Ask what else a saving moves — the retention it shortens, the region it crosses, the replica it removes — and hold the change for the platform owner who answers for the estate.
A lifecycle rule expires objects, and Zubulake IV calls that a routine a hold must suspend.
02
A retention is cut, and GDPR Art. 5(1)(e) reads progress where the record-keeping floors read breach.
Reason
03
A log pipeline carries records owed five years and records owed three, and one rule cannot honour both.
04
A region is changed for price, and GDPR Art. 44 reads the same workload as a transfer.
05
A replica is removed, and DORA Art. 12(4) reads that idle node as a redundant ICT capacity.
Decide
06
A storage class is migrated, and 17 CFR 240.17a-4(f)(2)(i) is the method a firm named to the SEC.
07
A deletion runs on a timer, and a court has reached FRCP 37(e)(2) on facts like those.
Out
08
A saving is booked, and no CFR section anywhere required the company to find it.
09
Execute write actions only inside the approval boundaries agreed during implementation.
→Product statement
Costing, duty-naming and the record belong to the agent. The action belongs to a named platform owner, who approves the change and answers for what it moved.
Example workflow
One saving, resource to action
AgentHuman
1Resource signal receivedBilling exports, usage telemetry, tagging inventory or a lifecycle policy
2Duties assembledThe retention floors, the residency rules, the capacity commitments and the owner who holds them
3Action proposedThe resource, the action, the duties it touches and confidence
4Controls appliedRetention checks, residency checks, redundancy and hold checks and confidence threshold
No human action required
Stages 1 to 4 run unaided, and nothing in the estate changes at any of them — the agent is costing, and the owner lane opens at the confidence gate.
5DecisionSplits at the confidence gate
No regulated axis touched
Goes to the named owner to approve.
Anything that moves one
Adds a records and resilience read first.
Owner approval
The action is held with the resource, the duties it touches and the confidence.
Approve · Exempt resource · Send to records review
Approved — by the named owner▼
6Cloud and inventory records updatedOnly where write access and change policy allow it
7Outcome evaluatedDuty coverage, hold conflicts, owner exemptions and what the change actually moved
Exemptions
Each owner exemption is counted in the evaluation.
What should not run autonomously
Human approval stays in control
Outside the boundary — human approval required8 items
Shortening a retention period on a regulated log.
Moving a workload into another jurisdiction.
Removing capacity a resilience commitment rests on.
Deleting data a litigation hold may reach.
Automation boundaryAgent acts unaided
✓Cost each proposed action against the live bill.
✓Name the retention, residency or redundancy duty an action touches.
✓Stop at the edge of a regulated axis and leave the change there.
✓Flag the duties a proposed saving would quietly move.
Nothing changes in the estate except by a named owner, inside the agreed boundaries.
Migrating records off a write-once storage tier.
Deciding a resource is genuinely unused.
Signing an infrastructure change for an auditor.
Changes to cost rules or automation thresholds.
Example output
One cost action, annotated
The KPI sibling finds a number that moved; this one moves the number, and moving it changes the architecture.
Cost-action output · single resourceIllustrative example
Resource
Recorded as
Action
Evidence of record
Confidence
Held for
Audit log bucket, primary region
Stamped with the duties it touches
Shorten retention
Retention register, 3 August 2026
Held unapplied
The named owner, by name
As receivedTaken from the billing export and the retention register recorded against it, and it claims nothing beyond them.
What the record holdsThe retention floorRegion and residencyLive legal holds
Why no action hereShortening a retention period is a judgement a named owner makes.
ActionApproveExempt resourceSend to records review
What the score decidesBelow the configured threshold an action gets a records read before the owner sees it.
Value
Where AI adds value
The same four claims, placed at the point in the workflow where each one applies.
Where the value landsValue 01 – 04
Each cost actionFrom the resource it touches
03Duty check
Which rules reach a bill
HIPAA 164.306(b)(2)(iii) and GDPR Art. 32(1) both admit cost into the test — as one factor inside a documented risk assessment, and the agent supplies the term, not the assessment.
01Approved path
One number, many duties
Nothing in 15 U.S.C. 7262 requires change control, and the ticket exists because an auditor asks for it, not because Congress did.
02Human review
What was checked, and not found
A full-text search of the Code of Federal Regulations returns no section for cloud cost, cloud spend, cost optimization, right-sizing or information technology general controls, while cloud computing returns hundreds, and no regulator supervises a FinOps function.
04Build an evidence trail
The saving, the resource it came from and the owner who approved it stay together.
Integrations
Typical integrations
Five system groups connect to the same agent. Which of them are in scope is decided in discovery.
Billing and cost dataAWS CUR · Azure Cost Management FOCUS billing exports and APIs
Usage and telemetryMetrics · logs · traces Idle, standby and burst signals
Storage and retention policyObject stores · archive tiers Lifecycle rules and retention locks
Agent
Cloud cost optimisation
Reads the bill Costs the action Holds for the owner
Change and approvalTerraform · ServiceNow · Jira Change tickets and approval records
Integration availability depends on the client's existing systems and API access.
Agent controls
Six meters between the model and the estate
Six meters on one board, the last the finest. What is counted is drawn in the map below.
L6 · Outermost — last line of defenceInward → L1 · closest to the model
L6Rollback / safe modeRecommend without acting when evaluation or production signals degrade.Roll back
L5Version monitoringTrack model, prompt, cost-rule and duty-register changes, and note the version each action ran under.Track
L4TraceabilityRecord the resource, the action, the duties named against it and the owner who approved.Record
L3Owner approvalHold the action for a named platform owner; the hold governs release, not whether the saving is safe, and a deletion approved in error cannot be reviewed back.Gate
L2Duty guardrailsTest each action against the retention, residency and redundancy register in code; a match stops it, and a duty nobody wrote into that register is not what this catches.Restrict
L1Confidence thresholdsRoute a low-confidence or duty-touching action to a records read before the owner sees it.Require review
Model coreAction proposed — the resource, the saving, the duties it touches and confidence
L1 – L2Test whether an action may stand
L3Leaves the approval to a named owner
L4 – L5Keep the saving and the resource behind it
L6Recommends without acting when signals degrade
How Nestack evaluates it
Evaluate the whole cost decision — not only the saving that comes out.
Coverage runs the whole depth of the workflow, and every layer is cut by slice.
Surface — the change that reaches the estate
Depth of coverage ▼
E1Final-output evaluationDid the action record the duties it was actually weighed against?
E2Step-level evaluationDid the agent read the right resource, the live holds and the current duty register?
E3Tool evaluationDid it read and write the correct account and the correct resource?
E4Confidence calibrationDo low-confidence actions actually attract more owner exemptions?
E5Slice evaluationHow does performance change across specific resource classes?
E6Business outcomeHow many actions needed an exemption before the owner approved?
Floor — the estate the company actually runs
Failure modes
Where each failure originates in the agent
Seven failure modes, set where each one first becomes visible.
Agent lifecycleDirection of processing →
01 · Retrieval1 mode
RX-03
Stale duty read
The register read is not the one now in force.
Stage gathersThe bill, the telemetry, the holds and the duties
02 · Reasoning2 modes
RX-04
Duty left out of the costing
An action is priced with a duty missing.
RX-06
Retired floor read as live
A superseded retention rule is worked as current.
Stage proposesThe resource, the action and the duties named
03 · Tool / write2 modes
RX-02
Thin saving passed forward
An action moves on without the records read.
RX-05
Action lands on the wrong resource
The change hits another account or bucket.
Stage writesOnly where write access and approval policy allow it
04 · Output1 mode
RX-01
Applied, no duty weighed
The change is live with no duty read behind it.
Stage returnsThe change that reaches the estate and the bill
05 · Change / Version1 mode
RX-07
Silent duty drift
A floor changes while the stored rule keeps the old one.
Stage tracksModel, prompt, cost rules and duty registers
Sev-1 · an action taken outside the boundarySev-2 · a regulated axis moves unrecordedSev-3 · signals degrade, action is withheld
An account-level retention figure reads clean while log and audit retention absorbs most of the exemptions and conflicts. Nestack reports the exemption rate by resource class, not only in total.
Slice performance — reported separately, not only in aggregateIllustrative example
Slice
Failure rate
Lift
Lift vs. threshold
Status
Log and audit retention
6.9%
3.7×
Review
Cross-region workloads
4.9%
2.6×
Review
Standby and replica capacity
3.0%
1.6×
Watch
Idle development resources
1.6%
0.9×
Normal
Bar: exemption-rate lift vs. idle-development baseline · scale 0–4.0× · tick marks the 2.0× review threshold2 of 4 slices over threshold
Evidence-linked improvement
What a quiet deletion costs
A loop closes when the log deleted under a hold is a standing case. That suite is what the next saving taken is measured against.
Improvement cycle · five stagesSwitchback — the path turns at Improve and returns at Learn
01Detect
Exemption rate rises on log and audit retention.
02Diagnose
The thirty-day expiry that saved money and deleted a hold is worked backwards until one duty is left standing.
03Improve
Number the change; the resources that drove it are filed beneath it.
04Verify
A single red resource case stops the whole change.
05Learn
One case joins the suite, one line joins the optimisation rules.
Learn → DetectThe return edge. The next saving is measured against a suite one case longer.
Typical build scope
Twelve workstreams across six weeks
The build scope read against the delivery timeline. Week structure follows the six-week plan — discovery, sources, cost workflow, evaluation, integration, then production validation and handover.
WorkstreamWeek 1Week 2Week 3Week 4Week 5Week 6
01Spend workflow discovery and automation-boundary work.
02Billing and resource inventory assessment.
03Retention, residency and redundancy-register mapping.
04Billing and usage ingestion.
05Duty binding and action costing.
06Impact scoring and review routing.
07Owner approval workflow.
08Cloud and change-system integration.
09Retention and topology cases.
10Guardrails and action controls.
11Resource-trail instrumentation.
12Deployment, documentation and Agent Care handover.
12 workstreams · 6 weeks · bar shows the weeks a workstream is active — several run in parallelFinal scope and sequence confirmed in discovery
Engagement tiers
What each tier includes
Rows are the capabilities named in each tier's scope. Higher tiers include everything below them.
Capability✓ in scope · — not at this tierPilotOne account, one teamProductionProduction cloud estateAdvancedMultiple accounts / estates
Introduced at Pilot
Costing to your duty register✓✓✓
Named owner approval✓✓✓
Spend-and-resource baseline✓✓✓
Introduced at Production
Reporting by resource class—✓✓
Records review workflow in your systems—✓✓
Approved cost actions—✓✓
Billing-and-inventory integration—✓✓
Introduced at Advanced
Multi-jurisdiction duty rules——✓
Multi-stage owner approvals——✓
Large resource inventories——✓
Multi-account action controls——✓
Build priceFrom $5,000From $8,000Custom quote
Final build priceConfirmed after discovery based on integrations, workflow complexity, resource volume, approval controls and deployment requirements.
Separate from buildBuild pricing is separate from recurring Agent Care, which covers managed monitoring, evaluations, incidents and verified improvements after launch.
What we need from you
What you bring, and what we build with it
Each input maps to a piece of build scope and a week in the delivery timeline.
You bringWe build with it
01Your live accounts and the duties each resource carries→Duty-register capture and boundary versioningWeek 1
02Representative billing exports and usage telemetry→Resource binding, cost logic and the spend baselineWeek 2
03Your change calendar and the owners it names→Duty-register mapping, hold capture and the automation boundaryWeek 1
04Access to relevant APIs, feeds or exports→Billing, telemetry and inventory assessment, then integration setupWeek 2
05Deletions you would not want subpoenaed→Retention cases and the failure-mode roundWeek 4
06What no saving may remove→Impact scoring, review routing, guardrails and release controlsWeek 3
07A named owner who approves the action→Owner exemption workflow, then pilot and production validationWeeks 5–6
Nothing else is requiredDeployment, documentation and Agent Care handover are ours.
Delivery timeline
Four phases across six weeks
The bands are as wide as the work in them, which is why a pair of them share the fifth week here.
PhaseW1W2W3W4W5W6
DiscoveryW1
BuildW2 – W3
EvaluateW4 – W5
Pilot & LaunchW5 – W6
Week focusW1Spend workflow discovery, duty-register mapping and the automation boundaryW2Billing and inventory integration and the spend baselineW3Cost workflow, confidence logic and approval controlsW4Evaluation suite, retention cases and failure-mode testingW5Change-system integration, pilot actions and targeted correctionsW6One billing quarter run under the platform owner, then Agent Care handover
Reading the bandEach bar covers only the weeks its own work is named for, and the week five overlap is real, not padding.
At the end of W6When the resource record validates, Agent Care assumes the agent.
DurationSix-week plan shown · typical delivery 4–6 weeks depending on scope confirmed in discovery.
Next step · Engineering AI agent
Build a cloud cost agent around the duties your last saving quietly moved.
Show us one account and the last lifecycle rule somebody shortened to save money. Something else moved with it — a retention floor, a residency position, a replica a regulator was told about. 18 U.S.C. 1519 wants knowledge and intent; an agent supplies neither.