The failure is rarely one runaway loop. It is a dozen agents each doing something individually reasonable, and a bill at the end of the month that nobody can attribute to a decision.
01 · Why spend caps don't solve it
The usual first move is a hard cap at the model provider. It is worth having, and it is not a control.
02 · Budget the work, not the agent
Rate-limiting an agent constrains the wrong thing. What has a purpose, an owner, and a value is the work — and that is what should carry a ceiling.
Work is created with a budget attached. Spend is tracked against that allocation as agents report progress, so consumption is visible per initiative while it is happening rather than at invoice time.
When work approaches or exceeds its ceiling, it stops and raises an escalation. That escalation reaches a human in Slack, Teams, or Telegram with the context attached: what was being attempted, what has been spent, what evidence exists so far.
Approve or reject is recorded as a decision attributed to the person who made it, appended to a ledger that cannot be edited afterwards. Six months later, "why did this cost what it cost" has an answer with a human at the end of it.
03 · What this is
Budget enforcement on its own degrades quickly into an approval queue nobody reads. It works when it sits alongside the rest: independent verification so spend maps to attested work rather than activity, validation that ratchets so you are not paying twice for the same regression, and a ledger that makes the whole thing reviewable afterwards.
That combination is what Provostry is — an operating system for AI organizations. Budgets are the organ you feel first, because cost is usually the first thing that gets someone's attention.
04 · Questions
05 · Try it
Related: an audit trail for AI agents.