Who can spend what — and the record that proves it.
Workspaces, seats and role-based access, with hard spend caps and an audit trail that outlives the people who set it.
- Spend caps at workspace, key and agent level, with auto-topup on idempotent per-charge keys.
- Roles and scoped invites for humans; SSO and passkeys for how they sign in.
- The audit log covers configuration changes, not just requests — who turned enforcement off, and when.
A cap that actually stops.
Set the ceiling at the workspace, the key or the agent. When it is reached, spend stops — it does not warn you and keep going. Auto-topup, when you want it, runs on idempotent per-charge keys so a retry never bills twice.
The record outlives the team.
Seats, scoped invites and roles for the humans. SSO and passkeys for how they get in. And an audit log that covers configuration, not just traffic — so “who turned enforcement off, and when” has an answer for as long as your retention window keeps it.