AI Spend Tracking
Sort your agents by what they cost. Then by what they can reach.
AI consumption is metered three different ways: interactions in the audit log, Copilot credits in admin-center reports, tokens and dollars on the Azure side. No console joins them, and none of them knows what the spending agent can actually touch. 1Security keeps all three currencies in one ledger per agent - starting on the licenses you already own - and puts the spend column next to the reach column, which is the pairing neither a FinOps tool nor a billing report can make.
- 3currencies reconciled per agent - interactions, credits, tokens and dollars
- Day 1per-agent interaction volume from the audit log, on plain E1
- 125%of prepaid credit capacity auto-disables agents - the alert fires while it is still a budget question
The problem
Three meters, three consoles, and no column for risk.
Every AI surface bills differently. Copilot interactions are free events in the audit log; Copilot Studio burns credits per answer and per agent action; Azure AI deployments meter prompt and completion tokens and settle in dollars. Budget owners see fragments: a credits report here, a cost analysis there, and interaction counts nowhere near either.
The fragments also expire. The credits report holds thirty days; Azure metrics age out on their own schedule. By the time a quarterly review asks "what did this agent cost us since spring", the primary sources have already forgotten.
And no billing surface knows what the spender can reach. An agent burning credits against a site full of payment data and an agent summarising a public FAQ look identical on an invoice. Spend without reach is a FinOps exercise; spend next to reach is a security signal - the pairing this screen exists for.
What you get
One ledger per agent, provenance kept per row.
Measured and estimated never mix silently: every number carries its source - audit log, imported report, or Azure meter.
Interactions on the licenses you own
Per-agent, per-user interaction volume from the audit log - daily activity, 7-day and 30-day columns, sortable across the whole agent estate. Free on E1, flowing from the day you connect.
Copilot credits, imported and kept
The credits report imports as a recurring export through the same flow as the agent registry - authoritative per-agent, per-user credits, with history that outlives the report's own 30-day window.
Tokens and dollars from Azure
Grant a reader role and prompt and completion tokens land per deployment and model, dollars per meter, per-run usage for Foundry agents - continuously ingested, so 1Security becomes the long-term store.
Budgets and pool burn
Your Azure budgets are read for context, and prepaid credit pools are watched against their allocation - with an alert while the burn is still a budget conversation, before the auto-disable threshold makes it an outage.
Consumption anomalies
Spend is scored like every other metric: against the agent's own history. A token spike on a deployment with no matching user activity, or cost-per-interaction climbing while volume stays flat, raises an episode within minutes.
Spend next to reach
The consumption column sits on the same row as files, sites and sensitive data in reach. "Our most expensive agent can read the finance site" is one sort - and the sentence that changes the meeting.
How deep it goes
The quarterly review, in three sorts.
What the AI line-item conversation looks like when the ledger already exists.
Sort by interactions descending: the agents that actually matter, regardless of what they cost. The tail of zeros below them is its own finding - built once, forgotten, still holding reach. Retiring the idle tail is the cheapest risk reduction available.
Sort by spend: imported credits and measured dollars, with history behind each number instead of a thirty-day snapshot. Cost-per-interaction exposes the quiet story - an agent whose model was switched to a premium tier shows up here while its volume looks perfectly normal.
Then cross with reach: filter to agents with sensitive data in reach and read their spend. The expensive-and-dangerous quadrant is usually two or three agents - a shortlist worth an owner conversation, not a program. That cross is the whole point: a billing report prices the estate, this screen prioritises it.
In practice
From free columns to the full ledger.
Each step is optional and adds a currency - nothing gates the previous one.
- 01
Start with what is already flowing
Interaction volume per agent is on the Agents screen from day one, from the audit log, on the licenses you already own. The sorting and the spike alerts work before any import or role grant.
- 02
Import the credits report
Upload the credits export on a schedule - the same import pattern as the agent registry. Per-agent and per-user credits accumulate as history, and the pool-burn alert arms itself against the allocation.
- 03
Grant the Azure reader roles
Monitoring Reader brings tokens per deployment and model; Cost Management Reader brings dollars per meter; the Foundry data plane adds per-run usage. All read-only, revocable in Azure at any time.
- 04
Let the detectors watch the curves
Consumption metrics join the anomaly engine: per-agent baselines, spike episodes, cost-per-interaction drift. The alerting rides the same instant and digest channels as everything else.
The difference
What the join adds over a billing export
The numbers exist in Microsoft surfaces. The joins below do not.
- Three consumption currencies in one ledger per agent, each row labeled with its source
- Credit history beyond the 30-day report window - the import becomes the system of record
- Continuous Azure metric ingestion, kept past the retention of the metrics themselves
- Cost-per-interaction as a derived signal - model escalation visible while volume looks flat
- Pool-burn alerting before the auto-disable threshold turns spend into an outage
- Spend anomalies scored per agent against its own history, on the same scale as every other detector
- The spend column next to reach, owners and sensitive data - the prioritisation no invoice can make
- Idle agents with standing reach surfaced as the cheapest risk reduction available
Licensing and access
Starts free, grows by one role at a time.
Interaction tracking runs on the standard read-only connection and plain E1 - no premium license involved. Credits arrive by importing reports you can already export. Azure metrics need reader roles only - Monitoring Reader and Cost Management Reader - assigned and revocable on your side. Every number keeps its provenance, and estimated figures are always badged as estimated.
- 0extra licenses for the interaction columns and spike alerts
- 2 rolesMonitoring Reader + Cost Management Reader for measured tokens and dollars
- 100%of rows carry their source - measured and estimated never mix silently
Related
Where this fits
Spend is one column of the agent estate. The pages below hold the columns it is joined against.
AI agent inventory
The population the ledger meters: every agent with its reach, owner and blueprint.
See agents →License optimization
The seat side of the same bill: purchased vs assigned vs used, with reclaim automation.
See licenses →Anomaly detection
The engine that scores consumption curves - baselines, episodes, one sensitivity dial.
See anomalies →
FAQ
Questions teams ask first
Do we need E5 or Copilot licenses to see anything?
No. Per-agent interaction volume comes from the audit log on plain E1, through the standard read-only connection. Credits and Azure metrics are additive layers: an import you schedule and reader roles you grant, each optional.
Where do the credit numbers come from?
From the Copilot credits report your admin center already produces. 1Security imports the export on a schedule - the same flow as the agent registry import - and keeps per-agent and per-user credits as history beyond the report's own 30-day window. Where only interaction shapes exist, estimated credits are computed from published rates and always badged as estimates.
What does the Azure side require?
Reader roles only: Monitoring Reader for token metrics per deployment and model, Cost Management Reader for dollars per meter, and the Foundry project role for per-run usage. No write access, no SDK changes, revocable in Azure at any time.
Why is spend on a security platform at all?
Because the joins are security signals. A token spike with no matching user activity looks like a stolen key or an abused workload identity. Cost-per-interaction climbing on a flat volume means the model changed. And an expensive agent with reach into restricted data is a priority no invoice can compute - spend per unit of risk is the column this platform uniquely holds.
What is the pool-burn alert exactly?
Prepaid credit pools are watched against their allocation, and an alert fires at a threshold you set - before the capacity mark where agents get automatically disabled. The failure mode it prevents is spend quietly becoming an outage over a weekend.
Put the spend column next to the reach column.
Connect read-only and the interaction columns fill the same day. The credits import and the Azure roles take an afternoon - and the quarterly review stops starting from a thirty-day snapshot.
Or reconstruct last quarter from three consoles again.