Govern
The controls — the rules the estate must obey, the gates changes must pass, the attribution that makes cost someone's responsibility, and the evidence trail.
The Govern group contains the controls. These modules define the rules the estate must obey, the gates that changes must pass, the attribution that makes cost someone's responsibility, and the evidence trail that proves all of it happened.
Dashboards report. Policies prevent.
The difference in cost terms is substantial: preventing a costly resource from being created is always cheaper than detecting and removing it after it has been running.
How the controls compose
The eight modules
Prevention
Policies
The guardrail engine — required tags, blocked resource types, cost and risk thresholds, budget limits. Advisory findings or hard blocks.
PR Cost Review
Pre-merge cost analysis. Prices Terraform changes against live pricing and comments on the pull request before merge.
Tag Governance
Tag policy definition and enforcement, with compliance scanning and an advisor that codifies your existing conventions.
Attribution
Ownership
The map from cloud resources to owning teams and services, with automated inference sweeps for untagged resources.
Cost Allocation
Chargeback and showback rules that distribute shared infrastructure cost to the teams consuming it.
Gating and evidence
Approvals
The central approval queue for every cost action, decidable from the dashboard, Slack, Teams, or Apex.
Resource Parking
Scheduled shutdown — AutoStopping, off-hours parking, hibernation, and scale-to-zero in one control plane.
Audit Logs
The immutable control-plane activity stream. Every action by a user, Apex, Autopilot, or a scheduled job.
The recommended order
Attribution comes before enforcement
Author normalization rules and establish tagging and ownership before turning on blocking policies. Policies evaluated against inconsistent dimensions produce false positives, and a policy that cries wolf gets disabled by the first team it inconveniences.
The staged path is in The first 90 days.
FinOps Maturity
An objective score across eight weighted dimensions, computed from measured workspace state rather than a questionnaire, with a roadmap ranked by points gained.
Policies
The guardrail engine — required tags, blocked resource types, cost and risk thresholds, and budget limits, enforced as advisory findings or hard blocks.