Bounded spending for AI agent treasuries: policy is enforced inside Safe.execTransaction, so an unsafe payment is refused on-chain before it runs. Live on Arbitrum Sepolia and Robinhood testnet.



Arb Guardian is an enforcement layer for treasuries that AI agents and bots are allowed to spend from.
The problem: a multisig controls who can sign, not what an agent is allowed to buy. Once an agent holds a key, or holds a standing approval, the only thing between your treasury and a bad payment is prompt engineering and an operator watching a dashboard. A recent Bitquery investigation linked one exploit group to 56 token launches on Robinhood Chain, about 13.3 million dollars. Those payments went through, and the alerts arrived after.
What Arb Guardian does: the spending policy lives inside the Safe's own transaction execution path. SafeTreasuryGuard reads policy from an on-chain PolicyManager during execTransaction and reverts before the inner call runs. Daily caps, per-asset recipient allowlists, and rejection of standing approvals are enforced at the moment of execution instead of reported afterwards.
The demo shows four real transactions on two testnet lanes running identical contracts:
Allowed payment, Arbitrum Sepolia: 0.001 ETH to an allowlisted vendor, settles in 115,476 gas, 3 logs.
https://sepolia.arbiscan.io/tx/0x1313db311ce1e99b3623c4b42e6d6f1e531f40bc3e7032f88c68a790343ba216
Refused payment, Arbitrum Sepolia: the same agent tries a 1 ETH payment against a 0.5 ETH daily cap. The transaction fails in exactly 90,135 gas, emits zero logs, and the treasury state never changes.
https://sepolia.arbiscan.io/tx/0xff26308871c5b7c36b477940dc1b7307f8fdbbd979190ef89760b86902a99524
Allowed payment, Robinhood Chain testnet: execTransaction succeeds, 118,492 of 145,051 gas.
Refused payment, Robinhood Chain testnet: reverts with CounterpartyNotAllowlisted(address destination), 93,410 of 1,500,000 gas.
Operators can also freeze an entire lane with a single on-chain call. In the recorded drill a bad request was detected and stopped in 1.6 seconds, the pause transaction was mined in 5.8 seconds, and the full incident response finished in under 34 seconds.
All six deployed contracts match the open repository source with exact matches on Sourcify across both lanes. 128 tests cover the contracts, the API, the shared policy engine, and the durable store.
What is not done yet, stated plainly: no external smart contract audit. No pilot users onboarded. No real USDG value has moved. The Arbiscan verification panel still needs an API key. Testnet only.
Live app: https://arb-guardian.sithunyein.com
Demo video, 3 minutes 47 seconds: https://youtu.be/hEbtdBj8tE4
Baseline disclosure: the repository was imported on Aug 1, 2026 with 121 files, and that import is not claimed as buildathon work. Every Arb Guardian commit came after that baseline.
All 65 subsequent commits are dated Oct 1 to Oct 3, 2026 and touch 131 files. What was built in that window:
Three Solidity contracts, PolicyManager, ExecutionGuard and SafeTreasuryGuard, plus a TreasurySafeShell, deployed and Sourcify-verified with exact matches on two testnets: Arbitrum Sepolia (chainId 421614) and Robinhood Chain testnet (chainId 46630).
Policy enforced inside Safe.execTransaction: daily caps on the native lane and on the USDG token lane, per-asset recipient allowlists, and rejection of standing approvals. The guard fails closed when a rule is unset or ambiguous.
A token lane built around a real 6 decimal asset, including an explicit test for the 18 versus 6 decimal trap that would otherwise let a wei sized number blow through a USDG cap.
Versioned policy digests, so every policy change and every allow or deny decision is stamped with a digest and can be audited later.
An operator app in React and Vite showing live spend counters, the review panel that explains a blocked spend, and a one click lane freeze.
An API in Node and Express, with schema validation, for policy reads and incident state, backed by a durable store.
Evidence recorded from the live chains: 6 of 6 contracts with exact Sourcify matches, 6 of 6 deployment drift matches, a guard proof, a settlement token check on both lanes, and an incident drill at 1.6 seconds to detect, 5.8 seconds to mine the pause, 33.8 seconds total.
128 tests passing: 69 contract, 25 API, 20 shared policy engine, 14 durable store.
CI, a production deployment, and a recorded 3 minute 47 second demo showing four explorer verifiable transactions.
Not claimed: no external audit, no pilot users, no real USDG transferred, and the Arbiscan verification panel is still pending an API key.
Bootstrapped. Not currently fundraising.