We Gave the Agent a Wallet

How a regulated exchange put coding agents behind five governance rules, why individuals use agents well and organizations do not, and what happens when agents start hiring other agents.

Share
We Gave the Agent a Wallet
Developers were already using coding agents privately, which created shadow IT nobody could see.

Based on a Bloom event in Seoul with AWS, a former OpenAI engineer, and the OKX team.

How a regulated company actually adopted it

The opening case was a major Korean crypto exchange, and the situation will sound familiar. Developers wanted coding agents for the productivity, security policy would not let the company provide them, so people started using them individually. Code was going places nobody could account for.

The fix was governance rather than prohibition. Five requirements: data privacy, isolation, network control, access control, and audit and monitoring. They deployed on managed infrastructure so data stayed inside the perimeter, wired identity to corporate SSO with MFA so nobody used the tool anonymously, and put an LLM gateway in the middle so every request passed one place where token usage, audit logging, and filtering happen.

Guardrails strip secrets and personal data before anything reaches a model. A shared skill hub keeps individual discoveries from dying as individual knowledge.

The result was that shadow IT disappeared, productivity rose, and they can swap to the best available model whenever it changes because the control layer is theirs.

Why individuals are fine and organizations are not

The first fireside guest spent two years as an engineer at OpenAI before leaving to start a company, and his problem statement was pointed.

OpenAI should be the best possible user of its own coding tools, and individually it is. That is exactly what broke collaboration. Everyone had their own workflow, so agents edited the same files and overwrote each other. One team wants exhaustive documentation and another believes code should speak for itself, and when those teams touch the same product the work gets written and unwritten repeatedly.

There is a frontier-lab-specific version too. Shipping an AI product means clearing an enormous compliance surface. Guardrails against catastrophic misuse, twenty or thirty teams coordinating, legal and ops. Code finishes and launch is still three to six months away.

The unit of work changed

His argument is that we used documentation tools because the unit of work between humans was the document. Write a PRD, write a design doc, share it, collaborate.

He considers that obsolete. In an agent era the unit is the workflow, the loop. His first instrument for that is a forward deployed agent: rather than every company hiring embedded engineers, integrate an agent into the workspace that discovers workflows on its own. Connect through APIs, scan asynchronously, find what repeats. Target finance, legal, and accounting first, where repetition is high and the return is obvious.

Asked what remains for humans when agents do most of the work, he named ownership and delegation. Running five agent sessions at once makes it obvious you only have one head. When someone asks who produced a piece of work, the answer is the person who built that agent. So communicating the boundary of ownership clearly, meaning what goal and what codebase, is the thing that matters most, and it is also what prevents agents from overwriting each other.

Trust becomes the currency

The second session was a panel with OKX. Asked to define the agent economy, the answer went back to fundamentals. An economy is service provision. One person provides a service another needs and value moves. An agent economy is the same thing between agents.

So what they are building is not the smartest AI but the infrastructure where any agent can find work, get hired, and get paid.

Asked what becomes valuable when anyone can build an agent, both said trust. You check someone's history before hiring them or buying from them. Agents need performance records and reputation before other agents will hire them.

On how much control to hand over, the answer was least privilege. An agent managing your email should get the minimum access that job requires. They cited an executive who delegated email management and watched messages disappear in front of him, stopping it only by killing the laptop. One catastrophic incident can take everything from a user, and every AI product should treat that as the first constraint.

The complementary view drew two lines: code, meaning what it may do, and money, meaning how much. Withhold the wallet entirely and a human has to complete every final step, so the loop never closes. The balance is letting it finish the job within a limit.

What stays with the human

The workshop closed the loop literally. Install an on-chain OS, create a wallet for the agent, fund it, and run a trading strategy. The OS installs from a single command and gives the agent a wallet plus pricing, trading, and payment abilities. The wallet is fully self-custodial.

The instructive part was that without stating budget, per-trade allocation, and stop-loss tolerance, no safe strategy emerges. The model will do what you asked and nothing you forgot to say.

An agent marketplace was also demonstrated, where you list an agent and other people, or other agents, pay to hire it. Asking your own agent to find a specialist agent and getting a report back for under a dollar is an economy that already runs.

Which leaves a clean summary. Give the agent the wallet. Keep three things: what it should do, how much it may spend, and the fact that it is yours and you are accountable for it.

Photos from the event


Join Bloom

Bloom builds offline rooms where people and technology meet. We run them in Seoul, and now beyond it.

Stop formatting proposals. Start winning them. Try Contrl Free Join Beta