Let them run. Watch every action as it happens, step in when it matters, and keep a record nobody can quietly edit. Every action passes one check first: inside its limit and on task? allow · over it, or stuck in a loop? deny · needs more to finish? escalate to you. A denied action never executes, so nothing is spent on it. Flip the switches below and watch your agents react live.
It reads the task you actually typed. Running the test suite on your priciest model gets you told, and so does debugging a race condition on the cheapest one. It moves one tier at a time, and says nothing when it is unsure.
Everything else caps a total, which only notices once the money is gone. This watches dollars a minute. A session fanning out into fifty subagents is stopped inside the first minute, not after four figures.
Not only what it may spend. Piping the internet into a shell is refused outright. Deleting a tree, rewriting git history, reading your credentials: those stop and ask you. All cheap commands, so a spend cap never sees them coming.
Hash-chained, naming the human it acted for, the tool it tried, the model answering and the rule that decided. Edit or delete one record and the chain breaks and says which line. Export the lot as a spreadsheet.
Five projects for five clients, and nobody has to label a session. It reads the folder the work is happening in. Cap a client for the month and that one stops while the other four carry on.
Watch it work. Each card is an agent running right now: what it was asked to do, which model is answering, and what it has cost. Green means healthy. The dashed line is where it stops and asks you.
Step in. Within a minute, scraper-07 gets stuck repeating itself. It is stopped on the fourth repeat, long before you would have noticed. You can stop any of them yourself, any time.
Check the record. Every decision is receipted and chained together. Approve or deny when an agent asks, and your call is recorded too. Change one record and the chain visibly breaks: press Check the records.
curl | sh, on rm -rf, or on reading your .env, because all of them are cheap. These fire on a full budget. Watch scraper-07 try one below.These cards are the real thing. The dashboard is where you set what they may spend and what they may do.
See the dashboardRunning the test suite on your most expensive model is the commonest way to overspend without noticing. It happens on Claude, on ChatGPT, on Gemini and on Grok alike, and Enforcer checks all of them the same way. Here is exactly how it decides.
Watch it decide.
Forty-three models across four providers are priced in, so a mixed fleet is measured at each model's own rate rather than one blended guess. A wrong downgrade costs more in bad work than it saves in tokens, which is why it moves one step and says nothing when it is unsure.
An agent you cannot ground is not autonomy. It is exposure.
The demo proves the mechanism. Putting agents in front of real budgets and real customers needs the unglamorous parts too. Here is what that looks like.
Halt one agent, one tool, one team, or the entire fleet. Automatic triggers on spend velocity and repeat loops, so the stop does not wait on a human noticing.
Every verdict hash-chained to the one before it, so an edited record breaks the chain and shows it. Exportable for whoever asks to see it.
A session that fans out to dozens of subagents reaches four figures in one sitting. Every spend cap is a total, and a total only notices once the money is gone. This watches three rates instead: dollars a minute, new agents a minute, and errors an agent keeps retrying through.
Per-team and per-project budgets, rules kept in version control and reviewed like any other code, and single sign-on so the approver is a real named person.
Everything above is a simulation. The real thing does the same job for your actual agents and runs entirely on your own machine, nothing leaves it. It is not built for one provider: Claude, ChatGPT, Gemini and Grok are all first-class, and anything that lets you set a base URL works the same way. Pick what you use and copy the line.
Where does this go? Into your computer's command line, not a chat window. On a Mac open Terminal, on Windows open PowerShell, then paste and press enter. You need Node.js installed first, it is free. The dashboard opens by itself.
The dashboard is yours alone, on your own machine. It shows nothing until one of your agents does something, then every decision appears on it live.