Main content

Capabilities

Varcio capabilities: 43 modules in one platform

43 modules across Operate, Analyze, Govern, Security, Admin, Account, and Help — backed by 305 active detectors and the 103-capability Apex control plane.

Varcio · OverviewLive
Total spend
$12,800 ↑8%
AWS: 65% Azure: 20% GCP: 15%
Apex AI agent

“What’s driving the 12% increase?”

Anomaly detected: EC2 instances in us-east-1 (Team: Analytics) increased by $4,200 starting Tuesday.

Waste detection2 high
14 unattached EBS volumesSave $214/moAuto-fix →
Modules across 7 groups
43
Active waste detectors
305
Apex AI capabilities
103
Infrastructure surfaces
5

Architecture

One dataset behind every capability

Each capability below reads from the same normalized, reconciled spend data — which is why a finding, a forecast, and a PR check never disagree.

How Varcio turns cloud billing data into governed actionCloud accounts connect through provider-native trust models into an ingestion and normalization layer, then into the Varcio engine, which produces pull request cost checks, waste findings, forecasts, and approval-gated remediation.SOURCESINGESTENGINEOUTCOMESAWSAssumeRoleAzureService PrincipalGCPSA JWTOCINative authKubernetesHelm agentIngestionnormalize · tagreconcile · verifyVarcioDetect wasteForecast spendEnforce policyApex AI agentPR cost checksbefore mergeWaste findings305 detectorsForecasts90-day horizonChatOps approvalsSlack / TeamsEvery write action is approval-gated and written to an immutable audit log
Provider-native trust models feed ingestion, which feeds the engine behind every outcome.

Kubernetes

Cluster spend, split by who actually used it

A cluster bill is one line item from the cloud provider. Varcio breaks it back down to namespaces, deployments, and the teams that own them.

Kubernetes cluster cost split by namespaceCluster spend attributed across five namespaces with monthly cost and idle percentage, showing machine learning training and internal tools carrying the highest idle capacity.NAMESPACEMONTHLYIDLEpayments$4,0208%data-platform$3,08022%web-frontend$2,1306%ml-training$1,65041%internal-tools$95035%ml-training and internal-tools show 35%+ idle capacity — rightsizing here recovers about $910/month
Idle percentage per namespace turns an unattributable cluster cost into a specific, ownable rightsizing task.
01

Multi-cloud spend visibility

Connect your cloud accounts in minutes and see consolidated spend across AWS, Azure, GCP, OCI, and Kubernetes — five surfaces treated as first-class citizens.

Daily and monthly spend trends with anomaly highlighting, budget posture tracking, service-level breakdowns, ingestion health, and 30-day variance summaries in one shared workspace.

Setup time per cloud
< 15 min
Connection verification
Live
Projection window
30-day
AWS
IAM AssumeRole + External ID, Cost Explorer, CUR via Athena, CloudWatch — 102 detectors
Azure
Service Principal, Resource Graph, Azure Monitor — 72 detectors
GCP
Service Account JWT, Billing export, Asset Inventory, Recommender — 58 detectors
OCI
OCI API signing key encrypted at rest, spend and inventory scanning — 37 detectors
Kubernetes
Kubecost, OpenCost, or bundled in-cluster agent — 13 detectors
02

Apex AI agent

A live operations assistant, not a chatbot. Ask questions, get answers, and create governed actions in plain English.

Guided capabilities across observability, governance, operations, and knowledge. Read operations execute immediately, write actions require explicit APPROVE confirmation, and high-impact actions route through full approval workflows.

Guided AI operations

  • Observability: Executive Briefing, Spend Summary, Top Services, Anomaly Scan
  • Governance: Open Findings, Active Policies, Budget Status, Pending Approvals
  • Configuration: Account Verification, Integration Status, Coverage Posture
  • Operations: Load Demo Spend, Request Remediation, Verify Accounts, Commitment Negotiator
  • Knowledge: Web Research with citations from public sources
  • Read actions execute immediately; writes require APPROVE and single-use execution tokens
  • High-impact actions go through full approval workflows before execution
  • 4 Instruction Profiles: Balanced, Concise, Guided, Executive
Explore all Apex capabilities
Apex
"What are our top 5 AWS services by cost this month?"
EC2 ($5,420 ↑8%), RDS ($2,880 ↑6%), S3 ($1,340 →), Lambda ($210 ↓2%), NAT ($95 ↑12%). Total: $10,945. Anomaly: NAT Gateway ↑12%.
"Negotiate our RI portfolio for next quarter with 3-year Savings Plans"
Analyzing 90 days on-demand... Recommendation: 1-Year Compute SP. Current: $6,420/mo → Committed: $5,120/mo. Savings: $1,300/mo (20%). Break-even: 3.4 months. Type APPROVE to create an approval-gated purchase run.
03

Pre-merge cost analysis (PR Cost Diff)

Catch cost surprises before they reach production by analyzing Terraform changes from GitHub PRs.

Extracts Terraform resource changes, prices them with live cloud pricing APIs, evaluates active policies, calculates budget impact, and posts a single evolving PR review comment.

  1. PR opened
  2. Resources extracted
  3. Live pricing
  4. Policies checked
  5. Budget impact
  6. Comment posted
  • Estimated monthly cost change (delta)
  • Risk assessment score and contributing factors
  • Policy compliance result (pass / advisory / block)
  • Budget impact projection
  • Tagging compliance check
  • Confidence score for pricing estimates
04

Waste detection engine

305 active detectors across five surfaces that identify structural savings, each finding costed and scored.

Every opportunity includes estimated monthly savings, confidence score, effort score, risk assessment, recommended action, and a composite priority score so teams know what to fix first.

  • AWS coverage8+

    Unused EIPs, unattached EBS, EC2 and RDS underutilization, stale AMIs, and network waste

  • Azure coverage5+

    Unattached disks, unused public IPs, idle SQL databases, and zero-workload App Service plans

  • GCP coverage5+

    Unattached disks, unused static IPs, idle Compute Engine, idle Cloud SQL, and stale snapshots

  • KubernetesAgent

    CPU and memory mismatch, idle pods, DaemonSet overhead, orphaned Persistent Volumes

Finding anatomy

Estimated savings
$214/month
Confidence
0.94
Effort level
Low / Medium / High
Risk
What could go wrong if you act
Priority score
Savings × confidence ÷ effort
05

Automated remediation

Don't just detect waste — fix it. Execute approved actions across all three major clouds.

Every remediation requires explicit human approval. Protected-tag safety, dry-run mode, credential isolation, and immutable audit trails make the workflow safe to operate in production.

Protected tags
Tag critical resources to exclude them from remediation
Human approval
Every action requires explicit confirmation
Dry-run mode
Preview the full action without making live API calls
Audit trail
Full before/after state captured for every action
Rate limiting
Max 10 actions per minute per workspace
  • AWSDelete unattached EBS volumes
  • AWSStop underutilized EC2 instances
  • AWSRelease unused Elastic IPs
  • AzureDeallocate idle VMs
  • GCPStop idle Compute Engine instances
06

AI commitment negotiator

Automate commitment analysis and purchasing across AWS, Azure, and GCP with integrated approval gates.

Reviews historical on-demand usage, recommends commitment strategies with projected savings and break-even periods, supports dry-run simulation, and executes purchases on approval.

Typical savings
15–30%
Break-even period
3–5 months
Lifecycle events
Tracked
AWS
1-Year RI, 3-Year Savings Plan (partial or all upfront)
Azure
1-Year Reserved Instance or 1-Year Savings Plan
GCP
1-Year or 3-Year Committed Use Discounts
  1. 1Analyze usage
  2. 2Recommend strategy
  3. 3Simulate purchase
  4. 4Approve
  5. 5Execute
  6. 6Track
07

Predictive cost forecasting

Two competing ML models run in parallel — the system automatically selects the more accurate one.

Daily predicted spend for 7, 14, 30, or 90-day horizons with confidence intervals, MAPE and RMSE transparency, and automatic fallback if data is too sparse.

  • Confidence intervals (80% and 95%)
  • Daily forecasts for 7, 14, 30, or 90-day horizons
  • MAPE and RMSE accuracy reporting
  • Budget breach probability calculation
  • Automatic model selection with fallback to linear extrapolation
  • Seasonal model
    Best for: Seasonality, holidays, trend changesMethod: Additive regression
  • Time-series model
    Best for: Steady-state, consistent patternsMethod: Classical time series
08

Policy engine and governance

Define and enforce cost policies across your organization — from advisory warnings to hard blocks.

Tag requirements, risk thresholds, resource restrictions, and budget guardrails are enforced consistently across pull requests, findings triage, approvals, and audits.

Example rules

  • BlockingBlock PRs adding GPU instances to staging
  • TagRequire cost-center tag on all EC2 instances
  • AdvisoryWarn if monthly forecast exceeds $15K
  • BlockingBlock new resources without team owner tag
Advisory
Creates findings but does not block the workflow
Blocking
Prevents non-compliant infrastructure from progressing
Tag requirements
Enforce mandatory tags such as team, service, env, and owner
Budget guardrails
Soft limits warn; hard limits block when thresholds are crossed
09

ChatOps integration

Bring cost operations directly into Slack and Microsoft Teams.

List pending approvals, approve or reject with inline buttons, and verify actor authorization — all from your team's communication channels.

  • Actor authorization verification
  • HMAC signature verification on inbound webhooks
  • Timestamp replay protection
  • Inline approve/reject buttons for fast review
  • Weekly digests and anomaly notifications
/finops pending
List pending approvals
/finops approve <id>
Approve a request
/finops reject <id>
Reject with optional note
/finops help
Show available commands
10

Cloud Control Tower 360

See the operational health of every connected account and provider in one posture view.

Control Tower 360 scores account trust posture, ingestion SLO posture, reconciliation posture, and detector coverage so teams know when their data and workflows are actually ready for decision-making.

Maturity score
0–100
Healthy / Warning / Critical
3 states
Next actions
Prioritized
Trust posture
Which accounts are verified, stale, or failing verification
Ingestion SLO
How fresh and reliable provider data is right now
Reconciliation
Whether connected accounts match coverage and inventory expectations
Detector coverage
How deep active scanning is per provider and environment
11

Kubernetes cost attribution

Turn opaque cluster bills into namespace, deployment, and team-level accountability.

The native Kubernetes agent ingests in-cluster metrics, maps costs to owners, and generates rightsizing and idle workload recommendations for teams running containerized platforms.

Agent
Lightweight Helm-deployed collector running inside the cluster
Attribution
Namespace, deployment, and label-based cost allocation snapshots
Optimization
CPU and memory drift, idle pods, and orphaned PV detection
Ownership
Team mapping from labels and annotations for chargeback clarity
  • Namespace and deployment-level cost attribution
  • Team-mapped allocation using Kubernetes labels and annotations
  • Rightsizing recommendations from request-vs-actual-usage drift
  • Idle pod identification for sustained zero-request workloads
  • Orphaned Persistent Volume detection for unused storage costs
12

FinOps maturity score

"Are we actually good at this, or just busy?" A single 0–100 number leadership understands instantly, with a concrete action plan attached.

Scored across eight real, data-driven dimensions and mapped to the industry-known Crawl, Walk, Run framework, with a prioritized roadmap of what to fix next — not a vague maturity survey.

Composite maturity score
0–100
Scored dimensions
8
Industry framework
Crawl → Walk → Run
  • Tagging compliance and coverage
  • Commitment coverage (Reserved Instances, Savings Plans)
  • Waste elimination rate
  • Budget guardrail coverage
  • Forecasting readiness and accuracy
  • Cost allocation completeness
  • Alerting and anomaly response
  • Spend trend health
13

Apex cost incidents

Think PagerDuty, but for cost spikes — with root cause, ownership, and an SLA.

When a cost spike happens, Apex runs a real investigation and opens an incident with a primary hypothesis, an evidence timeline, and a confidence rating, then assigns it to an owner with a tracked SLA — a full incident-response workflow, but for cost instead of uptime.

  • Primary hypothesis generated from real spend data
  • Evidence timeline showing exactly what changed
  • Confidence rating on the root-cause finding
  • Owner assignment with a tracked SLA
  • Routes to PagerDuty or Opsgenie like any other incident
14

Cloud inventory and security posture

You are not just buying a cost tool — you get a live security posture scan on top, at no extra integration effort.

A live, cross-cloud resource scan across AWS, Azure, GCP, and OCI that flags encryption status and open, sensitive network ports, layered on top of the same connection you already set up for cost visibility.

  • Live cross-cloud resource inventory
  • Encryption-at-rest status per resource
  • Open and sensitive network port detection
  • No extra integration effort beyond your existing cost connection
15

Savings tracker

"What did FinOps actually save us?" — answered with a provable, audited number, not a spreadsheet built the night before a board meeting.

Tracks realized savings against every opportunity identified, shows your realization rate and an ROI multiple comparing what you have saved to what the platform costs, and exports straight to CSV or PDF for a board deck.

Realized vs. identified savings
Tracked
Savings vs. platform cost
ROI multiple
Board-ready export
CSV / PDF
16

Autopilot and auto-stopping

Automation with a seatbelt — it will not touch production without your say-so, by design, not by promise.

A three-mode rule engine with hardcoded safety gates that refuse to touch production-tagged, publicly exposed, or critical-risk resources, plus a monthly budget cap so automation can never overspend. Scheduling can park and wake non-production resources on a calendar automatically, with dry-run on by default.

  • Hardcoded gates protect production, public-facing, and critical-risk resources
  • Monthly budget cap so automation can never overspend
  • Calendar-based scheduling parks and wakes non-prod resources automatically
  • Dry-run on by default
  1. 1Observe
  2. 2Suggest
  3. 3Autopilot
17

Tag governance and ownership

"Who owns this?" gets answered for every resource — with the exact rule to write, based on your real data.

An advisor scans your live inventory and recommends tagging policies based on what it actually finds, scores compliance by team, and lets you define inference rules that bulk-assign ownership in one sweep.

  • Tagging policy recommendations based on real inventory scans
  • Compliance scoring by team
  • Inference rules: tag match, naming pattern, account default
  • Bulk ownership assignment in one sweep
18

Workspaces and organization analytics

Full data segregation where you need it, full visibility where you want it — both, not a trade-off.

Segment data into isolated workspaces, each with its own connected cloud accounts, then roll everything up into one cross-workspace analytics view — spend trends, risk posture, and per-workspace optimization scorecards.

  • Isolated workspaces per business unit, environment, or client
  • Each workspace has its own connected cloud accounts
  • Cross-workspace roll-up for leadership
  • Per-workspace optimization scorecards
19

Reports studio and shared dashboards

Send your CFO a live link right now — no login needed, and you control exactly what they see.

Persona-driven reports for CFO, CTO, Engineering, or FinOps audiences, exportable on demand — plus a shareable dashboard link: a public, tokenized, redactable snapshot you control down to which numbers and team names are visible, fully revocable and audit-logged.

  • Persona-driven reports: CFO, CTO, Engineering, FinOps
  • Tokenized, redactable shareable dashboard links
  • No login required for the recipient
  • Fully revocable and audit-logged

Module reference

Every module, grouped by job

43 modules across seven groups. Account (plan, entitlements, credits) and Help & Updates (support tickets, error history) complete the set.

Operate

8 modules

Daily command surface — what is happening now and what to do about it.

  • ApexNatural-language control plane over 103 real capabilities across 11 screens
  • OverviewConsolidated spend, trends, anomalies, budget pressure, and ingestion health
  • OptimizationSavings pipeline that bundles opportunities into executable, guardrailed work
  • AI InfrastructureCost and waste analysis for SageMaker, Bedrock, Vertex AI, and Azure OpenAI
  • CEO ViewA deliberately minimal executive snapshot, readable in about thirty seconds
  • Opportunity QueueCross-cloud triage — every detection as a costed, scored, SLA-tracked finding
  • AutopilotAutonomous optimization inside your guardrails, with three graduated trust modes
  • CI/CD Control TowerLinks pipelines, deployments, and PR risk to their cost consequences

Analyze

13 modules

Depth — where money goes, why it moved, and what it buys.

  • IntelligenceTelemetry ingestion, waste scanning, commitment negotiation, and regression attribution
  • Cost CenterSeven analytical lenses over one normalised ledger
  • ReportsExecutive, FinOps, operations, and unit-economics reporting with scheduled delivery
  • Predictive AnalyticsTwo competing forecast models, honest error metrics, and change simulation
  • Unit EconomicsCost per active user, API request, order, or inference
  • FinOps MaturityAn objective score across eight weighted dimensions, from measured state
  • Database HealthConnections, storage, latency, replication lag, and query performance
  • KubernetesNamespace, deployment, and team allocation with utilisation-based rightsizing
  • API MonitoringThe invoice's view of the API layer — including the cost of failed requests
  • Cloud PlaygroundScenario modelling for multi-cloud architecture on live provider pricing
  • Deploy & MigrationRepository-to-cloud planning with cross-cloud comparison and blueprints
  • Vendor HubVendor portfolio, contracts, renewals, risk, and workflow
  • Cloud BillingPartner and reseller invoices, discounts, payments, and disputes

Govern

8 modules

Controls — rules, gates, attribution, and evidence.

  • PoliciesRequired tags, blocked resource types, cost and risk thresholds, budget limits
  • PR Cost ReviewPrices Terraform changes against live pricing and comments before merge
  • Tag GovernanceTag policy definition, compliance scanning, and convention advisor
  • OwnershipMaps resources to owning teams, with inference for untagged resources
  • Cost AllocationChargeback and showback rules for shared infrastructure
  • ApprovalsCentral approval queue, decidable from dashboard, Slack, Teams, or Apex
  • Resource ParkingAutoStopping, off-hours parking, hibernation, and scale-to-zero
  • Audit LogsImmutable stream of every action by a user, Apex, Autopilot, or scheduled job

Security

3 modules

Estate posture — inventory, threat, and compliance.

  • InventoryLive multi-cloud asset register with scan lineage and coverage measurement
  • FinSecOpsMulti-cloud threat posture, webhook and event-bus fabric, identity controls
  • ComplianceControl-mapped findings across SOC 2, CIS, NIST, and ISO 27001

Admin

7 modules

Tenancy — users, workspaces, connections, integrations, identity.

  • OrganizationUser and access administration
  • Workspace SetupWorkspace lifecycle management
  • Identity & SSOEnterprise identity federation
  • Org AnalyticsOrganisation-level analytics
  • Cloud AccountsCloud provider connections and trust verification
  • IntegrationsSlack, Teams, Jira, Linear, source control, and event buses
  • AI Provider AccountsLLM provider connections and model routing

Developer workflows

Where these capabilities show up

Move from product capability to day-to-day workflow with GitHub, CLI, ChatOps, IDE, and event delivery integrations.

GitHub App

Org-wide PR governance

Install once and get cost comments, policy checks, and comment upserts across repositories.

GitHub Actions

Custom CI control

Run cost analysis in workflow YAML when teams need pipeline-level customization.

FinOps CLI

Local and CI estimates

Estimate Terraform plan costs locally, in CI/CD, or before opening a pull request.

VS Code extension

Inline Terraform hints

Surface estimated monthly resource cost while engineers are still editing infrastructure.

Slack and Teams

Approval workflows

Approve, reject, and route remediation or commitment decisions from collaboration tools.

Event bus

Webhooks, EventBridge, Pub/Sub

Push findings, approvals, and execution events into alerting, ticketing, and data platforms.

See every feature in action

Free trial. All 43 modules unlocked. No credit card required.