Resource allowance accounting
Share budgets, direct limits, reset periods and pending usage.
Start with Resource allowances for setup. A rule belongs to one dedicated account pool in one workspace. Its account membership stays fixed while the rule exists. Members need a direct pool grant and a personal key bound to the rule; an ordinary key is not converted automatically. All of one member's keys for the rule share one ledger.
Share of a total budget
By share requires one total budget, a day or month reset period, and member percentages totaling at most 100%. Choose one accounting basis:
- By token share: enter the total in M tokens. Reported input plus output tokens count against each member's share; cached input is part of input and is not counted twice.
- By amount share: enter an internal USD total. Each request's input, cached input and output are converted using the model prices saved with that rule revision. These prices do not state the provider's subscription charging formula.
A member's limit is the configured total multiplied by their percentage, rounded down to the smallest accounting unit. For example, a 25% share of a 1 M token budget is 0.25 M tokens. Unassigned percentages and rounding remainders stay unused. The balance is shared across the rule's account pool rather than reset separately for each subscription account.
These are internal budgets. A configured token total does not reveal the subscription's actual capacity, and internal USD is not a cash balance or invoice. SubLane still checks available upstream quota; the provider may reject requests before the internal budget is exhausted.
Time-window amount limits
By time window is a separate allowance type. Add up to eight conditions, each using a whole number of hours or days (from 1 hour to 365 days) and a shared internal USD limit. Select members; each has an independent ledger even when using the same defaults. A member may override individual conditions. Leaving a condition's USD limit blank means unlimited for that condition; its usage is still recorded, without a quota or provisional risk reservation. Every settled request is priced once with the saved model rates and counts in every configured window. New requests stop if any limited condition is exhausted or reaches its provisional risk allowance.
All windows begin when the rule takes effect and renew after their respective elapsed durations. They are internal windows; their reset times do not track each subscription account's upstream reset. The instance time zone changes how reset instants are displayed, not their elapsed duration. Edits to an active time-window rule take effect at the next boundary of its longest current duration, starting all conditions again. A 30-day window can therefore delay an edit by nearly 30 days; the form shows the effective date before saving. Pausing access still takes effect immediately.
For priced allowances (By amount, By amount share, and By time window), SubLane reads the models supported by the dedicated pool and fills their catalog prices when saving a revision. User-supplied prices do not override this snapshot. If a model has no current catalog price, its previously saved rate is reused when available. A newly discovered model with no price is omitted from the snapshot, so requests to it remain blocked until a priced revision takes effect. Price-coverage warnings are calculated when a rule is read, not stored in its revision: a restored catalog price clears the catalog warning automatically, while a model absent from the saved price snapshot remains flagged until a new revision includes it. Unavailable account catalogs retain previously saved rates and show a warning until discovery recovers. Saving fails only if no usable price remains. Without a loaded price catalog or saved price cache, a new priced allowance cannot be created; refresh the catalog or provide a price fallback before retrying.
For a model missing from a rule's saved prices, the administrator warning shows when a save made now is expected to take effect. In time-window mode this date follows the longest current window, so saving again does not make the new price available immediately. An already scheduled revision instead shows its own effective date and warns that the model will still be blocked after that version starts unless a corrected version replaces it.
Direct limits and pending usage
By tokens sets a member's token limit directly. By amount sets a direct internal USD limit using saved model prices. Both use the same token or price accounting as the corresponding share basis.
Completed requests with known usage are charged without waiting for an upstream quota percentage update. A dispatched request without trustworthy token totals remains pending for administrator correction. Observed partial token counts remain visible, but pending entries do not count as used allowance or reserve capacity until confirmed. Within each limited current window, the system provisionally reserves 10% of that window's member limit (at least one accounting unit) for each active request. At most four requests may be in flight at once; admission also pauses when the next reservation would exceed the available headroom. The reservation is released when the request ends and is not a charge. Admission applies to new requests and does not interrupt a stream already in progress. These safeguards need no extra configuration. Pending entries outside one window remain available for correction; the same entry may still appear in another configured window. The administrator list shows the newest 256 pending entries first; older entries reappear as newer ones are corrected. A single large request can still finish above its member limit: this is a soft limit, not a guaranteed maximum charge.
For Codex streams, SubLane may keep reading upstream for up to 3 seconds after the client disconnects to capture trustworthy final usage. A failed terminal event that includes complete usage can also be charged. Repeated upstream failures cool the affected account temporarily; a successful response without final usage remains pending without cooling the account. If an accounting write fails temporarily, SubLane retries that request before admitting more allowance-backed work for the affected member; other members can continue.
Daily/monthly rules reset at their chosen clock or date and clock in the instance time zone. A monthly date missing from a shorter month falls back to that month's last day. Defaults are 00:00 daily or the first day at 00:00 monthly. Editing percentages, totals, direct limits, prices, type or reset schedule takes effect at the next boundary of the current schedule. Pausing a rule or revoking pool access blocks subsequent requests and WebSocket turns immediately. Neither action erases recorded usage or pending entries.
Choosing Start next period when creating a time-window rule starts it after the longest configured duration.
Read and correct balances
Members see their own allowance under Usage. Workspace administrators open Resource allowances → View usage for the full rule. All configured time windows appear under one member with their own limit, used amount, remaining amount, risk exposure, and reset instant; the member status reflects the most restrictive condition. Amount balances show internal USD alongside reported tokens; token balances use M, where 1 M = 1,000,000 tokens. Personal reports do not expose subscription-account identities.
The balance separates used (settled usage) from in-flight requests and pending usage in the current cycle. Temporary reservations reflect only in-flight requests; pending usage remains visible for correction and does not count as used allowance or reserve capacity. Admission headroom includes the automatic risk buffer; it is not extra spendable allowance. A positive remaining allowance can therefore coincide with New requests temporarily paused when another request needs more reservation than the current headroom, or four requests are still in flight. The status follows the same current-cycle risk check as gateway admission. It is a snapshot and can change as requests finish. Pending records outside the current cycle remain visible for correction but do not pause its admission.
When a pending entry cannot be resolved automatically, an administrator may enter input, output and cached-input totals supported by trustworthy evidence. The correction uses the request's saved accounting rule and writes an audit event. Do not treat missing usage as zero or enter invented totals.
Workspace administrators manage rules at /api/allocations; members read their own balances at /api/me/allocations. Keys bind to a rule with scheme_id. See workspaces and personal API keys.