Coming with the beta. Payees with an activation delay work on Solana devnet today. Managing them from the Mini App, and the address-poisoning watch, are in development. See what works today.
Add a payee
1
The owner adds it
The owner adds the payee with a label such as “Audit Firm”, and optionally a cap for that payee. The bot posts the full address in the chat so everyone can read it.
2
The activation delay runs
The payee becomes payable after the delay in your policy, for example 24 hours. During the delay, the owner can remove it.
3
It's active
Payments to the address can now go through, inside your caps and budget.
What the card tells you about an address
Every request card shows one line about the payee:Address poisoning
Address poisoning works like this: an attacker sends a tiny amount, sometimes zero, to your treasury from an address that starts and ends with the same characters as one you pay. Wallets shorten addresses to the first and last few characters, so the fake looks identical in your transaction history. The attacker waits for someone to copy it. Pact watches the transfers coming into your treasury. When a sender imitates a payee on your allowlist, Pact:- posts a warning in the chat, for example: “Someone sent a dust transfer from
7xKpA3…Qe2c, which imitates Audit Firm (7xKp9f…Qe2c). Review the full address.” - marks the address as flagged for later checks.