Teams and workspaces
Budgets, spend guard, and audit log
The Teams instruments for a shared pool: per-member budgets, the spend guard, usage by member, and the audit log.
A shared workspace shares money: one pool of tokens, one set of connected services, one bill. Teams gives the people running the workspace three instruments for it: budgets that bound each member, a spend guard that bounds each hour, and an audit log that shows who changed what. All three live with the workspace, not with any one project.
Watching usage
The token pill in the header always shows the pool of the workspace you are looking at. For the per-person view, the Members page shows each member's share of the burn alongside their role, so "where did this month go" has an answer with names on it.
Per-member budgets
An owner or admin can give any member a monthly budget: the most of the shared pool that one person may spend per calendar month. It is set right on the Members page, next to the person. A member who reaches their budget is paused with a clear message ("You have used your monthly budget for this workspace. Ask an admin to raise it.") while everyone else builds on unaffected.
Budgets are the calm instrument: set them once to match expectations, like a contractor's engagement or an experiment's allowance, and revisit monthly.
The spend guard
The spend guard is the fast instrument, for the accident budgets are too slow to catch: one person burning through the pool in an afternoon. By default, no member can spend more than 25% of the remaining pool within any 6 hour window. Trip it and that member's builds pause; an owner or admin can dismiss the pause on the spot (the dismissal lasts one window), or raise the guard's percentage and window in workspace settings within safe bounds.
The guard cannot be turned off entirely, by design: it exists for the moment nobody thought they needed it. Changes to it are recorded in the audit log.
The audit log
Workspace settings carries the audit log: who published an app, changed sign-in settings, connected or disconnected an integration, changed members, saved a private template, changed the design system, or changed the spend guard, each with who and when. Only owners and admins can read it, because it spells out roles and budget decisions.
One nice property: events are recorded on every plan, and Teams unlocks reading them. A workspace that upgrades gets its history, not an empty page.
Approving connections
On Teams, an editor connecting a new third-party service can be held for sign-off: the request waits in workspace settings, where an owner or admin approves or declines it. Connecting a service binds a real credential and opens a data path, so it is the same shape of decision as adding a paid seat. The full flow is on Connector limits and scope.
Frequently asked
A member is paused and we did not intend it
Two possibilities, both visible to an owner or admin: their monthly budget ran out (raise it on the Members page) or the spend guard tripped (dismiss the pause, and consider whether the burst was a runaway loop worth looking at before dismissing).
Do viewers affect any of this?
No. Viewers cannot spend tokens, so budgets and the guard never apply to them, and they cannot read the audit log.
Is the audit log a security camera on my team?
It records workspace-level administrative and publishing actions, listed above, not keystrokes or chat contents. Its job is answering "what changed and who changed it" when something surprises you.