Two kinds of money
Keep these separate. They are configured in different places and answer different questions.Gateway spend figures are catalog list-price estimates, not your provider invoice. Negotiated discounts, credits, and provider-side adjustments are not reflected.
How the controls stack
Each layer can only narrow what the layer above allows, never widen it. A request must pass every layer that is configured.Roles and permissions
Caveman Cloud has five organization roles. This table shows the governance and financial permissions each one holds.
Credential lifecycle, identity administration, and consent changes are human-only. Coding agents connected through MCP can read governance posture but cannot create or rotate keys or change identity settings.
A recommended setup
1
Give every person and app its own key
Issue personal keys for people and shared keys for services, so every request is attributed. See API keys.
2
Restrict models at the project level
Allow only the providers and models the project needs in Governance → Access. Keys can narrow this list further.
3
Set a project budget
Start with a soft cap to learn your baseline, then add a hard cap once you know normal spend.
4
Add per-key and spend-rate limits
Give high-risk keys (CI, experiments, autonomous agents) their own hard budgets and spend-rate quotas so a runaway loop cannot drain the project budget.
5
Label keys for reporting
Add team, environment, and cost-center labels so Finance can break spend down without asking engineering.
Explore this section
API Keys
Create personal and shared keys, set scopes and per-key limits, rotate, block, and revoke.
Access and Limits
Restrict providers and models, set project rate limits, and add guardrails.
Budgets
Configure soft and hard caps, spend-rate quotas, and handle budget errors.
Cost Allocation
Attribute spend to people, teams, workflows, and customers for chargeback.
Billing
Understand plans, metered products, packages, and billing limits.
Import Gateway Config
Bring keys, budgets, and teams over from LiteLLM or Kong AI Gateway.