Two tiers, and the one that is new

Every bound in a mandate is one of two kinds. Telling them apart is the difference between a rule engine and supervision.

Tier 1 bounds an action

Size, instrument pair, venue classification, expiry, agent identity. Each is decidable from the action in front of you and nothing else: this action is 240,000, the cap is 250,000, it passes.

Every serious platform has a rule engine that does this, and AMW checks these again because the contract is the authority and a check the authority did not make is a check somebody can route around. But this is not the contribution, and we say so plainly: tier 1 belongs to the rule engine every platform already has.

Tier 2 bounds a sequence

Aggregate notional per epoch, action count per epoch, and off-primary venue concentration. None of these can be decided from the action in front of you — they need the epoch's history, and they are the clauses an unauthorised outcome has to cross when every individual step is authorised.

The same nine actions, judged by each tier
QuestionTier 1 answersTier 2 answers
Is action nine permitted?Yes — 240,000 is under the 250,000 capYes, and irrelevant
Is the sequence permitted?Cannot ask the questionNo — the epoch would reach 2,160,000 against a 2,000,000 bound
Which clause stopped it?None3.4 and 3.7, cited in the case file and on the topic

Evaluated before settlement, on the intent

Tier 2 is checked before the action executes, against the window as it stands plus what this action would add. A check that runs afterwards produces a report; a check that runs before produces a hold, and only one of those is a control.

Every ancestor is debited

An action under a child mandate debits the window of every mandate in its delegation chain. Without that, delegation is the bypass: an agent given four child mandates of a quarter of the budget each would have the whole budget four times over. Child mandates narrow monotonically, and windowSeconds must be equal to the parent's — a shorter child window resets faster than the parent it debits, which is the same bypass in slower motion.

A hold consumes no budget. Window state is untouched when flags are non-zero, so a held action is not a spent action, and an agent that retries smaller is bounded by the action count rather than by luck.