{"id":26508,"date":"2026-03-30T16:59:07","date_gmt":"2026-03-30T11:29:07","guid":{"rendered":"https:\/\/blog.razorpay.in\/blog\/?p=26508"},"modified":"2026-03-30T16:59:07","modified_gmt":"2026-03-30T11:29:07","slug":"razorpay-agent-studio-principles-guardrails-and-merchant-control","status":"publish","type":"post","link":"https:\/\/razorpay.com\/blog\/razorpay-agent-studio-principles-guardrails-and-merchant-control\/","title":{"rendered":"Razorpay Agent Studio: Principles, Guardrails, and Merchant Control"},"content":{"rendered":"<p><span style=\"font-weight: 400;\">Razorpay Agent Studio launched at FTX 2026 as a marketplace of AI agents built on top of Razorpay&#8217;s payment infrastructure. Since launch, we&#8217;ve received questions from merchants, developers, journalists, and regulators about how these agents behave, who controls them, and what safeguards are in place.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">These are the right questions. AI agents that take actions on behalf of a business need clear boundaries, transparent behavior, and real accountability. This post explains how Agent Studio works \u2014 in detail.<\/span><\/p>\n<div style=\"background: #f5faff; border-radius: 14px; padding: 28px 24px; text-align: center; margin: 0; box-shadow: 0 8px 20px rgba(26,115,232,0.08);\">\n<h2 style=\"color: #1a73e8; font-size: 24px; font-weight: bold; margin: 0 0 10px 0;\"><strong>Explore Razorpay Agent Studio<\/strong><\/h2>\n<p style=\"color: #444; font-size: 16px; max-width: 720px; margin: 0 auto 16px auto; line-height: 1.6;\">Build and deploy AI agents that monitor payments, automate operations, and recover revenue across your financial workflows.<\/p>\n<p><a style=\"display: inline-block; background: #1a73e8; color: #ffffff; padding: 14px 26px; font-size: 16px; font-weight: bold; border-radius: 10px; text-decoration: none;\" href=\"https:\/\/razorpay.com\/agent-studio\/\"><em><strong>Learn More about Agent Studio<\/strong><\/em><br \/>\n<\/a><\/p>\n<\/div>\n<p>&nbsp;<\/p>\n<p><b style=\"color: #111111; font-family: Roboto, Arial, sans-serif; font-size: 1.6315em;\">What is Agent Studio?<\/b><\/p>\n<p><span style=\"font-weight: 400;\"><a href=\"https:\/\/razorpay.com\/agent-studio\/\">Agent Studio<\/a> is a marketplace inside your Razorpay dashboard where you can install AI agents that handle specific operational work for your business. Think of each agent as a specialist you hire for one job.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><b>Dispute Expert<\/b><span style=\"font-weight: 400;\"> fights chargebacks the moment they land \u2014 gathering evidence from Razorpay, Shopify, Shiprocket, and other connected platforms, scoring win probability, and submitting a response or sending you a ready-to-approve draft. The <\/span><b>Subscription Recovery Agent<\/b><span style=\"font-weight: 400;\"> catches failing payments before they churn a customer \u2014 calling at-risk subscribers with a personalized conversation in English or Hindi. The <\/span><b>Cart Abandonment Recovery Agent<\/b><span style=\"font-weight: 400;\"> follows up with customers who dropped off at checkout \u2014 with a voice call matched to why they left, and a payment link to complete the purchase on the spot.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">These aren&#8217;t dashboards or alerts. They reason through context, decide the right action, and execute within clear guardrails. But &#8220;clear guardrails&#8221; is a claim that deserves specifics. Here they are.<\/span><\/p>\n<h2><b>1. The merchant is always in control<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Every agent operates within boundaries the merchant defines. Before activation, the merchant reviews and approves exactly what data the agent can access, what actions it can take, and where it needs human approval before proceeding.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For sensitive actions, agents escalate to the merchant \u2014 typically on WhatsApp \u2014 rather than acting unilaterally.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Any agent can be configured in <\/span><b>review-first mode<\/b><span style=\"font-weight: 400;\">: the agent does all the work \u2014 gathers evidence, drafts a response, builds the case \u2014 but holds it for the merchant to review before anything is submitted or sent. The grunt work is handled by the agent. The final call stays with the merchant. This is a good starting point for teams that want to build confidence before turning on full automation.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">No agent takes an irreversible action without explicit merchant approval. Actions like large financial transfers or deletions require double confirmation and are never eligible for auto-approval.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The merchant can turn off any agent at any time. One tap. Immediate.<\/span><\/p>\n<h2><b>2. Agents don&#8217;t set prices or invent discounts<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">When an agent like the Cart Abandonment Recovery Agent reaches out to a customer, any discount or offer it extends comes from the merchant&#8217;s existing discount and coupon configuration on Razorpay. The agent does not create new discounts, modify pricing, or decide independently how much to offer.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The agent does personalize how it engages each customer \u2014 what it says, which of the merchant&#8217;s pre-approved offers it surfaces, how it frames the conversation based on what&#8217;s in the cart and why the customer dropped off. But the set of available offers and the maximum discount limits are defined by the merchant through Razorpay&#8217;s existing coupon system.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">If a merchant has configured a maximum 10% discount for cart recovery, no agent will offer 15%. The ceiling is the merchant&#8217;s ceiling. The agent picks from what the merchant has authorized. It doesn&#8217;t make up new deals.<\/span><\/p>\n<h2><b>3. Agents work with verified first-party data<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Agents on Agent Studio pull data directly from the merchant&#8217;s own connected systems \u2014 not from web scraping, external inference, or unverified sources.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Razorpay already has established connections with e-commerce platforms and order management systems like Shopify, Shiprocket, Tally, and QuickBooks. When a merchant installs an agent, they provide consent to connect these systems through a standard OAuth flow. The agent then reads product pricing, inventory status, order details, and transaction data from the merchant&#8217;s actual platform \u2014 the same source of truth the merchant&#8217;s own storefront uses.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">If a product is priced at \u20b9999 on the merchant&#8217;s Shopify store, that&#8217;s what the agent sees. If it&#8217;s out of stock, the agent knows from the inventory field, not from guessing. Payment links generated through Razorpay reflect the final transaction amount as configured by the merchant.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Several connectors are pre-enabled from day one with no setup required \u2014 Razorpay data, WhatsApp, SMS, email, ElevenLabs, and Shiprocket. Connectors that require access to external accounts \u2014 like Shopify and Tally \u2014 need a one-time OAuth connection. Once done, they&#8217;re available to all the merchant&#8217;s agents.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">If a merchant needs a connector that doesn&#8217;t exist yet, they can request it directly from the Connectors section in the dashboard. New connectors typically take about one week to build and release. For enterprise customers, we support private connectors scoped exclusively to the organization \u2014 data is accessible only to that merchant&#8217;s own agents and is never shared with other customers or agents outside their environment.<\/span><\/p>\n<h2><b>4. Every action is validated before it executes<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Beyond working with verified data, every agent action passes through Razorpay&#8217;s platform-level validation layer before execution. These checks cover:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Compliance boundaries<\/b><span style=\"font-weight: 400;\"> \u2014 the action must fall within regulatory and policy limits.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Amount validation<\/b><span style=\"font-weight: 400;\"> \u2014 payment amounts, discount values, and financial calculations are verified against the merchant&#8217;s configuration.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>PII handling<\/b><span style=\"font-weight: 400;\"> \u2014 personal data is processed in accordance with data protection requirements and the merchant&#8217;s consent framework.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Scope checks<\/b><span style=\"font-weight: 400;\"> \u2014 if an agent attempts something outside its approved permissions, the action is blocked before it executes.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Out-of-scope behavior detection<\/b><span style=\"font-weight: 400;\"> \u2014 the platform monitors for actions that don&#8217;t match the agent&#8217;s intended function and blocks them.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">This is a two-layer system: agents operate on verified merchant data, and the platform independently validates every action before it goes through. Errors are caught both before and after execution, with repeated mistakes triggering review and correction through our internal evaluation system.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Every single action is logged with a full audit trail. The merchant can see exactly what the agent did, when, and why \u2014 at any time from the agent&#8217;s performance dashboard.<\/span><\/p>\n<h2><b>5. Customer communication follows consent rules<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">When an agent makes an outbound call, sends a WhatsApp message, or sends an email, consent is verified before any communication is initiated.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For voice calls, telephony consent is validated against the merchant&#8217;s customer records. For WhatsApp, WABA compliance rules are enforced. Customers who opt out are permanently suppressed \u2014 no exceptions, no &#8220;just one more try.&#8221;<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Razorpay does not initiate any agent-driven communication to a customer without a valid consent signal.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">If a customer says no, that&#8217;s it. The agent stops. There is no escalation loop where the agent keeps trying with bigger offers or more urgent language. A no is a no.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Merchants can also bring their own WhatsApp Business Account provider, so they retain their existing number and provider relationship and aren&#8217;t locked into a single communication channel.<\/span><\/p>\n<h2><b>6. No false urgency, no manufactured pressure<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">We&#8217;ve seen questions about whether AI agents could create artificial urgency \u2014 countdown timers, &#8220;this offer expires in 24 hours&#8221; language, or escalating discounts designed to pressure a purchase.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Our position is clear: agents on Agent Studio must not employ dark patterns as defined under India&#8217;s Guidelines for Prevention and Regulation of Dark Patterns, 2023. This includes false urgency, confirm shaming, bait and switch, drip pricing, and subscription traps.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">If a merchant has configured a genuinely time-bound offer \u2014 a real flash sale that actually ends at midnight \u2014 the agent can communicate that truthfully. But the agent will not fabricate urgency that doesn&#8217;t exist or manufacture scarcity to pressure a purchase.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Our agent certification pipeline includes automated screening for communication patterns that could constitute dark patterns \u2014 and agents that don&#8217;t meet this standard are not approved for the marketplace.<\/span><\/p>\n<h2><b>7. Pricing is transparent and per-agent<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Each agent on the marketplace has its own pricing, set by the agent provider. Depending on the agent, this could be:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Usage-based<\/b><span style=\"font-weight: 400;\"> \u2014 pay per action (e.g., per dispute handled)<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Subscription-based<\/b><span style=\"font-weight: 400;\"> \u2014 flat monthly fee<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Outcome-based<\/b><span style=\"font-weight: 400;\"> \u2014 pay only when the agent delivers a measurable result<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">The pricing model for each agent is clearly displayed before the merchant installs it. No hidden fees. No surprise charges.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For early partners, Agent Studio is available on a <\/span><b>free 30-day trial<\/b><span style=\"font-weight: 400;\"> with a set credit limit \u2014 enough to run agents on real transactions and see actual outcomes before spending anything. If credits are exhausted during the trial, the merchant sees an &#8220;Agent requires action&#8221; prompt in the dashboard so they&#8217;re never caught off guard.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For outbound actions like voice calls, SMS, or email, there is an additional cost on top of the base agent fee to cover underlying communication costs (voice minutes, message delivery). These costs are shown transparently before the merchant activates an agent that uses them. Commercial relationships with third-party providers like ElevenLabs are handled by Razorpay \u2014 the merchant doesn&#8217;t need a separate account or contract.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">As the platform matures, the commercial model will evolve \u2014 but the principle stays the same: pricing is transparent and clearly visible to the merchant before they commit to anything.<\/span><\/p>\n<h2><b>8. Agent certification and accountability<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Every agent published to the Agent Studio marketplace goes through Razorpay&#8217;s validation process before it becomes available to merchants. We review:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The agent&#8217;s logic and decision-making approach<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data access scope \u2014 what it can see and what it can&#8217;t<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Available actions \u2014 what it can do and the boundaries around those actions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Compliance posture \u2014 adherence to data protection, dark pattern guidelines, and Razorpay&#8217;s platform standards<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Communication patterns \u2014 automated screening for language and behavior that could constitute dark patterns, including false urgency, confirm shaming, escalating pressure tactics, and manufactured scarcity<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">Agents that don&#8217;t pass this certification are not approved for the marketplace. This isn&#8217;t a one-time check \u2014 it&#8217;s continuous. Agent communication patterns are monitored post-launch as well, and agents that develop problematic patterns after certification are flagged for review and can be removed.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Agent performance is measured continuously using Razorpay&#8217;s internal evaluation system. Metrics, outcome rates, and error patterns are tracked. Underperforming agents are identified and improved. For third-party agents, this data is part of ongoing marketplace certification.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">On accountability: the developer or provider of each agent carries responsibility for its behavior. Razorpay maintains platform-level guardrails \u2014 amount checks, compliance validations, action boundaries \u2014 that prevent the most serious classes of errors from occurring. But the agent provider is accountable for the logic and outcomes of their agent.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Any merchant or developer will be able to build agents and publish them to the marketplace. Every publicly published agent goes through the validation process described above. The builder platform launches on <\/span><b>May 9th<\/b><span style=\"font-weight: 400;\"> with a Build Day event in Bangalore.<\/span><\/p>\n<h2><b>9. Data privacy, security, and compliance<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">All agents run entirely within Razorpay&#8217;s infrastructure. Merchant data never leaves Razorpay&#8217;s systems. Agents only access data scoped to the specific merchant account \u2014 no data is shared with other merchants, other agents, or third parties outside the merchant&#8217;s authorized connectors.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Agent Studio is built on Razorpay&#8217;s existing compliance infrastructure, which adheres to applicable data protection laws including India&#8217;s <\/span><b>Digital Personal Data Protection Act (DPDPA)<\/b><span style=\"font-weight: 400;\">. Customer data used by agents \u2014 including contact information for voice calls or WhatsApp outreach \u2014 is processed only under the consent frameworks and data handling policies already in place through the merchant&#8217;s Razorpay integration.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Razorpay is <\/span><b>SOC 2 certified<\/b><span style=\"font-weight: 400;\"> and maintains <\/span><b>PCI DSS compliance<\/b><span style=\"font-weight: 400;\"> as a payment infrastructure provider. Agent Studio inherits these certifications \u2014 agents operate within the same secure, audited environment that processes payments. Enterprise customers can request documentation on Razorpay&#8217;s security posture and data handling practices directly.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For enterprise deployments with private connectors, data access is restricted to the organization&#8217;s own environment. No cross-customer data exposure.<\/span><\/p>\n<h2>What&#8217;s next?<\/h2>\n<p><span style=\"font-weight: 400;\">We believe AI agents can do genuinely useful work for businesses \u2014 work that currently either gets done manually at significant cost, or doesn&#8217;t get done at all and costs revenue directly. Fighting a chargeback shouldn&#8217;t take 3 hours. A failing subscription shouldn&#8217;t silently lose a customer. An abandoned cart shouldn&#8217;t just be a statistic.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">But useful doesn&#8217;t mean uncontrolled. Every agent on this platform operates within boundaries set by the merchant, validated by the platform, logged with an audit trail, and certified before it reaches the marketplace.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">If you have questions about how any of this works, reach out to us at <span style=\"text-decoration: underline;\"><em>agentstudio@razorpay.com<\/em><\/span> or talk to your Razorpay account manager.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><\/p>\n<div style=\"background: #f5faff; border-radius: 14px; padding: 28px 24px; text-align: center; margin: 0; box-shadow: 0 8px 20px rgba(26,115,232,0.08);\">\n<h2 style=\"color: #1a73e8; font-size: 24px; font-weight: bold; margin: 0 0 10px 0;\"><strong>Automate Your Payment Operations with AI Agents<\/strong><\/h2>\n<p style=\"color: #444; font-size: 16px; max-width: 720px; margin: 0 auto 16px auto; line-height: 1.6;\">Reduce manual effort across disputes, failed payments, and reconciliation by deploying intelligent agents that work continuously in the background.<\/p>\n<p><a style=\"display: inline-block; background: #1a73e8; color: #ffffff; padding: 14px 26px; font-size: 16px; font-weight: bold; border-radius: 10px; text-decoration: none;\" href=\"https:\/\/razorpay.com\/agent-studio\/\"><strong><em>Discover Agent Studio<\/em><\/strong><br \/>\n<\/a><\/p>\n<\/div>\n<p>&nbsp;<\/p>\n<p><i><span style=\"font-weight: 400;\">Agent Studio is currently available in early access with a free 30-day trial for early partners. Visit razorpay.com\/agent-studio to learn more.<\/span><\/i><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Razorpay Agent Studio launched at FTX 2026 as a marketplace of AI agents built on top of Razorpay&#8217;s payment infrastructure. Since launch, we&#8217;ve received questions from merchants, developers, journalists, and regulators about how these agents behave, who controls them, and what safeguards are in place. These are the right questions. AI agents that take actions<\/p>\n","protected":false},"author":149,"featured_media":26509,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[1136],"tags":[],"class_list":{"0":"post-26508","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-ai-payments"},"_links":{"self":[{"href":"https:\/\/razorpay.com\/blog\/wp-json\/wp\/v2\/posts\/26508","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/razorpay.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/razorpay.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/razorpay.com\/blog\/wp-json\/wp\/v2\/users\/149"}],"replies":[{"embeddable":true,"href":"https:\/\/razorpay.com\/blog\/wp-json\/wp\/v2\/comments?post=26508"}],"version-history":[{"count":1,"href":"https:\/\/razorpay.com\/blog\/wp-json\/wp\/v2\/posts\/26508\/revisions"}],"predecessor-version":[{"id":26511,"href":"https:\/\/razorpay.com\/blog\/wp-json\/wp\/v2\/posts\/26508\/revisions\/26511"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/razorpay.com\/blog\/wp-json\/wp\/v2\/media\/26509"}],"wp:attachment":[{"href":"https:\/\/razorpay.com\/blog\/wp-json\/wp\/v2\/media?parent=26508"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/razorpay.com\/blog\/wp-json\/wp\/v2\/categories?post=26508"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/razorpay.com\/blog\/wp-json\/wp\/v2\/tags?post=26508"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}