Skip to main content
Automated Rebalance watches pooled seat spend and moves unused limit to the seats about to hit their cap, so nobody gets blocked mid-period. Because it writes to your provider, the default posture is that it cannot. It has to earn write access against a published scorecard you can watch in the product, and it loses that access the moment a write cannot be verified. This page documents exactly how that works, so you can decide whether to trust it before turning it on.
Automated Rebalance is an admin-only tab inside seat tracking, not a sidebar entry. It unlocks once your budget is ready. Unattended limit changes are supported for Claude Enterprise only — Cursor and ChatGPT / Codex seat limits are read-only in nOps.

Get started

  1. Sign in to nOps.
  2. Open your seat tracking project and go to the Automated Rebalance tab.
  3. Open the Automation card and read the Trust scorecard before changing anything.
  4. Leave the workflow on Observe until the scorecard says Eligible.
If you have no provider that supports limit writes, the tab tells you so: Enable an AI seat tracking provider with limit writes to configure automation. Seat recommendations still show; nothing can be applied.

Key features

The Automation card

A collapsible card with two tabs, Settings and Activity, plus two controls in its header:
  • Enable turns detection on and off.
  • Run now triggers a check immediately instead of waiting for the schedule.
The card’s status reads Detection off, Observing pool, Approve before apply, or Auto-rebalancing, depending on how it is configured.

Workflow modes

Under Settings, three tiles decide what a run is allowed to do. Checks happen about hourly; if raise or lower recommendations exist, the run honors whichever mode you picked. Click Save settings to apply. Email and chat notifications for rebalance runs are configured in project settings.
The workflow mode is a preference, not a permission. A policy still cannot write unattended until it has passed the trust scorecard, regardless of which tile is selected.

Triggers

By default every check runs on the schedule. Turn on Only run when pool is tight to skip the hourly check unless something actually warrants it: Under Advanced:
  • Custom pool cap overrides the pool size. Leave it blank to use the budget target.
  • Open requests before graduation lets runs open seat requests and wait for a human while the trust score is still building. Automation still never writes on its own — someone has to approve the run. This is unavailable in Observe, which never opens requests.

The trust scorecard

The Trust scorecard card shows the evidence required to graduate out of the current autonomy state, with a pill reading Eligible or Building trust. Every criterion must pass. The card shows your live figures next to these: elapsed versus required days, qualifying hours, forecast error with its settled sample count, churn with its reversal count, and Budget adherence, which reads No violations when clean.

What counts as evidence

Only outcomes that reflect an actual decision count toward graduation. Runs that errored out, found nothing worth deciding on (no pool to work with, no managed seats, or a conflicting policy already holds write access), or were held back before they got that far (rate-limit backoff, another run still in progress) don’t count. A policy cannot graduate because its runs kept failing or getting skipped. A run that looked at a healthy pool and correctly did nothing does count. Evidence accrues by the distinct UTC hour, not by the number of runs — several runs inside the same hour count once, and you can bank at most 24 hours of credit per day. The floor always implies real elapsed time.

Rebalance History

The Activity tab and the Rebalance History panel record every run. Each run also records what triggered it: Manual, Threshold, Forecast, or Scheduled. A run Awaiting approval offers Approve and Undo. A Proposed run offers Undo. Pending runs also point out that you can review each seat change individually as an open request on the Requests tab, if you would rather decide seat by seat than approve the whole run.

How often it runs

Every tracked budget is checked on a fixed hourly schedule. There is no faster path, and there is no way for a check to decide it should run more often. That is a deliberate constraint rather than a limitation. A check that can decide to run itself more often can drift into checking far more frequently than anyone intended, with no setting you could point to that explains why. Keeping the schedule as the only trigger means the frequency you see in Settings is the frequency you get — it can’t quietly speed up on its own. Raising a seat’s limit sooner is still possible: open a seat request and approve it, or use Run now.

Safeguards

Every write is verified. After changing a seat limit, nOps re-reads that user’s effective limit from the provider and confirms it matches the intended value. A write that cannot be verified — wrong value, unreadable, or the provider identity no longer matches — is recorded as a failure, not a success. Failed verification revokes autonomy. A policy that fails reconciliation is demoted back to Observe. It stops writing immediately and has to earn write access back through the scorecard. One unattended writer per provider. Only one policy per organization may hold write autonomy for a given provider. If a second policy would otherwise graduate, graduation is refused and the conflict is logged. Claude Enterprise spend limits are organization-wide, so two controllers writing to the same roster would fight each other with no audit trail explaining the result. Rate limits are respected. Provider calls back off and retry rather than hammering your provider organization’s shared request budget.

What it will never do

  • Write to your provider while in Observe.
  • Graduate itself without every scorecard criterion passing.
  • Raise a seat’s allocation past the budget pool.
  • Change Cursor or ChatGPT / Codex seat limits.
  • Keep writing after a write failed to verify.

FAQs

No. There is no setting that grants write access immediately. The scorecard is the only path.
Check which criterion is unmet on the scorecard. The two most common causes are Qualifying hours observed — runs that were skipped, backed off, or failed do not count, and multiple runs in the same hour count once — and Recommendation samples, because a policy that has never changed its recommendation has no churn sample to judge.
Set the workflow back to Observe, or turn off Enable. It stops writing on the next run.
Yes. Turn on Open requests before graduation under Advanced. Runs will open seat requests and wait for a human. Automation still never writes on its own.
It is admin-only, it lives inside seat tracking rather than the sidebar, and it unlocks only once the project’s budget is ready.