WI-066 · Platform & Contracts · cost-governance

Cost governance (hierarchical budgets, reserve->authorize->reconcile handshake, cost ledger, over-budget engine + quality floor, approval, local accounting, pricing catalog)

queued P1 medium risk   Owner: Paul   Reviewer: Mark Hilleary   0% · 0/1 tasks complete

Gates: P8 Requirements: Updated: 2026-06-22
Evidence
queued (P8 cost)

Goals

Make spend bounded and truthful: the reserve->authorize->reconcile budget handshake that P2/P3/P7 call before any paid attempt, hierarchical budgets with green/yellow/red/critical states, an append-only micro-unit cost ledger, an over-budget engine that never crosses the quality floor, and honest reconciliation of overruns.

Implementation — what to build

Build (governance)

  • budget-policy schema + scan-type policies; hierarchical budget evaluator; reservation service + attempt-authorization contract; cost estimation + reconciliation; append-only cost_ledger (micro-units); budget-state calculator; over-budget decision engine (typed outcomes, optional-only degradation, quality floor); paid-action approval; local-compute accounting; versioned pricing catalog.

Test

  • Paid attempt without authorization fails; expired/route-mismatch fails; hierarchical block precedence; retry accumulation (one cumulative budget); downgrade stays qualified + above floor; actual-cost variance recorded+alerted; ledger consistency; pricing version/stale/ceiling; MCP paid op routes through the handshake.

Entitlement in the handshake (D35)

  • The reserve→authorize step also checks plan entitlement + reserves/decrements credits against the ledger before any paid attempt; G4 reads the ledger for billing.

Checklist

  • P8 Observability and cost-control policy: scan trace structure, per-scan-type token/tier budgets, and quality/cost metrics are defined.

Gates & testing

  • P8 Observability and cost-control policy: scan trace structure, per-scan-type token/tier budgets, and quality/cost metrics are defined.
    CODE TEST

Requirements

No linked requirements.

Verify (done when)

No paid attempt begins without a versioned budget authorization; reserve->authorize->reconcile implemented with per-attempt authorization (retries share one cumulative operation budget); hierarchical budgets (tenant/plan/period/operation/scan) + green/yellow/red/critical; append-only cost ledger in integer micro-units; versioned pricing catalog (not in adapters); over-budget engine with typed outcomes that only reduces declared-optional scope + never crosses the quality floor; actual-over-reservation reconciled truthfully + alerted; paid-action approval (model can't self-authorize); local-compute accounting; paid MCP + ingestion cost linkage. Per spec section 12-27, 52 (cost rows). Unblocks paid work for P2/P3/P7.

Cost triggers

No paid API / infra spend triggered by this item.

Status & editing

queued   Sprint: P&C Wave 3: Vision Pipeline & Cost

Edit status / sprint on the ★ Live Board → — changes are logged live with who / when / why.

Human-in-the-loop

No human tasks linked.

Findings

None recorded yet.

Concerns

None recorded yet.

Risks

None recorded yet.

Tech debt

None recorded yet.

Tools used

No tool calls recorded.

Files & artifacts

No files / artifacts recorded.

Update log

No log entries yet.