# How to Set Per-Team LLM Budgets with Virtual Keys: Step by Step

> How to Set Per-Team LLM Budgets with Virtual Keys. A practical walkthrough with ZopNight: read-only setup, production excluded by default, reversible at every step.

Source: https://zop.dev/learn/how-to/set-per-team-llm-budgets
Published: 2026-07-01 · Author: avinash-gaurav · Tags: zopnight, how-to, learn

---

Step-by-step guide to governing LLM spend with ZopNight: connect a provider, issue per-team virtual keys with hard USD budgets and model allow-lists, and track AI spend.

This is the practical version, the one you can follow in a single sitting. It starts read-only, touches no production resource by default, and every step is reversible, so there is no point at which you are committed to something you cannot undo. Budget about 15 minutes. Before you start you will want: Admin access to Settings then Integrations; An API key for at least one AI provider.

## The steps

1. Connect an AI provider.
2. Issue a per-team virtual key.
3. Set a provider budget.
4. Track spend and alerts.

## Why this is safe to do today

The reason this is a low-stakes change is that nothing here is destructive. Scheduling stops and starts resources; it never deletes them, and your data persists across a stop exactly as it does across a normal reboot. Production is excluded by default, actions run in dependency order, and every state change is logged with what triggered it.

If you want the fuller context behind this task, the [FinOps](https://zop.dev/learn/finops) guide covers where it fits, and the [AWS EC2 scheduling](https://zop.dev/zopnight/aws/ec2) page shows the same loop applied to a specific resource.

## Getting started

Getting started is intentionally low-stakes:

- Connect your cloud provider with a read-only role. Nothing is scheduled or changed at this stage.
- Let ZopNight discover your non-production resources and review exactly what it found, filtered by account, region, and status.
- Create a schedule in your timezone and attach the non-production resources or groups you want it to cover.
- Watch the first cycle run, with Slack, Teams, or Google Chat notifications on every start, stop, and failure, then layer in idle cleanup and guided rightsizing.

Production stays excluded by default throughout, and because discovery and recommendations are read-only, you can prove the value before you enable a single action.

## Frequently asked questions

### Does ZopNight sit in the LLM request path?

No. ZopNight stores only a connection record; the hosted LiteLLM gateway is the store of record and owns request data.

### What happens when a key hits its budget?

The gateway enforces the hard budget, and ZopNight fires warning and exceeded alerts that name the key.
