Governance and usage
Who spent what, in which process, on what day
The company meter
Settings shows how much of your plan the month has used so far, and the last fourteen days in detail: which day and which process did the work. Process means which part of the system asked for it: an agent turn, a scheduled automation, the review that writes memory. It is the question a manager actually asks when they see a number, and almost no tool answers it.
- What you see is measured work, not an estimate from text length
- Indexing, search and people talking to people do not appear, because they are not charged
- Plan used so far this month
- 46%
- Jul 19 · agent:chat
- 29%
- Jul 19 · agent:scheduled
- 3%
- Jul 18 · agent:chat
- 8%
- Jul 18 · agent:memory
- 2%
- Jul 17 · agent:chat
- 4%
A retry cannot charge you twice
Every call to the model carries its own identifier and the charge is recorded under that key. If the network fails and the same charge arrives again, the second one adds nothing: it is marked duplicate and passes through. The spend increment, the detail row and the daily rollup are written in one transaction, so there is no in-between state where spend went up and no detail explains it.
- Call with its identifier
- Recorded once spend, detail and rollup
- Retry same identifier
- Marked duplicate adds nothing
A monthly log you can download
Beyond the panel, every call appends a line to a monthly file belonging to your company: date, person, department, process, how much work it was and the size of text it covered. The size, not the content: the log never stores what was written. The files are monthly so they do not grow without bound, and they download whenever your accountant asks.
- If the file write fails, billing does not break: the database is the source of the charge
- File totals and panel totals are compared in the test suite, so they do not drift
{"ts":"2026-07-19T14:02:11Z","process":"agent:chat",
"user":"u_412","dept":"sales",
"tool":"note_write","duplicate":false}
Which tool ran, and under whose permission. Never the content.
An audit that cannot be altered unnoticed
Every tool the agent runs leaves a row with the hash of its arguments (never the arguments in the clear), whether it succeeded and how long it took. Each row also carries the hash of the previous one, so rows form a chain per company. Delete or edit a row and the next one stops matching, and verifying the log is walking it from end to end.
- read_note 14:02:11
- previous
- 000000…0000
- row
- a41f9c…7d2e
- write_note 14:02:19
- previous
- a41f9c…7d2e
- row
- b8e310…44a1
- python_exec 14:03:02
- previous
- b8e310…44a1
- row
- 5c0d77…91bf
The chain stops matching here
Encrypted secrets, listed by name
Your company keys are stored encrypted and decrypted only inside the process that uses them. No endpoint returns the value: the screen shows the name and the words Value hidden, even to whoever created it. Only the company owner reaches that tab, and a secret reaches a run only if the tool asks for it explicitly. By default none travels.
- BILLING_API
- Value hidden
- SMTP_PASSWORD
- Value hidden
- WAREHOUSE_TOKEN
- Value hidden
Going over the plan has one written rule
Nobody has to authorize anything mid-month and nothing stops: your agents keep working. Work that fits inside your plan is already paid for by the plan. Work past it costs double and lands on the next month invoice. If the overage would come to less than 25 dollars, it is not charged. Anything past your plan is charged on the following month's invoice, never all at once mid-month. And when a month goes over repeatedly we say so, because past a certain point the plan above costs you less than the surcharge.
- The work continues nothing is interrupted
- The extra is recorded apart from the plan
- Next invoice never mid-month
- We tell you when the plan above is cheaper
What it does not do yet
The meter records and shows, but it does not cut off
If your company goes past what its plan includes you will see it on the panel and we will tell you, but the system does not interrupt the work on its own. The automatic cutoff is written and tested, and it is not yet wired into the agent path. We would rather say it that way than promise a ceiling that is not enforced today.
Related, and worth knowing before the first invoice: what you do not use in a month does not carry over to the next one. Every cycle starts from zero.