In August, agent blocks ran inside 1,240 of the 1,900 teams on Tessel and made a little over 300 million tool calls. Almost all of those calls did exactly what the prompt asked. A small number did something the prompt never mentioned, and 4,100 runs were stopped by a spend cap before they could cost anyone money. This post is about why we treat those limits as the real definition of an agent, and the prompt as a suggestion.
What a prompt cannot promise
A prompt describes intent. It says the agent should triage refund requests, or check a variance, or draft a reply. It cannot guarantee that the agent will never call a tool twice, never retry in a loop, never decide that a larger refund is the helpful thing to do. Models follow instructions well, and they still surprise you at a rate that matters when you run millions of times a month.
So we stopped asking how to write a better prompt and started asking a different question: what is this agent never allowed to do, no matter what it reads?
Three limits, always
Every agent block in Tessel has three limits. You can loosen them, but you cannot publish an agent without them.
A spend cap in dollars, per run and per day. When the cap is reached, the run stops and the trace shows the last tool call it made.
A tool list of exactly the connector actions the agent may call. Anything not on the list does not exist for that agent.
A named approver and a backup, for the actions you decide need a person. Approvals arrive in Slack, and the agent waits.
None of these depend on the model behaving. They are enforced by the runtime, outside the agent, in the same place that enforces timeouts.
A budget in code
Every logic block compiles to TypeScript, and agents are no exception. Here is a refund triage agent as it appears in the code view of the canvas.
Refunds above 200 euros wait for a person. Everything else runs, inside a budget small enough that a mistake is cheap.
When a cap trips
A cap that trips is not a failure. It is the system working, and the trace tells you why it happened.
The refund loop
In May, a customer on the Team plan connected an agent to a support inbox. A customer replied to an automated message, the agent read the reply as a new request, and the two started answering each other. The agent made 11 tool calls in four minutes before the per-run cap stopped it at 38 cents. Without the cap it would have kept going until someone noticed. With it, the team saw a stopped run in Slack, opened the trace, and added a filter for automated replies. Total cost of the incident: less than a coffee.
A prompt is a request. A budget is a rule.
We see the same pattern across workspaces. Caps trip most often in the first week after an agent is published, and almost never after that, because teams adjust the prompt and the tool list once they have seen a real trace.
Defaults we ship
New agents start with conservative defaults: 50 cents per run, 20 dollars per day, no write tools, and the workspace owner as approver. Since we introduced them, the median agent goes from draft to production in three days, a little faster than before, because reviewers approve a bounded agent sooner than an unbounded one.
We are also adding monthly caps at the workspace level, so finance can set one number for all agents and let teams divide it. The product page shows how agents, approvals and traces fit together on the canvas.
JV
Joost Verhoeven
Co-founder, CTO
Joost co-founded Tessel in Rotterdam in 2023 and owns the agent runtime and its safety model. Before that he spent six years building risk controls at a payments processor, where every limit had a named owner.