Bringing your own provider key, and the append-only log every real result gets tied to.
Add a provider key on Settings, or via sapling auth login / the in-session /model menu's “+ Register a new provider,” to route that provider's requests through your own account instead of your plan's included usage - still proxied through Sapling for a single, consistent client experience, just billed to you directly instead of counted against your plan.
An append-only, evidence-linked log at .sapling/research_log.jsonl - every real result the agent logs is tied to what backs it up, and a result can't be marked "promoted" without both a dev score and a held-out score if your project defines a held-out split. Inspect it with sapling log show, or ask the agent directly in a session.