Corporate cards for AI agents: one card per agent, task, or vendor?
An agent-specific virtual card seems cleaner than sharing a company card. It could have a hard limit, merchant allowlist, expiry, single-use behavior, and a clear owner in the audit log.
The downside is lifecycle management. Agents are created, cloned, paused, and replaced much faster than employees. That could produce hundreds of stale cards and unclear responsibility for spend.
If you are building this, would you issue one card per agent, per task, per vendor, or per human owner? Which controls should live at the card layer versus the agent policy layer? I am also curious whether anyone has tested how refunds and disputes map back to a short-lived agent.