WWarden
Portfolio

Spend Tracker

Spend Tracker · owned by Admin

Tracks AI spend across all four apps. It runs a sub-agent per app in parallel — each reads its own app’s AI usage — then adds the costs into one number. Read-only: it watches spend, it never spends.

Active

Sub-agents

It runs these in parallel — each a separate identity, read-only and scoped to a single app. One worker can't reach another app's data.

Spend · Portfolio
Active

Sub-agent of Spend Tracker — reads Portfolio's AI usage (tokens and cost) and reports it up. Read-only, scoped to Portfolio alone.

Autonomous·Acts on its own — within scope + guardrails
Owner · AdminConfigure
Spend · WealthEngine
Active

Sub-agent of Spend Tracker — reads WealthEngine's AI usage (tokens and cost) and reports it up. Read-only, scoped to WealthEngine alone.

Autonomous·Acts on its own — within scope + guardrails
Owner · AdminConfigure
Spend · Pathwise
Active

Sub-agent of Spend Tracker — reads Pathwise's AI usage (tokens and cost) and reports it up. Read-only, scoped to Pathwise alone.

Autonomous·Acts on its own — within scope + guardrails
Owner · AdminConfigure
Spend · Inkwell
Active

Sub-agent of Spend Tracker — reads Inkwell's AI usage (tokens and cost) and reports it up. Read-only, scoped to Inkwell alone.

Autonomous·Acts on its own — within scope + guardrails
Owner · AdminConfigure

Aggregated spend

What the sub-agents collected — total AI spend across all apps, and the per-app split.

Reading each app’s usage…

Autonomy

The trust dial: how freely the agent acts on things it's already allowed to do. Even at full autonomy, it can never reach beyond its permissions.

Acts on its own — within scope + guardrails

Scope

What the agent may touch. Anything not explicitly allowed here is off-limits by default — no exceptions.

ReadSyncFlushRestartRoll backRotateInvoke
Service
Integration
Deployment
Data store

Default deny — access exists only where explicitly granted. Toggle a cell to grant or revoke.

Guardrails

Safety rules on top of permissions — the strictest rule wins. A guardrail can send even a fully-autonomous agent to a human for approval.

Production needs approval
Any action on a production target drops to the approval queue.
Rollback needs approval
Rollbacks always require a human sign-off.
Blast-radius cap
Limit how many resources one action may touch.
Rate limit
Cap actions per rolling hour.
Max actions / hour
Ask when unsure
The agent acts on its rules alone, but anything it can’t confidently decide comes to you for approval.

Ownership

Every agent answers to a responsible human. If that person leaves, the agent pauses itself — nothing keeps running with nobody accountable.

Owner: Admin

Activity

What this agent has attempted, each decided live by the engine. Run its next scripted action, or type one in plain language.

Run this agent’s actions
Next · step 1 of 3
read anthropic-billing · production
Sub-agent A · read the provider’s billing totals.
Try:

No attempts yet — run an action and watch Warden decide.