Skip to main content
Blog

Why (and how) we're helping customers connect agent spend to the agent work driving it

Move from uncertainty to informed confidence on both risk and spend, with cross-platform spend aggregation and token-efficiency mapping.

Today we’re making Cost Intelligence generally available. It connects agent spend back to the agents, activities, and workflows that generated it; so the question stops being “how much are we spending on AI?” and becomes “is this spend doing useful work?”

Over the last few months, a lot of enterprises got a lesson in AI economics that no one had put on the roadmap.

Two things happened at once. Pricing and rate structures across the major model providers shifted, and employees found their stride with agents. Long-running coding sessions, research agents left to grind through a corpus overnight, workflows that fan out into a dozen sub-agents… the list goes on. Token consumption per person climbed sharply: a single agent run can now cost more than a month of the copilot-style usage that preceded it.

What caught AI and finance teams off guard was beyond just the increase. It was how late they found out about it.

Many enterprises came into this period holding large blocks of promotional or bundled token credits. While those credits lasted, the cost line stayed flat, so nothing in the numbers suggested anything was changing. Underneath, consumption was climbing fast.

The native usage dashboards did not close that gap. They report totals, not attribution: no view of spend by agent or by workflow, and no way to see that one team’s experiment had become the largest consumer in the organization. So the first accurate picture of demand arrived as an invoice, weeks after the activity that produced it.

This has led to huge demand for real-time cost intelligence: reliable, continuous view of what agents are consuming, and what work that consumption is tied to while it’s happening.

Another pillar of agent risk

For the past two years, agent risk has been discussed in two dimensions.

The first is security: what sensitive data can this agent reach, which tools and credentials does it hold, what happens when it connects to a skill that looks legitimate and is not. The second is operational: where might an agent take an action that breaks a process, corrupts a system of record, or brings a workflow to a halt.

As organizations move real work onto agents, a third dimension has arrived. Financial risk now behaves like the other two: it accumulates from agent activity, it concentrates in places where no one has visibility, and it surfaces only after the damage is already significant.

The failure modes are specific. One retailer was losing in the region of $1 million a month to model-routing waste; routine tasks handed to models far more capable, and far more expensive, than the job required. A bank consumed half of its monthly AI budget in a single day, because one agent was stuck in an endless tool loop, working hard and producing nothing. Neither of those is a security incident. Both are the direct financial consequence of agent activity that remained invisible until it became an invoice.

This is why security leaders, AI operations teams, and finance are increasingly looking at the agent estate through one lens rather than three. The evidence base is the same in every case: which agent acted, what it did, which tools and models it used, and who owns it. A team that can answer those questions assesses exposure and expenditure in the same conversation, from the same record.

A cost number on its own is not intelligence

Here is where most of the emerging tooling stops, and where we think the interesting problem starts.

Knowing that Agent 47 cost $12,000 last month tells you almost nothing. You cannot act on it. The agent might be the most valuable system in the company, or it might have been looping since a bad deploy weeks ago. A ranked list of agents by spend, absent any understanding of what those agents produced, mostly generates unproductive arguments between the people who own budgets and the people who own the work.

The question teams actually want answered is the ratio: what did this agent cost, and what did it do. Evaluating it requires a second record, describing production: what objective the agent was asked to pursue, how the attempt ended, who owned it, and which part of the business it served. Put the two together and you have the beginnings of Return on AI Investment (ROAI), a phrase currently doing a lot of work in board papers with very little underneath it. ROAI cannot be calculated from tokens and model calls, because tokens are the input. It starts with the objective an agent took on and the outcome it helped produce.

The unit of production is yours to define, and it should be. This includes tickets resolved, pull requests merged, claims adjudicated, documents reviewed, analyst hours displaced. The right denominator depends on what your organization already measures, and imposing a taxonomy on that from the outside would only force unfamiliar work into the nearest available category.

What the platform delivers is the connection: every dollar traceable back to the work behind it, and every piece of work traceable forward to what it cost. Because cost only becomes actionable when it sits alongside output. A busy, high-cost agent doing critical work should never be mistaken for the one burning tokens in a loop.

This changes the shape of the conversation. A $1500 charge filed under Software Engineering is a line item to be defended. The same $1500, attached to a specific workflow, an accountable owner, and two merged pull requests, is a data point in an investment decision. A decision that can also be compared against the product and business outcomes the organization already tracks.

Why Geordie can give you both sides

Producing that ratio requires understanding agents as systems, over time. It cannot be inferred from a snapshot of traffic taken at a gateway.

Geordie’s architecture sits close to the agent, inside the execution environment rather than at the network edge. That proximity is how we discover agents, map their tools and permissions, observe activity in real time, and apply controls through the agent’s own context, across cloud, code, and endpoint, and across every tool type an agent uses, from MCP servers to skills, extensions, plugins, and SaaS connectors.

Cost Intelligence is that same understanding applied to a different question. The instrumentation that captures what an agent did, for security and governance purposes, also captures token counts, model identifiers, and activity metadata. So we are not correlating a bill to a log after the fact. The record of work and the record of spend are the same record which makes it possible to say not only what an agent cost, but whether that spend bought useful work.

What ships today

  • Cross-platform spend aggregation: AI spend from every connected platform in one view, attributed to the agents and the work that generated it, rather than only the activity that happens to route through a single gateway or model router.
  • Multi-dimensional breakdown: drill from an organization-wide total down through platform, team, user, model, individual agent, or workflow.
  • Token-efficiency mapping: spend and volume mapped per agent, so the high-value workhorse and the runaway loop are distinguishable at a glance.
  • Cache-utilization insight: per-agent caching efficiency as a first-class metric, flagging which agents are under-caching and what that costs.
  • Cost anomaly detection: agents stuck in infinite loops, tasks routed to oversized models, and sessions burning tokens with little productive output, surfaced by the same inventory and posture visibility that already finds an agent, its tools, and its activity.

For most teams, the value is simply an honest baseline: a defensible number to take into budget season, built from agent activity rather than estimated from invoices. After that, it becomes an operating discipline: catching waste while it is still small, and making the case for the agents that are earning their keep. Assurance, for enterprises operating an agentic workforce, now extends beyond security into what that workforce costs and whether the investment is producing returns.

See both halves of the equation. Book a demo and see how your team can assess the security risk and the financial risk arising from agents from a single vantage point.

Keep reading