The signer follows the scope
You know the Envelope is the one authorization primitive. The next question is: who is allowed to sign one? Kestrel's answer is the two-signer rule, and its elegance is that the answer depends on nothing but the Envelope's scope. The scope is compiled into a signer requirement — it is not a label a caller can claim. This unit teaches where the line falls and why it falls there.
Two classes of signer, one line between them
A wallet may sign commerce-only, reversible scopes. Agentic commerce — a verified machine payer — can root authority for buying data, running a sim, earning a Grade, or paper trading. None of those is legally binding or irreversible: the worst outcome is a refund and a lesson. So a machine can settle them on its own, no human in the loop, which is exactly what makes proof-before-account possible.
A human must sign identity-bound, legally irreversible scopes. Connecting a broker, live trading authority, attestations, and unbounded-risk enablement all carry legal agreements or undefined worst-case loss. These cross a line a machine cannot cross alone — not because the machine is untrusted, but because the consequences are irreversible and legally personal. Live authority never extends past a human root.
The line is not "small versus large." It is reversible versus irreversible, commerce versus legal-and-risk. A wallet can spend a lot on data; it can never, by any amount of spending, mint the authority to place a live order. Price payment never supplies broker or live authority — that is the whole safety of the split.
The term sheet: the worst case, in dollars
When a scope requires a human signature, the request does not arrive as a wall of legalese or a checkbox. It renders as a term sheet — a plain-language approval page (the approval URL) that states, in words a person can act on:
- what the agent may do — the exact scope, not a vague permission,
- the worst case in dollars — the concrete downside, quantified,
- the duration — when the authority expires,
- revocation — how to end it, in one tap.
Two properties make the term sheet trustworthy rather than a rubber stamp. Its sliders may only tighten — a human can shrink the budget, narrow the scope, or shorten the duration, but the page offers no control that widens the grant beyond what was requested (the narrowing-only rule, surfaced to the person). And one tap revokes. The human is asked to approve a bounded, quantified, reversible-on-demand grant — never to sign a blank cheque.
Why show the worst case in dollars
The choice to render the worst case in dollars is deliberate. A human deciding whether to hand real authority to an agent should not have to reverse-engineer their exposure from scopes and limits. The one number that matters — how much can this go wrong — is put in front of them in plain money. That is what lets a person grant meaningful authority with genuine informed consent, and it is why the human signature sits exactly where scope becomes irreversible, and nowhere earlier.
See it in kestrel
Run a stressed session — the kind whose downside is exactly what a term sheet would put in dollars — entirely inside the wallet-signable, reversible tier:
npx kestrel.markets sim s-p-500-etf-pandemic-volatility-crashThat runs a deterministic simulation over a generic broad-ETF session with a real volatility spike — managed licensed data, no wall time, no signup, no card — and prints a certified proof URL. Point the CLI back at the proof and it recomputes the whole record on your own machine, byte for byte:
npx kestrel.markets certify https://kestrel.markets/proof/art_66d7dda7f0466f69c123463cKeep it one command away: drop the kestrel.markets MCP server into your client and the next session is already wired up — no account in between.