A coding agent with guardrails for a team
Teams rolling out an agent to many developers who need spend control and an audit trail.
| Cost | Agent plan per seat, plus self-hosted open-source gateway and tracing |
|---|
What is in it
| Role | Part | Why |
|---|---|---|
| Coding agent | OpenAI Codex Included in ChatGPT plans: Free $0, Go $8/month, Plus $20/month, Pro from $100/month... |
Workspace sandbox and approval policies on by default in a git repo. |
| Gateway | LiteLLM The SDK and proxy are open source and free. An enterprise edition with SSO, audit logs... |
Budgets, rate limits and spend per developer. |
| Tracing | Langfuse Free to self-host. Langfuse Cloud has a free Hobby tier, Core at $29 a month, Pro at... |
Every model and tool call with cost, for review and audits. |
Set it up
npm install -g @openai/codex- Keep the default workspace-write sandbox with on-request approvals; never ship --yolo to the team.
pip install 'litellm[proxy]' and route the team's API traffic through it with a key per developer.- Add a PreToolUse hook that blocks pushes to main and access outside the repository.
Trade-offs
More moving parts to run, and a gateway only sees traffic billed per token, not subscription usage.
Comments
- Using this stack? Share what worked and what did not.
Other stacks
Claude Code on a $20 plan, without hitting the limit Open-source agent with a cheap model, paid per token Plan with a frontier model, code with a fast one