Category rule
Separate budgets per category (compute, SaaS, data, ads).
How to configure it
In sipi.bot: category: compute, daily_max_usd: 50. Once set, every transaction matching the
causes below is BLOCKed or FLAGged
before any money moves.
A GPU splurge draining the budget meant for SaaS tools.
5 incidents this rule would have stopped
| Incident | Loss | Cause | Year |
|---|---|---|---|
| OpenAI agents burned $72,000 in a single night | $72,000 | Unattended sessions | 2025 |
| AI coding agent bills hit $2,000–$20,000 per developer per month | $2,000–$20,000/mo | Unattended sessions | 2026 |
| Developer spent $11,922 on Cursor in under four weeks | $11,922 | Unattended sessions | 2026 |
| Fake bug report tricked an agent into leaking a live AWS key | Cost not disclosed | Prompt injection | 2025 |
| Opaque per-token pricing triggered billing shock | Cost not disclosed | Unattended sessions | 2025 |
Configure this rule in sipi.bot
The pre-spend firewall evaluates every agent transaction in <5ms. Set this rule once and it runs on every proposed charge, forever.