# Valistry > AI FinOps for the agentic enterprise. Every AI dollar attributed, tied to its outcome, and every saving verified on the same ledger. Deterministic money: no model does arithmetic. ## Get started 1. Connect a source. A read-only key or a sign-in on the vendor's page. The key is tested on seven days before it is stored; the first sync reads ninety and the scan arrives by mail. 2. Give every dollar an owner. Unallocated is a named number. Attribution suggests rules from the evidence, previews the coverage each reaches, and publishes; every screen recomputes. 3. Realize a saving. A finding carries its evidence and the change to make. Approve it; the expected saving lands on the ledger, and the verified saving follows after seven days on the same baseline. ## Screens ### Overview (/overview) The estate on one screen: the total, coverage, what is realizable now, the governed share, the day-by-day chart with the spike ringed, and the three findings worth most. - Total: Every priced record in the window, summed in integer millionths of a dollar. Never sampled, never rounded until it is printed. - Attributed: The share of spend with a workflow or a team, from a tag, a published rule or the registry. - Realizable now: The findings that need no code — a rule, a cap, a flag, a seat — summed. - Governed: The share of spend under a policy that has an owner. - At this pace: The trailing week's daily rate times the days left in the month, added to the month so far. Labelled a projection. - The spike: A day more than a usual day by a fixed margin, ringed on the chart; the row under it names the workflow that carried it and how much was retries. - Do: Read the three findings; each opens with its evidence. - Do: Ask a question in the bar; the answer is computed, never guessed. - Do: Widen the range from the top bar; every figure follows. ### Connect (/connect) Every source, connected or not: what it reads, what it needs, and what the last sync found. A key is tested on seven days before it is stored, encrypted. - Sources: Connected sources with a sync in the last day; a silent one is named. - Last sync: Records read, the window, and the total against the vendor's bill for the same days, exact or with the difference. - The scan: Sources, spend, models, unallocated and realizable now after the first sync, as one card, one page and one mail. - Do: Connect a provider with a read-only key, or sign in on the vendor's page where it offers it. - Do: Open a connected source to read its receipt: one line per fact the sync verified. - Do: Upload an export where a vendor has no API; the ledger prices it the same way. ### Estate (/estate) What is running and for what: every provider, model, workflow and agent, with its share, its owner or its gap. - Attributed · Unallocated · Unavailable: Three numbers, never one. Unallocated is spend no rule has claimed; unavailable is a source that reports no meter. - By workload: Coding assistant, chat, in-product agent, retrieval, speech, image, evaluation, tool calls — from a tag, the registry or the call's shape. - Owner gaps: Agents with no business owner, counted, never assigned by guess. - Do: Drill any row to the records behind it. - Do: Send an unallocated row to Attribution; a rule is drafted from its evidence. ### Spend (/spend) The ledger by any dimension — provider, model, workflow, workload, team, agent, metering, status, day — with the change against the window before, both windows named. - Total: The window's spend; the same total under every grouping. - Change vs before: This window against the equal window behind it, as a percentage, with the earlier total over its dates. - Cost · Tokens · Requests · Cost + tokens: The chart's measure; the last draws tokens as a line over the cost bars, so a rate change and a volume change read apart. - Tokens by type: Input, output and cached tokens with their cost, where the record was priced from tokens. - Share: A row's part of the total; the rows sum to it exactly or the page says so. - Do: Switch the grouping in the table's tabs; the chart re-stacks. - Do: Export CSV from the head; it is the same rows. ### Attribution (/attribution) Where unallocated spend gets an owner: suggested rules from the evidence, a preview of the coverage each reaches, and every rule's history. - Coverage: The share of spend with an owner; it rises when a rule publishes and never by estimate. - A suggestion: Untagged runs beside tagged runs on the same key, profile or region; the rule says which. - Preview: The coverage the rule would reach, computed on the window before it is live. - History: Every version of a rule as it was, what changed, and a restore that makes a new version. - Do: Preview a suggestion, then publish; every screen recomputes. - Do: Open a rule's history to see who changed what and restore an older version. ### Teams (/attribution/hierarchy) The registry above the team: which department it sits in, and which business unit above that. A record still carries only its team; the levels above are read from here each time a window is read. - Rolled up: The share of spend whose team is placed in the registry. - Not placed: Teams the records carry that nobody has put anywhere. They roll up to nothing, and are named here. - Spend at a level: A department's figure is the spend of every team inside it, in this window. Every level sums to the same ledger. - Do: Add a business unit, then a department inside it, then place a team. - Do: Group Spend by department or business unit; the totals never move. - Do: Reorganise freely: nothing is written to a record, so no history is rewritten. ### Shared costs (/attribution/shared) Money no tag, rule or trace can give an owner — a shared key, a gateway, a platform team's own spend — divided by a method the business chose. A split is a decision, and stays apart from attribution, which is evidence. - Allocated: What the published rules divided this window. Counted apart from coverage, because it is a decision. - Still nobody's: What no rule could divide, and is honestly nobody's. - The six methods: Evenly; by each one's own spend; by a meter; by set percentages; at an internal rate; by what each produced. - The basis: The sentence under each line saying how its share was reached — 62% of tokens, $3.00 per 1M tokens × 412M, 30% as set. - A refusal: A rule whose basis weighs nothing says so and divides nothing. A split of nothing across nobody is never printed. - Do: Draft a rule; it shows what it would divide before you publish it. - Do: Publish it, and every team's figure on the AI P&L carries its share, on its own line. - Do: Retire it, and the money goes back to being nobody's. ### Outcomes (/outcomes) Spend against what it produced: each workflow with its outcome, joined by trace or by workflow, and its evidence class. - Measured: A trace joined an outcome from a business system; cost and result on one row. - Declared: The workflow's outcome is named but not yet joined by a trace. - Unmeasured: No outcome source is connected for this workload. Named, never filled. - Do: Connect an outcome source — Salesforce, Zendesk, GitHub, DevRev — to measure more. - Do: Declare a workflow's outcome in the registry until a trace can join it. ### Unit economics (/unit-economics) Cost per successful outcome, per workflow, with retry waste and failures kept apart from the successes. - Cost per successful outcome: Attributed spend over successful outcomes above the quality threshold. Never cost per token. - Retry waste: Spend on attempts after the first, summed apart. - Trend: The unit cost day by day; a bad day reads as a unit-cost spike, not only a spend spike. - Do: Compare workflows on the same unit; the cheapest per token is rarely the cheapest per outcome. - Do: Open a finding from a row where retries carry the cost. ### Opportunities (/opportunities) Every finding the detectors raised, with its evidence, the change to make, how it is verified, and what was decided. Expected savings by kind, and every finding by state. - Expected saving: Baseline cost minus forecast cost for the cohort, from the same records re-priced. - Confidence: How much of the cohort the evidence covers. - Effort class: No code, engineering, or re-architecture. - Realizable now: The no-code findings, summed. - Do: Approve a finding; the expected saving lands on the ledger with your name. - Do: Model it on Scenarios first if unsure; assign it to Jira from the card. - Do: Log a finding the detectors could not see — a contract, a seat audit; it is labelled declared and verified by hand. ### Scenarios (/scenario) Change one assumption and watch the forecast move: the same runs re-priced on another model, a cache TTL, a retry cap, a seat count. - Before · After: The cohort's cost as priced, and as it would be priced under the change. - The price ladder: The routing cohort's exact tokens on every model the rate card prices. - Quality: The measured quality delta where a benchmark exists; unchanged otherwise, and it says so. - Do: Move the slider; the figures recompute from the records. - Do: Approve from here; the parameters are written into the ledger entry as its note. ### Ledger (/ledger) Every decision on a finding: the saving expected on approval, the saving measured after the change, against the same baseline. Append-only. - Expected: Recorded on approval; never overwritten. - Verified: Measured at least seven days after the change ran, on the same cohort and baseline. - Realization rate: Verified over expected. The company's own metric. - Do: Mark a finding implemented when the change has run; verification follows on its own. - Do: Export the ledger for the finance system; the same rows. ### Agents (/registry) Every agent with its business owner, its monthly envelope and its mode. A gap is named, never filled. - Envelope: A monthly budget set from the agent's own history. - Spend this month: The agent's attributed spend, month to date. - Mode: Observe, warn, require approval, enforce — the policy's mode on this agent. - Do: Add an agent or assign an owner from its row. - Do: A new agent with a budget gets its envelope in observe. ### Policies (/policies) Templates with defaults from your own ledger, backtested on the window before a mode changes, and a ladder from observe to enforce. - Backtest: What the policy would have done on the window, in its mode: how many runs, how much spend. - At this pace: For an envelope: where the month lands at the trailing week's rate, and on which day it crosses. - Governed spend: The share of spend under a policy with an owner. - Do: Install a template; it starts in observe. - Do: Move a policy up the ladder once its backtest is clean. ### Approvals (/approvals) The held batch: runs waiting once a policy in Approve has breached, who decides, and the record of each decision. - Waiting: Runs after the breach, counted; their cost beside them. - Decided: Each batch's decision with who and when; the latest can be reversed. - Do: Approve or refuse the batch; the decision is on the change log. ### Alerts (/alerts) What the seven watches raised in the window, each with its severity, its cause and where it is decided; addressed or ignored with who and when; whether it was sent. - The seven watches: The spike, envelopes, policies, the queue, drift, the week and the close. Each runs after the sync and says a thing once. - Raised · Quiet · Not set up: A watch that found something today, one that ran and found nothing, one with nothing installed to watch. - Do: Address or ignore an alert; the decision lands on the change log with your name. - Do: Name a Slack or Teams channel under Settings → Notifications; mail goes to owners and admins regardless. ### AI P&L (/pnl) The report finance keeps: spend by team and workflow against the month before, coverage, realized savings, and the export — CSV and JSON from the same builder. - Month against month: This month and the one before, per team, from the ledger. - Realized: Verified savings in the month, from the Value Ledger. - Do: Toggle the views to shape it; export from the head. - Do: On Enterprise, the same figures are pushed nightly to an endpoint you name, signed. ### Ask Valistry (/ask) A question in plain words, answered with the figure, the plan that produced it and the rows behind it. The planner reads; the engine computes; a model narrates and never does arithmetic. - The plan: Which measure, which grouping, which window — shown, so the answer can be checked. - The figure: Computed by the same functions the screens use, from the same ledger. - The verdict: Whether the answer is exact, an estimate the engine labels, or a refusal because the ledger cannot say. - Do: Ask from the bar on any screen with ⌘K. - Do: Ask from Claude Code, Cursor or Claude: the MCP server serves the same seven tools. ## Words - Estate: Every AI source, model, agent, seat and workload an organization pays for. - Ledger: The reconciled record of every AI dollar, attributed, with what it produced. - Source: A connector that reads a vendor: OpenAI, Anthropic, Bedrock, a gateway, a seat tool, a business system. - Bill: What the vendor charged, read from the vendor, shown beside the ledger, never used to fill it. - Reconciled: The ledger's total for a source against the bill for the same days. Exact, or the difference is shown. - Unallocated: Spend no rule, tag or trace has given an owner. A named row on every screen, never hidden. - Allocation: A decision dividing shared cost across teams or workflows, by a method the business chose. Never evidence, never attribution, and it never moves the total. - Hierarchy: Team inside department inside business unit. A registry read onto every window, never written to a record, so a reorganisation rewrites no history. - Coverage: The share of spend with an owner. It rises when a rule publishes and never by estimate. - Finding: A saving or a risk the detectors found, with its evidence, its cohort, the change to make and its effort class. - Effort class: Easy money, engineering, or re-architecture. Easy money needs no code: a rule, a cap, a flag, a seat. - Realizable now: The findings that need no code, summed. The one figure Starter shows of the findings. - Outcome: The business result a workflow produced, from the system that recorded it, with its evidence class. - Evidence class: Observed, declared or unmeasured. Every cost-per-outcome figure says which. - Cost per successful outcome: Attributed spend divided by successful outcomes, retry waste kept apart. Never cost per token. - Value Ledger: Every decision on a finding: expected on approval, verified after the change, against the same baseline. - Verified saving: What the ledger measured after a change, at least seven days on, against the same baseline. Expected is never overwritten. - Realization rate: Verified savings over expected savings. The company's own metric. - Envelope: An agent's monthly budget, set from its own history. - Policy: A rule with a mode: observe, warn, require approval, enforce. Backtested on the window before a mode changes. - Governed spend: The share of AI spend under a policy with an owner. - Alert: What watches raised: the spike with its cause, an envelope, a policy, the queue, drift. Sent once; open until addressed or ignored. - Workload: The class of use: coding assistant, chat assistant, in-product agent, retrieval, speech, image, evaluation, tool calls. - Metering: What the vendor priced: tokens, seats, audio seconds, images, or the bill itself. - Starter · Platform · Enterprise: Free at any spend; 2 percent of AI spend under management; the Platform tier on an order form above $100,000 a month. ## The record - id (Identity): Stable within the organization; a re-sync never counts a record twice. - source (Identity): The connector that read it. - source_record_id (Identity): The vendor's own id for the line, or the hash of it. - invocation_id (Identity): One call, one id; attempts of the same call share it. - trace_id (Identity): The trace the call ran in, when the source carries one: the join to an outcome. - occurred_at (When and who): The instant, UTC. - provider_id (When and who): The vendor that served it. - model_id (When and who): The model, as the vendor names it. - application_id (When and who): The application or key that made the call. - agent_id (When and who): The agent, once attribution has given the call one. - workflow_id (When and who): The workflow, once attribution has given the call one. - team_id (When and who): The team, from a tag, a rule or the registry. - department_id · business_unit_id (When and who): Read from the team registry when a window is read, never stored: a reorganisation rewrites no history. - project_id · customer_id (When and who): When the vendor or a rule carries them. - input_tokens · output_tokens · cached_tokens (How much): By the vendor's own count. - request_count (How much): Calls in the line; one for a call, more for a daily bucket. - metering (How much): tokens, seats, audio_seconds, images, or bill. - workload (How much): The class of use, from a tag, the registry or the call's shape. - status (How it went): ok, error or timeout. - latency_ms (How it went): As the source reports it. - attempt · retry_count (How it went): Which attempt this was, and how many came before it: the retry line every finding reads. - normalized_cost_micros (What it cost): The ledger's figure, in integer millionths of a dollar, from the rate card that applied. - source_cost_micros (What it cost): What the source itself said it cost, when it said. - pricing_version (What it cost): Which rate card priced it; a price never changes without a person reading the diff. - currency (What it cost): USD. - inference_profile · api_key_id · region (Metadata): What the vendor attaches; what a rule can match on. - complexity (Metadata): One to five, when the source carries a signal. - prompt_signature (Metadata): A hash of the prompt's shape, never its text: the caching detector reads it. - person (Metadata): A hash of the seat holder, never a login or an email. - Never in the record: prompts, completions, conversations, transcripts, documents, source code, names. ## The read API GET https://app.valistry.ai/api/v1/ with the organization's MCP key or a signed-in token as the bearer. The MCP server at https://app.valistry.ai/api/mcp serves the same seven tools. POST /api/v1/records accepts your own records with the push key (https://valistry.ai/docs/push). - /api/v1/estate: Total, sources, coverage, unallocated, realizable now, governed share, the spike, the month at this pace. (params: days) - /api/v1/spend: Spend by one dimension, each group's share and tokens; against the period before when asked. (params: by · days · compare) - /api/v1/findings: Every finding with its evidence, the change to make, how it is verified, and where it is tracked. (params: status: open · approved · verified · all) - /api/v1/ledger: Every decision, with the saving expected on approval and the saving measured after. - /api/v1/policies: Every policy with its mode, owner, the metric against its threshold, and the envelope at this pace. (params: days) - /api/v1/alerts: What watches raised in the window, with its state and whether it was sent. (params: days · state) - /api/v1/ask: A question in plain words, answered with the figure, the plan that produced it and the evidence. (params: q · days) - POST /api/v1/records: Your own records, in the shape every connector writes: a bill, an export, a vendor we have no connector for. Needs the push key, not the read key. ## Connectors - Anthropic usage and cost (https://valistry.ai/docs/connectors/anthropic): Usage and cost reports: tokens per model, workspace and key per day, and the bill. Claude Code analytics: sessions, tokens and lines per person per day, with the person stored as a hash. Never prompts or completions, never members. - OpenAI usage and costs (https://valistry.ai/docs/connectors/openai): Organization usage and costs only: tokens per model, project and key per day, the bill by line item, and transcription minutes. Never prompts, completions, members or projects. - AWS Bedrock (https://valistry.ai/docs/connectors/aws-bedrock): CloudWatch's Bedrock token metrics per model per day and the Cost Explorer bill for the Bedrock service. Never invocation content, never other services. - GitHub Copilot seats (https://valistry.ai/docs/connectors/github-copilot): The Copilot seat list and plan: who holds a seat (stored as a hash, never the login), since when, the assigning team, and whether GitHub saw activity in the last 28 days. Never code, never repositories, never members. - Cursor team (https://valistry.ai/docs/connectors/cursor): The team roster (stored as hashes, never emails), each member's daily activity, usage events with tokens and the cents Cursor charged beyond the plan, and the cycle's spend. Never code, never prompts. - OpenRouter (https://valistry.ai/docs/connectors/openrouter): Daily totals per model and upstream provider, and the key's own usage counters. No prompt, no response, no request body. - Azure OpenAI (https://valistry.ai/docs/connectors/azure-openai): The Cost Management daily cost query for Azure OpenAI meters, and the token metrics on your Cognitive Services accounts. Never a prompt, never a response, never another service's cost. - Claude Enterprise seats (https://valistry.ai/docs/connectors/claude-enterprise): The organization's member list: an identifier, an email, a role and the day each person joined. Never a conversation, never a prompt, never usage. - Google Vertex AI (https://valistry.ai/docs/connectors/google-vertex): One query over your billing export, filtered to Vertex AI: the day, the SKU, the project and the cost. Never a prompt, never a response, never another service's spend. - Fireworks AI usage (https://valistry.ai/docs/connectors/fireworks): Serverless tokens per model, key and day, and the bill's rated line items per day. No prompt, no response, no request. - xAI usage (https://valistry.ai/docs/connectors/xai): Dollars per day and model for one team, from the Management API's usage query. No request, no prompt, no key list. - AWS cost and usage (https://valistry.ai/docs/connectors/aws-cost): Two Cost Explorer queries: the daily cost of every service, and the daily cost of the accelerated instance families. Never a resource, never a log, never anything but money. - Google Cloud billing (https://valistry.ai/docs/connectors/gcp-billing): Two queries over your billing export: the daily cost of every service by project, and the daily cost of the GPU and TPU SKUs. Never a prompt, never a resource, never anything but money. - Azure cost management (https://valistry.ai/docs/connectors/azure-cost): One Cost Management query: the daily cost of every service and meter on the subscription. Never a resource, never a log, never anything but money. - LangSmith (https://valistry.ai/docs/connectors/langsmith): The workspace's project list, then each project's LLM runs inside the window with twelve named fields: timing, status, tokens, cost and the metadata that names the model. Never an input, never an output, never a prompt. - Braintrust (https://valistry.ai/docs/connectors/braintrust): The organization's project list, then one BTQL query per project per day for totals per model: LLM spans, input, output and cached tokens, and estimated cost. Aggregates only — no span, no input, no output. - W&B Weave (https://valistry.ai/docs/connectors/weave): The project's calls inside the window, newest first and a page at a time, with six named columns: id, op name, when it started and ended, whether it raised, and the usage and cost summary. Never an input, never an output. - Microsoft 365 Copilot seats (https://valistry.ai/docs/connectors/m365-copilot): Which subscription is Microsoft 365 Copilot and how many units it consumes; the users who hold that licence, stored as hashes; and the Copilot usage report's last-activity date per holder. Never a document, never a prompt, never a chat, never a name. - Gemini Code Assist seats (https://valistry.ai/docs/connectors/gemini-code-assist): The billing account's orders, the Code Assist licence pool's counts, and each licensed user's email (stored as a hash), assignment day and last use. - Windsurf seats (https://valistry.ai/docs/connectors/windsurf): The roster with sign-up time, role and last feature use, and per member, per model and per day: messages and credits or ACUs. People are stored as hashes. No code, no prompt. - Perplexity Enterprise usage (https://valistry.ai/docs/connectors/perplexity): Per member and per day: credits by model and by credit source, and queries. Members are stored as hashes. No thread, no prompt, no answer. - Zendesk resolved cases (https://valistry.ai/docs/connectors/zendesk): The incremental metric-event export: one row per timing event on a ticket, of which we keep the ones that say a ticket was solved. Never a subject, never a comment, never a requester. - Intercom closed conversations (https://valistry.ai/docs/connectors/intercom): One search per page over conversations updated since the window opened, and three things on each: its id, its state and its close statistics. Never a message, never a contact, never an email address. - Salesforce opportunity stages (https://valistry.ai/docs/connectors/salesforce): One SOQL query per page over the opportunity history rows that entered your stage inside the window, and four fields on each: the row's id, the opportunity's id, the stage and the moment. Never the name, never the account, never the amount. - GitHub merged pull requests (https://valistry.ai/docs/connectors/github-prs): The organization's repositories, and the pull requests closed in each during the window: the number, when it merged or closed, and nothing else. Never a diff, never a comment, never a file. - Jira delivered issues (https://valistry.ai/docs/connectors/jira): One search per page over the issues your query matches, and three fields on each: when it resolved, its project and its resolution. Never a description, never a comment, never an attachment. - Twilio completed calls (https://valistry.ai/docs/connectors/twilio): The account's completed calls inside the window, a page at a time, and six fields on each: its sid, its status, when it started and ended, how long it lasted and which way it went. Never a phone number, never a recording, never a transcript. - DevRev resolved tickets (https://valistry.ai/docs/connectors/devrev): The works export for tickets closed in the period: each ticket's id, close date and stage. Never a title, never a conversation, never a customer. - Portkey gateway (https://valistry.ai/docs/connectors/portkey): Daily totals per virtual key: requests, errors, total tokens and the cost Portkey computed, plus the list of models it saw. Never a log, never a prompt, never a response. - Langfuse (https://valistry.ai/docs/connectors/langfuse): Daily totals per model and environment: observations, input and output tokens, and the cost Langfuse holds. The metrics endpoint returns aggregates only — no trace, no prompt, no completion. - LiteLLM proxy (https://valistry.ai/docs/connectors/litellm): The proxy's spend log: one row per request, with the model, the token counts, what the proxy charged, and the team and key it belongs to. Never the prompt or the response, which live in columns we do not ask for. - Helicone (https://valistry.ai/docs/connectors/helicone): One row per request: the model, the upstream provider, the token counts, the latency, the cost Helicone computed and the properties you set. The query asks for inputs to be left out, so no prompt and no response is returned. - Cloudflare AI Gateway (https://valistry.ai/docs/connectors/cloudflare-ai): Daily totals per model, upstream provider and gateway: requests, input and output tokens, cache reads, errors and the cost Cloudflare computed. Never a request body, never a response. - OpenTelemetry (https://valistry.ai/docs/connectors/otlp): Token counts and the attributes around them: the model, the provider, your service and environment, the agent, the conversation and the trace. Never a prompt, never a completion, never a tool argument — those attributes are not on the list this source will read, so they cannot reach a record even when you send them. - Linear completed issues (https://valistry.ai/docs/connectors/linear): One GraphQL query per page over the issues completed inside the window, and five fields on each: its id, its identifier, its url, when it completed and which team and state it is in. Never a description, never a comment. - Vercel AI Gateway (https://valistry.ai/docs/connectors/vercel-ai-gateway): One report per day of the window, grouped by model: the cost, the token counts and the request count. Never a prompt, never a response, never a generation's content. - Databricks (https://valistry.ai/docs/connectors/databricks): One query over system.billing.usage joined to system.billing.list_prices: the day, the SKU, the workspace, the DBUs and the cost. Never a table of yours, never a notebook, never a query anyone ran. - Snowflake Cortex (https://valistry.ai/docs/connectors/snowflake): One query over the account usage view for Cortex AI functions: the day, the function, the model, the credits, the tokens or pages, and how many queries. Never a table of yours, never a prompt. ## Changelog - 2026-09-13 — Team, department, business unit. One registry above the team, read onto every window; Spend groups by any level, and every level sums to the same ledger. - 2026-09-13 — Shared costs, divided six ways. A shared key or a platform cost, split evenly, by spend, by a meter, by set percentages, at an internal rate, or by what each team produced. - 2026-09-13 — A rule's history, with a diff and a restore. Every version of an attribution rule is kept as it was; the history says what changed; an older version restores as a new one. - 2026-09-13 — The spike with its cause, pacing per envelope, the month at this pace. Every spike is ringed and the first names the workflow that carried it; an envelope says where it lands and on which day it crosses. - 2026-09-13 — Spend Explorer compares with the period before. The equal window behind this one, not the window's halves; cost, tokens or requests on one toggle; tokens split by type with their cost. - 2026-09-13 — Alerts have a lifecycle. Open, addressed or ignored, with who and when, on the change log. Findings filter by status. - 2026-09-13 — Findings into Jira; Teams beside Slack. An approved or assigned finding becomes one Jira issue, once. The channel takes a Slack or a Teams webhook. - 2026-09-13 — Ask inside Claude Code, Cursor and Claude. A read-only MCP server with seven tools, one key per organization for the editor and sign-in for the chat. - 2026-09-13 — Card checkout, and pricing settled. Platform is 2 percent of AI spend under management, no minimum, by card. Starter is free at any spend. - 2026-09-12 — Enterprise: one P&L across organizations, the change log, nightly export, SAML and SCIM, enforcement events. What a group needs and a single estate does not, each built as a slice. - 2026-09-12 — What watches. After the nightly sync: the spike with its cause, envelopes, policies, the queue, drift, the week and the close, to Slack and by mail, each said once. - 2026-09-12 — Starter and the Platform tier. Locked screens print their real headline and the price for this estate; Ask answers discovery questions free. - 2026-09-12 — Connection by consent, Salesforce first. OAuth for the sources that offer it; the key form stays for the rest. - 2026-09-11 — Findings into Slack. A finding nobody sees is not realized: each new one posts with its saving and a link to its evidence. - 2026-09-10 — The price ladder on the Scenario Lab. The routing cohort's exact tokens on every model the rate card prices.