Local by default
Libra runs on your machine. Prompts, source code, tool output, ledger state, and policy decisions stay local by default. There is no account, login, hosted control plane, or SaaS dependency in this Developer Preview.
What it governs
Libra admits tasks only after a probabilistic estimate and reserved budget exist, then records estimated versus actual spend and makes material replans visible. The existing coding-agent UI remains the user experience.
Honest boundaries
Libra is not a generic token counter, LLM router, or coding-agent chat UI. Its optional gateway enforces limits only for traffic explicitly routed through it; it does not decide policy.