Yesterday's brief was about the industry writing down what agentic commerce means. Look at what shipped and what got funded around it this month and the same word keeps surfacing from a different direction. Not rails. Identity. A venture round for payment infrastructure built for machines, a workspace where every agent signs its own work, and merchant survey data saying the thing they need most is a way to tell which agent is knocking.

Thirty million on the bet that agents need their own rails

Natural closed a $30m Series A led by Kirsten Green at Forerunner, taking total funding to $40m, roughly six months after launch [1]. The pitch is not a plugin on top of an existing processor. It is financial rails where the agent itself holds the wallet, receives payments, pays invoices, issues cards and moves money across banks and currencies without a person approving each step [1].

That framing is the interesting part, more than the number. Stripe, Visa and Mastercard are all adapting human-designed rails to carry agent traffic. Natural is arguing the retrofit does not go far enough, and investors just priced that argument.

Every action signed, every agent keyed

Block released Buzz on 21 July, an open-source workspace under Apache 2.0 where humans and agents work in the same place [2]. The mechanism is what matters here. Each agent operates under its own public and private key pair, and every message, workflow step, review approval and Git event is written as a signed event in a hash chain [2]. It runs on Nostr, supports any model or agent framework, and can be self-hosted or run as a managed service [2].

If a tamper-evident hash chain of agent actions sounds familiar, it should. It is structurally the same answer the A-Comm evidence protocol proposed for agent purchases, arriving from the workflow side rather than the payments side. Two different problems, one shape of solution.

The merchant view: identity first

PayPal's merchant pulse research puts numbers on the demand. Fifty-five per cent of merchants expect AI agents to become a major new transaction channel, and more than two thirds think agents could initiate at least ten per cent of their e-commerce transactions within three years [3]. Asked what they actually need to support it, merchants ranked trusted identity and authentication for agents acting on a customer's behalf alongside data privacy and regulatory compliance at the top [3].

And the plumbing gets easier

Salesforce made Agentforce Commerce generally available on 6 July, with Shopper, Buyer and Merchant agents and a native ChatGPT integration that syncs a retailer's product catalogue straight from Business Manager, no third-party tooling [4]. The retailer stays merchant of record and order data returns to the same platform running service, loyalty and marketing [4]. Google Search and Gemini integrations are flagged for later.

Read from the rails

The merchant-of-record detail in the Salesforce release is the one I would underline. It sounds like housekeeping. It decides who owns the dispute. Whoever is merchant of record answers the chargeback, holds the customer relationship, and carries the compliance obligation, regardless of which surface the shopper was standing on when they bought. A retailer selling through ChatGPT while remaining merchant of record has kept the liability it already knew how to carry. A retailer selling through a surface that becomes merchant of record has traded away both the risk and the customer.

The identity thread underneath all four items is the same instinct I learned the hard way in operations. Ten years of reconciliation taught me that an instruction without an attributable originator is not an instruction, it is a problem waiting for someone to own it. Every message format that survives has a field for who sent it, and every settlement dispute I ever worked came down to reconstructing that field after the fact. Agents are arriving into a system that has no equivalent. Key pairs and signed events are the industry building that field before the dispute queue forces it.

What I would watch is revocation. Signing an action proves which key produced it. It does not tell you whether that key should still have been trusted at the moment it signed. A compromised or retired agent whose credential is still floating around is the agentic version of a card that was never properly cancelled, and none of this week's announcements says much about how the key gets turned off.

Anyone can build a wallet. The hard part is proving who was holding it.

Building in agentic commerce or payments?

This is the intersection I work in. Book thirty minutes and we will scope the build worth doing.

Join the waitlist