Administrator guide
For the people who run Lumière PayCheck inside your company: controls, alerts, reviews, and audit.
Roles and access
- Owner key: full control, including people and billing. Store it in a password manager; if it's ever exposed, ask us to send a new owner access link, and the old key stops working as soon as the new one is claimed.
- Administrators: each person has their own key and a role (viewer, approver, admin). The owner can change roles or remove people from People; removal takes effect immediately.
- Every change is recorded in the activity log with who made it, including any change made by Lumière PayCheck and any time our support opens a read-only view of your workspace.
Agent keys
- One key per agent, so each has its own limits and its own audit trail.
- New key replaces an agent's key (the old one stops working immediately); Revoke retires the agent.
- Expiry retires keys automatically after a number of days.
- IP allowlist: list addresses or ranges (for example
203.0.113.5or10.0.0.0/8); requests from anywhere else are denied, with the reason recorded. - Test keys: decisions are marked test and never count toward spending, caps, alerts, or reports; receipts carry
"test": true, so production wallets can refuse them.
How a decision is made
A payment is denied if any of these apply, and every reason is listed on the decision:
- The agent key is revoked or expired, or the request comes from outside its IP allowlist
- The seller isn't one of the agent's allowed sellers, or is on your company blocklist
- The endpoint is failing, risky, or the amount or wallet doesn't match what we observed
- The payment would exceed the agent's per-payment, daily, or monthly limit
- It would exceed a company-wide cap, the maximum single payment, or uses a network you don't allow
- The freeze switch is on, or the workspace is suspended
Otherwise it goes to review if it's above the agent's review threshold or to a wallet the agent hasn't paid before (Business and Enterprise), and is allowed if not.
Human review
Payments waiting for approval appear under Waiting for your approval. Approvers, admins, and the owner can approve or deny them; they expire after 24 hours. You can also receive a webhook for each new review.
Company controls
- Freeze switch: pauses every agent at once. Use it if you suspect a leaked key or a misbehaving agent; unfreeze when resolved.
- Company blocklist: hostnames and payout wallets that are always denied.
- Caps and limits (Enterprise): company-wide daily and monthly caps, a maximum single payment, and allowed networks, set for your workspace on request. Your agreed terms are shown on the account page, with spending against each cap.
Alerts
Set an alert email and/or alert webhook under Company controls.
| Alert | When |
|---|---|
| Budget | Spending reaches 50%, 80%, and 100% of a company cap or an agent's daily or monthly limit (thresholds adjustable), once per threshold per period |
| Spike | An agent spends at least 10 times its 7-day daily average in a day (multiplier and minimum amount adjustable) |
Webhooks are signed with your workspace's secret; see verifying webhooks.
Reports and audit
- Spending by team: allowed spending over 30 days by each agent's team, with a CSV download by agent.
- Recent decisions and CSV export (Business and Enterprise) of the full audit trail.
- Replay: any decision can be re-evaluated from its stored inputs to show exactly why it was made.
- Verify audit trail: recomputes the hash chain over your decisions and reports the first record that was altered or is missing, if any. The oldest retained record anchors the chain after the retention period.
- Security tool streaming: every decision sent to your SIEM as it happens, including its chain hash.
Retention
Decisions are kept for your plan's audit period (30 days on Builder, 1 year on Business, custom on Enterprise). Full retention details are on the security page.