---
title: "Cost ceilings in the autonomy envelope"
description: "Cost is not the core assurance system. In the record it is the ceiling in the autonomy envelope, evaluated before every autonomous action and chained."
url: https://policycortex.com/platform/finops
sealed: 2026-09-02
amended: 2026-09-05
register: platform/finops
records: 3
digest: sha3:d5bb0dd1701a2734372d71d3f37349ef499f27318802e98fa6aaf26f1a8c9626
---

# Cost is a ceiling in the envelope, and a record.

Register / Mechanism / Cost ceiling

Cost is not the core assurance system. Where cost appears in the record, it is the ceiling in the autonomy envelope: evaluated by the policy gates at pre-check before anything runs, enforced during execution, and recorded on the chain every time. A supporting FinOps cost-intelligence module, described on the pricing page, sits beside the register, not inside it.

[Request Access](https://app.policycortex.com/auth?mode=request-access) · [The autonomy envelope](https://policycortex.com/architecture#envelope)

## One constraint of the envelope.

The autonomy envelope is a machine-enforced object read before every autonomous action. It carries eight constraints and a dry-run flag, and the cost ceiling is one of them. The envelope is evaluated at PRE-CHECK, before execution; 3/3 policy gates are required; and every evaluation of it is itself a chained record.

- **allowed_action_types**: The action classes that may run under this envelope.
- **blocked_action_types**: The action classes this envelope refuses; a proposal in one of them stops at PRE-CHECK and the stop is recorded.
- **max_affected_resources**: Blast radius, capped by count.
- **min_confidence**: The published confidence a proposal must clear; 0.94 for high-volume drift classes.
- **cost_ceiling_per_action**: The most a single action may spend. Evaluated before execution, enforced during it, recorded either way.
- **excluded_environments**: Environments no autonomous action may touch.
- **change_windows**: When an action may run at all.
- **emergency_stop**: The andon cord: any operator halts all autonomous classes.
- **dry_run_first**: Required for high-impact action classes before the action may run.

See also

- [The envelope in the architecture](https://policycortex.com/architecture#envelope)
- [Proof of agency](https://policycortex.com/proof/agency)

## Evaluated before, recorded always.

At 01 PRE-CHECK the gates evaluate the envelope: blast radius bounded, target state pinned by hash, 3/3 gates required, or the action stops there and the stop is recorded. At 03 EXECUTE the action runs inside the envelope it passed, within the change window, under the cost ceiling.

Cost ceilings and change windows bound sustained invocation, which is how the register answers inference denial of service (MITRE ATLAS AML.T0040), and every ceiling evaluation is a chained record. What the record then shows a reader is the ceiling that applied, the evaluation that enforced it, and the action that ran under it, each committed to the digest of the record before it.

Cost intelligence is a supporting module, not the core assurance system. The [FinOps cost-intelligence module](https://policycortex.com/pricing#finops-module) is described on the pricing page: included in Full Platform or available separately. What this page records is narrower, and it is the part an assessor can recompute.

The whole wrapper an action runs inside, from detect to rollback identifier, is on [the mechanism page](https://policycortex.com/platform) and in full on [proof of agency](https://policycortex.com/proof/agency).

## What this page is not.

**Stated limit.** This page states what the register records about cost: the ceiling in the envelope, the evaluation that enforces it, and the record that proves both. Cost intelligence is a supporting module, not the core assurance system, and the register does not replace your cloud provider's billing console.

Set a ceiling, then read what the record says about it. [Request Access](https://app.policycortex.com/auth?mode=request-access)

## Register colophon

| Seq | Label | SHA3-256 | Prev |
|---|---|---|---|
| REC 0000 | THE FIELD | b652004cd3d2 | a0ace6facfef |
| REC 0001 | THE EVALUATION | 407da2565ad7 | b652004cd3d2 |
| REC 0002 | STATED LIMIT | d5bb0dd1701a | 407da2565ad7 |

Head sha3:d5bb0dd1701a2734372d71d3f37349ef499f27318802e98fa6aaf26f1a8c9626. Each digest is SHA3-256 over the previous digest, the register key, the record label, and the record copy; a second party can recompute it from this document.
