One enterprise reportedly spent half a billion dollars on Claude in a single month. No breach, no attack. Just thousands of employees with API access and zero spending caps. Nobody watched the meter until the invoice arrived.
Gartner’s diagnosis of why AI agent programs fail is blunt: it’s governance, not capability. The fix is not a committee or a quarterly review cycle. According to the source, it’s a one-page policy with exactly three controls, and you can draft it in about two minutes with the prompt below.
The Three Controls
The policy template is built around three mechanisms. Each one handles a different failure mode.
- Spend caps: per-user and per-team monthly limits on every tool with usage-based pricing, with an alert at 80% of the cap and an exception path for high-value workflows.
- Visibility: a daily-refreshed dashboard of AI spend by team, tool, and model, with an alert to a designated channel whenever a team runs 20% above its trailing 30-day average.
- Agent tiers: a written rule that classifies agentic workflows by risk rather than uniformly. Tier 1 runs unattended. Tier 2 requires a human to review output. Tier 3 requires human approval before any external action or spend above a defined threshold.

The Prompt
Paste this into Claude or ChatGPT, fill in the brackets, and send the output to your leadership channel today:
You are an AI FinOps lead. Draft a one-page AI Token Spend Policy for
[COMPANY], a [SIZE AND INDUSTRY] company spending roughly [$X/MONTH] on
AI across [TOOLS IN USE, e.g., Claude, ChatGPT, Copilot, API access].
The policy must ship exactly three controls:
1. SPEND CAPS — Per-user and per-team monthly caps on every tool with
usage-based pricing. Default cap: [$X PER USER]. Include an exception
path for high-value workflows, owned by [ROLE], so the policy funds
wins instead of just blocking spend. Alert at 80% of cap.
2. VISIBILITY — A daily-refreshed dashboard of AI spend by team, tool,
and model, owned by [ROLE], with an alert to [CHANNEL] whenever a team
runs 20% above its trailing 30-day average.
3. AGENT TIERS — A written rule for which agentic workflows run
unattended and which need a human checkpoint. Tier 1: low-risk, runs
unattended. Tier 2: human reviews output. Tier 3: human approves before
any external action or spend above [$X]. Tier by risk, not uniformly.
Format: one page, plain language, an effective date, and a 90-day
review. Close with the question every team lead answers monthly:
"What was our value per token this month?"Sample Output
Here is an excerpt from the caps section, generated for a 400-person software firm:
Spend Caps. Each user receives a $150/month default allocation across Claude and Copilot. Team caps equal headcount × $150. Requests to exceed a cap go to the VP of Engineering with a one-line business case; approved exceptions are logged and reviewed at 90 days. Alerts fire at 80% of any cap — no one learns about a limit by hitting it.

What This Actually Changes
Without the policy, you discover AI spend on the invoice. With it, you govern AI like any other metered utility. The cap is the circuit breaker. The dashboard is the meter. The agent tiers keep your highest-value automations running while the risky ones get a human in the loop.
Where Else This Works
The same three-control skeleton can draft policies for other variable, metered, invisible-until-the-bill-lands categories:
- Cloud egress budgets
- SaaS seat audits
- Vendor API spend limits
- Experimentation budgets for data teams
Anything with usage-based pricing and no default guardrails fits the same template. The structure transfers directly.
