This isn't incompatible with the agent placing the purchase. I already let Claude Code do _most_ of what it wants but make it ask permission before sending a message on Slack. An LLM having the capability to do X is not incompatible with it being deterministically forced to seek permission to do X.