Core Capabilities

19 Capabilities.
One Platform.

Everything you need to see, understand, prevent, find, and fix cloud cost problems — with AI intelligence and enterprise governance built in.

Total Spend
Live
$12,800 ↑8%
AWS: 65%Azure: 20%GCP: 15%
Apex AI Agent
"What’s driving the 12% increase?"
Anomaly Detected:
EC2 instances in us-east-1 (Team: Analytics) increased by $4,200 starting Tuesday.
Waste Detection
2 High
14 Unattached EBS Volumes
Save $214/moAuto-Fix →
19Operational Capabilities
18+Waste Detectors
8+AI Operations
4Coverage Domains

One Dataset Behind Every Capability

Each capability below reads from the same normalized, reconciled spend data — which is why a finding, a forecast, and a PR check never disagree.

How FinOps Co-Pilot turns cloud billing data into governed actionCloud accounts connect through provider-native trust models into an ingestion and normalization layer, then into the FinOps Co-Pilot engine, which produces pull request cost checks, waste findings, forecasts, and approval-gated remediation.SOURCESINGESTENGINEOUTCOMESAWSAssumeRoleAzureService PrincipalGCPSA JWTOCINative authKubernetesHelm agentIngestionnormalize · tagreconcile · verifyFinOps Co-PilotDetect wasteForecast spendEnforce policyApex AI agentPR cost checksbefore mergeWaste findings18+ detectorsForecasts90-day horizonChatOps approvalsSlack / TeamsEvery write action is approval-gated and written to an immutable audit log
Provider-native trust models feed ingestion, which feeds the engine behind every outcome.

Cluster Spend, Split by Who Actually Used It

A cluster bill is one line item from the cloud provider. FinOps Co-Pilot breaks it back down to namespaces, deployments, and the teams that own them.

Kubernetes cluster cost split by namespaceCluster spend attributed across five namespaces with monthly cost and idle percentage, showing machine learning training and internal tools carrying the highest idle capacity.NAMESPACEMONTHLYIDLEpayments$4,0208%data-platform$3,08022%web-frontend$2,1306%ml-training$1,65041%internal-tools$95035%ml-training and internal-tools show 35%+ idle capacity — rightsizing here recovers about $910/month
Idle percentage per namespace turns an unattributable cluster cost into a specific, ownable rightsizing task.

1. Multi-Cloud Spend Visibility

Connect your cloud accounts in minutes and see consolidated spend data across AWS, Azure, GCP, and Kubernetes.

Daily and monthly spend trends with anomaly highlighting, budget posture tracking, service-level breakdowns, ingestion health, and 30-day variance summaries in one shared workspace.

< 15 minSetup time per cloud
LiveConnection verification
30-dayProjection window
AWSIAM AssumeRole, Cost Explorer, CloudWatch, 8+ detectors
AzureService Principal, Resource Graph, Azure Monitor, 5+ detectors
GCPService Account JWT, Asset Inventory, Monitoring, 5+ detectors
OCINative credential flow, spend visibility, inventory scanning
KubernetesIn-cluster agent, namespace attribution, rightsizing + idle workloads

2. Apex AI Agent

A live operations assistant, not a chatbot. Ask questions, get answers, and create governed actions in plain English.

Guided capabilities across observability, governance, operations, and knowledge. Read operations execute immediately, write actions require explicit APPROVE confirmation, and high-impact actions route through full approval workflows.

Guided AI Operations

  • Observability: Executive Briefing, Spend Summary, Top Services, Anomaly Scan
  • Governance: Open Findings, Active Policies, Budget Status, Pending Approvals
  • Configuration: Account Verification, Integration Status, Coverage Posture
  • Operations: Load Demo Spend, Request Remediation, Verify Accounts, Commitment Negotiator
  • Knowledge: Web Research with citations from public sources
  • Read actions execute immediately; writes require APPROVE and single-use execution tokens
  • High-impact actions go through full approval workflows before execution
  • 4 Instruction Profiles: Balanced, Concise, Guided, Executive
Explore All AI Capabilities →
"What are our top 5 AWS services by cost this month?"
EC2 ($5,420 ↑8%), RDS ($2,880 ↑6%), S3 ($1,340 →), Lambda ($210 ↓2%), NAT ($95 ↑12%). Total: $10,945. Anomaly: NAT Gateway ↑12%.
"Negotiate our RI portfolio for next quarter with 3-year Savings Plans"
Analyzing 90 days on-demand... Recommendation: 1-Year Compute SP. Current: $6,420/mo → Committed: $5,120/mo. Savings: $1,300/mo (20%). Break-even: 3.4 months. Type APPROVE to create an approval-gated purchase run.

3. Pre-Merge Cost Analysis (PR Cost Diff)

Catch cost surprises before they reach production by analyzing Terraform changes from GitHub PRs.

Extracts Terraform resource changes, prices them with live cloud pricing APIs, evaluates active policies, calculates budget impact, and posts a single evolving PR review comment.

PR opened → Resources extracted → Live pricing → Policies checked → Budget impact → Comment posted
  • Estimated monthly cost change (delta)
  • Risk assessment score and contributing factors
  • Policy compliance result (pass / advisory / block)
  • Budget impact projection
  • Tagging compliance check
  • Confidence score for pricing estimates

4. Waste Detection Engine

18+ automated detectors across all clouds and Kubernetes that identify structural savings.

Every opportunity includes estimated monthly savings, confidence score, effort score, risk assessment, recommended action, and a composite priority score so teams know what to fix first.

AWS Coverage8+
Unused EIPs, unattached EBS, EC2 and RDS underutilization, stale AMIs, and network waste
Azure Coverage5+
Unattached disks, unused public IPs, idle SQL databases, and zero-workload App Service plans
GCP Coverage5+
Unattached disks, unused static IPs, idle Compute Engine, idle Cloud SQL, and stale snapshots
KubernetesAgent
CPU and memory mismatch, idle pods, DaemonSet overhead, orphaned Persistent Volumes
Finding Anatomy
Estimated Savings$214/month
Confidence0.94
Effort LevelLow / Medium / High
RiskWhat could go wrong if you act
Priority ScoreSavings × confidence ÷ effort

5. Automated Remediation

Don't just detect waste — fix it. Execute approved actions across all three major clouds.

Every remediation requires explicit human approval. Protected-tag safety, dry-run mode, credential isolation, and immutable audit trails make the workflow safe to operate in production.

Protected Tags
Tag critical resources to exclude them from remediation
Human Approval
Every action requires explicit confirmation
Dry-Run Mode
Preview the full action without making live API calls
Audit Trail
Full before/after state captured for every action
Rate Limiting
Max 10 actions per minute per workspace
AWSDelete unattached EBS volumes
AWSStop underutilized EC2 instances
AWSRelease unused Elastic IPs
AzureDeallocate idle VMs
GCPStop idle Compute Engine instances

6. AI Commitment Negotiator

Automate commitment analysis and purchasing across AWS, Azure, and GCP with integrated approval gates.

Reviews historical on-demand usage, recommends commitment strategies with projected savings and break-even periods, supports dry-run simulation, and executes purchases on approval.

15–30%Typical Savings
3–5 monthsBreak-even Period
TrackedLifecycle Events
AWS1-Year RI, 3-Year Savings Plan (partial or all upfront)
Azure1-Year Reserved Instance or 1-Year Savings Plan
GCP1-Year or 3-Year Committed Use Discounts
1Analyze Usage
2Recommend Strategy
3Simulate Purchase
4Approve
5Execute
6Track

7. Predictive Cost Forecasting

Two competing ML models run in parallel — the system automatically selects the more accurate one.

Daily predicted spend for 7, 14, 30, or 90-day horizons with confidence intervals, MAPE and RMSE transparency, and automatic fallback if data is too sparse.

  • Confidence intervals (80% and 95%)
  • Daily forecasts for 7, 14, 30, or 90-day horizons
  • MAPE and RMSE accuracy reporting
  • Budget breach probability calculation
  • Automatic model selection with fallback to linear extrapolation
Prophet (Meta)
Best for: Seasonality, holidays, trend changesMethod: Additive regression
SARIMAX
Best for: Steady-state, consistent patternsMethod: Classical time series

8. Policy Engine & Governance

Define and enforce cost policies across your organization — from advisory warnings to hard blocks.

Tag requirements, risk thresholds, resource restrictions, and budget guardrails are enforced consistently across pull requests, findings triage, approvals, and audits.

Example Rules

BlockingBlock PRs adding GPU instances to staging
TagRequire cost-center tag on all EC2 instances
AdvisoryWarn if monthly forecast exceeds $15K
BlockingBlock new resources without team owner tag
AdvisoryCreates findings but does not block the workflow
BlockingPrevents non-compliant infrastructure from progressing
Tag RequirementsEnforce mandatory tags such as team, service, env, and owner
Budget GuardrailsSoft limits warn; hard limits block when thresholds are crossed

9. ChatOps Integration

Bring cost operations directly into Slack and Microsoft Teams.

List pending approvals, approve or reject with inline buttons, and verify actor authorization — all from your team's communication channels.

  • Actor authorization verification
  • HMAC signature verification on inbound webhooks
  • Timestamp replay protection
  • Inline approve/reject buttons for fast review
  • Weekly digests and anomaly notifications
/finops pendingList pending approvals
/finops approve <id>Approve a request
/finops reject <id>Reject with optional note
/finops helpShow available commands

10. Cloud Control Tower 360

See the operational health of every connected account and provider in one posture view.

Control Tower 360 scores account trust posture, ingestion SLO posture, reconciliation posture, and detector coverage so teams know when their data and workflows are actually ready for decision-making.

0–100Maturity score
3 statesHealthy / Warning / Critical
PrioritizedNext actions
TPTrust PostureWhich accounts are verified, stale, or failing verification
ISIngestion SLOHow fresh and reliable provider data is right now
REReconciliationWhether connected accounts match coverage and inventory expectations
DCDetector CoverageHow deep active scanning is per provider and environment

11. Kubernetes Cost Attribution

Turn opaque cluster bills into namespace, deployment, and team-level accountability.

The native Kubernetes agent ingests in-cluster metrics, maps costs to owners, and generates rightsizing and idle workload recommendations for teams running containerized platforms.

AGAgentLightweight Helm-deployed collector running inside the cluster
ATAttributionNamespace, deployment, and label-based cost allocation snapshots
OPOptimizationCPU and memory drift, idle pods, and orphaned PV detection
OWOwnershipTeam mapping from labels and annotations for chargeback clarity
  • Namespace and deployment-level cost attribution
  • Team-mapped allocation using Kubernetes labels and annotations
  • Rightsizing recommendations from request-vs-actual-usage drift
  • Idle pod identification for sustained zero-request workloads
  • Orphaned Persistent Volume detection for unused storage costs

12. FinOps Maturity Score

"Are we actually good at this, or just busy?" A single 0–100 number leadership understands instantly, with a concrete action plan attached.

Scored across eight real, data-driven dimensions and mapped to the industry-known Crawl, Walk, Run framework, with a prioritized roadmap of what to fix next — not a vague maturity survey.

0–100Composite maturity score
8Scored dimensions
Crawl → Walk → RunIndustry framework
  • Tagging compliance and coverage
  • Commitment coverage (Reserved Instances, Savings Plans)
  • Waste elimination rate
  • Budget guardrail coverage
  • Forecasting readiness and accuracy
  • Cost allocation completeness
  • Alerting and anomaly response
  • Spend trend health

13. Apex Cost Incidents

Think PagerDuty, but for cost spikes — with root cause, ownership, and an SLA.

When a cost spike happens, Apex runs a real investigation and opens an incident with a primary hypothesis, an evidence timeline, and a confidence rating, then assigns it to an owner with a tracked SLA — a full incident-response workflow, but for cost instead of uptime.

  • Primary hypothesis generated from real spend data
  • Evidence timeline showing exactly what changed
  • Confidence rating on the root-cause finding
  • Owner assignment with a tracked SLA
  • Routes to PagerDuty or Opsgenie like any other incident

14. Cloud Inventory & Security Posture

You are not just buying a cost tool — you get a live security posture scan on top, at no extra integration effort.

A live, cross-cloud resource scan across AWS, Azure, GCP, and OCI that flags encryption status and open, sensitive network ports, layered on top of the same connection you already set up for cost visibility.

  • Live cross-cloud resource inventory
  • Encryption-at-rest status per resource
  • Open and sensitive network port detection
  • No extra integration effort beyond your existing cost connection

15. Savings Tracker

"What did FinOps actually save us?" — answered with a provable, audited number, not a spreadsheet built the night before a board meeting.

Tracks realized savings against every opportunity identified, shows your realization rate and an ROI multiple comparing what you have saved to what the platform costs, and exports straight to CSV or PDF for a board deck.

TrackedRealized vs. identified savings
ROI multipleSavings vs. platform cost
CSV / PDFBoard-ready export

16. Autopilot & Auto-Stopping

Automation with a seatbelt — it will not touch production without your say-so, by design, not by promise.

A three-mode rule engine with hardcoded safety gates that refuse to touch production-tagged, publicly exposed, or critical-risk resources, plus a monthly budget cap so automation can never overspend. Scheduling can park and wake non-production resources on a calendar automatically, with dry-run on by default.

  • Hardcoded gates protect production, public-facing, and critical-risk resources
  • Monthly budget cap so automation can never overspend
  • Calendar-based scheduling parks and wakes non-prod resources automatically
  • Dry-run on by default
1Observe
2Suggest
3Autopilot

17. Tag Governance & Ownership

"Who owns this?" gets answered for every resource — with the exact rule to write, based on your real data.

An advisor scans your live inventory and recommends tagging policies based on what it actually finds, scores compliance by team, and lets you define inference rules that bulk-assign ownership in one sweep.

  • Tagging policy recommendations based on real inventory scans
  • Compliance scoring by team
  • Inference rules: tag match, naming pattern, account default
  • Bulk ownership assignment in one sweep

18. Workspaces & Organization Analytics

Full data segregation where you need it, full visibility where you want it — both, not a trade-off.

Segment data into isolated workspaces, each with its own connected cloud accounts, then roll everything up into one cross-workspace analytics view — spend trends, risk posture, and per-workspace optimization scorecards.

  • Isolated workspaces per business unit, environment, or client
  • Each workspace has its own connected cloud accounts
  • Cross-workspace roll-up for leadership
  • Per-workspace optimization scorecards

19. Reports Studio & Shared Dashboards

Send your CFO a live link right now — no login needed, and you control exactly what they see.

Persona-driven reports for CFO, CTO, Engineering, or FinOps audiences, exportable on demand — plus a shareable dashboard link: a public, tokenized, redactable snapshot you control down to which numbers and team names are visible, fully revocable and audit-logged.

  • Persona-driven reports: CFO, CTO, Engineering, FinOps
  • Tokenized, redactable shareable dashboard links
  • No login required for the recipient
  • Fully revocable and audit-logged

Where These Capabilities Show Up

Move from product capability to day-to-day workflow with GitHub, CLI, ChatOps, IDE, and event delivery integrations.

GitHub App
Org-wide PR governance
Install once and get cost comments, policy checks, and comment upserts across repositories.
GitHub Actions
Custom CI control
Run cost analysis in workflow YAML when teams need pipeline-level customization.
FinOps CLI
Local and CI estimates
Estimate Terraform plan costs locally, in CI/CD, or before opening a pull request.
VS Code Extension
Inline Terraform hints
Surface estimated monthly resource cost while engineers are still editing infrastructure.
Slack & Teams
Approval workflows
Approve, reject, and route remediation or commitment decisions from collaboration tools.
Event Bus
Webhooks, EventBridge, Pub/Sub
Push findings, approvals, and execution events into alerting, ticketing, and data platforms.

See Every Feature In Action

Free trial. All 19 capabilities unlocked. No credit card required.