PAYMENTS FM
PAYMENTS FM
Agentic Commerce with Colin Luce, CEO Basis Theory
0:00
-56:16

Agentic Commerce with Colin Luce, CEO Basis Theory

Colin Luce from Basis Theory joined PAYMENTS FM to talk about agentic commerce, tokenization, payment data security, and how teams can give agents useful access without giving away too much control.

State of Payments survey

We are launching the State of Payments survey. It takes about four minutes to complete, and anonymous responses are welcome. We will publish the results at the end of the year.

Participate in Survey

Why this matters

Agentic commerce changes the checkout question. A customer may ask an agent to research, choose, and buy. That creates new decisions around identity, consent, payment credentials, data access, and authorization.

Payment teams need to know where sensitive data appears, which systems can touch it, and what an agent is allowed to do before a transaction is approved.

Tokenization, vaulting, and permission design become part of the product experience, because trust depends on what happens behind the scenes.

What to watch

Map the flow before adding agents to payment journeys.

  • Payment data entry points

  • Systems with card access

  • Token coverage

  • Agent permissions

  • Consent capture

  • Authorization steps

  • Vendor data sharing

  • Compliance scope

What it means for your team

Agentic checkout will involve product, engineering, security, compliance, risk, and payments from the beginning.

Product needs a clear customer experience. Engineering needs controlled interfaces. Security needs to reduce sensitive data exposure. Compliance needs evidence around consent and scope. Risk teams need to understand what can be initiated by an agent and what requires the customer.

What to do next

Start with data access and permission boundaries.

  • Map the full payment flow

  • Tokenize sensitive data

  • Limit agent permissions

  • Define approval moments

  • Review consent language

  • Audit vendor access

  • Keep logs for review

Questions to ask internally

  • Where does sensitive payment data enter the flow?

  • Which systems can store or process it?

  • What can an agent do before customer approval?

  • How is consent captured and shown later?

  • Which tokens can be used, where, and by whom?

  • What changes in compliance scope?

Guest perspective

  1. Agentic commerce needs payment infrastructure that keeps data controlled and useful.

  2. Tokenization helps teams reduce exposure while still supporting new checkout flows.

  3. Permissions matter as much as storage. Teams need to define what an agent can initiate, view, and approve.

  4. The customer experience depends on trust, consent, and clear boundaries around payment credentials.

Listen or watch

Resources

Related episodes

Subscribe

PAYMENTS FM helps merchants, platforms, marketplaces, and payment product teams understand how payments work in practice through podcast episodes, expert interviews, community conversations, and practical payments education. Subscribe for operator-focused conversations about money movement.

Discussion about this episode

User's avatar

Ready for more?