How does spend and rate limiting per agent satisfy ISO 27001 requirements?

Kastra enforces spend and rate limiting per agent at the moment of execution and writes a signed evidence record for every request. Auditors get a complete, append-only trail of who attempted what, what policy fired, why the decision was made, and what data was touched. This evidence maps directly to ISO 27001, IEC 62443, ITAR control families.