Who holds the keys
You do. Pact is non-custodial. Your treasury is an account owned by the smart contract, with your team’s wallet as its authority. Pact never holds your wallet keys, and only the owner wallet can withdraw.What the agent can do
The agent can propose payments, trades, and service payments. That is all it can do. It can’t withdraw, choose a payee, add a member, or change the policy. What it spends on paid services comes from a small purse, topped up only inside the service budget you set. Every request also needs the requesting member’s own device key, so the agent can’t invent a request in a teammate’s name. The smart contract checks every proposal against your live policy before anything moves.If something is compromised
If Pact’s servers go down
The agent, the Telegram bot, the Mini App, and our indexer make Pact convenient, and none of them enforces anything. Switch them all off and your treasury still refuses payments that break the policy, and the owner can still withdraw by signing with the owner wallet. A signer may refuse; only the chain may permit.Revoke the agent
The owner revokes the agent in one transaction, and it takes effect in that transaction. The next request is refused as revoked. Your funds stay in the treasury, and the owner keeps full control to withdraw.Revoking is verified on Solana devnet. Revoking from the Mini App, and letting any member revoke the agent in an emergency, are coming with the beta.