Register:Mechanism/Cost3 recordsSHA3-256 chainedSealed Amended head sha3:d5bb0dd1701a2734372d71d3f37349ef499f27318802e98fa6aaf26f1a8c9626Intact

Register / Mechanism / Cost ceiling

Cost is a ceiling in the envelope, and a record.

Cost is not the core assurance system. Where cost appears in the record, it is the ceiling in the autonomy envelope: evaluated by the policy gates at pre-check before anything runs, enforced during execution, and recorded on the chain every time. A supporting FinOps cost-intelligence module, described on the pricing page, sits beside the register, not inside it.

autonomy_envelopeoperator-set values shown
{
  "allowed_action_types":      ["tag.enforce", "storage.public_access.revoke"],
  "blocked_action_types":      ["identity.role.grant", "network.route.modify"],
  "max_affected_resources":    25,
  "min_confidence":            0.94,
  "cost_ceiling_per_action":   "50.00 USD",
  "excluded_environments":     ["production"],
  "change_windows":            ["Sat 01:00 to 05:00 UTC"],
  "emergency_stop":            "andon: any operator halts all autonomous classes",
  "dry_run_first":             "required for high-impact classes"
}
REC 0000THE FIELDsha3-256b652004cd3d27eeda93c8935edffd252586b6dd844ffc63d47ed68b58985d3b2prev:a0ace6facfef

One constraint of the envelope.

The autonomy envelope is a machine-enforced object read before every autonomous action. It carries eight constraints and a dry-run flag, and the cost ceiling is one of them. The envelope is evaluated at PRE-CHECK, before execution; 3/3 policy gates are required; and every evaluation of it is itself a chained record.

allowed_action_types
The action classes that may run under this envelope.
blocked_action_types
The action classes this envelope refuses; a proposal in one of them stops at PRE-CHECK and the stop is recorded.
max_affected_resources
Blast radius, capped by count.
min_confidence
The published confidence a proposal must clear; 0.94 for high-volume drift classes.
cost_ceiling_per_action
The most a single action may spend. Evaluated before execution, enforced during it, recorded either way.
excluded_environments
Environments no autonomous action may touch.
change_windows
When an action may run at all.
emergency_stop
The andon cord: any operator halts all autonomous classes.
dry_run_first
Required for high-impact action classes before the action may run.

See alsoThe envelope in the architectureProof of agency

REC 0001THE EVALUATIONsha3-256407da2565ad7ba7ef6d176f52c5e51c21ac049bc5a706f95a6aff9f6431cec0aprev:b652004cd3d2

Evaluated before, recorded always.

At 01 PRE-CHECK the gates evaluate the envelope: blast radius bounded, target state pinned by hash, 3/3 gates required, or the action stops there and the stop is recorded. At 03 EXECUTE the action runs inside the envelope it passed, within the change window, under the cost ceiling.

Cost ceilings and change windows bound sustained invocation, which is how the register answers inference denial of service (MITRE ATLAS AML.T0040), and every ceiling evaluation is a chained record. What the record then shows a reader is the ceiling that applied, the evaluation that enforced it, and the action that ran under it, each committed to the digest of the record before it.

Cost intelligence is a supporting module, not the core assurance system. The FinOps cost-intelligence module is described on the pricing page: included in Full Platform or available separately. What this page records is narrower, and it is the part an assessor can recompute.

The whole wrapper an action runs inside, from detect to rollback identifier, is on the mechanism page and in full on proof of agency.

REC 0002STATED LIMITsha3-256d5bb0dd1701a2734372d71d3f37349ef499f27318802e98fa6aaf26f1a8c9626prev:407da2565ad7

What this page is not.

Set a ceiling, then read what the record says about it.

Request Access
Register colophonRecomputable by a second party
SeqLabelSHA3-256Prev
REC 0000THE FIELDb652004cd3d2a0ace6facfef
REC 0001THE EVALUATION407da2565ad7b652004cd3d2
REC 0002STATED LIMITd5bb0dd1701a407da2565ad7

The record headers on this page are SHA3-256 digests of this page's own copy, chained in sequence from a fixed genesis value. Edit one word of any record's copy above and every digest after it changes. Head of chain: sha3:d5bb0dd1701a. The product does the same thing to your evidence.

Photograph: Bill Hrybyk, NASA Goddard Space Flight Center, Public domain (NASA, 17 U.S.C. 105). Source