Capabilities
Varcio capabilities: 43 modules in one platform
43 modules across Operate, Analyze, Govern, Security, Admin, Account, and Help — backed by 305 active detectors and the 103-capability Apex control plane.
“What’s driving the 12% increase?”
Anomaly detected: EC2 instances in us-east-1 (Team: Analytics) increased by $4,200 starting Tuesday.
- Modules across 7 groups
- 43
- Active waste detectors
- 305
- Apex AI capabilities
- 103
- Infrastructure surfaces
- 5
Architecture
One dataset behind every capability
Each capability below reads from the same normalized, reconciled spend data — which is why a finding, a forecast, and a PR check never disagree.
Kubernetes
Cluster spend, split by who actually used it
A cluster bill is one line item from the cloud provider. Varcio breaks it back down to namespaces, deployments, and the teams that own them.
Multi-cloud spend visibility
Connect your cloud accounts in minutes and see consolidated spend across AWS, Azure, GCP, OCI, and Kubernetes — five surfaces treated as first-class citizens.
Daily and monthly spend trends with anomaly highlighting, budget posture tracking, service-level breakdowns, ingestion health, and 30-day variance summaries in one shared workspace.
- Setup time per cloud
- < 15 min
- Connection verification
- Live
- Projection window
- 30-day
- AWS
- IAM AssumeRole + External ID, Cost Explorer, CUR via Athena, CloudWatch — 102 detectors
- Azure
- Service Principal, Resource Graph, Azure Monitor — 72 detectors
- GCP
- Service Account JWT, Billing export, Asset Inventory, Recommender — 58 detectors
- OCI
- OCI API signing key encrypted at rest, spend and inventory scanning — 37 detectors
- Kubernetes
- Kubecost, OpenCost, or bundled in-cluster agent — 13 detectors
Apex AI agent
A live operations assistant, not a chatbot. Ask questions, get answers, and create governed actions in plain English.
Guided capabilities across observability, governance, operations, and knowledge. Read operations execute immediately, write actions require explicit APPROVE confirmation, and high-impact actions route through full approval workflows.
Guided AI operations
- Observability: Executive Briefing, Spend Summary, Top Services, Anomaly Scan
- Governance: Open Findings, Active Policies, Budget Status, Pending Approvals
- Configuration: Account Verification, Integration Status, Coverage Posture
- Operations: Load Demo Spend, Request Remediation, Verify Accounts, Commitment Negotiator
- Knowledge: Web Research with citations from public sources
- Read actions execute immediately; writes require APPROVE and single-use execution tokens
- High-impact actions go through full approval workflows before execution
- 4 Instruction Profiles: Balanced, Concise, Guided, Executive
Pre-merge cost analysis (PR Cost Diff)
Catch cost surprises before they reach production by analyzing Terraform changes from GitHub PRs.
Extracts Terraform resource changes, prices them with live cloud pricing APIs, evaluates active policies, calculates budget impact, and posts a single evolving PR review comment.
- PR opened
- Resources extracted
- Live pricing
- Policies checked
- Budget impact
- Comment posted
- Estimated monthly cost change (delta)
- Risk assessment score and contributing factors
- Policy compliance result (pass / advisory / block)
- Budget impact projection
- Tagging compliance check
- Confidence score for pricing estimates
Waste detection engine
305 active detectors across five surfaces that identify structural savings, each finding costed and scored.
Every opportunity includes estimated monthly savings, confidence score, effort score, risk assessment, recommended action, and a composite priority score so teams know what to fix first.
- AWS coverage8+
Unused EIPs, unattached EBS, EC2 and RDS underutilization, stale AMIs, and network waste
- Azure coverage5+
Unattached disks, unused public IPs, idle SQL databases, and zero-workload App Service plans
- GCP coverage5+
Unattached disks, unused static IPs, idle Compute Engine, idle Cloud SQL, and stale snapshots
- KubernetesAgent
CPU and memory mismatch, idle pods, DaemonSet overhead, orphaned Persistent Volumes
Finding anatomy
- Estimated savings
- $214/month
- Confidence
- 0.94
- Effort level
- Low / Medium / High
- Risk
- What could go wrong if you act
- Priority score
- Savings × confidence ÷ effort
Automated remediation
Don't just detect waste — fix it. Execute approved actions across all three major clouds.
Every remediation requires explicit human approval. Protected-tag safety, dry-run mode, credential isolation, and immutable audit trails make the workflow safe to operate in production.
- AWSDelete unattached EBS volumes
- AWSStop underutilized EC2 instances
- AWSRelease unused Elastic IPs
- AzureDeallocate idle VMs
- GCPStop idle Compute Engine instances
AI commitment negotiator
Automate commitment analysis and purchasing across AWS, Azure, and GCP with integrated approval gates.
Reviews historical on-demand usage, recommends commitment strategies with projected savings and break-even periods, supports dry-run simulation, and executes purchases on approval.
- Typical savings
- 15–30%
- Break-even period
- 3–5 months
- Lifecycle events
- Tracked
- AWS
- 1-Year RI, 3-Year Savings Plan (partial or all upfront)
- Azure
- 1-Year Reserved Instance or 1-Year Savings Plan
- GCP
- 1-Year or 3-Year Committed Use Discounts
- 1Analyze usage
- 2Recommend strategy
- 3Simulate purchase
- 4Approve
- 5Execute
- 6Track
Predictive cost forecasting
Two competing ML models run in parallel — the system automatically selects the more accurate one.
Daily predicted spend for 7, 14, 30, or 90-day horizons with confidence intervals, MAPE and RMSE transparency, and automatic fallback if data is too sparse.
- Confidence intervals (80% and 95%)
- Daily forecasts for 7, 14, 30, or 90-day horizons
- MAPE and RMSE accuracy reporting
- Budget breach probability calculation
- Automatic model selection with fallback to linear extrapolation
- Seasonal modelBest for: Seasonality, holidays, trend changesMethod: Additive regression
- Time-series modelBest for: Steady-state, consistent patternsMethod: Classical time series
Policy engine and governance
Define and enforce cost policies across your organization — from advisory warnings to hard blocks.
Tag requirements, risk thresholds, resource restrictions, and budget guardrails are enforced consistently across pull requests, findings triage, approvals, and audits.
Example rules
- BlockingBlock PRs adding GPU instances to staging
- TagRequire cost-center tag on all EC2 instances
- AdvisoryWarn if monthly forecast exceeds $15K
- BlockingBlock new resources without team owner tag
- Advisory
- Creates findings but does not block the workflow
- Blocking
- Prevents non-compliant infrastructure from progressing
- Tag requirements
- Enforce mandatory tags such as team, service, env, and owner
- Budget guardrails
- Soft limits warn; hard limits block when thresholds are crossed
ChatOps integration
Bring cost operations directly into Slack and Microsoft Teams.
List pending approvals, approve or reject with inline buttons, and verify actor authorization — all from your team's communication channels.
- Actor authorization verification
- HMAC signature verification on inbound webhooks
- Timestamp replay protection
- Inline approve/reject buttons for fast review
- Weekly digests and anomaly notifications
/finops pending- List pending approvals
/finops approve <id>- Approve a request
/finops reject <id>- Reject with optional note
/finops help- Show available commands
Cloud Control Tower 360
See the operational health of every connected account and provider in one posture view.
Control Tower 360 scores account trust posture, ingestion SLO posture, reconciliation posture, and detector coverage so teams know when their data and workflows are actually ready for decision-making.
- Maturity score
- 0–100
- Healthy / Warning / Critical
- 3 states
- Next actions
- Prioritized
- Trust posture
- Which accounts are verified, stale, or failing verification
- Ingestion SLO
- How fresh and reliable provider data is right now
- Reconciliation
- Whether connected accounts match coverage and inventory expectations
- Detector coverage
- How deep active scanning is per provider and environment
Kubernetes cost attribution
Turn opaque cluster bills into namespace, deployment, and team-level accountability.
The native Kubernetes agent ingests in-cluster metrics, maps costs to owners, and generates rightsizing and idle workload recommendations for teams running containerized platforms.
- Agent
- Lightweight Helm-deployed collector running inside the cluster
- Attribution
- Namespace, deployment, and label-based cost allocation snapshots
- Optimization
- CPU and memory drift, idle pods, and orphaned PV detection
- Ownership
- Team mapping from labels and annotations for chargeback clarity
- Namespace and deployment-level cost attribution
- Team-mapped allocation using Kubernetes labels and annotations
- Rightsizing recommendations from request-vs-actual-usage drift
- Idle pod identification for sustained zero-request workloads
- Orphaned Persistent Volume detection for unused storage costs
FinOps maturity score
"Are we actually good at this, or just busy?" A single 0–100 number leadership understands instantly, with a concrete action plan attached.
Scored across eight real, data-driven dimensions and mapped to the industry-known Crawl, Walk, Run framework, with a prioritized roadmap of what to fix next — not a vague maturity survey.
- Composite maturity score
- 0–100
- Scored dimensions
- 8
- Industry framework
- Crawl → Walk → Run
- Tagging compliance and coverage
- Commitment coverage (Reserved Instances, Savings Plans)
- Waste elimination rate
- Budget guardrail coverage
- Forecasting readiness and accuracy
- Cost allocation completeness
- Alerting and anomaly response
- Spend trend health
Apex cost incidents
Think PagerDuty, but for cost spikes — with root cause, ownership, and an SLA.
When a cost spike happens, Apex runs a real investigation and opens an incident with a primary hypothesis, an evidence timeline, and a confidence rating, then assigns it to an owner with a tracked SLA — a full incident-response workflow, but for cost instead of uptime.
- Primary hypothesis generated from real spend data
- Evidence timeline showing exactly what changed
- Confidence rating on the root-cause finding
- Owner assignment with a tracked SLA
- Routes to PagerDuty or Opsgenie like any other incident
Cloud inventory and security posture
You are not just buying a cost tool — you get a live security posture scan on top, at no extra integration effort.
A live, cross-cloud resource scan across AWS, Azure, GCP, and OCI that flags encryption status and open, sensitive network ports, layered on top of the same connection you already set up for cost visibility.
- Live cross-cloud resource inventory
- Encryption-at-rest status per resource
- Open and sensitive network port detection
- No extra integration effort beyond your existing cost connection
Savings tracker
"What did FinOps actually save us?" — answered with a provable, audited number, not a spreadsheet built the night before a board meeting.
Tracks realized savings against every opportunity identified, shows your realization rate and an ROI multiple comparing what you have saved to what the platform costs, and exports straight to CSV or PDF for a board deck.
- Realized vs. identified savings
- Tracked
- Savings vs. platform cost
- ROI multiple
- Board-ready export
- CSV / PDF
Autopilot and auto-stopping
Automation with a seatbelt — it will not touch production without your say-so, by design, not by promise.
A three-mode rule engine with hardcoded safety gates that refuse to touch production-tagged, publicly exposed, or critical-risk resources, plus a monthly budget cap so automation can never overspend. Scheduling can park and wake non-production resources on a calendar automatically, with dry-run on by default.
- Hardcoded gates protect production, public-facing, and critical-risk resources
- Monthly budget cap so automation can never overspend
- Calendar-based scheduling parks and wakes non-prod resources automatically
- Dry-run on by default
- 1Observe
- 2Suggest
- 3Autopilot
Tag governance and ownership
"Who owns this?" gets answered for every resource — with the exact rule to write, based on your real data.
An advisor scans your live inventory and recommends tagging policies based on what it actually finds, scores compliance by team, and lets you define inference rules that bulk-assign ownership in one sweep.
- Tagging policy recommendations based on real inventory scans
- Compliance scoring by team
- Inference rules: tag match, naming pattern, account default
- Bulk ownership assignment in one sweep
Workspaces and organization analytics
Full data segregation where you need it, full visibility where you want it — both, not a trade-off.
Segment data into isolated workspaces, each with its own connected cloud accounts, then roll everything up into one cross-workspace analytics view — spend trends, risk posture, and per-workspace optimization scorecards.
- Isolated workspaces per business unit, environment, or client
- Each workspace has its own connected cloud accounts
- Cross-workspace roll-up for leadership
- Per-workspace optimization scorecards
Reports studio and shared dashboards
Send your CFO a live link right now — no login needed, and you control exactly what they see.
Persona-driven reports for CFO, CTO, Engineering, or FinOps audiences, exportable on demand — plus a shareable dashboard link: a public, tokenized, redactable snapshot you control down to which numbers and team names are visible, fully revocable and audit-logged.
- Persona-driven reports: CFO, CTO, Engineering, FinOps
- Tokenized, redactable shareable dashboard links
- No login required for the recipient
- Fully revocable and audit-logged
Module reference
Every module, grouped by job
43 modules across seven groups. Account (plan, entitlements, credits) and Help & Updates (support tickets, error history) complete the set.
Operate
8 modules
Daily command surface — what is happening now and what to do about it.
- ApexNatural-language control plane over 103 real capabilities across 11 screens
- OverviewConsolidated spend, trends, anomalies, budget pressure, and ingestion health
- OptimizationSavings pipeline that bundles opportunities into executable, guardrailed work
- AI InfrastructureCost and waste analysis for SageMaker, Bedrock, Vertex AI, and Azure OpenAI
- CEO ViewA deliberately minimal executive snapshot, readable in about thirty seconds
- Opportunity QueueCross-cloud triage — every detection as a costed, scored, SLA-tracked finding
- AutopilotAutonomous optimization inside your guardrails, with three graduated trust modes
- CI/CD Control TowerLinks pipelines, deployments, and PR risk to their cost consequences
Analyze
13 modules
Depth — where money goes, why it moved, and what it buys.
- IntelligenceTelemetry ingestion, waste scanning, commitment negotiation, and regression attribution
- Cost CenterSeven analytical lenses over one normalised ledger
- ReportsExecutive, FinOps, operations, and unit-economics reporting with scheduled delivery
- Predictive AnalyticsTwo competing forecast models, honest error metrics, and change simulation
- Unit EconomicsCost per active user, API request, order, or inference
- FinOps MaturityAn objective score across eight weighted dimensions, from measured state
- Database HealthConnections, storage, latency, replication lag, and query performance
- KubernetesNamespace, deployment, and team allocation with utilisation-based rightsizing
- API MonitoringThe invoice's view of the API layer — including the cost of failed requests
- Cloud PlaygroundScenario modelling for multi-cloud architecture on live provider pricing
- Deploy & MigrationRepository-to-cloud planning with cross-cloud comparison and blueprints
- Vendor HubVendor portfolio, contracts, renewals, risk, and workflow
- Cloud BillingPartner and reseller invoices, discounts, payments, and disputes
Govern
8 modules
Controls — rules, gates, attribution, and evidence.
- PoliciesRequired tags, blocked resource types, cost and risk thresholds, budget limits
- PR Cost ReviewPrices Terraform changes against live pricing and comments before merge
- Tag GovernanceTag policy definition, compliance scanning, and convention advisor
- OwnershipMaps resources to owning teams, with inference for untagged resources
- Cost AllocationChargeback and showback rules for shared infrastructure
- ApprovalsCentral approval queue, decidable from dashboard, Slack, Teams, or Apex
- Resource ParkingAutoStopping, off-hours parking, hibernation, and scale-to-zero
- Audit LogsImmutable stream of every action by a user, Apex, Autopilot, or scheduled job
Security
3 modules
Estate posture — inventory, threat, and compliance.
- InventoryLive multi-cloud asset register with scan lineage and coverage measurement
- FinSecOpsMulti-cloud threat posture, webhook and event-bus fabric, identity controls
- ComplianceControl-mapped findings across SOC 2, CIS, NIST, and ISO 27001
Admin
7 modules
Tenancy — users, workspaces, connections, integrations, identity.
- OrganizationUser and access administration
- Workspace SetupWorkspace lifecycle management
- Identity & SSOEnterprise identity federation
- Org AnalyticsOrganisation-level analytics
- Cloud AccountsCloud provider connections and trust verification
- IntegrationsSlack, Teams, Jira, Linear, source control, and event buses
- AI Provider AccountsLLM provider connections and model routing
Developer workflows
Where these capabilities show up
Move from product capability to day-to-day workflow with GitHub, CLI, ChatOps, IDE, and event delivery integrations.
GitHub App
Org-wide PR governance
Install once and get cost comments, policy checks, and comment upserts across repositories.
GitHub Actions
Custom CI control
Run cost analysis in workflow YAML when teams need pipeline-level customization.
FinOps CLI
Local and CI estimates
Estimate Terraform plan costs locally, in CI/CD, or before opening a pull request.
VS Code extension
Inline Terraform hints
Surface estimated monthly resource cost while engineers are still editing infrastructure.
Slack and Teams
Approval workflows
Approve, reject, and route remediation or commitment decisions from collaboration tools.
Event bus
Webhooks, EventBridge, Pub/Sub
Push findings, approvals, and execution events into alerting, ticketing, and data platforms.
See every feature in action
Free trial. All 43 modules unlocked. No credit card required.