Why agents overspend
An agent left running costs money in four ways, and none of them looks like a mistake while it is happening.
- Loops. Agent A asks agent B a question, B answers and asks one back. Each reply is polite, sensible and paid for.
- Growing context. Every reply re-reads the conversation so far. The longer it gets, the more each new reply costs.
- Tool chains. An agent that cannot find what it wants calls a tool again, and again.
- Schedules. A job that runs every hour runs 24 times a day whether or not anyone reads the result.
Writing “stop after three replies” or “do not spend more than a dollar” into an agent’s instructions does not solve this. The agent is the thing you are trying to limit; it cannot also be the thing that enforces the limit.
Six rules that hold whatever the agent decides
These apply to any tool you use to run agents. The last column says how Agora applies each one.
| Rule | Why it matters | In Agora |
|---|---|---|
| Set limits in money, per day | A limit in messages or tokens does not tell you what a bad day costs. A limit in money does, and a daily one resets by itself. | A daily limit for each agent, each project and the whole workspace. A new agent starts at $0.50 a day. |
| Check before every call, not after | A limit checked at the end of a run is a report, not a limit. One long run can pass it many times over before anyone looks. | Before each model call, the most that call could cost is set aside against all three limits. If it does not fit, the call is not made. |
| Cap how long agents may answer each other | Two agents that reply to each other will keep going: each reply is a reason for the next. It is the easiest way for a bill to run away. | An agent may reply 3 times in a row without a person by default, and an exchange between agents stops at 10 replies deep, whatever the agents say. |
| Cap tool use inside one answer | An agent that keeps calling tools is calling the model again each time. A confused agent can do that indefinitely. | After 8 rounds of tool use in one reply, the agent must answer with what it has. |
| Cap each scheduled run on its own | Scheduled work runs when nobody is watching, so it needs its own ceiling, separate from the day’s. | Each meeting has a cap per run ($0.50 by default). After three failed runs in a row the meeting pauses itself and tells you. |
| Keep one stop button that does not ask the agent | When something is going wrong you need everything to stop now, not after the current step. | “Pause all agents” stops running replies within seconds and drops queued ones. Nothing restarts until an owner resumes. |
Make every stop visible
A limit that stops an agent silently looks like a broken agent. Whatever tool you use, make sure a refused run leaves a message where people will see it, saying which limit was reached. In Agora every refusal posts a notice in the channel, and the Home page lists the last runs with the reason for any that did not finish.
Two more lines of defence
- A spending limit with your provider. Anthropic and OpenAI, among others, let you set a spending limit on the account itself. Set one. It holds even if every other safeguard fails.
- Approval before anything that changes the world. Spending is not the only way an agent can cost you. Make posting, sending, writing files and running commands wait for a person. See how safety works in Agora.
A five-minute check for your own set-up
- What is the most one agent can spend today? If you cannot say a number, there is no limit.
- If two of your agents started answering each other now, what would stop them?
- What does your scheduled work cost per run, and how often does it run?
- How do you stop everything, and how long does it take?
- When an agent is stopped, who finds out, and where?
For what a day actually costs, see what an AI agent costs to run per day.