This shield uses specially crafted limiter to detect out of policy usage of tokens by user or ip per configurable time interval for example it can detect excessive use of a user of a specific app per minute/hour/day so it can alert the security team if a user or IP are abusing the number of model tokens above the configured policy