The assistant
It answers questions about one venue’s sales: what August came to, which dish sells most, which hour is quietest. It writes the query, runs it against the database and answers in the language you asked in.

The account that answers
The key is yours and so is the spending. It is stored sealed in the database and never returned to the screen.
It can be the same key that reads the tickets or a different one: reading a ticket needs a model that can see, and answering needs one that can use tools. DeepSeek, for instance, answers well and cannot read a ticket at all.
Which model answers is the installation owner’s choice, because the daily ceiling counts tokens, not money, and the same number of tokens costs several times more on a large model.
What it may spend
Every venue has its own daily token ceiling — ten million by default. A day that reaches it stops answering until midnight in the venue’s own timezone. An admin may lower that ceiling; raising it past the installation’s figure is the owner’s.
What it sees
Only the sales of the venue being asked about, and only for reading: it reaches the database as that venue’s own role, with no permission to write and a time limit per statement. It does not see raw tickets or the installation’s settings.
What it does not do
It does not invent figures. When the data does not answer the question, it says so. And a message that is not about the venue — a complaint, an insult — gets one sentence and no query at all.