Skip to main content
Enterprise organizations on the standard dollar-commit contract pay against a committed dollar amount for the contract period. Usage shows up in dollars on Plan & Usage, so you can see how Clark work and published apps draw down that commit. This page covers the concepts. For a walkthrough of the Plan & Usage UI, see Plan & Usage. To set limits and alerts, see Spend management.

What is a Governed Agent Unit?

A Governed Agent Unit (GAU) measures the amount of secure orchestration, governance, cost optimization, and reliability work Superblocks performs around AI model inference. On a dollar-commit contract, GAU consumption is priced into dollars and counted against your commit and any overage.

Platform work included in each GAU

Each GAU covers Superblocks platform work across the following areas:

Security and governance

  • Prompt-injection protection: Superblocks scans prompts and model interactions for malicious instructions designed to manipulate Clark or gain unauthorized access to company systems and data.
  • Isolated sandbox orchestration: Superblocks runs agent work inside isolated execution environments and manages the lifecycle of each sandbox, including creation, pausing, resuming, and termination.
  • Integration authentication and authorization: Whenever Clark accesses an integration, Superblocks authenticates the connection and verifies that the user and agent are authorized to perform the requested action.
  • Application security scanning: Before deployment, Superblocks performs static and runtime security checks on generated applications to identify vulnerabilities and unsafe behavior.
  • Package and supply-chain security: When packages are installed, Superblocks checks them against vulnerability and malware intelligence to reduce the risk of compromised or malicious dependencies.
  • Security agents: Specialized agents inspect applications for security risks that traditional code scanning may miss, including authorization flaws, unsafe data access, and business-logic vulnerabilities.
  • Audit logging: Superblocks records prompts, agent actions, integration calls, policy decisions, and results to provide traceability across the application lifecycle.

Cost optimization

  • Prompt and token caching: Superblocks reuses eligible prompt and context data to avoid unnecessary model processing and reduce inference costs.
  • Context management: Superblocks determines which information should be retained, summarized, retrieved, or removed so models receive the context they need without repeatedly processing the entire session history.
  • Model routing: Superblocks routes work across frontier and open-source models based on the complexity of the task, balancing output quality, latency, and cost.

Infrastructure automation and reliability

  • Inference failover and retries: Superblocks detects failed or degraded model requests and manages retries, fallback models, and recovery workflows to keep agent execution moving.
  • Execution monitoring: Superblocks tracks agent progress, errors, tool calls, and intermediate results so long-running tasks can be observed and recovered.
  • Database provisioning and migration: Superblocks provisions application databases inside the customer’s AWS private cloud and manages schema migration across development and production environments.
  • Application deployment: Superblocks packages and deploys applications while applying the required security, infrastructure, and organizational controls.

Dollar-commit contracts

With a dollar-commit Enterprise contract:
  • Your organization has a committed dollar amount for the contract period
  • Clark / GAU usage and published application charges both count toward that commit and any overage
  • Plan & Usage shows spend in dollars, including a commitment / usage bar for the main contract type
  • Billing type on usage rows can show Committed vs Overage when your contract distinguishes them
For Teams (self-serve) packs and refills, see Self-serve plans.

Enterprise platform license

The enterprise platform license provides unlimited platform access, enterprise identity and governance controls, spend management, support, and hands-on onboarding for builders and administrators.
  • Unlimited builders and end users: Create and use unlimited applications without per-seat builder or end-user fees.
  • SSO and SCIM: Connect your identity provider to centralize authentication and automatically provision and deprovision users and groups.
  • Bring Your Own Key inference — Cloud-Prem: Use model inference through your own cloud accounts and credentials, keeping model usage and spend within your cloud environment.
  • Application RBAC: Control who can access each application and what actions they can perform based on assigned roles.
  • Platform audit logging: Maintain a centralized record of administrative activity, access changes, application events, and platform actions.
  • Platform Admin MCP: Allow authorized AI agents and administrative tools to securely manage the Superblocks platform through governed interfaces.
  • Spend management: Set budgets, usage limits, and policies to monitor and control AI and platform consumption across teams.
  • Enterprise Support SLA: Receive priority support with contracted response times and escalation paths for business-critical issues.
  • Shared Slack or Microsoft Teams channel: Collaborate directly with the Superblocks team through a dedicated shared support and coordination channel.
  • Forward Deployed Engineer: Receive part-time hands-on support for platform administration, implementation guidance, builder onboarding, and training.

Published applications

Each published application is charged every month it stays published. On Plan & Usage, the Published apps view shows which apps are billed for which months, including Pending charges for the current month before the period closes. Superblocks manages deployments, infrastructure, scaling, infrastructure security, incident recovery, and uptime for published applications.

Fully managed AWS Cloud Prem

Superblocks can provision, operate, monitor, upgrade, and support the platform inside your AWS account with an enterprise uptime SLA, so you do not need to dedicate internal DevOps resources to managing it.