Resources

Where does cost leak between agent discovery and publishing?

Cost leaks when discovery, experimentation, and published production agents share keys, identities, or event budgets. An AI gateway in your network attributes spend to agents — not seats — so you can cap unpublished work without starving production.

This is a cost path for buyers who already accept that security and CRA-style logs come first. Generic token-saving tips do not help if you cannot name the agent, see the tool call, or stop it. UnitOne Gateway inspects that path in your network, then lets FinOps set caps per agent.

Discovery → experiment → publish

  1. 1

    Discovery: unnamed traffic is unowned spend

    The first leak is a shared API key and no agent identity. Every prototype completion still creates gateway events and model cost. Register discovery agents as workloads on Gateway before the prompt-tweaking week begins.

  2. 2

    Experimentation: loops without a deny or a cap

    Eval harnesses, retries, and tool-calling agents can burn a monthly event budget in a day. Put basic spend caps on experiment agents. Keep runtime security on — a cheap experiment that calls an over-scoped tool is still a security incident.

  3. 3

    Publishing: do not reuse the discovery identity

    When an agent is published to production, give it a new identity, its own event budget, and production retention. If it keeps the lab name, discovery spikes will look like customer load and production caps will halt experiments — or worse, the reverse.

  4. 4

    Attribute to agent, team, and project

    Console seats tell you who can click. They do not tell you which workload spent. Gateway attributes spend by agent, team, or project so FinOps and security look at the same object. Free has basic attribution; Team has full; Enterprise has advanced plus org policies.

  5. 5

    Meter Gateway events, not headcount

    Plans are sized by agents and gateway events per month, with Gateway in your network included. Buying more seats does not contain discovery spend. Buying a cap on the unpublished agents does.

  6. 6

    Measure a short scoreboard

    Off-path agents; denies vs allows; events and dollars per agent; discovery-to-publish time; whether a published agent's logs are exportable for vulnerability handling. If CRA-style evidence is missing on a published agent, cost control is the wrong first ticket — turn inspection on first.

Frequently asked questions

What is agent discovery spend?
Agent discovery spend is model, tool, and gateway-event cost incurred while teams find, prompt, and trial agents that are not yet published to production. It is usually unattributed: a shared key, a seat-based SaaS bill, or a lab project that never gets an agent identity. UnitOne treats that path as workloads through Gateway in your network, not as extra human licenses.
Where does cost leak between discovery, experimentation, and publishing?
Leak is traffic that never gets an agent identity: prototype keys reused in production, published agents still sharing a discovery budget, retries and tool loops with no cap, and shadow MCP servers off the gateway path. If spend is rolled up to a team seat, you cannot tell a failed experiment from a live customer workflow.
How do you attribute spend to agents, not just seats?
Seats are humans in the UnitOne console (Free: 2, Team: 5). Agents are AI workloads that pass through Gateway (Free: 10, Team: 100). Attribute tokens, tool calls, and gateway events to the agent and project. A seat limit does not cap a runaway discovery agent.
How do spend caps and Gateway events control discovery vs published agents?
Give discovery agents their own event budget and a hard cap. Give published agents a separate identity, a production cap, and longer log retention. Gateway events are the metering unit (Free: 25,000/month, Team: 500,000). Caps only work if unpublished experiments cannot borrow the production identity.
What should a security/FinOps team measure from discovery to publish?
Measure: agents on the gateway vs off-path; deny rate on tool calls; events and spend per agent; time from first discovery traffic to a published identity; exportable logs for anything that reaches users. Security and CRA-style evidence stay ahead of cost. If you cannot deny a tool, a cap is a report, not control.

Cap discovery without blinding production

Start free on Gateway to attribute spend to agents in your network. See plans for Team event volume. Talk to us for Enterprise org policies. Remediation PRs remain a scoped POC.