HEAD OF IT AND IT DIRECTOR

IT leadership

Finance can tell you the total. Which team, which tool and who signed it off lands on you.

Token Observe puts a vendor, a tool, a team and a named owner on every AI subscription and API account your business pays for. You record what was billed by mapping the charge lines out of your own finance export onto a ten-column import template — as CSV in the dashboard, previewed before anything commits, or the same fields as JSON. No billing credential, no vendor console login, nothing for security to review. Metered estimates stay a separate number, because a charge and an estimate are different measurements. Every entry holds one of three authorization states — approved, prohibited or unknown, unknown by default — and coverage is reported on its own axis, so an unconnected source reads as unknown rather than as zero.
What you give it
Your vendor list, and your finance export mapped onto the import template
How the money reads
Billed per currency, subscription apart from API, estimates never added in
Register states
Approved, prohibited, unknown — unknown is the default
Where it runs
One container, one SQLite file, your keys, no phone-home
What an import cannot findAn invoice import finds what the invoice lists; nothing here discovers a subscription on its own
the pressure

This is already on your desk.

  1. 01

    You gave a number, and the question after it has no answer

    The total is the easy part. What follows it — which teams, which tools, who approved them, why it went up — is written down nowhere, and the first number stops being believed the moment the second cannot be produced.
  2. 02

    The register that exists is a spreadsheet and an email thread

    Somebody started a subscriptions tab eighteen months ago and three rows are still right. The approval that happened happened in an email, from a manager who has since changed teams. Neither survives a question asked in front of a board.
  3. 03

    Agents are already spending on somebody's key

    A process in engineering is calling a model on a key belonging to a person rather than to the business, and the cost lands at month end. A USD ceiling that refuses the call before egress is a different control from a dashboard reporting it afterwards.
the hard questions

Answered in the words you would use.

  1. 01· asked

    What is this going to cost us?

    answered

    No figure is published, and /pricing says why rather than making you ask. The licence carries a thirty-day evaluation grant — no order form, no signature, no fee — bounded in the same clause: no production traffic, no regulated personal data, no support. What you buy after it is a design-partner arrangement rather than a standard subscription. There can be no per-token component: your tokens are billed by your own provider.

  2. 02· asked

    How long before it tells me something I do not already know?

    answered

    Register the subscriptions you already know about against a vendor, tool, team and owner, then map last month's finance export onto the import template and load it — CSV through the dashboard, previewed before anything commits, or the same fields as JSON. The report then tells you what was billed per currency, which team it belongs to and whose name is on it. No time-to-value figure is published, because none has been measured on a customer's estate.

  3. 03· asked

    Who else is running this?

    answered

    Nobody yet. There are no reference customers, no logos and no case studies, and we will not produce one for a first call. Broad general availability is a published no-go decision rather than a date we are being coy about, which is what the Early access badge means. If that is disqualifying, it should disqualify us now rather than in week three.

  4. 04· asked

    I am not installing employee surveillance on my own staff.

    answered

    Then do not, and this is not that. An approved, paid subscription is legitimate usage and is never reported as unauthorised use — the scope is narrower than it sounds, because the register is consulted in exactly one detector, per-user seat spend. A network egress export you supply names a source host and a destination host, which is not a verified employee identity and cannot establish what was typed. Conversation capture is off by default.

Self-hosted, your keys, nothing phones home — and a five-minute check on your own copy that proves it. The 24 limits we publish, and the 9 risks a named person has to accept in writing, are on one page.

What we do not claim

Two inputs, and neither needs a vendor to cooperate.

You write down the subscriptions you already know about, against a vendor, tool, team and owner email. Then you map the charge lines out of the export finance produces onto the ten-column import template, and the dashboard shows you the parsed lines before anything commits. No billing connector, no vendor admin credential, no security review of its own.

Import bounds
Ten required columns, 1,000 lines and 2 MiB. Unknown fields, credentials in metadata, inconsistent attribution and invalid periods are rejected outright.
Built to be run every month
Identity is team, source and external id together. Reimporting the same invoice adds nothing; reusing an identity with different data returns a conflict and rolls the whole import back.
Refusals are recorded like the successes
A request refused at a ceiling produces the same evidence as one that ran, so month-end is about decisions rather than a gap in the record.
the register, and the only three states it stores

One row per vendor, tool, team and owner. Approval attaches to that exact combination rather than to a vendor in general, so approving an assistant for marketing approves nothing for finance.

vendortoolteamowner emailauthorization
vendor-achat assistantMarketingpriya.shah@example.comapproved
vendor-bcoding agentEngineeringsam.ellis@example.comunknown
vendor-cmeeting notetakerSalesdana.reid@example.comprohibited
approved
shown as “Approved

A person decided this exact vendor, tool, team and owner is legitimate. A matching per-user seat-spend finding is suppressed; every other detector is unaffected.

prohibited
shown as “Prohibited

A person decided this one is not permitted. Matching evidence carries that classification, which is a finding worth somebody’s time.

unknown
shown as “Awaiting review

The default on creation, so nothing passes by silence. A queue of decisions waiting for an owner rather than an accusation.

what makes it three rather than a convention
authorization TEXT NOT NULL
  CHECK (authorization IN ('approved','prohibited','unknown')),
UNIQUE(vendor, tool, team, owner_email)

Field names, states and the constraint are the product’s own; the rows are illustrative. Vendor, tool and owner email are lower-cased on write, so capitalisation cannot open a second entry for the same service — the team is kept as it was typed.

It does not tell you what your staff typed.

The register records decisions about services, attributed to a team and an owner email — the person accountable for the subscription, not the person typing into it. An approved entry suppresses the matching seat-spend finding, so staff using a tool the business already pays for stop appearing on a report as though they had done something wrong.

Capture off, or capture bounded
The default mode stores no message text. Switched to redacted, the prompt as sent and the assistant's reply are both kept, mask-redacted before truncation and bounded.
The seat census is the exception
It holds employees by name, and it sits outside both the trace retention window and subject erasure. Put that in front of whoever advises you on data protection.

We already pay Microsoft and Google for AI. Why another tool?

Keep them. Token Observe adds one register spanning every vendor you buy from, with a vendor, a tool, a team and a named owner on every entry and one of three states against it. It records what you were billed per currency, with subscription and API charges kept apart and metered estimates never folded in, and reports coverage as its own axis.

Do we need a vendor admin credential to import invoices?

No, and that is deliberate. You map an export you already hold onto the import template, so there is no billing connector and no standing credential into a vendor console anywhere in it. Two scheduled pull connectors are the honest exception: GitHub Copilot and Cisco Umbrella, each on a narrow read-scoped credential you supply and can withhold.

Will it cancel a subscription nobody is using?

No. It records the decision and names the owner; only the vendor can end the seat. Marking a service prohibited classifies later evidence accordingly; it does not stop anyone opening that tool in a browser or reclaim a licence from somebody who left. What changes is that the cancellation conversation has a named owner and an invoice line attached.

what happens next

Bring the objection that is not on this page.

Write to hello@tenhaw.com with your AI vendor list and last month's invoices. James Rooney replies. You will get a straight answer about whether Token Observe fits, including when it does not.

no form · no qualification step · no sales desk