Set limits at each boundary
Start with cost auto-stop, rate limiting, execution policy, and HTTP streaming. A limit enforced around one model call is not automatically a budget for a team or an external service.
Collect evidence you can act on
Track run status, tool outcomes, latency, token/cost accounting, cancellation, and correlated request/run IDs. Keep sensitive content out of routine telemetry unless you have explicitly configured bounded capture at the tracer and destination. Use observability for exporters and ownership. Independently configured webhooks can transmit payloads; telemetry settings do not redact them automatically.Shut down in ownership order
- Stop accepting new work and stop new job claims.
- Drain work within a deadline; cancel connection-owned requests when their owners leave.
- Wait for or reconcile in-flight external actions according to the task contract.
- Close owned Agents, sessions, providers, browsers, and stores after their users finish.
- Shut down observers/exporters so queued telemetry can drain.
Rehearse startup and drain
- Start the owned-session API and wait for its listener message before sending requests. For a worker, wait for your queue connection and executor registration before reporting readiness.
- Make one request or queue job. Retain its terminal result and any correlated trace. A listening port alone does not prove model availability.
- Stop admission, signal shutdown, and verify that already admitted work settles before its Agent and backing services close. Apply a host-owned deadline when dependencies can stall.
- Confirm that the process exits, sockets close, and telemetry artifacts are flushed. The quality-gate project demonstrates closing the Agent before shutting down its observer.