Write the rules. Test the transaction.
Describe the policy, write what the agent would send, and see the verdict from the rules engine in your browser. Then ask Solana about every address you named. Nothing is signed or sent.
1. The policy
Call list deny by default: a program and its first bytes
Token limits transfer, approve, burn
Recipients wallets; used when "money only to recipients" is on
2. The transaction
The instructions the agent would send in one transaction. One refused instruction fails them all.
3. The verdict
In your browser
On Solana mainnet
Reads every program and mint in your setup from the cluster. Nothing is sent.
The vault, the agent and the people on the street are stand-in keys. Paste real program and mint addresses (Jupiter, USDC, any token) to check them against the cluster.
4. Take it with you
set_policy data
execute data
Send it with @solana/web3.js
The Heel program is specified, not written, not audited and not deployed: there is no program id to send this to. The rules engine behind the verdicts is tested, and these bytes are the wire format the program will have to read.