Meet Apex

Meet Apex

Your AI-powered cloud cost agent. Ask questions in plain English, get instant answers, and execute guided cloud cost operations directly from your data.

💡Spend Intelligence
Analyze
"Why did EC2 jump 15%?"
New ASG in us-east-1 launched 12 m5.2xlarge instances.
View Resources →
Auto-Remediation
Execute
"Clean up unattached volumes"
Found 7 volumes. Requesting approval to delete (Save $214/mo).
Approve & Delete →
🤝Commitment Negotiator
Model
"Model 3-yr Compute SP"
Analyzed 90 days. Recommend $5k/mo commit. Break-even: 3.5 mos.
Create Purchase Plan →
8+AI Capabilities
5Safety Layers
4Instruction Profiles
Multi-StepPipeline Support

See It In Action

Four real conversation flows — from simple queries to multi-step pipelines and commitment purchases.

Apex AI Agent
You
How much are we spending this month?
AI
Your 30-day spend shows $14,250 across 3 AWS accounts.
Projected monthly: $16,400. Budget utilization: 75% of $22,000.
Top drivers: EC2 ($5,420), RDS ($2,880), S3 ($1,340).
No anomalies. 2 open high-severity findings.
You
Show me those high-severity findings
AI
2 findings match severity=high:
1. Underutilized RDS (db.r5.xlarge, 12% CPU) — $620/mo savings
2. 7 unattached EBS volumes — $214/mo savings
Recommended: Request auto-remediation for both.

Everything You Can Do

Organized into five categories — from read-only queries to approval-gated write actions.

👁️

Observability

4 capabilities
Executive Briefing
Unified FinOps briefing across spend, risk, approvals, and operational posture
"Give me an executive FinOps briefing"
Spend Summary
Total spend trends, projected 30-day cost, and budget posture
"How much are we spending this month?"
Top Services
Services contributing the highest spend in the selected window
"What are our top 5 AWS services by cost?"
Anomaly Scan
Identifies unusual spend spikes against baseline behavior
"Any cost anomalies this week?"
🛡️

Governance

5 capabilities
Open Findings
Active policy and budget findings with severity and actions
"Show open findings"
Policy Guardrails
Active policies and enforcement modes (advisory vs. blocking)
"What enforcement rules do we have?"
Budget Status
Budget guardrail configuration and projected utilization
"Are we above budget thresholds?"
Pending Approvals
Approval queue across budget, remediation, and agent workflows
"What actions are waiting for approval?"
Control Tower 360
Account trust posture, ingestion freshness, reconciliation, and detector coverage
"Show our operational posture"
⚙️

Configuration

2 capabilities
Connected Accounts
Connected cloud accounts, verification status, and re-verification posture
"Show connected cloud accounts"
Integrations Status
GitHub, ChatOps, Kubernetes, and event delivery posture
"Is auto-remediation enabled?"

Operations

6 capabilities
Load Demo Spend
Medium
Ingest sample data to explore without real accounts
"Load demo spend data for 30 days"
Resolve Finding
Medium
Close an open finding by ID or most recent
"Resolve the latest finding"
Approve Latest
High
Approve newest pending approval (filtered by type)
"Approve latest auto-remediation"
Request Remediation
Medium
Create approval request to remediate a finding
"Request auto-remediation for latest high finding"
Verify Connected Account
Medium
Trigger verification for a connected cloud account
"Verify the latest connected account"
Commitment Negotiator
High
Model strategies and create approval-gated purchase runs
"Negotiate our RI portfolio for next quarter"
🧠

Knowledge

1 capability
Web Research
Search public sources for pricing, best practices, and trends — with citations
"Research latest AWS Graviton pricing trends"

Four Steps, Every Time

01💬

You Type a Message

Natural language — questions, action requests, multi-step instructions, or contextual follow-ups.

02🧠

AI Plans a Response

Identifies intent, extracts parameters, checks permissions, and builds an execution plan.

03👁️

You Review the Plan

See capability, parameters, risk level, and action mode. Read actions run instantly; writes need APPROVE.

04📊

Results Delivered

Structured responses with summaries, data tables, recommendations, and links to dashboards.

Adapts to Your Style

Four instruction profiles control how the AI responds — from terse data tables to guided explanations.

Five Layers of Protection

The AI can never run arbitrary commands, access other workspaces, or execute without your explicit confirmation.

🔒

Capability Allow-List

Only registered capabilities execute. No arbitrary commands, scripts, or API calls.

👤

Workspace & Identity Scoping

Every action is bound to your workspace and user identity. Zero cross-tenant access.

🎟️

Single-Use Tokens

Write actions generate a unique JTI token. Once used, it cannot be replayed.

Explicit Approval

All write actions require APPROVE. The system shows exactly what will happen first.

Approval Workflows

High-impact actions go through full approval. An approver must review before execution.

Execution Rules That Never Change:
Act outside your workspace
Reuse a write token
Make changes without APPROVE
Skip approval workflows for high-risk actions
Expose cloud credentials in responses

Available on Every Plan

Core AI capabilities are free. Advanced features unlock with Pro and above.

FeatureExplorerProBusinessEnterprise
AI Queries10/dayUnlimitedUnlimitedUnlimited
Read Capabilities (13)
Write Capabilities (6)
Multi-Step Pipelines
Commitment Negotiator
Web Research
Knowledge Base
Instruction ProfilesDefaultAllAllAll + Custom
History Retention7 days90 days365 daysUnlimited

Apex FAQ

Can the AI access my cloud credentials?

No. It uses the same secure connection layer as the rest of FinOps Co-Pilot. Credentials are never exposed in the conversation interface.

What if I APPROVE a write action by accident?

Write tokens are single-use. If the action succeeds, it runs once and only once. High-risk actions also require approval before execution.

Can I use it from Slack or Teams?

Approval actions are available via ChatOps (/finops approve, /finops reject). Full conversational access from Slack/Teams is on the roadmap.

How accurate is the spend data?

Apex queries the same underlying data as every dashboard. If ingestion is up to date, responses match what you see everywhere else.

Can I restrict who uses Apex?

Yes. It respects page and action permissions. Users without access won't see it in navigation, and can't execute restricted actions.

Is my conversation data used for AI training?

No. Conversations are stored in your workspace database only. They are not sent to any external training pipeline.

Try Apex

Free trial. Guided workflows unlocked. No credit card required.