Skip to main content
Cutting an agent platform's LLM spend by 79%

A multi-agent software development platform was spending about $107 a day on model calls before it had any product traffic, and nobody could say which agent was spending it. The fix was attribution first, then caching, routing and hard caps, each verified against a full day of real traffic rather than a projection.

Read More
Cutting Microsoft Sentinel cost without blinding your detections

Most of a Microsoft Sentinel bill is ingestion, and the usual ways to cut it are cheaper table plans, ingest-time filtering and moving old data out of the workspace. For a regional healthcare group we found that each of these can do exactly what its change record says while quietly damaging something else: in one case, 33 of the workspace’s 83 detections were running against no data. Measure the detections and the whole bill after every change, not only the setting you changed.

Read More
The logging feedback loop that quadrupled an AWS bill

A client’s AWS bill went from roughly $1.7K in one month to $7.8K the next. Nothing in the application had changed. Three security and logging features, each reasonable on its own, had been connected so that each one’s output became another’s input. Logging needs to be designed as a system, because a single console change can turn it into a loop that pays for itself to grow.

Read More