Control Packs · AUT-003 · v1.0.0
Cost and Quota Boundary
Make expensive, high-volume, or quota-consuming automation bounded and observable.
Status: review · Review: not independent. This is design guidance; review status does not establish independent verification or compliance.
What this safeguard addresses
Define and enforce resource, cost, rate, and quota boundaries with safe degradation and operator visibility.
- Automation consumes resources without a confirmed limitA loop, batch, model, or provider call can exceed a budget, quota, or rate boundary without a safe stop or operator-visible warning.
Versioned applicability rule
{
"characteristic": "HIGH_COST_CONSUMPTION",
"equals": true
}Decisions for the project owner
Leave a decision open when its value is unknown. Suggested values become confirmed only through an explicit user decision.
- What resource, rate, or cost limit must stop or escalate the operation?A safe boundary cannot be invented from the feature description.AUT-003-Q1 · threshold
Requirements for the coding agent
- AUT-003-R1Enforce confirmed resource and cost limits, bounded concurrency, safe degradation, and an operator-visible stop path.
Tests and evidence to retain
- RESOURCE_LIMIT_TESTExercise normal usage, threshold, exhaustion, concurrency, retry, and safe-stop behavior.
- configuration_or_policy
- implementation_location
- test_result
- telemetry_definition
Passing a published example shows that example's behavior. A coding agent's implementation report remains a claim until its evidence is independently checked.
Related guidance
- SC-6 · Resource AvailabilityNIST_SP_800_53_5_2_0 · partially addressesConfirmed limits and bounded concurrency protect a defined resource boundary; they do not establish overall availability.
- SC-5 · Denial-of-Service ProtectionNIST_SP_800_53_5_2_0 · informsRate and concurrency limits inform overload protection for this operation; they are not a complete denial-of-service control.
- SI-4 · System MonitoringNIST_SP_800_53_5_2_0 · partially addressesOperator-visible usage and limit events support focused monitoring; they do not cover system monitoring broadly.
Mappings indicate contextual relevance or partial support. They do not establish equivalence, certification, government endorsement, or complete framework implementation.
- National Institute of Standards and Technology — Artificial Intelligence Risk Management FrameworkGUIDANCE_AUTOMATION
- Amazon Web Services Builders' Library — Timeouts, retries, and backoff with jitterGUIDANCE_RELIABILITY
- National Institute of Standards and Technology — Security and Privacy Controls for Information Systems and OrganizationsGUIDANCE_NIST_SP_800_53_5_2_0