Spend guard layers for an unattended Sume video agent, in order
Five layers cap a Sume agent that runs unattended: key scope, per-run cap, max_spend_usd and dry_run, generation admission, and the wallet. What each one stops.

An agent that runs overnight has no human to click Allow. The guardrails have to be in the request and the account. Sume's docs describe several, spread over different pages; this lists them in the order a request meets them.
| Layer | What it stops | Where it is set |
|---|---|---|
| Key scope | A key that was never meant to start agents (403 insufficient_scope) | API key creation |
| Per-run cap | One run spending beyond its ceiling | generation_spend_cap_usd, required on Agent Completions |
| max_spend_usd and dry_run | One MCP call spending more than you named, or running at all | Tool arguments |
| Generation admission | More paid jobs than concurrency and queue allow (429 queue_full) | Plan |
| Balance | Anything without funds (402 insufficient_credits) | Wallet |
Notes on each
Agent Completions require the cap because a backend caller gets no interactive spend prompt; the docs say the cap replaces it. Schedules default to $1.00 per run, and an override can only lower it (Create a schedule). On hosted MCP, max_spend_usd is enforced only when you provide it, and dry_run=true previews without submitting (tools and gates).
Admission has four separate controls, concurrency, queue capacity, submit rate limits and balance, that are easy to confuse (Generation admission).
What none of them cover
The run cap bounds generation, not the agent's own LLM turn, which bills a separate Agent wallet. And a cap says nothing about whether the output is good. Add a reviewer step or a webhook that flags failures, and keep logs free of keys and signed URLs, as Safe automation advises.
Start with the smallest cap that fits one run, watch the receipts for a week, then raise it by hand.
Sources
Related posts
More in Agents
- One Sume schedule on a clock and on call: api_trigger_enabled
A Sume cron schedule can also set api_trigger_enabled to accept API runs. trigger_type is fixed at create time, so choose once. Overlap defaults to skip.
- What a Sume MCP create result tells the agent to call next
A Sume MCP create result carries agent.next_step: jobs_wait with the job_id and timeout 50, plus poll_after_seconds 5. Follow it; do not resubmit.
- Agent says Sume MCP is down after one timeout: retry once, name it
One errored or timed-out Sume MCP call is just that call failing. Retry it once, report that tool's error, and never say the server is down.
- Sume MCP tool_name_typo: avatar_image_to_video_create is a typo
avatar_image_to_video_create gives tool_not_found; the real name is avatar-image-to-video_create. Sume sends did_you_mean and a tools_schema next_step.
Written by Sume