Skip to content

Budget is data, not policy

Source/status: Current decision. Source: harness/docs/decisions/budget-is-data-not-policy.md.

Platform does not enforce spend policy. Wall-clock limits for lane map/reduce are a separate, narrower host mechanism (mapCapMs / reduceCapMs): timeout drops or skips that arm rather than inventing a money kill-switch in the kernel.

Usage hooks may report amounts/currencies (default currency "unknown" on unbilled / local paths). A durable per-currency fold as a platform primitive is not shipped — actors may call usage sinks; policy plugins that read a fold and self-limit are the intended shape when that data exists, not hard platform enforcement.

Subscription-based and local providers are unbilled by default. Alternate branches (forks), if ever metered, account at project/global level, never session-level (sessions fork).

“Money-metered for what we meter, yolo for others”: API calls can cost money; filesystem and local models should not force a second policy machine. Runaway spend is plugin/user kill-switch territory once usage data is real — do not invent a kernel kill-switch. Session-scoped accounting fragments or double-counts across forks.