AWS cost remediation for engineering teams

Turn AWS waste into reviewed fixes.

OpsTiller will connect cloud-cost findings to their owners, route safe approvals, and prepare narrow Terraform pull requests—so savings can move from backlog to production.

No spam. Just product updates and an invitation when we’re ready.

Exploring a design partnership?Book a founder call →

A workflow, not another list

From signal to pull request.

Explore how a future OpsTiller workflow could turn an unused load balancer signal into an evidence-backed, owner-approved change.

Remediation workflow Workflow OT-0142

Evidence

Unused load balancer detected

Thirty days with no requests or healthy targets support this finding.

Requests0
Healthy targets0
Lookback30 days
1 / 5

The missing middle

Finding waste is the easy part.

Most recommendations stop exactly where engineering work begins: proving the signal, finding the owner, changing code, managing risk, and checking the result.

Today’s backlog

  • 01 Generic recommendation
  • 02 Unknown service owner
  • 03 Screenshot in a ticket
  • 04 Savings never verified

With OpsTiller

  • 01 Evidence and confidence
  • 02 Terraform ownership match
  • 03 Approval-gated draft PR
  • 04 Observed savings window

How it would work

Guardrails at every step.

A deliberate path from observation to action, built to fit existing engineering controls.

01

Detect

Combine billing, utilization, tags, and account context into a defensible finding.

02

Verify

Recheck evidence and match the live resource to its owner and Terraform source.

03

Remediate

Route an approval and prepare a narrow draft pull request—never merge or apply it.

04

Measure

Compare the accepted opportunity with observed billing data after deployment.

Prompt to policy

Describe the outcome. Review every rule.

Natural language could become a validated, versioned workflow—not arbitrary production code.

“Find internal load balancers with no requests or healthy targets for 30 days. Exclude protected resources and require platform approval.”
unused-internal-alb.yaml
scope:
  environments: [non-production]
  excludeTags:
    cost-remediation: protected
detector:
  type: idle_resource
  lookbackDays: 30
  thresholds:
    requestCountMaximum: 0
    healthyTargetCount: 0
action: terraform_pull_request
approval:
  required: true

Safety is the product

Designed for earned trust.

OpsTiller starts with constrained access and explicit control—not an autonomous agent with production credentials.

01

Read-only first

Discovery would begin with temporary credentials from a customer-deployed, read-only AWS role.

02

Approval is explicit

Every proposed mutation would bind an approver to a specific preview and immutable workflow version.

03

Terraform stays authoritative

Owned resources would change through draft pull requests. OpsTiller would never merge or apply them.

04

Stale findings stop

Evidence would be revalidated immediately before a proposed action proceeds.

05

Actions are allowlisted

Direct API actions, if introduced, would use narrow adapters with declared permissions and preconditions.

06

Every outcome is auditable

Findings, decisions, workflow versions, and verification status would retain a clear history.

A note from the founder

Help us build the part that actually ships.

Cloud teams rarely need one more dashboard telling them what they already suspect. They need a trustworthy way to move from opportunity to owned, reviewed work.

We’re speaking with platform and infrastructure leaders about the last optimization they tried to ship: where it stalled, who had to approve it, and what proof made the change safe.

Book a 25-minute conversation →

FAQ

Questions, answered plainly.

Is OpsTiller available today?+

Not yet. OpsTiller is in product discovery. We’re inviting a small group of engineering teams to shape a read-only alpha and validate its remediation workflows.

Will OpsTiller make production changes?+

Not autonomously. Terraform-owned resources would be changed through draft pull requests, with explicit human approval and your existing CI controls.

What access would the alpha require?+

The proposed alpha would use a customer-deployed read-only AWS role and a GitHub App. Remediation permissions would be separate and optional later.

How is this different from another cost dashboard?+

The product is being designed around the work after detection: evidence, ownership, approvals, reviewable changes, and verification.

Who is it for?+

AWS-heavy SaaS teams using GitHub and Terraform, especially platform, infrastructure, DevOps, and FinOps leaders responsible for cloud outcomes.

Early access

Make cost optimization
an engineering workflow.

Join the waitlist for product updates and an invitation to the read-only alpha.

No spam. Just product updates and an invitation when we’re ready.