
Rodrigo Coelho
Rodrigo Coelho (pronounced KWAY-lee-o) is a serial entrepreneur and seasoned technology leader and early web3 innovator with over two decades of experience in engineering, entrepreneurship, and decentralized infrastructure. In 2025, he became Chief Executive Officer of Edge & Node, the core developer of The Graph, where he guides the company’s vision, strategy, and global growth.
Rodrigo was the first hire for The Graph, playing a pivotal role in its early architecture, ecosystem development, and community expansion. His career began in the late 1990s, when he co-founded an application development firm during the early web era, delivering solutions for Fortune 500 clients. He later founded and successfully exited two technology startups, further solidifying his track record in innovation and leadership.
With a foundation in Industrial Engineering, Rodrigo is recognized for his strategic vision and deep technical expertise. He is committed to advancing the decentralized web, empowering developers, and fostering a thriving global community through research, partnerships, and open innovation. He is based in the San Francisco Bay area.
We spend a lot of time talking about AI that recommends, drafts, and advises. This episode is about the moment AI stops advising and starts spending. Rodrigo Coelho, CEO of Edge & Node and a founding member of Ampersand, joins Kristina Podnar to talk through what actually changes when an agent can move money on behalf of a person or a company. On the new agentic payment rails, the money is gone the second it moves. No chargebacks, no calling the bank to reverse the wire. That means the guardrails must sit in front of the transaction, not after it, and Rodrigo makes the case for putting policy checks at the wallet level, outside the LLM, where a hallucination or prompt injection can't reach them.
This episode also digs into the distinction every organization needs to get precise about: giving an agent permission is not the same as giving it authorization. Because an agent can technically hit a payment rail doesn't mean it's been given the authority to act. And when something goes wrong, someone is still on the hook, and that someone is a human. If you're running POCs or just trying to figure out what agentic commerce means for your organization, this conversation gives you a practical way to think about identity, authorization, observability, and governance before you hand any system a wallet.
[00:00:00] INTRO: Welcome to The Power of Digital Policy, a show that helps digital marketers, online communications directors, and others throughout the organization balance out risks and opportunities created by using digital channels. Here's your host, Kristina Podnar.
[00:00:19] KRISTINA: Hello, everyone. Today, we're talking about a problem that sounds futuristic until you realize that much of enabling infrastructure is already being built. AI agents that can act on behalf of people and organizations, interact with financial systems, initiate transactions, and potentially move money. That raises an obvious question for us all.
What happens when we give an autonomous system the authority to spend? Underneath that much harder question about identity, authorization, accountability, auditability, and really we're focused on what happens when something goes wrong. I know we don't wanna think all about risk, just about the opportunity, but sometimes there's risk we need to pay attention to as well.
My guest today is Rodrigo Coelho. He's the CEO of Edge & Node, the core developer of The Graph. Rodrigo has spent more than two decades across engineering, entrepreneurship, centralized infrastructure, which means that he's been in it deep. He was the first hire at The Graph and played an important role in the early architecture, ecosystem development, and community growth there.
He's also a founding member of Ampersand, which is working on policy and compliance infrastructure for agentic commerce. So we definitely have somebody in the house who's an expert and ready to give us the details. Rodrigo, welcome to the Power of Digital Policy.
[00:01:37] Rodrigo: Thank you so much. Happy to be here.
[00:01:40] KRISTINA: Hey, before we jump into payments, I wanna start with a shift you're seeing more broadly today. What changes really when we have AI moving from recommending what should happen to actually taking action on behalf of a person or an organization?
[00:01:56] Rodrigo: Yeah. There's a big leap, obviously, because the question is the human in the loop, quote unquote, w-which we talk about. So, , what needs to be in place are the pieces of infrastructure and control that we're all working on and what we've been focused on. And those pieces need to be in place such that the human who ends up being the responsible party feels comfortable enough to sign off on this and let the thing run by itself. So, so what we need to have are rules, guardrails policies and procedures so that the agent itself cannot act out of bounds. Today there are still risks, and I think that's why we haven't seen, like, a mass takeoff or mass adoption. What we're seeing is more kind of, I would say, experimental use. We've got people developers using OpenClaw and kind of like paying for things within bounds, like maybe buying something on Amazon or doing like an Instacart order. And just really there's-- we're at this sort of early adopter phase of people experimenting with these tools, seeing what's possible and it's still early. And so when we're talking about broader adoption or enterprise adoption, there needs to be a lot more pieces in place, which is hopefully what we'll talk about today and what we've all been working towards to, to put in place to where humans will feel comfortable enough to, to let these systems run on their own.
[00:03:31] KRISTINA: Yeah, you mentioned something really important, and it seems to me like we've spent years now discussing AI systems that generate content. They surface recommendations. They help us all make decisions, maybe in the workforce. Payments cross a different boundary because the system can create an immediate, external, and sometimes really irreversible consequence, it seems to me.
So what becomes materially different when that AI agent can initiate a transaction or maybe move money around rather than simply recommend what a person can do? Like, is it actually- it's like- ... like, I guess, I'm won- Yeah. I'm wondering like is, is the payment itself the key threshold, I guess, is what I'm getting at, or is there differ- deeper issues we should be thinking about?
[00:04:14] Rodrigo: When you're dealing with a pay- like you said, once the payment is released, it's gone at that point. Now, when we talk about older systems like Visa and MasterCard, they have built-in mechanisms for chargebacks, right? Like, that's kinda what 2% to 3% fee baked into those systems are and like the, the merchant fee and the interchange fee. So there's like the rails fees, but then there's also kind of that 2% to 3% that's, that's paid, and that covers when things go wrong, meaning like I'm not happy with my purchase, or it's not working right, I want a credit back. And so when we're-- we've built these systems today like X four O two and AP two with Google and NPP. So these are like acronyms for different payment rails over stable coins and internet rails. Those are very low fee low cost, very tiny transactions, and they really don't have this, this part baked in for what goes wrong. It's really there's an assumption made that's like, okay, I'm dealing with a counterparty. I make a request, and I make the payment, and it's done, and it's kinda like irreversible at that point. And especially on stable coin rails, it's like, you know, when you're dealing with like crypto, you send the money, and it's kinda gone. Like it's not like a wire transfer where you call the bank, say, "Hey, that was a mistake. Can you like reverse the wire?" That doesn't exist in these kind of like crypto stable coin rails. It's like it's gone, and they consider it gone, like the money is gone. So that's why we need to have these kind of like extra protections in advance of the transaction happening because these, these new systems for agentic commerce were built to be super high speed, super low cost, super... it happening at machine speed, not where it's like there's a payment, and then there's like a person, an authorization, and like let me check the policy, right? Like a, a slower, maybe like larger transaction. It's sort of like a different use case and different model where you've got what we used to call bots that we now call agents are just interacting, you know, millions of times a second doing all kinds of things. And the main use cases we're seeing or what are being discussed is like agents paying for-- paying other agents for tools and things they might need along the way of completing a task. And so you have an agent that says, "Hey, I need to get from point A to point B," or like, "I'm trying to book a ticket to Bangkok." And it's got to, it's gotta reach out and search this sort of marketplace for what other agents offer. It might need like-- and you might ask it like, "Okay, book a ticket where the weather's great," or- Find me a ticket that whatever task you're given. So it might need more information that it doesn't contain. And so what's being built are sort of marketplace of agents where they will go out and seek and get other information, but they might pay a thousandth of a cent to that agent that holds that information to give that agent the information it needs to complete kind of the steps along its task. And it might have multiple steps along the way while it's thinking about it and gathering the context it needs to complete that.
And so what's being envisioned are these like, this economy of micro payments and negotiations and transactions that may not necessarily be in the case of like, okay, I need a chargeback in case this is faulty or it's a different kind of mental model for those. But it can also scale to that sort of thing. Like you could have agents doing like larger, say asset transfers at financial institutions, or it could do like treasury management, or it could do like large scale trading. So the thing scales from, you know, micro payments happening millions of times a second to a large transaction. Obviously it goes from fast to slow, like extremely slow- many checks, policies, and guardrails. So in the case of like the low risk, like thousandth of a cent transaction- It's in terms of, like, the amount of process control needed there, it could be sort of like, okay, don't spend more than X amount per transaction, or the thing you wanna get away from is having the agent get in an endless loop and continue spending out of control, which has happened, actually. There was a case where two agents kinda got in this loop, and they spent, like, 11,000... or $47,000 in, like, 11 days of just going back and forth, and that was where there was no kind of, like, check or policy or... So that's a real example of of needing those guardrails in place. So yeah, that's kind of a long-winded way to say that, like, these these pieces for being able to stop and put boundaries around what these agents are doing are, are absolutely required when they deal with, like, getting money in their hands and doing things that are irreversible.
[00:09:40] KRISTINA: I think one of the key distinctions that you're pointing us towards is that organizations will have to become more precise about what's different, what a agent can technically do something and what it actually has been authorized to do, right? , Things like access to accounts, an API or a payment rail is not the same thing as permission, right? Just because you can do it technically doesn't mean that's the authority that we give it. So how should organizations define and enforce the difference between an agent's technical capability and its legitimate authority? Like, when you're working with folks, how do you get them to think about authorization and, what does authorization really mean in context?
[00:10:23] Rodrigo: Yeah, that is the key decision that organizations need to make is whether or not I, I give this autonomous agent authorization to execute. And I-- what will happen in my view is that there's gonna be sort of a soft off-boarding so that you might give an agent permission, but not authorization. And so the agent will get to the point where it needs a human, a final human to, like, sign off and do the actual authorization step. And I think things will run that way for a while, until such time that there's been enough time elapsed where nothing's gone wrong, and then there will be a point where an organization says, "Okay, we've run for six months or a year or two year," however long it is to say, "Okay, we feel confident enough that we've got enough cycles. We've seen kind of boundary and edge cases to say, 'Okay, we can now give this this agent the authorization to to complete the task at hand.'"
[00:11:30] KRISTINA: What are the triggers or what are some of the testing scenarios that folks should be thinking about? Because I'm thinking about what you're saying in terms of an agent running for a certain period of time, and certainly if it can run for a certain period of time without having negative consequences or behaving within expected parameters, it gives us a level of trust. But we have to remember that agents are different, right? AI models are different than traditional software in the sense that they can, at some point in time, have a different path than what they've previously demonstrated. And so there's a little bit more of a leeway. There's more freedom technically there. How should an agent behave when the instruction becomes ambiguous or something changes in the environment or maybe two policies conflict? Are there triggers and parameters that you recommend so that we can understand when a transaction falls outside of an approved pattern?
[00:12:20] Rodrigo: So in our case, our approach has been that we built the policy engine outside of the LLM. And so when you think about a harness the agent harness or the LLM is subject to, like, prompt injection or hallucination. So you wanna build the policy system outside of that. And so with Ampersand, we've taken the approach of putting that at the wallet level. So really it's a hard stop. The policy checks happen where at the wallet level, so it really protects against, like, hallucination and prompt injection or... And so, that would be one recommendation we have is that, Is not having the, the rules and policies sort of at the same level of like the LLM model that can be, subject to yeah, hallucinations and things going off the rails, which we've seen. And so when, when it sits outside of that, the policy check happens, and when you get any conflicting results or anything, it simply goes to, like, a human checker or a human authorizer. And that can be additionally optional. So you could say, "Okay, we wanna have a human do the final check-off before..."
So it's like signing in a crypto transaction, you sign a wallet transaction. And so you might need a human to actually click on it and make that, like, a policy or a rule that needs to be set in place, so a human has the final check before it, they hit Send. And then you could turn that off. And so then as I was saying, like, enough time has elapsed. We could say, "Okay we're comfortable enough that the rules are being respected at the wallet level. We haven't seen any kind of hallucinations be able to circumvent that, and so we're gonna take off that human check. And so we don't need a human to actually click, Send on each transaction." And so that's how I view the, the progression happening.
[00:14:22] KRISTINA: I know for a, a lot of the listeners that we have out there, there's probably a bright red neon light somewhere flashing saying, "Who should be accountable when an AI agent makes that unauthorized, incorrect, or harmful payment that will ultimately happen," right? Is it the deploying organization? Is it the person who delegated the authority? Is it the developer? Is it the model provider? Is it the agent platform? Is it the financial institution? You mentioned Visa, MasterCard, 3%. Is that enough really to deal with that, whatever bad situation might come? What happens when it's not MasterCard or Visa, it's somebody else? So who really becomes accountable, or is it a combination of those parties? How's that working, or how do you see that working?
[00:15:03] Rodrigo: This is an open question and people are really struggling or debating and discussing around like authorization and who maintains responsibility. At the end of the day, it's gonna be human, even though we're dealing with agentic systems, like some human is, the proverbial buck stops here. It's gonna flow up to the highest executive at an organization that has oversight over that. So maybe it's like legal officer, chief policy officer, chief financial officer when it comes to that. And so again, those people who ultimately have the final sign-off are gonna be the ones that have to be comfortable enough to say, "Okay, I accept the risk of this if like, if things go haywire." And that's where you put the kind of per transaction risk threshold in place. So It's a lot different if you say, "Okay, this, this agent has authorization to transact $10 million per transaction," or if it's just, like, a thousandth of a cent. So okay, if things went wrong on a thousandth of a cent, no big deal. But on a $10 million transaction, like, that's a big deal. So that's where you kind of create your level of comfort, and maybe, like, above a certain dollar threshold as a human final sign-off. Below a certain threshold we can accept the risk that if it does in the event of of something, some catastrophic failure, the loss is capped at, like, whatever dollar amount that is. Say, it's... And then that varies based on organization. Maybe it's $5, maybe it's $5,000 or 50, so that comes down to math. So it's based on, like, dollar amount, risk, ri- potential risk of going off the rails, and you sort of come up with a formula that works for your risk tolerance within that organization, weighed against the cost of human intervention or having humans doing compliance checks and authorization checks, like the staffing costs of that. And whether or not that you wanna streamline operations and it will greatly benefit your manner of doing business. So I think those are all the sort of parameters upon which you would make that determination- in terms of how you set up the system.
[00:17:20] KRISTINA: I can see that working really well when maybe you have a procurement agent working within an organization. But if you have an enterprise agent, a model provider, and then you get into, third-party tools maybe a vendor's agent, a payment processor, you get financial institutions, you're going across the enterprise between different enterprises. It seems like each party then starts to control only a part of the chain. Are we creating an environment in which responsibility is distributed across so many participants that everyone can plausibly point a finger in a different direction and say the failure happened somewhere else?
[00:17:57] Rodrigo: Yeah. And so this is this is actually an area that needs to emerge, which are, like, standards-based systems that that can talk to each other in a, in a unified format. And that's being worked on. We've been talking to Amazon, we've been talking to Microsoft. Like, all these large organizations are coming up with a means in which in a standards-based way for how these varying systems can talk to each other and deal with that. And I believe that has to emerge as well in order for this to scale. Like, for example- Something as simple as partially what is a blocker for agentic commerce to scale is simply on the merchant side. So you have, like, the buyers that have these agents, and they, they can now, get credit cards and pay. But then on the merchant side, think of all the millions of merchants globally, and then accepting that form of payment. They have to, set it up and, they're thinking, "Oh, do I have to set up a wallet now?" And then, "How do I, receive these funds, and how do I account for them?" And, there's a lot of questions that go into that. And I think, people like Stripe and Amazon and Microsoft are working on ways to, to onboard companies into this, these new forms of payments in a structured manner that's also interoperable and standards-based. So it becomes much easier for companies to adopt. And so when we're dealing with procurement and companies across borders and wanting to transact, we need to have a more universal language. And I know there are various teams, like, working on manners in which that can work, and yeah, large companies and consortiums working on, A means in which they all can talk to each other and deal with permissions and authorizations and I know Microsoft is- wants to implement, an Azure ID for identity and use that for permissions. And so amongst, like, global Microsoft clients, then if they're on that standard, they can easily transact and talk to each other. Or, Amazon is working on an agent kit. So yeah, there's lots of different large organizations that deal with many large enterprises that are working on standards for that.
[00:20:24] KRISTINA: Where do you think we are in the evolution of that? Where are we in terms of the timescale, because I think everybody's so excited about the possibility here, but the reality is you're talking about, like, well, we're working around standards, and Microsoft. Well, that's great for the azure environment. But like TikTok, clock is ticking how long i- is it going to be until... let's pretend we're back in the early days of HTTP, right? And we're gonna take five years until we get a really nice website without the spinning logo. How long before we get the spinning logo, Rodrigo?
[00:20:52] Rodrigo: All right. Yes. Well, if I had my crystal ball. So I think what happened was everyone, it was this super excited hype cycle at the beginning la- like, last year when Explorer 2 came out, and then we had all these leaders come out, like Circle, Jeremy Lair was like, "Billions of agents are gonna transact." And Coinbase is, Brian Armstrong, we're like, "We're gonna have billions of agents." So I think the, that is coming, but people maybe thought, oh, this is coming, like, right now, so fast. And so there was this race and hype to build. And then, so , there was this initial kind of excitement, and I think reality set in as like, okay, there's a lot of things we didn't, like, think about that we need to put in place, which are these kinds of questions that we're talking about now, and especially at the enterprise level. And then we're finding on the demand side, so on the buy side we haven't seen, like, tremendous uptake by the, broad adoption. There hasn't been, like, the killer app or the killer use case where people are like- I absolutely have to use an agent to buy this thing for me, right? Like, we were talking about this future, maybe devices becoming voice-based, right? This transition to where we're interacting with compute in a different way. And maybe that is when these converge and, and then you're, you're talking to your computer, and then you're having this thing do the what you would normally click around your computer on. So to me, it still feels like a couple of or more years off to get there.
At first, I'd thought, "Okay, next year we're gonna see this uptake." If you would've asked me this last year, I would've said, yeah, within like a year we'll start to see this. And now that we're a year longer in and seeing what has been transpiring and in terms of like the lack of the sort of buyer side demand, consumer demand, or we're seeing a lot of supply. So we're seeing a lot of infrastructure built in place. We're seeing all the rails being put in place which is similar to what happened kind of in the crypto market, right? We had so many blockchains, so many layer ones and layer twos built for this demand that sort of never came. And so I think we're seeing this now as like all these companies spinning up and infrastructure tools and providers and da, da, da. But like, where's like the demand happening? And so that is what there are teams working on that now on the demand side and like consumer-based applications that will drive people towards that behavior. And then on the enterprise side, it still feels, yeah, a couple years off at least. Because you know, I'm talking to tier one financial institutions that are very much interested in this, but They, they might have an AI team and a blockchain team, and they're sort of like separate teams, and they're talking about it, and they're just looking at like, "What are the use cases that we could use internally? And let's build a POC." And it's still very, very early in terms of like, let's build kind of this demo thing that does this thing. But nowhere near we're gonna put this in full scale production and manage, 100 billion in treasury, right? Like we're very far off from that. And even, if you look at the TradFi world, I mean, even adopting like stable coins and crypto. Like Bitcoin's been around for over a decade. Blockchain adoption has taken, Ethereum launched in what? 2014. So almost a decade for that. So I don't wanna say we're a decade away on this kind of stuff, but I'd definitely say we're several years away from seeing it more more adoption on the enterprise side.
[00:24:43] KRISTINA: Obviously there's a lot that needs to be done on the technical architecture front, which you've pointed out. But, what really do we need to do on the regulatory part at this point, and what's non-negotiable in that technology layer? The identity, the authorization? Is it the relocation? Is it the providence? Like, what, what do we need?
[00:24:59] Rodrigo: These are all like just the identity one alone is like a big thorny issue that has been discussed for a long time. No one has really been able to, to come to a universal standard. And there's many different teams and companies and consortiums working on, on standards in that front. But of course, identity is absolutely important because, when you're dealing with an agent that just sees like a wallet address as the counterparty, it needs to know like where did this come from? Who created it? What's the reputation? What's the provenance, the authorization of this before it can proceed. And yeah, right now there's no kind of universal or even like consistent way in that and that's handled. There are open standards towards that end. Like the, there's an ERC-8004 standard that sort of has an open kind of an open source, decentralized sort of marketplace with reputation where agents can advertise their services. Coinbase has like a bazaar type of thing. I think there's gonna be others that emerge. So that's on the like identity and reputation front. You mentioned earlier we talk about four things like identity, authorization observability, and governance. So those are the top four that I think regulators need to look at of having the pieces in place and have rules around those. With governance, like is there a kill switch or is there a authority that can be withdrawn or, or put forth and how is that done? And then with observability. So that's the beauty of using stable coin and blockchain rails is the transactions are open and transparent and not going into a black box. So observability of what happened on the transaction, but also the agent's kind of decision-making basis and sort of, the verifiability over what checks were made before the transaction happened is important. So log of that. And then yeah, the authorization. So yeah, who designated and delegated the authority and, yeah, what are the, the parties that are responsible. So I think those are the four main areas that, policy makers need to look at to have rules and regulations around those.
[00:27:29] KRISTINA: I think there's so much potential here, we've been talking about agents that can transact on behalf of organizations. They can remove all of that friction that you mentioned. Certainly, the idea that we can accelerate business processes is very enticing. What does responsible agentic commerce look like in five years from now if we get policy and infrastructure right? Especially for folks that are sitting inside of an enterprise, they might be doing some POCs, they might be playing around, right? But they're still not at a point of doing any type of agentic payment processing. What would that kind of confident ecosystem look like so that we have that trustworthy direction, and what do you think leaders need to be thinking about right now?
[00:28:08] Rodrigo: I believe in five years we will have these pieces in place, and it will be easy for enterprises to pick and choose from open standards to drop in to their systems. I think it'll be a lot easier than it is today in terms of like picking, agentic frameworks and how to go about it. I think it'll be kind of like, drag and drop even or, you speak to an agent and it it forms itself in a very easy way much easier than in today's world. And then we'll have these policies and rules around it in five years' time. So, enterprises and people will understand, what, what pieces will need to be in place, and there'll be options to pick and choose. I think there'll be open identity standards, for example, that can be utilized. Okay, what-- which ID system are we gonna use, first of all, for this agent? And then what policy engine are we gonna drop in? And I think it'll be a matter of just picking and choosing. I think it will be configurable. You'll be able to configure policy engines kinda with natural language. You'll give-- you'll tell the system what rules you want, in natural language, like do not spend more than this, do not... rather than like, a web interface where you check off. I think you'll be speaking to the system, and then it will set the deterministic policies based on you speaking to it. The observability will be built in. And then yeah, in terms of governance, those also will be the ability to be configured in this sort of dynamic policy engine that you put in place when you set up your agents. I just think it's gonna be a lot, lot easier than today in terms of using frameworks to build agents and get those set up. And we'll have more open standards by then, and I just think it'll be an entirely, different world in five years where this will be just be like, extremely easy to implement.
[00:30:08] KRISTINA: Rodrigo, thank you so much. I think what you're pointing us out towards here is really that autonomous payments are a window into a much larger governance challenge. Obviously, as these AI systems that we're talking about gain the ability to act rather than simply advise, everybody who's listening will have to become much more precise about that authority fact. Who can act? What can they do? Under what conditions can agents act? And how those actions are monitored. Like you said, human in the loop. Who ultimately remains accountable is going to be a thing. Technology can obviously automate any action, it can't eliminate the need for someone to decide where authority begins and ends. And so, Rodrigo, CEO of Edge & Node, the core developer of The Graph and a founding member of Ampersand Sign, really appreciate you being with us here today. And to everyone listening, thanks for joining us. Looking forward to hearing more from you in the future, Rodrigo. And for everybody else, we'll talk to you very soon, and tune in next time. Thanks.
[00:31:06] OUTRO: Thank you for joining the Power of Digital Policy; get access to policy checklists, detailed information on policies, and other helpful resources, head over to the power of digital policy.com. If you get a moment, please leave a review on iTunes to help your digital colleagues find out about the podcast.
Feel free to respond to this podcast here: