Control Packs · AUT-003 · v1.0.0

Cost and Quota Boundary

Make expensive, high-volume, or quota-consuming automation bounded and observable.

Status: review · Review: not independent. This is design guidance; review status does not establish independent verification or compliance.

What this safeguard addresses

Define and enforce resource, cost, rate, and quota boundaries with safe degradation and operator visibility.

  • Automation consumes resources without a confirmed limitA loop, batch, model, or provider call can exceed a budget, quota, or rate boundary without a safe stop or operator-visible warning.
Versioned applicability rule
{
  "characteristic": "HIGH_COST_CONSUMPTION",
  "equals": true
}

Decisions for the project owner

Leave a decision open when its value is unknown. Suggested values become confirmed only through an explicit user decision.

  • What resource, rate, or cost limit must stop or escalate the operation?A safe boundary cannot be invented from the feature description.AUT-003-Q1 · threshold

Requirements for the coding agent

  • AUT-003-R1Enforce confirmed resource and cost limits, bounded concurrency, safe degradation, and an operator-visible stop path.

Tests and evidence to retain

  • RESOURCE_LIMIT_TESTExercise normal usage, threshold, exhaustion, concurrency, retry, and safe-stop behavior.
  • configuration_or_policy
  • implementation_location
  • test_result
  • telemetry_definition

Passing a published example shows that example's behavior. A coding agent's implementation report remains a claim until its evidence is independently checked.

Related guidance

  • SC-6 · Resource AvailabilityNIST_SP_800_53_5_2_0 · partially addressesConfirmed limits and bounded concurrency protect a defined resource boundary; they do not establish overall availability.
  • SC-5 · Denial-of-Service ProtectionNIST_SP_800_53_5_2_0 · informsRate and concurrency limits inform overload protection for this operation; they are not a complete denial-of-service control.
  • SI-4 · System MonitoringNIST_SP_800_53_5_2_0 · partially addressesOperator-visible usage and limit events support focused monitoring; they do not cover system monitoring broadly.

Mappings indicate contextual relevance or partial support. They do not establish equivalence, certification, government endorsement, or complete framework implementation.

Continue your review