Main content
Varcio Workforce

An AI managed-service team for your cloud, on shift around the clock

Varcio Workforce is a standing team of AI agents across 24 managed-service roles: 23 you can staff, plus an AI Evaluator included free. Seats come on shift on your rota, read your cloud estate, decide whether anything needs doing and hand work up a reporting line, so only the few decisions that genuinely need a person reach you.

roles: 23 to staff, plus a free AI Evaluator
24
functions, from leadership to the service desk
7
grades, Associate (L1) to Principal (L5)
5
from, per seat-hour at current list rates
$0.15
Where Workforce fits

A team that turns up, not a tool you open

Managed service is what most FinOps teams want and few can afford, because it is priced as people. Workforce organises AI agents the way a managed-service provider organises engineers, and prices them per seat-hour.

Apex

A colleague you ask

Apex answers a question when someone types one, working across your connected clouds in plain English.

  • Starts when a person asks
  • Reads use live data
  • Every write needs explicit approval
Explore Apex
Workforce

A team that turns up

A Workforce seat comes on shift, looks at the estate, decides whether anything needs doing, and hands the work to the seat above it when it cannot finish alone.

  • Runs on a rota you set, around the clock or business hours
  • Hands off, refers and escalates like a managed-service organisation
  • One daily brief and a short list of decisions for people
Autopilot

Rules inside your guardrails

Autopilot is the separate rules-based optimiser that acts on idle and orphaned resources within the mode you choose.

  • Three modes: observe, suggest and autopilot
  • Deletes only orphaned disks, snapshots and load balancers when explicitly allowed, never in production
  • Deterministic rules rather than judgement
See platform capabilities
The org chart

24 roles, one reporting line, one place work surfaces

The Service Delivery Lead reports to you. Five practice leads and the Communications Manager report to it, and the practice teams report to their leads. The AI Evaluator sits outside the line and reviews everyone's work. Each seat shows its default grade; you can staff any role at any grade from L1 to L5, and the rate follows the grade you choose.

  • Service Leadership
  • Architecture
  • Cloud Operations
  • Reliability
  • Security & Compliance
  • Financial Operations
  • Service Desk

Select any seat to trace its escalation path and read its charter.

YouDaily brief, escalation list and approvals
L1 · AssociateReliability

NOC Analyst

First-line multi-cloud watch: notices what changed, and hands it on.

Escalation path
  1. NOC Analyst
  2. Site Reliability Engineer
  3. Incident Manager
  4. Service Delivery Lead
  5. You

Sweeps every connected provider more often than any other seat and does one job well — notice that something moved and raise it. Deliberately the cheapest grade, because first-line watch is about coverage and consistency rather than depth.

Watches
  • Spend spikes
  • New errors
  • Open incidents
  • Resource state
Produces
Watch notes: what changed on each provider this cycle
Escalates when
  • A signal crosses its threshold
  • Something appears that has no matching known issue
  • The same signal repeats across more than one provider
Cadence · risk ceiling · reports to
Looks every 15 minutes.Read. Observes only. Never changes anything.Reports to Site Reliability Engineer
The roster

Every role, by function

Seven functions mirror how a managed-services organisation is actually structured: leadership, then the technical practices, then the desk. A team holds one seat per role. Open any role for its charter, cadence, what it watches, what it hands upward and when it escalates.

Service Leadership

Owns the engagement: what the team worked on, what it found, and what needs a decision.

4 roles
L5Service Delivery LeadRuns the team and writes the one report you actually read

Reads every other seat's output at the end of each cycle, resolves disagreements between them, and publishes a single brief instead of a notification stream from every seat. Owns the escalation list: the small number of things that genuinely need a human this week.

Watches
Team output · Escalations · Service maturity
Produces
The daily brief, and the escalation list for a human
Brings to a person when
  • Anything that commits money or changes production
  • Two seats disagree and the evidence does not settle it
  • A risk stays open past the service level the team agreed to
Reports to
You
Cadence
Every 12 hours
Changes
Observes and advises. Its allowlist has no change capabilities.
Risk ceiling: Read
Observes only. Never changes anything.
L4Change & Release ManagerKeeps the approval queue moving and change inside its window

Chases approval requests before they go stale, checks that queued work falls inside an agreed execution window, and flags policies drifting out of date. In a managed service this is the person who stops a good change happening at a bad time.

Watches
Pending approvals · Execution windows · Policy drift
Produces
A change calendar and the list of approvals about to expire
Escalates when
  • An approval has sat unanswered past its window
  • A change is requested outside every agreed window
  • A policy that gates other seats has lapsed
Reports to
Service Delivery Lead
Cadence
Every 8 hours
Changes
Can propose changes within its allowlist and risk ceiling.
Risk ceiling: High
Can run low- and medium-risk changes unattended when the band allows. Also prepares high-impact work, such as commitments, release promotions and change sets, which always goes to a person.
L3AI EvaluatorChecks every other seat's work before and after it happens. Included free

Independent of the reporting line. Before a change runs unattended it screens it for security risk, grounding and scope, and holds anything short of a clean pass for a person. After each cycle it reviews what every seat concluded, escalated and proposed against the evidence that seat was actually given, and flags invented facts, off-topic work, unsafe recommendations and anything unethical. It can hold work for a person; it can never approve anything.

Watches
Unattended changes · Claims against evidence · Security and conduct
Produces
A review of the team's work: what was sound, what was held, and why
Escalates when
  • A seat recommends or proposes something that would weaken security
  • A seat states facts its evidence does not contain
  • A seat's work is unethical, deceptive or outside what it was staffed for
Reports to
Outside the reporting line (oversight)
Cadence
After every team cycle
Changes
Screens and reviews other seats’ work. Never changes anything.
Risk ceiling: Read
Observes only. Never changes anything.
L3Communications ManagerOwns the team's email: answers questions, sends updates, routes requests

Works the team's mailbox like a person would. Reads what allowed senders ask, answers from what the platform actually knows — the product, the connected clouds, what every seat is doing and what is running — and hands anything that needs work to the seat that can do it, then writes back with the outcome. Follows your rules on who it may hear from, who it may write to, who is copied and what it may discuss, and every message it sends is cleared by the AI Evaluator first.

Watches
Inbound email · Requests waiting on the team · Escalations people should hear about
Produces
Replies and updates sent, requests routed to the right seat, and what needs a person
Escalates when
  • A message asks for something no staffed seat can do
  • A message needs a decision only the customer can make
  • A sender could not be authenticated or is not allowed
Reports to
Service Delivery Lead
Cadence
Every 4 hours for its own cycle; new mail is answered within 15 minutes
Changes
Sends email under your rules. No infrastructure changes.
Risk ceiling: Read
Observes only. Never changes anything.

Architecture

Design authority. Reviews workload shape, placement and posture before cost becomes structural.

3 roles
L5Chief Cloud ArchitectDesign authority over the estate's shape and posture

Reviews the estate the way a principal architect would at a quarterly design review: is the workload in the right place, is the account structure still right, is posture drifting. Catches the decisions that make cost structural rather than incidental.

Watches
Workload placement · Account structure · Runtime posture
Produces
A design verdict on what the operations seats found
Escalates when
  • A fix requires re-architecting rather than tuning
  • Posture has drifted far enough to need a decision, not a change
  • Two operations seats propose changes that conflict
Reports to
Service Delivery Lead
Cadence
Every 12 hours
Changes
Observes and advises. Its allowlist has no change capabilities.
Risk ceiling: Read
Observes only. Never changes anything.
L4Solutions ArchitectSizes and prices workloads before they are built

Turns a proposed workload into a costed shape — instance families, storage class, container density — and compares it against what the estate already runs. The seat you ask before committing to a design, not after the bill arrives.

Watches
Proposed workloads · Migration plans · Unit cost per workload
Produces
A costed design option set for each proposed workload
Escalates when
  • The cheapest viable design still breaks the budget
  • A design needs a commitment purchase to be affordable
Reports to
Chief Cloud Architect
Cadence
Every 12 hours
Changes
Observes and advises. Its allowlist has no change capabilities.
Risk ceiling: Read
Observes only. Never changes anything.
L3Capacity PlannerProjects where growth runs out of budget or headroom

Extends today's consumption forward: which budget breaches first at the current rate, which cluster runs out of headroom, which storage curve turns into a problem next quarter. Planning work that only pays off if somebody does it before the quarter starts.

Watches
Budget trajectory · Cluster headroom · Storage growth
Produces
A forward projection of budget and headroom exhaustion
Escalates when
  • A budget is projected to breach inside the current period
  • Headroom runs out before the next planning cycle
Reports to
Chief Cloud Architect
Cadence
Once a day
Changes
Observes and advises. Its allowlist has no change capabilities.
Risk ceiling: Read
Observes only. Never changes anything.

Cloud Operations

Day-to-day estate management: compute, containers, data stores, pipelines and configuration.

6 roles
L3Database AdministratorWatches instance health, storage growth and query cost

Monitors managed database instances the way a DBA would: connection saturation, storage trajectory, slow queries and engine versions drifting out of support. Databases are usually the largest single line on a cloud bill and the least often reviewed.

Watches
Instance health · Storage growth · Slow queries
Produces
A database health note with the queries and instances to fix
Escalates when
  • An instance is saturating and needs resizing in production
  • An engine version is approaching end of support
Reports to
Chief Cloud Architect
Cadence
Every 4 hours
Changes
Can propose changes within its allowlist and risk ceiling.
Risk ceiling: High
Can run low- and medium-risk changes unattended when the band allows. Also prepares high-impact work, such as commitments, release promotions and change sets, which always goes to a person.
L3DevOps EngineerWatches pipelines and catches the change that will move the bill

Reads build and deploy history alongside cost: which pipeline is failing and why, which release changed spend, which infrastructure-as-code change introduces a resource nobody priced. Catches it at review rather than at month end.

Watches
Failed pipelines · Risky releases · IaC changes
Produces
A pipeline health note and the cost delta of each release
Escalates when
  • A release needs rolling back
  • A pipeline has failed repeatedly on the same cause
  • An IaC change adds spend beyond the agreed threshold
Reports to
Chief Cloud Architect
Cadence
Every 4 hours
Changes
Can propose changes within its allowlist and risk ceiling.
Risk ceiling: High
Can run low- and medium-risk changes unattended when the band allows. Also prepares high-impact work, such as commitments, release promotions and change sets, which always goes to a person.
L3Kubernetes Platform EngineerTracks cluster cost, density and the gap between request and use

Watches the difference between what workloads request and what they consume, which is where container platforms quietly waste money. Attributes cluster cost back to namespace and workload so the number lands on a team rather than on the cluster.

Watches
Cluster spend · Request vs usage · Node utilisation
Produces
Namespace-level cost attribution and right-sizing candidates
Escalates when
  • A cluster needs re-shaping rather than re-sizing
  • Node pressure threatens workload stability
Reports to
Chief Cloud Architect
Cadence
Every 4 hours
Changes
Can propose changes within its allowlist and risk ceiling.
Risk ceiling: Medium
Can run low- and medium-risk changes unattended, when your team’s auto-run band allows it.
L3Platform EngineerFinds idle, oversized and orphaned resources and costs the fix

Works the estate for waste: instances running at 4% CPU, volumes attached to nothing, environments awake at 3am on a Sunday. Produces a costed, reversible recommendation for each one rather than a list of resource IDs.

Watches
Idle resources · Rightsizing candidates · Parking opportunities
Produces
Costed, reversible remediation proposals
Escalates when
  • A fix touches a resource with no recorded owner
  • The saving is large enough to justify an architecture change instead
Reports to
Chief Cloud Architect
Cadence
Every 4 hours
Changes
Can propose changes within its allowlist and risk ceiling.
Risk ceiling: High
Can run low- and medium-risk changes unattended when the band allows. Also prepares high-impact work, such as commitments, release promotions and change sets, which always goes to a person.
L2Asset & Configuration ManagerKeeps the inventory honest — what exists, who owns it, how it is tagged

Maintains the record of what is actually running: reconciles scan results, finds resources with no owner and no tags, and proposes the tags that would make the rest of the estate attributable. Unglamorous, and the reason every other seat's numbers can be trusted.

Watches
Untagged resources · Ownership gaps · Scan freshness
Produces
An inventory reconciliation and the list of unattributable resources
Escalates when
  • A scan has not completed and the estate picture is stale
  • Ownership cannot be inferred and someone must assign it
Reports to
Change & Release Manager
Cadence
Every 2 hours
Changes
Can propose changes within its allowlist and risk ceiling.
Risk ceiling: Medium
Can run low- and medium-risk changes unattended, when your team’s auto-run band allows it.
L2Cloud Connectivity EngineerKeeps cloud connections and integrations alive so everyone else has data

Checks that every cloud account still authenticates, every integration still delivers, and no provider has silently stopped reporting. Every other seat's findings are worthless if a connection broke three days ago and nobody noticed.

Watches
Account connectivity · Integration health · Provider coverage
Produces
A connection health report across every provider and integration
Escalates when
  • A cloud account has stopped authenticating
  • An integration has been failing long enough to create a blind spot
Reports to
Change & Release Manager
Cadence
Every 4 hours
Changes
Can propose changes within its allowlist and risk ceiling.
Risk ceiling: Medium
Can run low- and medium-risk changes unattended, when your team’s auto-run band allows it.

Reliability

Detects, triages and eliminates. First-line monitoring through to root cause and recurrence.

4 roles
L4Incident ManagerTakes an open incident and drives it to an explanation

Owns an incident from raise to explanation: assembles the timeline, tests root-cause hypotheses against the data, and writes the account of what happened. Staffed at a senior grade because the difference between a plausible cause and the real one is worth paying for.

Watches
Open incidents · Root cause · Bill impact
Produces
An incident brief with a tested root cause
Escalates when
  • The fix needs a change to production
  • The incident crosses a service level the customer agreed
  • Root cause is architectural rather than operational
Reports to
Service Delivery Lead
Cadence
Every hour
Changes
Can propose changes within its allowlist and risk ceiling.
Risk ceiling: High
Can run low- and medium-risk changes unattended when the band allows. Also prepares high-impact work, such as commitments, release promotions and change sets, which always goes to a person.
L3Problem ManagerHunts the recurring incident nobody has permanently fixed

Looks across incidents rather than at one: which of these has happened four times, which remediation keeps being re-applied, which finding keeps reopening. Incident management restores service; this seat stops the same thing happening again.

Watches
Repeat incidents · Reopened findings · Re-applied fixes
Produces
A recurrence report naming the underlying problem
Escalates when
  • A recurring problem needs a permanent change to eliminate
  • The same remediation has been applied more than twice
Reports to
Incident Manager
Cadence
Every 4 hours
Changes
Observes and advises. Its allowlist has no change capabilities.
Risk ceiling: Low
Can run low-risk changes unattended, when your team’s auto-run band allows it.
L3Site Reliability EngineerCorrelates errors, latency and resource pressure into one picture

Joins signals that normally sit in separate tools — API error rates, database pressure, container health, release timing — and says which of them are the same incident. The seat where overnight cover genuinely earns its rate.

Watches
Error rates · Endpoint latency · Resource pressure
Produces
A correlated picture of what is degrading and why
Escalates when
  • Degradation is customer-visible
  • The cause sits outside what this seat can see
  • A rollback looks like the right answer
Reports to
Incident Manager
Cadence
Every hour
Changes
Can propose changes within its allowlist and risk ceiling.
Risk ceiling: Medium
Can run low- and medium-risk changes unattended, when your team’s auto-run band allows it.
L1NOC AnalystFirst-line multi-cloud watch: notices what changed, and hands it on

Sweeps every connected provider more often than any other seat and does one job well — notice that something moved and raise it. Deliberately the cheapest grade, because first-line watch is about coverage and consistency rather than depth.

Watches
Spend spikes · New errors · Open incidents · Resource state
Produces
Watch notes: what changed on each provider this cycle
Escalates when
  • A signal crosses its threshold
  • Something appears that has no matching known issue
  • The same signal repeats across more than one provider
Reports to
Site Reliability Engineer
Cadence
Every 15 minutes
Changes
Observes and advises. Its allowlist has no change capabilities.
Risk ceiling: Read
Observes only. Never changes anything.

Security & Compliance

Exposure, posture drift, policy adherence and the evidence an auditor will ask for.

3 roles
L4Cloud Security EngineerWatches exposure and posture drift across the estate

Reviews what is reachable from the internet, which permissions are broader than the workload needs, and where posture has drifted since the last check. Drafts remediation that runs only inside the change rules you set; anything beyond them goes to a person.

Watches
Public exposure · Posture drift · IaC risk
Produces
An exposure report ranked by what an attacker would reach first
Escalates when
  • Something is publicly reachable that should not be
  • A fix would interrupt a running service
  • Exposure persists past the agreed remediation window
Reports to
Service Delivery Lead
Cadence
Every 8 hours
Changes
Can propose changes within its allowlist and risk ceiling.
Risk ceiling: Medium
Can run low- and medium-risk changes unattended, when your team’s auto-run band allows it.
L3Compliance & GRC AnalystAssembles the evidence an auditor will ask for, continuously

Tracks control coverage against the frameworks in scope, checks that policies are actually enforced rather than merely written, and keeps the evidence trail current. Turns audit preparation from a quarter into a page.

Watches
Control coverage · Policy enforcement · Evidence freshness
Produces
A control-coverage position with the evidence attached
Escalates when
  • A control in scope has no evidence behind it
  • A policy is written but demonstrably not enforced
Reports to
Cloud Security Engineer
Cadence
Once a day
Changes
Can propose changes within its allowlist and risk ceiling.
Risk ceiling: Medium
Can run low- and medium-risk changes unattended, when your team’s auto-run band allows it.
L3Identity & Access ManagerWatches who can do what, and whether that is still right

Reviews organisation membership, single sign-on configuration and who holds approval authority. The access review an auditor asks for once a quarter, run continuously instead of assembled in a panic.

Watches
Member accounts · SSO configuration · Approval authority
Produces
An access review: who holds what, and what looks stale
Escalates when
  • An account holds authority beyond its role
  • Single sign-on enforcement has weakened
  • An approver has left but still holds authority
Reports to
Cloud Security Engineer
Cadence
Once a day
Changes
Observes and advises. Its allowlist has no change capabilities.
Risk ceiling: Low
Can run low-risk changes unattended, when your team’s auto-run band allows it.

Financial Operations

Rate and commitment strategy, budgets, allocation and the numbers leadership reports on.

3 roles
L4Cloud EconomistOwns rate strategy: commitments, coverage and what to buy next

Works the rate side of the bill rather than the usage side — commitment coverage, expiry cliffs, whether a three-year term is defensible given the trajectory. Prepares purchases and takes every one to a person; committing a customer's money stays a human decision.

Watches
Commitment coverage · Expiring terms · Discount opportunities
Produces
A rate strategy with the commitments worth buying and why
Escalates when
  • A commitment purchase is worth making
  • Coverage is expiring inside the notice period
Reports to
Service Delivery Lead
Cadence
Every 8 hours
Changes
Can propose changes within its allowlist and risk ceiling.
Risk ceiling: High
Can run low- and medium-risk changes unattended when the band allows. Also prepares high-impact work, such as commitments, release promotions and change sets, which always goes to a person.
L3Infrastructure Research AnalystReads the outside world and reports what applies to this estate

Builds a picture of how comparable organisations run and pay for infrastructure, and keeps it current. Reports only what connects to something you actually run, with the source attached; a finding that cannot be tied back to your estate is discarded rather than padded into a report. External research stays off until your workspace opts in.

Watches
Comparable estates · Published architectures · Optimisation practice
Produces
Sourced findings about your market, joined to your infrastructure
Escalates when
  • Public practice suggests the current architecture is an outlier
  • A vendor or approach the estate depends on looks to be losing support
Reports to
Cloud Economist
Cadence
Every 4 hours
Changes
Observes and advises. Its allowlist has no change capabilities.
Risk ceiling: Read
Observes only. Never changes anything.
L2FinOps AnalystReports the numbers: spend, budgets, showback and unit cost

Produces the recurring financial picture — where spend landed, which budgets are tracking to breach, what each team owes on showback, and what a unit of the business costs to serve. The reporting seat every finance team asks for first.

Watches
Daily spend · Budget burn · Cost per unit
Produces
The spend, budget and showback position for the period
Escalates when
  • A budget crosses its alert threshold
  • Unit cost moves outside its normal band
Reports to
Cloud Economist
Cadence
Every 2 hours
Changes
Can propose changes within its allowlist and risk ceiling.
Risk ceiling: Medium
Can run low- and medium-risk changes unattended, when your team’s auto-run band allows it.

Service Desk

Inbound requests: triage, known-error matching and drafted first responses.

1 role
L1Service Desk EngineerTriages inbound tickets and drafts the first reply

Reads new tickets, matches them against known errors and open findings, and drafts a first response for a human to send. Highest volume, lowest grade — which is exactly how a service desk is staffed.

Watches
New tickets · Known errors · Response backlog
Produces
Triaged tickets with a drafted first response
Escalates when
  • A ticket matches no known error
  • A ticket reports something the monitoring seats have not raised
  • The backlog is ageing past its response target
Reports to
Change & Release Manager
Cadence
Every 30 minutes
Changes
Can propose changes within its allowlist and risk ceiling.
Risk ceiling: Low
Can run low-risk changes unattended, when your team’s auto-run band allows it.
How a shift runs

From coming on shift to a decision on your desk

Every cycle follows the same loop. Seats do the looking and the judging; people keep the decisions.

  1. Come on shift

    When its rota starts, a seat checks whether it is due to look, based on its role’s cadence and how the estate has behaved.

  2. Read the estate

    It reads your connected cloud accounts through its role’s capability allowlist, which covers what the job needs and nothing more.

  3. Judge

    It decides whether anything needs doing, and every conclusion carries the reads that support it. Where its allowlist includes change capabilities, it can propose a change within its risk ceiling.

  4. Hand off, refer or escalate

    It finishes what it can, refers a finding to the seat that holds the remedy, or hands it up to its manager. Juniors run first, so managers see this cycle’s hand-offs.

  5. The Lead publishes

    The Service Delivery Lead reads every seat’s output, resolves disagreements and publishes one daily brief plus an escalation list.

  6. People decide

    You clear Needs you and decide proposed changes. After the cycle, the AI Evaluator checks every seat’s work against the evidence it was given.

An escalation, seat by seat

A NOC Analyst notices a signal and hands it to the seat above it, and each seat adds what it can before passing it on. If an escalation reaches the team's paging floor, critical by default, the team also pages your on-call through your existing PagerDuty and Slack integrations: at most 4 pages an hour, deduplicated, and respecting any quiet hours you set.

  1. L1NOC AnalystNotices a signal cross its threshold and raises it.
  2. L3Site Reliability EngineerCorrelates it with errors, latency and resource pressure.
  3. L4Incident ManagerTests root-cause hypotheses and writes the incident brief.
  4. L5Service Delivery LeadDecides whether a human needs to see it.
  5. YouYour teamReads the brief, clears Needs you, decides changes.

Referrals go to the remedy

A finding with a known remedy goes to the staffed seat that can act on it, wherever it sits on the chart. An unencrypted volume goes to the Cloud Security Engineer, not up a release manager’s chain.

Partial teams are normal

Buy one or two seats and the reporting line resolves to the seats you staffed. The most senior seat reports to you, and writes the brief if no Service Delivery Lead is on the team.

One place work surfaces

Every escalation eventually reaches the top of your team, so unfinished work always lands in one list instead of scattering across notification streams.

Grades and rotas

Five grades, from first-line watch to principal judgement

Higher grades think harder; lower grades reason more simply and cost less. How often a seat looks is set by its role: grade baselines run from every 30 minutes at L1 to every 12 hours at L5, and 9 roles set their own, so cadence ranges from 15 minutes to 24 hours.

Workforce seat grades with tagline, best use, trade-off, baseline cadence and current list rates
GradeWhat it doesBest forTrade-offBaseline cadencePer seat-hourBusiness hours / monthAround the clock / month
L1AssociateWatches, reports, and follows a runbookHigh-volume watching where the answer is usually the obvious one.Reports what it sees. It will miss a subtle cause and escalate more often.30 min$0.15$33$112
L2AnalystConnects a few signals and explains themRoutine analysis on estates that behave predictably.Handles the common cases well; unusual ones still go up the chain.2 h$0.31$67$224
L3EngineerDiagnoses across systems and proposes the fixThe default. Most seats do their best work here.Balanced. Deep enough for real diagnosis without paying for the top tier.4 h$0.62$134$448
L4SeniorWeighs competing explanations before committingProduction estates where a wrong call is expensive.Costs more per hour and thinks for longer on each cycle.8 h$1.23$267$896
L5PrincipalHandles the ambiguous and the first-of-its-kindIncidents with no precedent, and decisions that set direction.The most expensive tier. Worth it where judgement matters more than volume.12 h$1.85$401$1,344

Current list rates, rounded to the cent. A seat's rate is fixed when it is added, so later price changes never reprice a running seat. Monthly figures use 217 hours for business hours and 728 hours for around the clock, rounded to the dollar, before quiet-cycle discounts and metered model usage.

The 9 roles that set their own cadence
Roles whose cadence differs from their grade baseline
RoleDefault gradeLooks
NOC AnalystL1every 15 minutes
Service Desk EngineerL1every 30 minutes
Incident ManagerL4every hour
Site Reliability EngineerL3every hour
Cloud Connectivity EngineerL2every 4 hours
Solutions ArchitectL4every 12 hours
Capacity PlannerL3once a day
Compliance & GRC AnalystL3once a day
Identity & Access ManagerL3once a day

Rotas

Around the clock

24×7 cover, 728 hours a month.

Business hours

08:00–18:00, Monday to Friday: 217 hours a month, roughly 30% of continuous cover.

Custom rota

One start–end window within a day, repeated on the days you choose, with a timezone per seat. Overnight windows are not supported.

Adaptive cadence

Every cycle, a seat decides when to look next, inside a band around its role's cadence: a team that raises a blocker once and waits, rather than forty times overnight.

A seat can look up to four times more often than its cadence, or up to three times less often.

Critical finding

The next look comes at a quarter of the cadence, and never sooner than 5 minutes.

High-severity finding

The next look comes at half the cadence.

Blocked

A seat waiting on you or a colleague backs off to 3× its cadence, unless it has just escalated, and is due immediately when the blocker changes.

Planned follow-up

A seat that plans a follow-up read comes back at half its cadence. It can also ask to look sooner or later, inside the band.

Quiet estate

From the third quiet cycle in a row, the interval grows 1.5× with each quiet cycle, up to 3× the cadence.

Monthly cap approaching

From 80% of the cap, seats with nothing above low severity slow steadily: normal cadence at 80%, 3× slower at 100%.

Guardrails

Agents do the looking. People keep the authority.

Workforce runs in a supervised stage. Out of the box no team can change anything, and widening what a seat can do is never the thing that lets a high-impact change run without a person.

Capability allowlists

Each role works through an allowlist scoped to its job. For 14 roles it includes change capabilities, and a seat can only propose changes inside its allowlist and risk ceiling.

Change access off by default

No team can run a change until you turn change access on for it. Until then, seats can still propose changes for a person to decide.

Every change waits for a person

Even with change access on, the auto-run band starts at none. Changes run unattended only once you raise it to low or medium. There is no high band.

High and critical need a person

Whatever the seat’s grade or ceiling. Anything above a seat’s ceiling becomes an approval request, which a person can still approve.

Quality hold

A seat whose recent cycles score poorly keeps working, but every change it proposes goes to a person until its scores recover.

Screened by the AI Evaluator

Hard rules hold anything that opens a resource to the internet, disables encryption, carries a credential or touches a resource the seat never saw.

Windows and leases

Where you have set execution windows, changes wait for the next opening, approved ones included. Only one seat holds change authority over a resource at a time.

A complete audit trail

Changes lists every change proposed, approved and run. Activity records every cycle, including the ones that found nothing.

Risk ceilings

Every role carries one of four ceilings, and the roster shows each seat's. A ceiling only matters once you have turned change access on and raised the auto-run band; anything above it becomes an approval request for a person.

Read
Observes only. Never changes anything.
8 roles
Low
Can run low-risk changes unattended, when your team’s auto-run band allows it.
3 roles
Medium
Can run low- and medium-risk changes unattended, when your team’s auto-run band allows it.
7 roles
High
Can run low- and medium-risk changes unattended when the band allows. Also prepares high-impact work, such as commitments, release promotions and change sets, which always goes to a person.
6 roles

Before a change runs unattended

A change runs without a person only if it clears every check below, in this order. Fail any one and it waits for a person or for its window. A team runs at most 3 changes per cycle.

The checks an unattended change must pass, in order
StepCheckWhat it takes to pass
1AllowlistThe change is one the seat’s role is staffed to make.
2Change accessYou have turned change access on for this team.
3Risk ceilingThe change’s risk is within the seat’s ceiling. Otherwise it becomes an approval request.
4Quality holdThe seat is not on a quality hold.
5Capability approval ruleThe capability itself does not always require a person to approve it.
6Auto-run bandThe change’s risk is within the band you set: none, low or medium.
7Prompt-injection checkIf this cycle’s evidence contained text addressed to the agent, auto-run is withheld and a person decides.
8AI Evaluator screenAnything short of a clean pass is held for a person. If the evaluator cannot run, medium risk and above waits.
9Execution windowWhere you have configured windows, the change waits for the next opening.
10Resource leaseThe seat holds the resource’s lease: 5 minutes by default, 15 at most, one seat at a time.

When a change needs a person

A proposed change becomes an ordinary approval request in the platform's approval queue, listed in Changes. You decide it in the dashboard, or by email reply when email approvals are turned on. If the proposing seat's manager seat is staffed, it reviews the proposal first. Senior seats never approve a change into execution.

What each senior review verdict does
Senior review verdictWhat happens
EndorseThe manager seat’s advice is attached to the request. A person still decides.
RejectThe proposal is closed without troubling a person. Nothing runs.
Needs a personThe proposal goes to the approval queue as it would have anyway.
Running the service

Measured like a managed service, improving on the record

Response is measured against targets, hard calls are deliberated, and every claim of progress rests on evidence.

Response targets

Escalations are measured against targets you can adjust per team: critical 15 minutes, high 60 minutes, medium 8 hours, low 24 hours. Rota coverage is measured too.

Deliberation

For high-severity findings the chairing seat consults up to 3 colleagues, who answer from what they read this cycle. Dissent is kept on the record.

Learning

Your helpful or unhelpful feedback shapes a seat’s next cycle, and seats leave each other notes. Skill cards come from real outcomes, and past cases are recalled with outcomes marked unknown until confirmed.

Weekly report

Written every Monday for the week just ended. Every number is computed from real runs, changes and spend before any prose is written.

Outcome contracts

Outcomes are held to a share of days, with service credits and quarterly business reviews. Savings count as verified only once evidence confirms them.

Research

External research is off until your workspace opts in. The research seat ties each finding to your estate, and every note cites its sources.

The Communications Manager's mailbox rules

The Communications Manager works the team's mailbox: it answers questions, sends updates and routes requests to the seat that can do the work, inside rules you set.

Rules the Communications Manager follows
RuleHow it works
Inbound mailMust be addressed to the team’s alias. Blocked senders, and senders that fail SPF, DKIM or DMARC checks, are quarantined.
Who it answersOnly senders on the allowed list.
Who it writes toOnly people on the recipients list, whether addressed or copied.
Limits10 replies per thread and 100 sends a day.
SendingSend mode starts at approval, so a person clears each message. Every outbound message is screened by the AI Evaluator.
AuthorityAn email never executes anything, except through email approvals. Those are off by default and limited to named decision makers who are active members with approval rights and pass sender authentication. The risk cap defaults to medium and never allows critical, and requests expire after 7 days.
What you see

Every view a service owner needs, and nothing hidden

Workforce shows its work: what each seat is doing now, what it said, what it proposed and what it cost.

Roster

Staff a managed-services team of agents.

Teams

Staff a team, set rotas, and see the cost before launch.

Live

What each seat is doing, this minute.

Structure

Who reports to whom, and every open conversation.

Conversations

What each seat reported, asked and agreed.

Skills

Each seat’s track record.

Research

What the research seat established, and the pages it read.

Daily brief

The one report your team lead writes.

Weekly report

The week’s work, written every Monday from real numbers.

Spend

Seat hours by role and AI usage, month to date.

Balance

Workforce funds, and how long they last.

Changes

Every change proposed, approved and run.

Communications

The team’s mailbox and its rules.

Activity

Every cycle your seats have run.

Missions

Outcomes measured every cycle.

Outcome contracts

Outcomes held to a share of days, with service credits and business reviews.

Needs you

What the team is waiting on you for.

Escalations

Hand-offs waiting to be picked up, worst first.

How it works

The reporting chain, and when it reaches you.

Pricing model

Managed-service coverage, priced per seat-hour

Workforce is included on the Pro, Business and Enterprise plans, and the 14-day trial runs on Business. Seats bill per seat-hour while on rota, from a funded Workforce balance.

How billing works

  • Each cycle bills the on-rota minutes since the seat’s previous cycle, up to four cadences, at the rate fixed on the seat when it was added.
  • Off-rota time bills nothing, quiet cycles bill at 25% and failed cycles bill $0.
  • AI model usage is metered at 1.5× provider cost.
  • Workforce has its own funded balance, separate from Apex AI credits. A team can’t launch with no funds, pauses when funds run out and restarts automatically when they’re added.
  • Every team needs a monthly cap above $0, and launch is blocked if the projected rota cost exceeds it.
  • The AI Evaluator is included free on every team with a paid seat, and its running costs are never billed.
Compare Varcio platform plans

Worked examples

Monthly cost of example Workforce seats at current list rates
SeatRotaHoursRate≈ / month
Platform EngineerL3 EngineerBusiness hours217$0.62$134
NOC AnalystL1 AssociateAround the clock728$0.15$112
Cloud EconomistL4 SeniorBusiness hours217$1.23$267

Current list rates, before quiet-cycle discounts and metered model usage. Business hours are 10 h × 5 days × 52/12 weeks ≈ 217 h; around the clock is 24 h × 7 days × 52/12 weeks ≈ 728 h. The AI Evaluator adds nothing to these figures.

Getting started

A seven-step path to a team you trust

Build trust the way you would with a new managed-service provider: small scope first, evidence before authority.

  1. Staff one or two seats

    Start on your most acute coverage gap, not a full team.

  2. Fund and cap the team

    Add Workforce funds, review the projected monthly cost and set a cap above it.

  3. Watch Live

    Follow what each seat does through its first few shifts.

  4. Clear Needs you daily

    It is the single list of what the team is waiting on you for.

  5. Approve deliberately

    Read the supporting evidence on each change before you decide it.

  6. Define Missions

    Once the team is reliable, give it outcomes to work toward and re-measure.

  7. Reconcile monthly

    Compare seat-hour spend against delivered value in Spend.

FAQ

Questions about Varcio Workforce

What is an AI agent workforce?

Varcio Workforce is a standing team of AI agent seats, each staffed into a managed-service role such as NOC Analyst, Site Reliability Engineer or Cloud Economist. Seats come on shift on a rota you set, read your connected cloud estate through a capability allowlist scoped to their role, decide whether anything needs doing, and hand work up a reporting line that ends at a Service Delivery Lead, who brings the small number of real decisions to people.

How is Workforce different from a managed service provider?

It is organised the way a managed service provider is: named roles, a reporting line, escalation, a daily brief and a change queue. The difference is the commercial model and the authority model. You staff only the seats you need, pay per seat-hour while they are on rota rather than per person, and no seat can ever approve a change into execution. If you want people running your estate, Varcio Cloud Services offers a human managed service that works alongside Workforce.

Can the agents change my infrastructure on their own?

Only inside limits you set, and never for high-impact work. Change access is off for every team until you turn it on, and even then every change waits for a person until you raise the team's auto-run band to low or medium; there is no high band. A seat can only propose changes inside its role's allowlist and risk ceiling, anything above its ceiling becomes an approval request for a person, and high- and critical-risk changes always need a person. Before a change runs unattended it must also clear the seat's quality hold, the capability's own approval rule, a prompt-injection check, the AI Evaluator's screen, any execution window you have configured and a resource lease, so only one seat holds change authority over a resource at a time. A team runs at most 3 changes per cycle, and every one is listed in Changes.

Do I need to staff all 24 roles?

No. The catalogue has 24 roles: 23 you can staff, plus the AI Evaluator, which is added free to every team with a paid seat and cannot be removed. Most teams start with one or two seats on their most acute coverage gap. You can staff any role at any grade from L1 to L5, and the rate follows the grade you choose. A team holds one seat per role, a workspace can run up to 10 teams, and the reporting line resolves to the seats you staffed: the most senior seat reports to you, and writes the daily brief if there is no Service Delivery Lead.

Which Varcio plans include Workforce?

Workforce is included on the Pro, Business and Enterprise plans, but not on Explorer. The 14-day free trial runs on Business. Seats draw on a funded Workforce balance, separate from Apex AI credits, so a team cannot launch until funds are added.

How are Workforce seats billed?

Each cycle bills the on-rota minutes since the seat's previous cycle, up to four cadences, at the rate fixed on the seat when it was added. Current list rates run from $0.15 per seat-hour at L1 to $1.85 at L5, and a later price change never reprices a running seat. Off-rota time bills nothing, quiet cycles bill at 25%, failed cycles bill $0, and AI model usage is metered at 1.5 times provider cost. Workforce draws on its own funded balance: a team pauses when funds run out and restarts automatically when they are added. The AI Evaluator is included free.

What happens when a team reaches its monthly cap?

Every team needs a monthly cap above $0, and launch is blocked if the projected rota cost exceeds it. Before each run, spend already billed this month is checked against the cap. From 80% of the cap, seats with nothing above low severity slow down steadily, from their normal cadence at 80% to three times slower at 100%. At the cap the team pauses and restarts on the 1st of the next month. Pausing at the cap is on by default; if you turn it off, seats simply stop running until the month rolls over.

How is Workforce different from Apex and Autopilot?

Apex answers a question when someone types one: it is a colleague you ask. A Workforce seat comes on shift, looks at the estate, decides whether anything needs doing, and hands the work to the seat above it when it cannot finish alone: it is a team that turns up. Autopilot is the separate rules-based optimiser with three modes (observe, suggest and autopilot). It deletes only orphaned disks, snapshots and load balancers when explicitly allowed, and never in production environments.

Who approves changes made by Workforce seats?

People. A proposed change becomes an ordinary approval request in the platform's approval queue, listed in Changes, and is decided in the dashboard, or by email reply when email approvals are turned on. If a junior seat's manager seat is staffed, that seat reviews the proposal first: it can endorse it (its advice is attached and a person still decides), reject it (it is closed without troubling a person) or say it needs a person. No seat of any grade can approve a change into execution, and each proposal carries the reads that support it.

Can Workforce page my on-call team?

Yes. Each team has a paging policy. Escalations at or above its severity floor, critical by default, page through the PagerDuty and Slack integrations your workspace already has: at most 4 pages an hour, deduplicated, and respecting any quiet hours you set. Nothing pages until an alert channel is connected.

Which clouds does Workforce cover?

Workforce seats read AWS, Microsoft Azure, Google Cloud and Oracle Cloud Infrastructure (OCI) through the cloud accounts you connect to Varcio, and Kubernetes cost through the Kubernetes integration. A seat can only use what its role's allowlist and your connections allow.

What does the AI Evaluator do?

The AI Evaluator is an oversight seat outside the reporting line. It is added free to every team with a paid seat, cannot be removed, and its running costs are never billed. Before a change runs unattended it screens it: hard rules hold anything that opens a resource to the internet, disables encryption, carries a credential or touches a resource the seat never saw, and anything short of a clean pass is held for a person. If the evaluator cannot run, unattended changes at medium risk and above wait for a person. After each cycle it reviews the team's runs against the evidence each seat was given; flags lower a seat's quality score, and serious ones are escalated to you. It can hold work, but never approve it.

Staff your first seat

Start with one or two seats on your biggest coverage gap, fund the team, set a monthly cap, and follow the first shifts in Live.