Nobody can say which agent spent what.
Agents spend in bursts, across providers, on credentials issued to individuals, so the bill arrives aggregated and late.
Run any harness on any model. Govern every call from outside the agent, where the agent cannot edit the rules. Keep a signed record of everything it did.
They run untrusted code against production systems, for hours, and they have to survive a restart. The unit is not a request — it is a session.
Agents spend in bursts, across providers, on credentials issued to individuals, so the bill arrives aggregated and late.
They cannot say “stop once this session has spent $25”, and cannot tell rm -rf ./build from rm -rf /.
Each agent is built against one harness and one model, so next month's better or cheaper option means a rebuild, not an edit.
Most platforms bind you to one framework, one harness, one model and their idea of safe. Orca is an open, declarative runtime that governs agents from outside the harness, where they cannot bypass it.
Run the harness you already use, and swap it with a config change.
Route to any provider, and switch models without touching agent code.
Guardrails that only tighten, credentials held at the gateway, a signed record.
The loop, the isolation, the credentials, and the record of everything it did — one runtime, driven through the API, the CLI or the SDKs.

Most of the agent lifecycle already has good tooling. What has been missing — and mostly closed — is the runtime in the middle: the thing that actually runs an agent, and governs it while it runs.
Agent Engine runs the session. AI Gateway governs what leaves it. Eval & Observability exports what happened.
The declarative runtime for any harness and any model.
Guardrails that hold, and a record you can verify.
Session logs as OpenTelemetry traces, in your own stack.