Keep a differential-privacy ledger: accept releases in order until their epsilon costs would overspend the declared budget.
Required APIdef privacy_budget(queries, epsilon_budget):
return {'accepted': [...], 'rejected': [...], 'remaining': ...}BehaviorThink through the mechanism first if you want the extra reasoning step. It never blocks the editor.
privacy_budget([{'name': 'mean', 'epsilon': 0.3}, {'name': 'count', 'epsilon': 0.4}], 1.0)accepted releases leave an auditable remainder
privacy_budget([{'name': 'a', 'epsilon': 0.7}, {'name': 'b', 'epsilon': 0.5}], 1.0)composition cannot cross the privacy barrier
2 hidden edge tests run after the visible contract passes.
Run Tests to see the contract verdicts here.