Centralized Policy Engine
Configure user token budgets, LLM provider credentials, agent tool rules and role privileges. All changes hot-reload in runtime with zero restarts.
💰 User Budget Caps & Spend Governance
Enforce hard dollar caps on LLM spend. Requests exceeding caps are rejected instantly (<1ms, $0) without downstream token burn.
| User | Role | Current Total Spend | Hard Budget Cap (USD) | Update Cap |
|---|---|---|---|---|
| Loading user budget limits... | ||||
🔑 External Providers & API Tokens
Configure upstream AI provider credentials stored securely in SQLite.
🧰 Agent Tool Rules (Hybrid Tool Gate)
Every tool call: deny rules (final, even for admin) → argument DLP scan → allow rules → gray zone: AI tool guard + role privileges. Tool patterns match the whole tool name; ALLOW argument patterns must match the whole value, DENY patterns match anywhere. Changes apply instantly.
| # | Action | Tool | Argument | Pattern | Role | Description |
|---|
👥 Roles & Privileges
Toggle a privilege to grant or revoke it for the whole role. Applies to the next tool call.
⏸ Tool Call Approval Queue
Paused agent runs resume as soon as their last pending call is decided.