Varcio FinOps Copilot

Tag Governance

Tag policy definition and enforcement across cloud resources, with compliance scanning and an advisor that codifies your existing conventions.

At a glance

Route/tag-governance (/tag-policies also resolves)
GroupGovern
Page permissiontag_policies

What it is

Definition and enforcement of tag policies across cloud resources, with compliance scanning, an advisor that proposes policies from existing tag usage, and per-policy scan results.

Who it is for

Platform teams establishing tagging standards, and FinOps practitioners for whom tagging compliance is the foundation everything else rests on.

How it works

A tag policy declares which tags are required, on which resources, with what permitted values. Compliance scanning evaluates live resources against those policies, producing both an overall compliance percentage and the specific non-compliant resources.

The advisor codifies rather than imposes

The advisor analyses tags already in use and proposes policies that codify existing good practice — rather than imposing a scheme nobody follows.

This is consistently the fastest route to real compliance.

Features

  • Tag policy creation, editing, and deletion
  • Required-tag definition with permitted value constraints
  • Workspace-wide compliance scanning and per-policy scanning
  • Latest scan results with overall compliance percentage
  • Tag advisor proposing policies from observed tag usage
  • Non-compliant resource identification for remediation
  • Integration with PR Cost Review so tag requirements are enforced pre-merge
  • "Draft with Apex" policy drafting

How to use it

Run the advisor before authoring anything

Codifying the conventions already in use achieves compliance far faster than imposing a new scheme.

Define the minimum viable required tag set

Owner, environment, and cost centre are usually sufficient to unlock allocation.

Longer lists reduce compliance. Every additional required tag is another reason for a team to route around the policy.

Remediate the largest non-compliant resources first

Compliance by resource count and by spend are very different numbers — and the second one is the one that matters.

Enforce pre-merge through PR Cost Review

So newly created resources are compliant by construction and the problem stops growing.

Use Ownership inference sweeps for the existing estate

To attribute resources that will never be retrospectively tagged. See Ownership.

Why it matters

Tagging compliance is the highest-weighted FinOps maturity dimension at 20% — and for good reason. Allocation, chargeback, unit economics, and ownership all depend on it.

Combining three things is what makes tagging tractable rather than a permanent aspiration:

An advisor that codifies existing practice

Rather than imposing a scheme from outside.

Scanning that measures reality

Rather than assuming the policy is followed.

Pre-merge enforcement

So new non-compliance stops being created.

Connects to

On this page