We meter exactly one number: total bytes stored. Not seats, not API calls, not the number of objects, not features.
Why that one. It is the only cost that a determined bad actor can drive up without limit and without paying anything, and it is the only cost that persists after they leave. Compute is self-limiting — a rate limiter handles it and the cost stops when the traffic stops. Storage does not stop.
Why not the others, specifically: seats punish the collaboration we want; API calls punish the agent-driven usage that is the entire product; object counts are a proxy for storage that is wrong in both directions, so it walls someone with a thousand tiny items while waving through someone with three enormous ones.
The property that makes a single number worth defending is that a user can predict it and can act on it. Two meters mean a user can be under both walls and still blocked, and every error has to explain which wall it hit and why.