Rails
What pays when a request is approved. Honest status per row.
| Rail | Status | What happens on approve | What you configure |
|---|---|---|---|
| Log-only | Live | Nothing pays. Agent reports the payment it made; RailGuard verifies merchant + amount. | — |
| Stripe Issuing | Preview | Single-use virtual card issued, capped to the approved amount. | Stripe Issuing account + secret key in Settings |
| Ramp | Preview | Virtual card with a limit for the approved amount. | Ramp API connection in Settings |
| USDC | Preview — not live | Signed transfer from your wallet to recipient_address. | Not for production use yet |
"Preview" means the code path exists and runs with sandbox credentials, but has not been reconciled end-to-end against a live provider account.
- Demo workspaces always use sandbox credentials — they can never move money.
- Live workspaces fail closed: no configured rail → no payout, the transaction records why.
- Card secrets are handed to the agent once, then wiped from storage.