# The cost check your agents call before they act.

> Markdown twin of https://getnable.com/agents , which is the canonical page. Generated from its HTML, so the two cannot drift.
> Index of this site: https://getnable.com/llms.txt

One command wires nable into your agent. Before it runs `terraform destroy`, resizes a database, or buys a commitment, nable prices the change, checks your budget, offers the cheaper path, and holds anything a human hasn't approved. It governs the whole run, model spend plus the cloud your agent touches, not a single prompt.

[Install free: `uvx nable`](https://getnable.com/)
 See the one-command setup

your agent, gated by nable

```
agent › terraform apply
+ aws_instance.api db.r6g.4xlarge +$4,100/mo
nable › check_action_policy
gate ESCALATE over the platform budget (91% of limit)
impact +$4,100/mo ($49,200/yr)
cheaper run it on spot ~$1,200/mo (estimate)
budget as of 6h ago
⧗ waiting for a human. nable never applies anything itself.
```

Seamless, not another prompt to babysit

## One command, and it's on for the whole run.

You don't have to hope your agent remembers to check costs. `finops guard install` writes a hook into Claude Code, and from then on every infrastructure command the agent runs in Claude Code is checked automatically, before it executes. Like `gh auth login`: run it once, and it's just on.

## Wire it in

1. **Run once.** `finops guard install` adds a PreToolUse hook to your project (or `--global` for every repo).

2. **Set the policy.** Optional. A dollar threshold and an allowlist via two env vars. Sensible defaults ship in.

3. **Nothing else.** Your agent works as before. nable steps in only when a command touches money.

finops guard

```
$ finops guard install
✓ Agent cost guardrail installed → .claude/settings.json
# later, mid-session…
agent › terraform destroy -auto-approve
- aws_db_instance.primary (prod database)
nable guard › ASK
'delete_resource' is a one-way door.
A human must review before it runs.
```

Prefer any other MCP client, Cursor, Windsurf, your own loop? A one-line system-prompt instruction gives you the same gate. See both paths ↓

The difference

## Every cost tool shows you charts after the money is gone.

Dashboards are post-mortems. By the time a spike shows up in Cost Explorer, an agent has already spun up the oversized database, run the redundant job, and left the scratch resources running. nable moves the cost check to where it matters: **inside the agent's loop, before the spend resolves.** The agent asks first, and nable answers with a verdict it can act on.

Governs the run, not the prompt

## An LLM gateway caps a call. nable governs the whole footprint.

Gateways like Portkey and LiteLLM cap model spend per key. Useful, but they never see your cloud bill, so they cannot catch the change that actually costs money. nable is a cross-cloud FinOps tool sitting in the loop, so it governs model spend **and** the cloud the agent provisions, against your real budget.

An LLM gateway
 
 Caps token spend per API key
 Optimizes a single model call
 Never sees your AWS, Azure, or GCP bill
 Blind to the infrastructure the agent creates

nable
 
 Budgets the whole run: model plus cloud
 Gates the infra action, not just the prompt
 Cross-cloud, and includes AI and LLM spend
 Offers a cheaper path and drafts the fix

Propose-only, always

## It can say no. It cannot act.

The gate returns `allow`, `warn`, `block`, or `escalate` against your policy. One-way doors, deleting, terminating, buying a commitment, and any over-budget change always escalate to a human. nable proposes and a human approves. It never edits, deletes, or buys anything in your environment on its own, so you can wire an agent through it without handing it the keys.

**What it is not:** a network-level egress intercept. The Claude Code hook is a chokepoint for your agent inside that harness, and it fails open by design, a guard bug never blocks your terminal. The hard guarantee isn't the hook, it's that nable is read-only and holds no execution credentials: it proposes every change as a PR a human merges, so there is nothing for a misaligned agent to route around.

Reversible and in budgetPasses silently. The command runs as normal, with the dollar impact and a cheaper path on record.

One-way or over budgetPauses for a human. The irreversible or expensive move is surfaced with the reason before anything happens.

It remembers

## A fresh agent starts from zero. nable does not.

A stateless agent calling a cloud API can fetch a number. It cannot tell you this change is three times your trailing baseline, or that you tried this exact fix in March and it verified at $4,100 saved, or that the instance it wants to stop is a warm standby you flagged in April. nable holds that history across clouds and AI spend, so its answers carry memory the calling agent cannot have. The longer it runs, the more it knows.

Two ways to adopt

## Automatic in Claude Code, or one line anywhere.

The hook is the seamless path. If you're outside Claude Code, or you want the agent to reason about cost out loud, point it at the same gate with a single system-prompt instruction. Either way your credentials stay on your machine.

### Automatic · the hook

$ finops guard install

Every infra command your agent runs in Claude Code is checked first. No prompt to maintain. Restart Claude Code and it's live.

Manual · the one-liner
 Works in Cursor, Windsurf, or any MCP client. Drop this into the agent's system prompt:

system prompt

Before you apply any infrastructure change (a terraform apply, a
helm upgrade, creating or resizing a resource) or start an
expensive job, first call check_action_policy with the action and
the change. Relay the verdict, the dollar impact, and the cheaper
path when one is offered. Never apply a block or an escalate
action; surface it to the human. nable is advisory and propose-only.

Honest status

## What ships today, and what is next.

We will not put a number on the site we cannot reproduce. Here is exactly where this is.

Live now
 
 The `finops guard install` hook: infra commands checked automatically in Claude Code
 The pre-action gate: price a change, check it against your budget, get a verdict
 A cheaper-path suggestion for compute, labeled an estimate
 Budget verdicts labeled with the age of the data
 Propose-only, in the live `uvx nable` MCP

Coming
 
 Per-run budgets that span model spend and cloud together
 A savings view attributing what the controls actually saved
 Orphaned-resource and agent-loop waste detection
 An opt-in auto-remediation mode, bounded to reversible cleanup

## Give your agents a cost conscience.

Local-first, propose-only, cross-cloud. One command to wire in. Free to start.

```
[Install free: `uvx nable`](https://getnable.com/)  [Compare FinOps tools](https://getnable.com/finops-mcp-comparison)
```
