Reserves projected model spend before the prompt is forwarded and restrains runs that would blow the project wallet.
For: Agency and platform teams paying for agent runs per client or per project
Restrains an agent run that would exceed the allocated project token wallet.
Escalates a task whose projected cost exceeds the per-task cap before the prompt is forwarded.
Restrains a new run while a prior reservation for the same project is still unreconciled.
# Copilot Token-Budget Guard
# Fork: this is the ai_agency "Token Budgeting" gate, expressed against the
# agent gateway's pre-prompt reservation. Set your own caps.
apiVersion: decionis.dev/v1
kind: PolicyPack
metadata:
name: copilot-token-budget-guard
surface: copilot
standards: [SOC2-CC7.2, ISO27001-A.8.9]
defaults:
mode: shadow
emit_dossier: true
fail_closed: true
rules:
- name: project_wallet_ceiling
when: "task.projected_tokens != null"
decision: |
RESTRAIN IF wallet.consumed_tokens + task.projected_tokens > wallet.allocated_tokens
ALLOW OTHERWISE
reason_code: project_token_wallet_exhausted
- name: per_task_reservation
when: "task.projected_cost_usd != null"
decision: |
ESCALATE IF task.projected_cost_usd > 25
ALLOW OTHERWISE
reason_code: task_cost_over_cap
- name: unreconciled_run_guard
when: "always"
decision: |
RESTRAIN IF wallet.open_reservations > 0
ALLOW OTHERWISE
reason_code: prior_reservation_unreconciled
Fork it, change the thresholds to match your environment, and deploy in shadow mode first — it defaults to listen-only so nothing in your live pipeline changes.
Follow the install path for this surface, then paste the forked YAML as your policy config.
This recipe is one step in a path. The same five steps apply to every recipe in the exchange.
Run the policy against a realistic action in the browser. Push it past what the rules allow and watch the verdict come back. No account.
See exactly what was decided and why: the rule that fired, the evidence it read, the policy version in force, and an Ed25519 signature you can verify yourself.
Measure what the policy would have caught on your own traffic without touching the live path. Every recipe defaults to shadow, so the first deployment carries no execution risk.
Point the same policy at the system where the action actually originates — a checkout, an ERP posting, a Zap, an agent's tool call.
Publish the proof: a public verification link, an embeddable badge, a PR comment, or an anonymized shadow-mode finding. This is how the next person discovers Decionis.