Governance is the layer almost nobody reaches.
Four layers take a FinOps programme from a chart to an enforced policy. Each one names what it actually contains.
01 Surface
- 1.01 Cost Explorer by owner, pool, service, region, account and day
- 1.02 Interactive geographic Cost Map
- 1.03 Resource inventory across 12 first-class resource types
- 1.04 Kubernetes cost and utilisation by namespace, node and service
- 1.05 Reserved Instance and Savings Plan coverage analysis
- 1.06 Inter-region data transfer and traffic expense breakdown
2 more in Visibility
- 1.07 Native FOCUS support — the FinOps open cost and usage specification
- 1.08 Raw billing export to external BI, plus scheduled email reporting
02 Cut
- 2.01 Abandoned instances, images, load balancers, S3 buckets and Kinesis streams
- 2.02 Obsolete images, IPs, snapshots and snapshot chains
- 2.03 Instance rightsizing and underutilised RDS detection
- 2.04 Instances stopped but not deallocated, and volumes long unattached
- 2.05 Instance generation upgrade and cross-region migration opportunities
- 2.06 Reserved Instance and Savings Plan purchase opportunities
4 more in Optimization
- 2.07 Short-living instances flagged as spot and preemptible candidates
- 2.08 Kubernetes rightsizing and object-storage duplicate finder
- 2.09 VM power schedules for automated start and stop
- 2.10 Per-check thresholds, pool exclusions and account skips
03 Allocate
- 3.01 Cost pools typed as budget, business unit, team, project, CI/CD or asset
- 3.02 Assignment rules with nine condition types for automatic ownership
- 3.03 Virtual tagging computed independently of cloud-native tags
- 3.04 Shareable environments with booking, SSH keys and CI/CD webhooks
- 3.05 Slack bot for pool alerts, TTL management and expense tracking
- 3.06 Three built-in roles across five permission groups
1 more in Management
- 3.07 Thirty-plus notification templates with custom SMTP and branding
04 Bedrock
- 4.01 Expense anomaly detection against a rolling daily average
- 4.02 Expiring and recurring budget policies
- 4.03 Resource count anomaly detection and resource quota policies
- 4.04 Tag compliance: required tags, prohibited tags and correlation rules
- 4.05 Resource TTL with automatic lifecycle enforcement
- 4.06 Total and daily expense limits per resource or pool
3 more in Governance
- 4.07 Constraint violation history and detected-constraints tracking
- 4.08 Security signals: inactive IAM users, unused console access, open security groups
- 4.09 Pool-based showback and chargeback with forecast-aware overspend states
Thirty-four named capabilities across the four layers. The same four layers
govern ITAM, SAM, SaaS and AI on the same platform, so five asset classes run
on one model.