Execution
Authorization is not settlement.
Paymod, not the agent, creates the constrained Stellar execution. The agent credential is scoped to one wallet and cannot sign arbitrary network transactions.
Execution creates a deterministic payment identifier, records attempts and confirms the result. Confirmed settlement converts reserved budget to spend. An unknown outcome remains reserved to avoid a second payment.