Write the leash. Test the batch.
Describe the policy, write what the agent would send, and see the verdict twice: from the rules engine in your browser, and from Robinhood Chain itself running the contract's code on its real state. Nothing is signed or sent.
1. The policy
Call list deny by default
Token limits transfer, approve, transferFrom
Recipients used when "money only to recipients" is on
2. The batch
What the agent would send in one transaction. One refused call cancels all of them.
3. The verdict
In your browser
On Robinhood Chain
Asks the chain to run the contract's code against your policy and batch. Nothing is sent.
Use a real holder as the owner address and its real token balances apply too. The chain run replaces that address's code with the contract's for the simulation only.
4. Take it with you
setPolicy calldata
execute calldata
Delegate and set the policy in one transaction (viem)
The contract is written, compiled and tested, not audited and not deployed. Its planned address (CREATE2): . Do not send any of this to a mainnet account you care about until it is audited and deployed.