens.
    • Pause, revoke and expiry stop the agent at once. Replacing a policy restarts its counters.

    What it cannot do

    • The program does not exist yet. What is built is the rules engine, the wire format and this site. Not audited, not deployed: nothing here holds funds.
    • Only what is in the vault is at stake. That is the design: keep savings out of it. Anything you put in is the agent's ceiling.
    • Limits are ceilings, not judgement. An agent can still spend its whole allowance on things you listed.
    • For a program the rules cannot read, like a swap, the vault's balances are measured around the call. That is a measurement, not a parse.
    • Periods are fixed windows: a burst at the end of one and the start of the next can reach twice the cap.
    FAQ

    The honest answers.

    Is the page above real?

    The verdicts come from the real rules engine, the code the tests check. The instructions it reads are built byte for byte like the ones @solana/web3.js and spl-token build, and the button reads the programs and the USDC mint from mainnet-beta. What does not exist yet is the Solana program that will enforce the same rules on the cluster.

    Do I lose control of my wallet?

    No. Your wallet is not touched. You open a separate vault, fund it with an allowance and own it: you can pause the agent, revoke it or close the vault and take everything back.

    Why a vault and not my own wallet?

    A Solana wallet cannot hand its signing to a program, there is nothing like EIP-7702. A program-owned vault is the way Solana does it, and it is safer by construction: the agent can never reach more than the vault holds.

    What stops the agent from editing its own rules?

    Only the owner can set a policy. An agent that points an instruction at the Heel program is refused (SelfCall), so it cannot change a policy or revoke itself, or anyone else, through the vault.

    Is it live?

    No. The program is specified and its rules engine is tested, but it is not written, not audited and not deployed. The site says so everywhere.

    Do I need $HEEL?

    No. The program has no token and no fee. See the token page.

    A dog on a long red rope, with gold coins marking the limits along it

    A long rope still keeps it at heel.

    Build a policy in the studio, test a transaction against it, and take the instruction data with you. Nothing to install, no wallet to connect.

    $HEELCommunity coin: address to be announced. It will be posted here and on the project's X first. Token page.