Rainkernel

Product 02 · In build — pilots from December 2026

Agent Cost Governor

A budget the agent cannot exceed — per task, per step, per model — enforced before the invoice, not after.

Explainer for a product in build: the six controls, the weekly cost-per-task report (sample figures), how the four-week rollout runs and the published prices — captioned, no sound required. A recorded walkthrough replaces it when pilots start in December 2026. · Open the video file

The problem

Every budget control on the market stops at the API key. The agent loop is where the money goes.

Gateways cap spend per key, team or month. Cloud billing alerts arrive about a day later. Neither knows what a task is — so a single agent can retry, escalate models, spawn sub-agents and burn a quarter's budget in an hour while every dashboard stays green. The Governor sits in the loop and knows the task.

>5×

rise in inference cost per agentic workflow through 2028 — 'unbounded costs' is now Gartner's phrase.

source

Gartner, August 2026

$50,000

burned by one accounting agent in under an hour, from 15,000 API calls, with no attacker involved.

source

Google Mandiant report, via Help Net Security, September 2026

~24 h

lag on cloud billing alerts, while the actions that caused the spend are in CloudTrail within minutes.

source

InfoQ, July 2026

The place nobody else holds

What we publish that the alternatives do not.

Cost per finished task as test evidence. Of about 35 testing and assurance providers reviewed in October 2026, one names runaway cost as something it tests. The Gate measures it on real traffic and the Governor enforces the ceiling — a reliability result with a number, not a FinOps afterthought.

From the Lab's October 2026 review of the market — the six open places, and how we earn them.

What it does

Six things the Agent Cost Governor does that the alternatives do not.

  1. 01

    Cost ceiling per task

    A budget attached to the unit of work your business recognises — a resolved ticket, an invoice, a document, a case — not to an API key. When the ceiling is reached the task halts or degrades gracefully, and the owner is told why.

  2. 02

    Step, depth and spawn caps

    Maximum steps per task, maximum tool-call depth, maximum child agents. The controls that would have stopped the documented spawn storms and tool-chain amplification attacks that inflated single queries by hundreds of times.

  3. 03

    Model lock

    Agents may not silently escalate to a larger model. Escalation is a policy decision with a budget, logged, not a prompt's whim.

  4. 04

    Server-side circuit breaker

    Enforcement lives in the gateway, not in client code the agent can route around. Per-agent cloud accounts with CloudTrail-driven kill switches for the actions that cost money outside the model.

  5. 05

    Nightly reconciliation

    Client-side token counts reconciled against the provider's billing export every night; drift reported, because client counters and invoices have been shown to disagree by multiples.

  6. 06

    Weekly cost-per-task report

    Before and after, per agent and per task type, in a page your CFO reads without a glossary. The same event log feeds the Compliance Evidence Pack later.

What you receive

Deliverables

  • The Governor gateway deployed in your cloud (proxy plus policy)
  • Task budgets, step/depth/spawn caps and model locks as reviewed policy
  • Circuit-breaker and kill-switch runbook
  • Nightly reconciliation job and drift report
  • Weekly cost-per-task report; monthly reconciliation statement
  • Hash-chained event log of every budget decision

Who buys it

Built for

  • Whoever owns the cloud bill and the agent estate — platform leads, FinOps, the CTO
  • Companies that have had one surprise invoice and do not want the second
  • Retainer clients, where the Governor ships as the headline control

Built on open engines: LiteLLM, Open-source MCP gateways, AWS CloudTrail — under Rainkernel's corpus, rubric, report generator and BOM emitter.

Pricing

Published prices. A quote never exceeds the price on this page for the scope on this page.

In build — pilots from December 2026

Inside the Run and Improve retainer

included

The retainer runs $8,000–15,000 a month; the Governor and its weekly report are its headline deliverable.

Ask about this tier

Standalone — per estate

$2,500–5,000 / month

For agent estates Rainkernel did not build. Deployment inside your cloud; price by number of agents and gateways.

Ask about this tier

Prices in USD and exclusive of applicable taxes; Indian clients are invoiced in INR with GST. Window: Build November–December 2026 · live in paying estates by January 2027. Our public commitment for this product: By 31 January 2027 the Governor is live in paying estates with published before-and-after cost per task and zero unbounded incidents — or we say so here.

FAQ

Questions we are asked

We already have budgets in our LLM gateway. Why is this different?

Gateway budgets are per key, team or month. They cannot tell a $4 task from a $4,000 one until the month's budget is gone. The Governor attaches the budget to the task and enforces it on every step, server-side.

Will it slow the agents down?

The policy check is a local decision on the proxy — single-digit milliseconds. Reconciliation runs nightly, off the hot path.

Which model providers and frameworks?

Anything that speaks HTTP to a model or an MCP server: OpenAI, Anthropic, Bedrock, Azure OpenAI, Vertex, self-hosted. Framework-agnostic because it sits on the network, not in your code.

Works with

Talk to us about the Agent Cost Governor.

A 30-minute call with the engineers who build it, no deck, no charge. If it fits, a fixed-price proposal within 48 hours.