Limits and guardrails

Limits and guardrails

Apply shared resource policies and hosted user-specific request, token, and spend boundaries accurately.

Last updated July 10, 2026

Core resource policies

AnchorShell Relay supports request, token, spend, and concurrency policies across these scopes:

  • global Relay traffic;
  • provider;
  • endpoint;
  • Relay Lane.

Policies use second, minute, hour, day, or month windows. Configured policies and observed upstream limits are kept separately; the effective decision uses the tighter applicable value.

Hosted user policies

AnchorShell Relay adds user-specific policies for:

  • one user across all Relay traffic;
  • one user and incoming model/lane key;
  • one user and provider.

User policies currently cover requests, tokens, and spend—not per-user concurrency. A user-specific hit defers or rejects that request without globally cooling a shared provider. A user-provider hit can leave candidates on other providers eligible.

Runaway agents

Relay does not detect semantic loops. It contains their operational impact through configured request, token, spend, and shared-concurrency boundaries. Use per-user and per-model policies when one agent must not consume the entire organization allowance.

Spend precision

Token and spend decisions can reserve estimates before execution and reconcile terminal usage afterward. This is not an exact billing reservation or quota-leasing system, and public copy should not describe it as one.