You will find out on the 5th, not the 31st.
Budgets and thresholds by team, project, provider, model or workflow. Automatic spike detection from day one. A month tracking at five times normal is visible in its first days, not at close.
How do AI cost alerts work?
Camaze watches every source of AI spend continuously and compares it against three things: the budgets you set, the thresholds you define, and each workload's own normal behavior. When any of them is breached, an alert goes to the owner of that number in Slack, Microsoft Teams, email or a webhook, carrying the likely cause and the projected month-end total. The forecast re-runs on the change, so the alert tells you not just that spend moved but where the month now lands. Spike detection is on from the first day and requires no configuration.
The invoice is a very slow alarm.
A retry loop ships on a Thursday. It runs all weekend.
More detail
It is not noticed on Monday because nothing is broken, only expensive. The charge appears on the invoice three weeks later, and by then the money is gone and the month is closed.
This is not an unusual failure. It is the normal way AI cost incidents are discovered, because the billing cycle is the only monitoring most companies have.
- Prepaid credits that drain quietly with no monthly charge to notice
- A workload that doubles while total spend still looks broadly normal
- Agent retries that produce cost without producing errors
- A model change that raises unit cost on a workload nobody is watching
Illustrative product view. Figures are examples.
Three ways to be told, all running at once.
Budgets catch the planned overrun. Thresholds catch the specific condition you care about. Anomaly detection catches the thing you did not think to configure, which is where most real incidents come from.
All three carry a projected month-end figure, because knowing that spend moved is only half the answer. The useful half is what it costs if nothing changes.
- Budgets by team, project, provider, model, workflow or company total
- Thresholds as a dollar amount, a percent of budget, or a departure from normal
- Automatic spike detection on every workload, active from day one
- A projected month-end total on every alert, updated as soon as spend moves
- Forecast breach alerts, which fire before the budget is actually crossed
Set the conditions once.
Every rule watches something specific and goes somewhere specific. A team budget goes to the team's channel and its owner.
More detail
A provider threshold goes to whoever negotiated the contract. A retry-rate rule goes to the engineering group that runs the agent.
Rules can be scoped as narrowly as a single workflow or as broadly as total company spend, and new sources inherit sensible defaults so nothing is unwatched by accident.
- Scope: company, department, team, project, workflow, provider or model
- Trigger: absolute amount, percent of budget, rate of change, or forecast breach
- A first-charge rule that fires when any new AI provider appears
- Rules on derived measures, such as retry share of run cost or cost per run
| Watching | Threshold | Goes to | Status |
|---|---|---|---|
| Support team monthly budget | 80% of $90,000 | Slack, #finance-alerts | Active |
| Any workflow, daily spend | 3x the 30 day normal | Slack and email to owner | Active |
| Anthropic, month to date | Over $60,000 | Email to FP&A | Active |
| Agent retries | Over 25% of run cost | Webhook | Active |
| Any new provider detected | First charge | Slack, #procurement | Active |
| Company total | Forecast over plan | Weekly digest, Teams | Active |
Illustrative product view. Figures are examples.
The alerts you did not think to set up.
Most costly incidents are not budget overruns. They are one workflow behaving unlike itself.
More detail
Camaze learns the normal daily pattern of every workload, including its weekly shape, and flags departures from it.
That catches the cases a static threshold misses: a single workflow tripling while the company total stays inside budget, a slow drift that never trips a limit, or a cost jump on the same volume because unit cost changed underneath.
- Per-workload baselines, aware of weekday and weekend patterns
- Spikes flagged even when total spend remains within budget
- Unit cost movements separated from volume movements
- Slow drift detected before it becomes a step change
| Workflow | Runs | Calls per run | Cost per run | Spent on retries |
|---|---|---|---|---|
| Ticket resolution agent | 18,400 | 3.2 | $0.41 | 34% |
| Contract review workflow | 2,100 | 11.8 | $2.90 | 71% |
| Lead enrichment agent | 44,900 | 1.4 | $0.06 | 12% |
| Code review agent | 6,300 | 6.1 | $0.88 | 48% |
| Weekly report generator | 310 | 22.4 | $4.15 | 9% |
Illustrative product view. Figures are examples.
It reaches the person who can act on it.
An alert with no owner is noise. Each rule names a recipient: a team channel, a named owner, a distribution list or an existing on-call route.
More detail
Escalation applies when nobody acknowledges within a window you set.
The message itself carries what is needed to act: what changed, when it started, the likely cause, who owns it, and what it costs if nothing is done. Alerts are grouped so a single incident produces one notification rather than forty.
- Slack, Microsoft Teams, email and webhook, per rule
- Daily and weekly digests for anything that does not warrant an interrupt
- Escalation when an alert is not acknowledged, and snooze with a reason
- Related alerts grouped into one incident, so a spike does not flood a channel
Support automation is running 3.1x its normal daily spend. Started yesterday at 14:20. At this rate the Support team lands about $58,000 over budget this month.
- Yesterday
- $4,180
- Normal day
- $1,350
- Likely cause
- Retry loop on the ticket summarizer
- Owner
- Support Engineering
Illustrative product view. Figures are examples.
Stop finding out at month end.
We will set up budgets and alerts on your own structure during the walkthrough, so you can see what the day 5 version looks like.
Day 5 versus day 31
The same incident, discovered at two different points in the month.
Discovered on day 5
A retry loop is flagged the morning after it starts, with the projection already showing the month landing at five times normal. The owner is named in the alert. It is fixed that day. The overrun is four days of elevated spend, and the month lands on plan.
Discovered on day 31
The same loop runs for the rest of the month. The overrun is 26 days. It surfaces during close, as a variance nobody can explain, in a pack that has already been circulated.
The difference compounds
Discovering incidents late does not only cost the overrun. It costs the credibility of the forecast, which is what determines whether the next AI budget request is approved.
Keep reading
Forecasting
Where the month lands, what next quarter looks like, and what happens as usage grows.
Read moreAgent and workflow cost control
Retries, loops and runaway agents: the most common source of a spend spike.
Read moreCost optimization
The standing list of what to change, with a dollar figure against each optimization.
Read moreQuestions people ask
How quickly does an alert fire after a spike starts?
It depends on how quickly the source reports usage. Most provider APIs publish usage within hours, so a spike that starts overnight is typically flagged the following morning. Some cloud billing exports settle daily, which puts those sources a day behind. Each alert states the freshness of the data behind it.
Do we have to configure anything to get spike detection?
No. Anomaly detection runs on every workload from the first day, using backfilled history to establish a baseline. Budgets and custom thresholds are optional additions on top of it.
Can alerts go to different people for different teams?
Yes. Routing is per rule. A team budget can go to that team's channel and owner, a provider threshold to procurement, and a retry-rate rule to the engineering group that runs the agent.
Will this create alert fatigue?
It is designed not to. Related alerts are grouped into a single incident, anything that does not need an interrupt goes into a digest instead, and alerts can be snoozed with a reason that stays attached. If a rule fires repeatedly without action, Camaze flags the rule itself as a problem.
Can we alert on a forecast rather than actual spend?
Yes, and it is the most useful rule most teams set. A forecast breach alert fires when the projection crosses the budget, which is typically well before the actual figure does. See forecasting.
Does it work if we only use one provider?
Yes. Budgets, thresholds and spike detection all operate at workflow level, so a single provider still gives you per-workflow baselines and per-team budgets. See single-provider visibility.