Trust, earned

Autonomy you grant one action type at a time

Every action type starts at “approve each” in every account. Promotion is offered after a clean, verified record. Nothing runs on its own until you turn automatic execution on.

It doesn’t run anything on its own until the workspace turns on automatic execution and saves a guardrail configuration.

The problem

Letting automation run everything is too much, too soon, and approving every change forever is too slow. You need a setting per action type and per account, based on what actually happened.

How it works

  1. Start at approve each

    Every action type waits for an owner or admin in every account, and each run is classified by what its post-check could actually confirm.

  2. Build a record

    Verified successes add up per account and action type over 30 days, including runs people approved. One bad signal in the window blocks promotion.

  3. Graduate or drop back

    An owner or admin promotes one level when the action type is eligible. A post-check rollback, a reverted saving or a used override moves it back automatically.

  • Approve each

    is where every action type starts, in every account

  • 10 successes

    verified in 30 days, with no bad signals: the default threshold

  • Automatic

    drop back on a post-check rollback, a reverted saving or a used override

  • Irreversible

    actions, such as deleting a volume or snapshot, don’t run without a person

Capabilities

Choose, per account and action type, when a change must wait for a person.

  1. Three levels, set where they apply

    Observe runs nothing, even with approval. Approve each waits for a person. Auto + rollback lets a reversible action run without one. Set a level for the workspace or one cloud account; the more restrictive always wins.

  2. Only verified successes count

    A run counts toward promotion only if its post-check compared the result with the intent and it matched. Successes with nothing to compare are neutral, and a failed check, a failed rollback or a reverted saving blocks promotion.

  3. Promotion is a click, demotion is automatic

    When an action type has enough verified successes and no bad signals, Settings → Autonomy offers Graduate, re-checked when you click. A post-check rollback, a saving found reverted or a used override moves it back to approve each.

  4. Irreversible actions stay with people

    Only action types with an automatic rollback, such as stopping an EC2 or RDS instance, adding tags or turning on S3 Block Public Access, can reach auto + rollback. Deleting a volume or snapshot always needs approval.

In depth

The three levels

A level is set per action type, either for the whole workspace or for one cloud account. Every action type starts at approve each, and the level is enforced at the plan stage that every change passes through.

  • Observe: nothing runs, even if a person approves. The run stops before any change and records why.
  • Approve each: an owner or admin approves in the app, in Slack or through the API. Runs nobody approved are refused.
  • Auto + rollback: a reversible action type may run without a person, and a failed post-check rolls the change back.

How levels combine

Levels combine the opposite way to safety policy: the most restrictive setting wins. A workspace level replaces the default, and an account level can lower it but never raise it.

An account doesn’t inherit a workspace-wide auto + rollback either. Without a level of its own it stays at approve each, because a record built in a sandbox account says nothing about production. If a level can’t be read, or a run’s account can’t be resolved, the run is treated as approve each.

What counts as evidence

Each finished run is classified from its stage log: for example a verified success, a success that couldn’t be verified, a block by a safety check or guardrail, a cloud error, or a rollback after a failed post-check. Only a verified success counts toward promotion, meaning the post-check had state to compare and it matched.

The record is kept per account and action type over a 30-day window, and it includes runs people approved. A single bad signal blocks promotion: a failed post-check that was rolled back, a rollback that failed, an irreversible change whose check failed, or a saving the ledger later found reverted or rolled back.

Graduating and dropping back

Settings → Autonomy lists every action type GetFinOps can run, for the workspace and for each AWS account, with its level, where that level was set, and progress toward the threshold: by default ten verified successes in 30 days with no bad signals. When an action type qualifies, Graduate raises it one level. The check runs again when you click, a recent demotion blocks it, and an account can’t graduate above the workspace’s level.

Dropping back needs no click. A post-check rollback, a saving found reverted at re-check, or a used safety override moves an action type from auto + rollback to approve each. The change is audited, you get an in-app notification, and the action type has to build a new record before it can graduate again.

Running without a person

After a scan, the plan’s safe actions are handed to the unattended lane. It can only run an action whose type is at auto + rollback for the account, and only when all of these hold:

  • The workspace is on a paid plan or an active trial.
  • The workspace has turned on agentic execution and automatic execution of safe actions, and has saved a guardrail configuration.
  • The plan marked the action safe: every pre-check passed and no plan guardrail asked for a person.
  • The workspace has fewer than ten queued, running or successful executions of that action type from the last 24 hours.
  • The safety checks and guardrails pass again when the run starts.

What it does not do

  • It doesn’t run anything on its own until the workspace turns on automatic execution and saves a guardrail configuration.
  • It doesn’t promote anything by itself. Every step up is an owner’s or admin’s decision.
  • It doesn’t let irreversible actions, such as deleting a volume or snapshot, run without a person.
  • It doesn’t let an account’s level go above the workspace’s level. Raise the workspace level first.
  • It can’t qualify every action type as safe yet. Some pre-checks aren’t measured, so stopping an EC2 instance, for example, always waits for a person today.
  • It doesn’t apply to GCP, where GetFinOps makes no changes.

FAQ

Questions

Does raising one action type remove approvals everywhere?

No. A level applies to one action type, for the workspace or for one cloud account. A workspace-wide auto + rollback doesn’t reach an account with no level of its own, and action types left at approve each still ask a person.

What makes an action type eligible to graduate?

By default, at least ten verified successes for that account and action type in the last 30 days, with no bad signals and no demotion in that window. The Graduate button checks again when you click it.

Can an admin skip the record?

Yes. An owner or admin can set a level directly; the record gates the Graduate suggestion, not the manual setting. An irreversible action type still can’t be set to auto + rollback.

Will an action at auto + rollback run on its own?

Only when the other conditions hold too. A scan must mark the action safe, the workspace must be on a paid plan or active trial, turn on automatic execution and save a guardrail configuration, and the action type must be under ten executions in 24 hours. The safety checks run again when it starts.

Try free — no credit card

Create a workspace and connect an AWS or GCP account, or book a demo first.