The pattern is consistent: control before action.
When agents can touch real services, MeterPlane decides who can act, what they can do, when approval is needed, how much they can spend, and what evidence remains.
Case study library
Use these cases to see how keys, permissions, approvals, budgets, and audit turn agent actions into governed operations.
When agents can touch real services, MeterPlane decides who can act, what they can do, when approval is needed, how much they can spend, and what evidence remains.
POST /v1/services/{provider}/{operation}
Database tools, AI APIs, and frontend apps all benefit from constrained gateway keys while provider keys remain vaulted.
Layer 1 + Layer 4Money movement, deploys, external publishing, and destructive database actions can pause for explicit approval.
Layer 2 + Layer 3Per-agent caps, quotas, and organization limits define the spend boundary at request time.
Layer 4Policy decisions, MCP operations, data publishing, and usage events produce evidence your team can review.
Layer 5The product architecture study: identity, authorization, approval, spend control, and audit around every provider call.
Read Full Case 01 9 secDestructive database operations can be denied or sent to approval before provider credentials are read.
Read Full Case 02 $82,314Exposed AI provider keys become safer when raw credentials stay vaulted and budgets execute in real time.
Read Full Case 03 $440K+Encoded instructions still resolve to operation types. token.transfer remains money movement and can require approval.
Read Full Case 04 $250KParsing errors and large transfers are easier to contain when signing follows budget and approval controls.
Read Full Case 05 1,200+Production database writes and deletes move from natural-language instruction to executable policy.
Read Full Case 06 CVSS 9.3Sensitive context can be read while external publishing follows separate permission, approval, and audit.
Read Full Case 07 4 moCoding-agent loops stay manageable when every agent has a daily cap and the organization has a hard limit.
Read Full Case 08 $2.2KBrowser-side apps can expose constrained gateway keys while raw AI provider credentials stay vaulted.
Read Full Case 09 300 orgsBuilt-in MCP, explicit email.send permission, and parameter audit make the send route inspectable.
Read Full Case 10 65%Security, spend, data, and compliance pressure all point to reconstructable action evidence.
Read Full CaseEach study turns public facts into a product control map: credentials, policy, spend, approval, and audit evidence.