Coming with the beta. Payees with an activation delay work on Solana devnet today. Managing them from the Mini App, and the address-poisoning watch, are in development. See what works today.
Most crypto losses at small teams happen when someone pays a new or changed address, not inside the treasury. Pact only pays addresses on your team’s allowlist, and it checks every address against who your team actually pays.

Add a payee

1

The owner adds it

The owner adds the payee with a label such as “Audit Firm”, and optionally a cap for that payee. The bot posts the full address in the chat so everyone can read it.
2

The activation delay runs

The payee becomes payable after the delay in your policy, for example 24 hours. During the delay, the owner can remove it.
3

It's active

Payments to the address can now go through, inside your caps and budget.
Until the delay ends, a payment to the new address is refused. Payees you list when you first set the policy are active straight away.

What the card tells you about an address

Every request card shows one line about the payee:

Address poisoning

Address poisoning works like this: an attacker sends a tiny amount, sometimes zero, to your treasury from an address that starts and ends with the same characters as one you pay. Wallets shorten addresses to the first and last few characters, so the fake looks identical in your transaction history. The attacker waits for someone to copy it. Pact watches the transfers coming into your treasury. When a sender imitates a payee on your allowlist, Pact:
  1. posts a warning in the chat, for example: “Someone sent a dust transfer from 7xKpA3…Qe2c, which imitates Audit Firm (7xKp9f…Qe2c). Review the full address.”
  2. marks the address as flagged for later checks.
These checks are advisory. The chain enforces your payee allowlist and spending limits. If the address shows up later in an invoice, the card says “Flagged lookalike”, and the smart contract refuses the payment anyway, because the address isn’t an active payee.
Never copy an address from transaction history. Pay payees from your allowlist, and confirm any changed address with the person through a channel you already trust.