Workflow

Four steps from your cloud account to a verified saving.

Tallywyrmconnects to AWS, GCP and Azure through read-only OIDC trust roles in minutes, analyzes idle / oversized resources and unscheduled persistent volumes across providers, opens auto-generated rightsizing pull requests against your Terraform, Pulumi or Crossplane repo, and logs every verified saving to the audit trail — tied to the methodology finance signs off on.

See pricing Talk to us
4 steps · 24/7 · audit-ready
The short version
One PR per resource. One signed deploy. One audit line.
Every saving ties to a PR, a deploy timestamp and a post-deploy measurement, and lines up with the methodology on /methodology. The audit trail backs the dollars, the PR backs the change. Full pricing rail on /pricing.
The four-step loop
Connect → Analyze → PR → Audit trail.
Four stages, one review-friendly artifact at every step — read-only OIDC trust, scored idle and unscheduled-PVC findings, a single PR per change, and a methodology-backed line on the audit trail. The pillar-post visitors will recognise the same pattern from the home page band and the AWS, GCP and Azure rightsizing guides.
  1. 01

    Connect cloud + IaC via read-only roles in minutes

    AWS, GCP and Azure are read through your existing OIDC trust. The agent opens scoped pull requests against your Terraform, Pulumi or Crossplane repo. Ten minutes from a README to a first run, no agent running in your account.

  2. 02

    Analyze idle/oversized resources and unscheduled PVCs across providers

    Compute, storage and managed services are reconciled against trailing usage, trailing spend and native cost signal every hour. Unscheduled persistent volumes across providers are surfaced separately so cleanup, not suspension, is the obvious next move.

  3. 03

    Auto-generated rightsizing pull requests land in your repo for review

    One small, reversible change per resource, opened as a pull request against your Terraform, Pulumi or Crossplane repo. Diff, rollback and post-deploy measurement written into the description so the reviewer signs with the same context they would have written themselves.

  4. 04

    Verified savings logged to the audit trail and tied to a methodology

    Every realized dollar ties back to a diff, a deploy timestamp and a post-deploy measurement, and lines up with the methodology on /methodology. The audit trail writes itself; finance signs the weekly report because every line carries the receipts.

The merge loop

A PR per resource, not a stateful agent running in your account.

Read-only cloud credentials are brokered through your OIDC trust. The agent’s only write path is the pull request into your Terraform, Pulumi or Crossplane repo. Reviewer signs; your CI reconciles; the audit trail carries the deploy timestamp.

Full credential model on /faq and /security-and-compliance.

Tallywyrm four-step loop01Connect02Analyze03Scoped PR04Audit trailCloud account → read-only OIDC trust → your IaC repo → merged → measuredSame loop on Terraform, Pulumi and Crossplane

The same four-step loop runs against Terraform, Pulumi and Crossplane. The shape of the diff changes; the merge loop, the credential model and the audit trail all stay the same.

See it in your account

Ready to see the loop run against your inventory?

A 30-minute read-only connector. First PR lands within an hour. First verified saving on the next weekly report, logged to the audit trail and tied to the methodology.