TL;DR: Put each autonomous agent's spend ceiling in a control plane the agent cannot write to, and give each workload its own production credential. During key rotation, accept both old and new credentials briefly, move traffic, then revoke the old one. This keeps a compromised tutoring agent from raising its own allowance or turning one leaked key into an account-wide billing event. The rule is deliberately boring: the process choosing model calls must not also control the maximum cost of th...