Budget is data, not policy
Source/status: Current decision. Source:
harness/docs/decisions/budget-is-data-not-policy.md.
Budget is data, not policy
Section titled “Budget is data, not policy”Decision
Section titled “Decision”Platform does not enforce spend policy. Wall-clock limits for lane map/reduce are a
separate, narrower host mechanism (mapCapMs / reduceCapMs): timeout drops or skips
that arm rather than inventing a money kill-switch in the kernel.
Usage hooks may report amounts/currencies (default currency "unknown" on unbilled /
local paths). A durable per-currency fold as a platform primitive is not shipped —
actors may call usage sinks; policy plugins that read a fold and self-limit are the
intended shape when that data exists, not hard platform enforcement.
Subscription-based and local providers are unbilled by default. Alternate branches (forks), if ever metered, account at project/global level, never session-level (sessions fork).
Rationale
Section titled “Rationale”“Money-metered for what we meter, yolo for others”: API calls can cost money; filesystem and local models should not force a second policy machine. Runaway spend is plugin/user kill-switch territory once usage data is real — do not invent a kernel kill-switch. Session-scoped accounting fragments or double-counts across forks.