Qeravio
Public AI action-limit policy

Every AI action needs a limit before it needs a tool.

Every declared safe tool policy receives a normalized planning budget, time ceiling, request rate, concurrency cap and zero external spend. These are dry-run policy limits, not a live control plane.

9declared AI units
24bounded tool policies
6normalized limit profiles
0external spend or actions
Dry-run policy evaluation, not live enforcement.

Budget units are internal, normalized and non-currency. They are not a provider billing measurement. Allow and verification-required results cannot run a tool, spend money, send, publish, deploy or prove that a real request was stopped.

Closed limit map

Twenty-four safe tool policies have exact, non-executing ceilings.

Anything outside the exact unit, tool, task, Worker, budget, time, rate and concurrency tuple is denied.

Fail-closed controls

A missing or excessive request is denied before it can be mistaken for authority.

The public endpoint is read-only and stores no evaluated request. It has no connector, credential or execution path.

  • Normalized budgetA low bounded request may pass. A request near the ceiling requires verification. Any excess is denied.
  • Time ceilingEvery policy has an exact duration ceiling and a maximum fifteen-minute evaluation window.
  • Request rateMissing, zero, malformed or excessive per-minute rates are denied.
  • Single concurrencyThis first policy slice permits only one synthetic action at a time.
  • Zero external effectAny external spend, send, publish, delete, purchase, deployment, credential or real-world action is denied.
  • Exact source and WorkerA changed source policy, task scope or Worker fails closed.
What is still missing

A verified limit evaluator is not a live control plane.

These gaps block any claim that Qeravio currently enforces provider cost, rate, time, concurrency or external-action limits.

  • Gate 1Measure real provider costs before replacing normalized planning units with a billing claim.
  • Gate 2Connect no evaluator to a live tool until authenticated assignment, revocation and per-invocation enforcement pass independent security review.
  • Gate 3Keep external spend at zero until the project owner approves one exact amount, recipient, purpose and expiry at action time.
  • Gate 4Keep send, publication, purchase, deletion, deployment and account mutation denied until an exact owner approval gateway exists.
  • Gate 5Verify organization and member isolation, live concurrency, replay protection, rate-limit persistence and rollback in authorized accounts.
  • Gate 6Measure denied overreach, repeated use, provider cost and member outcomes before claiming whole-product enforcement or value.
Version binding

This limit set belongs to one exact Worker and least-privilege source.

A unit, tool, source, budget, time, rate, checker or Worker change requires a new independent review.

Evidence identifier
qeravio-qtop199-public-ai-action-limits-release-20260820T185710Z
Least-privilege evidence
qeravio-qtop198-public-ai-least-privilege-release-20260820T185710Z
Tested Worker
56bbaf52-e861-4c6d-870e-87c2369a2b78
Completed
Aug 20, 2026, 6:57 PM
Allowed dry-run proofs
24
Verification-required proofs
24
Denied adversarial proofs
30
Live actions executed
0