Idle and unattached resources
Resources that keep billing after the instance or project that needed them has gone. These are usually the lowest-effort savings in an AWS account.
- Unattached EBS volumes
- Unused Elastic IP addresses
- Old snapshots
Varcio is an AWS cost optimization tool that connects through a read-only IAM role, runs 102 AWS detectors over Cost Explorer, the Cost and Usage Report, CloudWatch and live resource scans, and ranks every finding by savings, confidence and effort. When you choose, approved fixes run behind protected tags, dry-run and a full audit log.
AWS is Varcio’s deepest surface. Its 102 detectors look for structural waste — spend that keeps billing without producing value — and cost every finding in dollars per month.
AWS bills grow in predictable ways. Resources outlive the workloads that created them, instances are sized for a launch-day peak that never returns, and on-demand usage stays on-demand long after it has become steady. None of this shows up as a single large line item; it shows up as hundreds of small ones spread across accounts and Regions.
Every Varcio finding carries an estimated monthly saving, a confidence score, an effort level, a note on what could go wrong if you act, and a recommended action. Findings are ranked on those scores, so the first item in the queue is the one most worth an engineer’s time rather than simply the largest number.
Resources that keep billing after the instance or project that needed them has gone. These are usually the lowest-effort savings in an AWS account.
Capacity provisioned well above what the workload uses. Findings compare the size you pay for with utilisation measured in CloudWatch.
Network charges rarely belong to one obvious owner, which is why they tend to grow unnoticed. Varcio surfaces network waste as its own finding category.
Sudden changes in service or account spend, caught by anomaly detection and forecasting rather than at month-end invoice review.
Steady on-demand usage that is a candidate for a Reserved Instance or Savings Plan once waste and oversizing have been removed.
If you also run Azure, Google Cloud, OCI or Kubernetes, 23 cross-cloud detectors run on the normalised ledger after ingestion.
Each AWS detector uses the signals that answer its question. Not every signal applies to every resource type; these are the kinds of evidence Varcio reads.
Cost Explorer and the Cost and Usage Report, queried through Athena, show services, accounts and usage types whose cost is moving without a matching change in demand, along with Savings Plan and Reserved Instance coverage and utilisation.
Resources are scanned directly to see what is attached, running or referenced, which is how unattached EBS volumes, unused Elastic IPs and old snapshots are found.
CloudWatch metrics and Compute Optimizer recommendations compare what EC2, RDS and other resources are provisioned for with what they actually consume.
CloudWatch Logs Insights queries supply diagnostic signals, such as slow queries and deadlocks on RDS and Aurora databases that export their logs.
Identity and security settings are evaluated alongside cost, so a finding is reviewed with its access context rather than in isolation.
A cross-account IAM role, the AWS data sources that matter for cost, and a hard line between reading your account and changing it.
You create an IAM role in your account that Varcio assumes. Each customer receives a unique External ID that must match on every AssumeRole call, which prevents confused-deputy attacks: another Varcio customer cannot trick the service into using your role. Varcio stores no long-lived access keys.
Findings, forecasting, anomaly detection, allocation, tag governance and Apex questions all run on read-only credentials, with no time limit. You never have to grant write access to get value from the platform.
If you later want Varcio to act on findings, you add a second IAM role for execution, with its own External ID, and Varcio verifies it separately from the read-only role. Granting it is a deliberate decision you make after you have seen what Varcio found.
AWS has the fullest remediation action set in Varcio, a Savings Plan purchase path, and partner billing reconciliation for organisations that buy AWS through a partner.
Removing waste lowers what you run. Commitments lower the rate you pay for what remains.
Reserved Instances and Savings Plans are the largest single rate lever on AWS, and also the easiest to get wrong. Commit before rightsizing and you lock in capacity you were about to remove; commit too cautiously and steady workloads stay on on-demand pricing for another year.
Varcio analyses historical on-demand usage, models commitment options with projected savings and a break-even period, and lets you simulate a purchase before anything is bought. Live purchases are Compute Savings Plans with no upfront payment. Each one needs approval and a typed confirmation, and commitments are tracked after purchase. Varcio does not buy Reserved Instances.
Commitment Autopilot, available on AWS only, can take over Compute Savings Plan purchasing within the limits you set.
Detection is where most tools stop. On AWS, Varcio can carry a finding through to the change itself.
Through Apex, a request such as “clean up the unattached volumes in the staging account” returns a plan listing the resources, the expected saving and the guardrails that apply. It runs only after an authorised person types APPROVE with a single-use token, or approves it from Slack or Teams. If you turn on Autopilot mode, some low-risk actions can run without a person, within the limits described below.
Supported changes record what they replaced, so Varcio can roll them back automatically. Varcio tracks identified savings separately from realised savings and verifies the realised figure against subsequent spend, so a closed ticket is never mistaken for a smaller bill.
These controls apply to all remediation Varcio executes, on every cloud, alongside the write permissions you grant and Varcio verifies before anything changes.
Resources carrying a protected tag are excluded from every remediation run, so a production database or a regulated workload cannot be changed by a rule that happens to match it.
Approved changes run only inside the windows you define, which keeps stops, deletions and resizes away from peak traffic, release trains and change freezes.
Before a live run, Varcio checks for step-up approval on high blast-radius changes, a rollback success floor, and a maintenance window for larger blast radius. If a gate is not met, the run drops to a dry run instead.
Any action can be previewed without making live API calls, and individual rules can be held to dry run. Per-rule action caps, a maximum number of actions per run and a monthly action budget bound how much changes at once.
Write actions requested through Apex come back as a plan that runs only after an authorised person types APPROVE, backed by a single-use token, or approves from Slack or Microsoft Teams. Autopilot runs in observe, suggest or autopilot mode. In autopilot mode it can act without a person above a confidence threshold, including deleting unattached volumes and orphaned snapshots, but resources that look production, public, critical or deletion-protected go to approval instead.
Every action records who requested it, who approved it, what changed and when, so finance, security and auditors can reconstruct any change after the fact.
AWS provides capable native cost tools, and most teams that adopt Varcio keep using them. Here is what each does well, according to AWS documentation.
Visualises cost and usage with filters and groupings, shows up to 13 months of history, forecasts spend for the next 18 months and recommends Reserved Instance purchases. The console is free to use; the API is charged per paginated request.
Tracks cost, usage, and Reserved Instance or Savings Plans utilisation and coverage against thresholds, alerts on actual or forecasted amounts by email or Amazon SNS, and can apply actions such as a custom IAM policy when a threshold is crossed.
Consolidates rightsizing, idle resource, Savings Plans and Reserved Instance recommendations across accounts and Regions, deduplicates overlapping savings and accounts for your AWS pricing and discounts.
Analyses CloudWatch utilisation (14 days by default, up to 93 days with paid enhanced infrastructure metrics) to recommend rightsizing and flag idle resources across EC2, Auto Scaling groups, EBS, Lambda, RDS and more.
| Capability | AWS native tools | Varcio |
|---|---|---|
| Cost visibility | Cost Explorer for AWS cost and usage, with 13 months of history and an 18-month forecast | One normalised ledger across AWS, Azure, Google Cloud, OCI and Kubernetes |
| Waste and rightsizing | Compute Optimizer and Cost Optimization Hub rightsizing and idle resource recommendations | 102 AWS detectors, plus 23 cross-cloud detectors |
| Prioritisation | Filter, sort and group recommendations by estimated savings | Findings costed and ranked by savings, confidence and effort |
| Commitments | Savings Plans and Reserved Instance recommendations in Cost Optimization Hub and Cost Explorer | 1-Year RI and 3-Year Savings Plan modelling with dry-run; approval-gated Compute Savings Plan purchases |
| Budgets and alerts | AWS Budgets with email or SNS notifications and budget actions | Anomaly detection, forecasting and policy guardrails, with alerts in Slack or Teams |
| Acting on findings | Changes made in service consoles, APIs or infrastructure code; budget actions respond to thresholds | Plan confirmed with APPROVE, protected tags, execution windows, rollout-safety gates, dry-run, action caps and audit log |
| Pre-merge cost review | Not covered by the tools listed here | PR cost review prices Terraform changes before they merge |
| Savings tracking | Cost efficiency metric and savings benchmarks in Cost Optimization Hub | Identified versus realised savings, verified against subsequent spend |
Scroll sideways to see the full table.
If AWS is your only cloud and your team is comfortable working from recommendations in the console, the native tools may be enough. Varcio earns its place when cost work has to cross boundaries: several clouds or Kubernetes clusters in one ledger, findings that need to reach the team that owns the resource, and changes that need an approval record finance and security will accept.
Varcio adds tag governance, cost allocation and showback across every connected surface, policies that can advise or block, PR cost review so new waste is caught before merge, and Slack and Teams workflows for approvals. Apex, the natural-language assistant with 135 live capabilities, answers spend questions and turns requests into governed plans.
Cost is shared work. Each team sees the same findings and ledger, framed for the decisions it owns.
Gets findings with the resource, the evidence and a recommended action instead of a spreadsheet export, and sees the cost impact of Terraform changes in the pull request before they merge.
Works from one ledger that holds AWS alongside every other surface, allocates cost through tag governance and showback, reconciles partner billing, and reports identified against realised savings.
Approves or rejects remediation from Slack or Teams, relies on protected tags and execution windows to keep production out of scope, and reviews cost anomalies next to operational context.
Asks Apex plain-language questions about where spend is going, sees forecasts against budget, and gets a ranked backlog of savings that can be planned like any other engineering work.
Work in order of effort. First remove resources that bill without doing anything, such as unattached EBS volumes, unused Elastic IPs and old snapshots. Next, rightsize EC2 and RDS instances using measured utilisation. Then cover the steady usage that remains with Reserved Instances or Savings Plans. Finally, stop new waste at source with tag policies and cost review on infrastructure pull requests. Varcio automates the finding and ranking at each step with 102 AWS detectors.
It can be, if the access model is designed for it. Varcio connects through IAM AssumeRole with a per-customer External ID, which prevents confused-deputy attacks, and stores no long-lived access keys. The entire analytical product runs on read-only credentials indefinitely. Execution uses a separate IAM role with its own External ID that you add later if you choose, and every write action is protected by tag exemptions, rollout-safety gates, dry-run, approval or Autopilot limits, and audit logging.
Cost Optimization Hub consolidates AWS rightsizing, idle resource, Savings Plans and Reserved Instance recommendations across your accounts and Regions, using your AWS pricing. Varcio covers AWS with 102 detectors and puts AWS in the same ledger as Azure, Google Cloud, OCI and Kubernetes. It also adds approval-gated execution, PR cost review, allocation and governance, and Slack and Teams workflows.
Many teams keep using Cost Explorer for ad hoc analysis inside AWS, and Varcio uses Cost Explorer as one of its data sources. Varcio does not ask you to turn off native tools. It adds a ranked queue of costed findings, a multi-cloud view and a governed path from finding to change.
Cost Explorer, including Savings Plan and Reserved Instance coverage and utilisation, the Cost and Usage Report queried through Athena, CloudWatch metrics, Compute Optimizer, CloudWatch Logs Insights, AWS Organizations, live resource scanning and the AWS Pricing API. Together these let Varcio see what you are billed for, what exists, how heavily it is used and what a change would cost or save.
Varcio models 1-Year Reserved Instances and 3-Year Savings Plans with partial or all upfront payment, shows projected savings and break-even periods, and supports a dry-run simulation. Live purchases are Compute Savings Plans with no upfront payment, and each needs approval and a typed confirmation. Commitment Autopilot, on AWS only, can automate those purchases within limits you set. Varcio does not buy Reserved Instances.
Not on read-only credentials, which is how every account starts. Changes require a separate execution role that Varcio verifies, and write actions requested through Apex come back as a plan that runs only after approval. If you turn on Autopilot mode, Varcio can act without a person above a confidence threshold, for example deleting unattached volumes and orphaned snapshots. Resources that look production, public, critical or deletion-protected still go to approval, and everything counts against a monthly action budget.
Findings appear from the first scan after you connect an AWS account. You can start with a free trial and connect an account without granting any write permissions.
Connect a read-only IAM role, review costed findings for your accounts, and decide later whether Varcio should act on them.