Getting Started
From a fresh account to your first verified saving — the shortest sensible path through the platform.
This page is the fast route. It assumes nothing except that you have a cloud account and permission to create a read-only role in it.
Read-only first is the recommended posture
You can run the entire analytical product indefinitely with read-only credentials. Execution access is a separate, later, deliberate decision. Nothing on this page requires granting Varcio permission to change anything in your cloud.
The path
Step by step
Connect a cloud account
Go to Cloud Accounts and read the platform identity panel first — it tells you the identity your role must trust and the External ID to put in its trust policy. Create the read-only role in your provider, then register the connection.
Full detail, per provider: Connecting your cloud.
Run the permission preflight
Hit Verify. The preflight reports precisely which permissions are missing rather than failing opaquely at scan time. Resolve anything it flags before moving on — a partially permissioned connection produces confidently wrong numbers later.
Confirm data is landing
Open Overview. The ingestion panel shows run counts, record counts, timing, and errors for every connected provider. You are looking for a recent successful run.
A spend figure is only as trustworthy as the freshness of the data behind it. If a provider is missing or errored here, fix that before reading anything else in the product.
Configure scan regions
Back in Cloud Accounts, restrict scanning to the regions you actually use. Scanning every region wastes time and API quota; scanning too few creates blind spots you will not notice.
Run your first scan
Open Opportunity Queue and trigger a scan, or wait for the scheduled one. The detector registry runs against your live inventory, ingested telemetry, and the normalised ledger.
Every result carries an estimated monthly saving, a confidence score, an effort score, a risk assessment, and a recommended action.
Triage the queue
Sort by composite priority and work top-down — the ranking already accounts for savings, confidence, and effort, so you do not need to do that arithmetic yourself.
Filter to the automatable remediation class for the fastest wins.
Fix something, safely
Route an automatable opportunity to Optimization. Set the execution policy to approval-first. Run it in dry run mode first — this simulates the entire action without calling your provider. Then execute.
Come back and prove it
After a full billing cycle, return to Optimization and read realised savings against identified savings. That delta is the number to report upward.
What good looks like after a week
All accounts connected
Not a representative sample. Partial connection produces confidently wrong totals — the most damaging failure mode in cost tooling.
Ingestion green daily
Every provider showing a recent successful run on Overview.
A scan you trust
You have spot-checked a few findings against your own dashboards and the numbers hold up.
One saving realised
Small and low-risk. The point is to complete the loop once, end to end, before scaling up.
Where to go from here
The first 90 days
A staged rollout plan — what to turn on when, and in what order to earn trust.
Understand the lifecycle
The nine stages every piece of data moves through, and where each module sits.
Ask Apex instead
If you would rather ask questions in plain English than learn the dashboard, start here.
Set up guardrails
Policies prevent expensive changes rather than reporting them after the fact.
Welcome
Varcio FinOps Copilot is a closed-loop cloud cost operations platform — it finds waste, prices it, routes it through approval, fixes it, and proves the money was saved.
Connecting Your Cloud
How each provider connects, what credentials are used, how they are protected, and why read and execution access are kept separate.