The counterfactual ledger

Operant·

Any tool can claim it saves money. The hard part is a savings number someone else can check — one you would put in front of a CFO, or a board, and defend line by line. That is what the ledger is for, and it is the commercial core of Operant: every call through the gateway carries a POTENTIAL / ACTUAL / SAVED decomposition against what the same work would have cost without it.

What a counterfactual is here

POTENTIAL is not a guess. It is the same call, re-priced under three explicit reversals of what the gateway did: the same tokens priced at the model the agent asked for, masked tokens restored, and gateway-shaped cache unwound. ACTUAL is what the call really cost. SAVED is the difference — attributed to the lever that earned it.

  • A cache line says how many input tokens were read from cache instead of re-sent at full price — and only counts the reads Operant's own breakpoints caused.
  • A compression line names the stale tool results that were masked and the tokens that never traveled.
  • A routing line names the rule that served a cheaper model with its skill, and prices the turn at the model the agent originally asked for.
A conversation's savings view: per-call POTENTIAL, ACTUAL, and SAVED with lever attributions.
An illustrative conversation ledger: each call's POTENTIAL, ACTUAL and SAVED, with the lever that earned each line.

The assumptions are part of the artifact, not a footnote to it. Every ledger view states them — counterfactuals are stated estimates, and the anchor model and cache unwind are named — because a number whose assumptions are hidden cannot be defended, and a number whose assumptions are explicit can be recomputed by someone who does not trust us. That property is the whole point.

What the ledger is not

It is not a dashboard of vibes. Spend charts tell you what you paid; they cannot tell you what you would have paid, so they can neither prove a saving nor price one. The ledger is per call, per lever, and stated as an estimate with its reversal rules in the open — arithmetic you can argue with, rather than a chart you have to take on faith.

It is also not a scoreboard that only ever goes up. A lever that saves nothing on a workload shows that it saved nothing. The ledger's credibility comes from its willingness to report a boring number.

How pricing hangs off it

Gateways are free and observability is priced per seat. Operant refuses both comparisons and prices the one thing neither can produce: verified savings. Paid plans combine a modest platform fee with a share of ledger-verified savings, capped so the customer always keeps the large majority — and buyers who dislike variable pricing can take a flat fee set at the trailing share, with the same economics.

The known failure mode of savings-share pricing is a dispute over the baseline. The ledger exists to close exactly that dispute: its counterfactual assumptions are explicit, they go in the contract, and an independent party can compute them again. We price the proof, not the proxy — details on the pricing page.