Unattached and orphaned storage
Storage that keeps billing after the instance or volume that needed it has gone, or that never moves to a cheaper tier.
- Unattached block and boot volumes
- Orphaned volume backups
- Buckets without lifecycle policies
Varcio is an Oracle Cloud (OCI) cost optimization tool that connects with an API signing key encrypted at rest, reads OCI’s own cost, inventory, monitoring, Cloud Advisor, Cloud Guard and Budgets data, and runs 38 OCI detectors. Ten remediation types, from stopping idle instances to deleting unattached volumes, run behind the same guardrails as every other cloud, and OCI cost sits in one ledger with the rest of your estate.
38 OCI detectors look across your tenancy for storage, compute and databases that bill without delivering value, and put a monthly cost on each one.
Oracle Cloud often arrives through a specific route — a database workload, an Oracle licensing decision, or a migration programme — and then runs beside a larger AWS, Azure or Google Cloud estate. The risk is that OCI becomes the cloud nobody reviews, with its own console, its own reports and no place in the organisation’s cost process.
Varcio brings OCI into the same process. Spend, inventory, monitoring and Oracle’s own recommendations feed 38 OCI detectors, and every finding is costed and ranked by savings, confidence and effort alongside findings from your other clouds.
Storage that keeps billing after the instance or volume that needed it has gone, or that never moves to a cheaper tier.
Capacity that is provisioned but not doing meaningful work, including instances that are stopped but still hold capacity.
Resources running on older shapes, or provisioned well above what they need.
Oracle’s own signals, read into the same ranked queue as Varcio’s detectors.
Unexpected changes in OCI spend are caught by anomaly detection, and tag governance, allocation, showback and policies apply to OCI as they do everywhere else.
23 cross-cloud detectors run on the normalised ledger, which matters when OCI is the destination or source of a migration.
Each OCI detector uses the OCI signals that answer its question. These are the sources Varcio reads from your tenancy.
The Usage API and Cost and Usage Reports from Object Storage, in FOCUS and native formats, show cost that is moving without a matching change in demand.
Resource Search shows what exists in the tenancy and what it is attached to, which is how unattached volumes and orphaned backups are found.
OCI Monitoring shows whether compute instances and databases are doing meaningful work.
Cloud Advisor recommendations are read alongside Varcio’s own detectors, and can be applied back through Cloud Advisor.
Cloud Guard problems, IAM configuration and Budgets are evaluated alongside cost, so findings carry their governance context.
OCI’s standard API signing model, encrypted key storage, OCI’s own cost and inventory services, and the same read-only-first boundary as every other cloud.
You create an API signing key for an OCI user and give Varcio the private key (PEM), its fingerprint and, if you set one, the passphrase. Varcio stores them encrypted at rest. You manage the user, its public key and the IAM policies that govern it in your tenancy, so access can be rotated or revoked on your side.
Findings, forecasts, anomaly detection, allocation, tag governance and Apex questions all run on read-only credentials with no time limit.
If you want Varcio to act, you grant write policies to the same OCI user. Varcio probes those permissions separately from the read connection, and every change still passes the guardrails below.
Governed OCI write actions cover Budgets sync, Resource Scheduler schedules, instance actions and Cloud Advisor bulk apply. Instance actions and Cloud Advisor bulk apply always require approval.
Once waste is removed, a Universal Credits commitment lowers the rate you pay for steady OCI usage.
Varcio models OCI Universal Credits scenarios from your usage, covering a monthly commit, an annual commit and a 3-year commit, each with an estimated discount range, so you can see how coverage and savings change before you talk to Oracle.
These scenarios are modelled only. Varcio does not purchase OCI commitments; the commercial agreement stays between you and Oracle.
OCI findings can be carried through to the change itself, with the same approval and audit trail as the rest of the estate.
Varcio has ten OCI remediation types, ordered the way a careful operator works: stop before delete, and reversible changes before anything that is not. Deleting an unattached volume takes a backup first and keeps it as the undo path. Deleting an orphaned volume backup cannot be undone, and Varcio says so before it runs.
Parking schedules can stop instances and scale instance pools outside working hours. Approvals can be handled in Slack or Teams, and Varcio verifies realised savings against subsequent spend rather than counting a closed ticket as a result.
These controls apply to all remediation Varcio executes, on every cloud, alongside the write permissions you grant and Varcio verifies before anything changes.
Resources carrying a protected tag are excluded from every remediation run, so a production database or a regulated workload cannot be changed by a rule that happens to match it.
Approved changes run only inside the windows you define, which keeps stops, deletions and resizes away from peak traffic, release trains and change freezes.
Before a live run, Varcio checks for step-up approval on high blast-radius changes, a rollback success floor, and a maintenance window for larger blast radius. If a gate is not met, the run drops to a dry run instead.
Any action can be previewed without making live API calls, and individual rules can be held to dry run. Per-rule action caps, a maximum number of actions per run and a monthly action budget bound how much changes at once.
Write actions requested through Apex come back as a plan that runs only after an authorised person types APPROVE, backed by a single-use token, or approves from Slack or Microsoft Teams. Autopilot runs in observe, suggest or autopilot mode. In autopilot mode it can act without a person above a confidence threshold, including deleting unattached volumes and orphaned snapshots, but resources that look production, public, critical or deletion-protected go to approval instead.
Every action records who requested it, who approved it, what changed and when, so finance, security and auditors can reconstruct any change after the fact.
Oracle provides solid native cost tooling in every OCI tenancy. Here is what each tool offers, according to Oracle documentation.
Charts and downloadable reports of cost data, filtered and grouped by compartment, tag, service, region, SKU and resource OCID, with forecasting based on past usage and up to ten saved reports.
CSV files generated daily and stored in Object Storage, useful for detailed breakdowns by SKU and resource.
Budgets scoped to compartments or tags, with alert rules on actual or forecasted spend, evaluated every 24 hours and delivered by email, with Events service integration.
Daily analysis with cost recommendations for underutilised Compute instances, unattached block and boot volumes, Object Storage buckets without lifecycle policies and overprovisioned Autonomous AI Lakehouse instances.
| Capability | OCI native tools | Varcio |
|---|---|---|
| Cost visibility | Cost Analysis grouped by compartment, tag, service and more; daily Cost and Usage Reports | OCI in one normalised ledger with AWS, Azure, Google Cloud and Kubernetes |
| Waste detection | Cloud Advisor cost recommendations with estimated savings | 38 OCI detectors on spend and inventory, plus 23 cross-cloud detectors |
| Prioritisation | Recommendations with cost savings estimates | Findings costed and ranked by savings, confidence and effort across every cloud |
| Budgets and alerts | Budgets on compartments or tags with actual and forecast alert rules | Anomaly detection, forecasting, budget and policy guardrails, alerts in Slack or Teams |
| Allocation | Compartment and tag grouping in Cost Analysis | Tag governance, cost allocation and showback applied consistently across clouds |
| Commitments | Universal Credits agreed with Oracle | Monthly, annual and 3-year Universal Credits scenarios modelled with estimated discount ranges; no purchase |
| Acting on findings | Changes made in the OCI Console, CLI or infrastructure code; Cloud Advisor can apply its own recommendations | 10 remediation types plus parking, with approval, protected tags, execution windows, rollout-safety gates and audit log |
| Pre-merge cost review | Not covered by the tools listed here | PR cost review prices Terraform changes before they merge |
Scroll sideways to see the full table.
If OCI is your only cloud, Cost Analysis, Budgets and Cloud Advisor give you visibility, alerting and a useful set of recommendations at no extra cost. Varcio matters when OCI is one part of a wider estate and you need a single cost process rather than one per provider.
Varcio brings OCI into the same ledger, ranking, allocation and governance as AWS, Azure, Google Cloud and Kubernetes, runs cross-cloud detectors across all of them, and gives FinOps, engineering and leadership one place to see and act on cost. Apex, the natural-language assistant, answers questions that span clouds.
Cost is shared work. Each team sees the same findings and ledger, framed for the decisions it owns.
Sees OCI findings in the same queue as findings from other clouds, with evidence and a recommended action, instead of checking a separate console.
Allocates OCI spend with the same tag governance and showback model as the rest of the estate, and reports on every cloud in one place.
Receives OCI anomalies and policy alerts in Slack or Teams alongside alerts from other clouds.
Gets a complete multi-cloud picture that includes Oracle Cloud, with forecasts and a ranked savings backlog.
Use Cost Analysis grouped by compartment and tag to see where spend is concentrated. Act on Cloud Advisor cost recommendations such as underutilised Compute instances, unattached block and boot volumes, and Object Storage buckets without lifecycle policies. Set budgets on compartments or tags, enforce consistent tagging, and if you run other clouds, bring OCI into the same cost process so it is reviewed with everything else.
Yes. Varcio connects to OCI with an API signing key encrypted at rest, reads the Usage API, Cost and Usage Reports, Monitoring, Resource Search, Cloud Advisor, Cloud Guard and Budgets, and runs 38 OCI detectors. OCI cost sits in the same normalised ledger as AWS, Azure, Google Cloud and Kubernetes.
Varcio stores the OCI API signing key, fingerprint and optional passphrase encrypted at rest, and the whole analytical product runs on read-only access indefinitely. You manage the associated user and policies in your tenancy. If you want Varcio to act, you grant write policies to the same user and Varcio probes those permissions separately. Instance actions and Cloud Advisor bulk apply always require approval.
Cloud Advisor analyses your tenancy daily and recommends cost, performance and availability improvements for OCI. Varcio reads those recommendations, runs its own 38 OCI detectors, adds cross-cloud detection, ranks OCI findings alongside findings from other clouds, and applies the same allocation, governance and approval workflow across your estate.
Yes. Varcio has ten OCI remediation types: stopping idle instances, deactivating unused API keys, applying governance tags, making public buckets private, enabling bucket versioning, adding bucket lifecycle policies, deleting unattached volumes, deleting orphaned volume backups, deleting orphaned network gateways and security lists, and applying Cloud Advisor recommendations. Parking schedules cover instances and instance pools. Every action runs behind the same guardrails as other clouds.
No. Varcio models Universal Credits scenarios, covering a monthly commit, an annual commit and a 3-year commit, with estimated discount ranges. The purchase itself stays between you and Oracle.
When OCI runs beside other clouds, a separate process tends to leave it unreviewed. A shared ledger lets cross-cloud detectors catch duplicated environments and redundant workloads, and lets finance allocate every cloud with one model.
Findings appear from the first scan after you connect. The free trial runs entirely on read-only access.
Connect OCI with a read-only signing key and see it in the same ledger as the rest of your clouds.