The Wired Connection faster Updated i Leads only

Automation team · internal

Token Governance

Every TWC Claude API key tied to an application or process: what it powers, why we are billed for it, who issued it, and its spend. Flag keys for rotation and disable them in place.

-
Scope: these figures are Claude API usage only, measured per API key. They include Claude Code in the terminal and any other tools or scripts that call the API. They do not include Claude.ai (web), the Claude desktop and mobile apps, or seat-signed Claude Code: those bill separately as seat fees plus monthly usage credits, tracked on Seat Usage. Both pipes are real money at about the same per-token rates.

Spend & usage i

How we measure this · the frameworks behind the dashboard

This dashboard mirrors how companies are governing AI spend and risk today, not an in-house invention. Each feature maps to a published standard:

  • FinOps for AI (FinOps Foundation) - cost attribution and showback, unit economics (cost per token / per call), and Crawl/Walk/Run maturity. Drives the per-key spend, issuer/owner attribution, and unit-economics tiles. framework
  • Spend-spike alerts - a sudden, sustained jump in a key's cost is treated as a security signal, not just a billing surprise: it often means a runaway or looping job, a misconfigured automation, or a leaked key. We compare each key's last 7 days against the 7 before (same calendar window for every key) and flag any that at least doubled, skipping brand-new keys that have no real prior week to compare against. The published basis is the OWASP LLM Top 10, LLM10:2025 Unbounded Consumption ("denial of wallet"). OWASP
  • OWASP Secrets Management + CIS AWS Foundations - credential lifecycle (create, rotate, revoke, audit). TWC has no formal rotation policy yet, so keys older than the CIS ~90-day guideline (and credentials unused 45+ days) are surfaced as suggestions to review, not hard rules. Rotation supports HIPAA access-management safeguards (45 CFR 164.308(a)), is the kind of control cyber-liability policies increasingly expect, and limits the blast radius of a leaked key. Drives key hygiene and rotation flags. CIS
  • NIST AI RMF (Govern / Map / Measure / Manage) and ISO/IEC 42001 (AI management system) - inventory, ownership, purpose, and lifecycle. Drives the governance scorecard. AI RMF
  • HIPAA / BAA (third-party data controls) - PHI is only covered on eligible surfaces (the native first-party API with Zero Data Retention); the Batch API, Files API, API-side code execution, and any MCP connector are out of scope. Drives the BAA term countdown and the per-key PHI coverage check. Aligns with ISO/IEC 42001 third-party and data controls. BAA
  • Model routing / cascade and AWS Well-Architected GenAI Lens - use the smallest model that does the job; escalate only when needed. Drives the rightsizing recommendation and the cost/speed differential. lens

Key inventory i

All Active Has spend Untagged (spend) Spiking i Stale i PHI PHI review i Fable 5 i Unapproved Fable 5 i Ready for rotation i Flagged for rotation
Key Assigned to Env Purpose Status Rotation i 31d cost 31d tokens Last used