Tag Governance
Tag policy definition and enforcement across cloud resources, with compliance scanning and an advisor that codifies your existing conventions.
At a glance
| Route | /tag-governance (/tag-policies also resolves) |
| Group | Govern |
| Page permission | tag_policies |
What it is
Definition and enforcement of tag policies across cloud resources, with compliance scanning, an advisor that proposes policies from existing tag usage, and per-policy scan results.
Who it is for
Platform teams establishing tagging standards, and FinOps practitioners for whom tagging compliance is the foundation everything else rests on.
How it works
A tag policy declares which tags are required, on which resources, with what permitted values. Compliance scanning evaluates live resources against those policies, producing both an overall compliance percentage and the specific non-compliant resources.
The advisor codifies rather than imposes
The advisor analyses tags already in use and proposes policies that codify existing good practice — rather than imposing a scheme nobody follows.
This is consistently the fastest route to real compliance.
Features
- Tag policy creation, editing, and deletion
- Required-tag definition with permitted value constraints
- Workspace-wide compliance scanning and per-policy scanning
- Latest scan results with overall compliance percentage
- Tag advisor proposing policies from observed tag usage
- Non-compliant resource identification for remediation
- Integration with PR Cost Review so tag requirements are enforced pre-merge
- "Draft with Apex" policy drafting
How to use it
Run the advisor before authoring anything
Codifying the conventions already in use achieves compliance far faster than imposing a new scheme.
Define the minimum viable required tag set
Owner, environment, and cost centre are usually sufficient to unlock allocation.
Longer lists reduce compliance. Every additional required tag is another reason for a team to route around the policy.
Remediate the largest non-compliant resources first
Compliance by resource count and by spend are very different numbers — and the second one is the one that matters.
Enforce pre-merge through PR Cost Review
So newly created resources are compliant by construction and the problem stops growing.
Use Ownership inference sweeps for the existing estate
To attribute resources that will never be retrospectively tagged. See Ownership.
Why it matters
Tagging compliance is the highest-weighted FinOps maturity dimension at 20% — and for good reason. Allocation, chargeback, unit economics, and ownership all depend on it.
Combining three things is what makes tagging tractable rather than a permanent aspiration:
An advisor that codifies existing practice
Rather than imposing a scheme from outside.
Scanning that measures reality
Rather than assuming the policy is followed.
Pre-merge enforcement
So new non-compliance stops being created.
Connects to
- Enforced through PR Cost Review and Policies
- Feeds Cost Allocation, Ownership, and Unit Economics
- The highest-weighted FinOps Maturity dimension