FEATURES11 capabilities · every one under your control

Eleven capabilities. One rule none of them can break.

Every capability below detects, diagnoses, and proposes a fix — and every one of them stops at a hard approval step before anything touches your infrastructure. Detection is automatic. Action never is, unless you say so.

CAPABILITY·01STARTER

CI/CD Pipeline Failure Triage

Detects a failed pipeline run, surfaces the root-cause step from the logs, and proposes the exact config or code fix — before you’ve finished reading the Slack alert.

TOUCHES GitHub Actions / Azure DevOps pipelines, the failing repo
ON APPROVAL Reopen the PR with the fix, or open a new PR — your call, always reviewed first
CAPABILITY·02STARTER

Kubernetes Alert Fatigue & Remediation

Separates the pod restart that self-healed from the one that needs a human, and proposes the scale-up, rollback, or config patch for the ones that matter.

TOUCHES Your cluster’s K8s API (read for triage, write only on approval)
ON APPROVAL Apply directly via kubectl, or route through a GitOps PR — whichever your team runs
CAPABILITY·03STARTER

PR Review — Architecture & Security

Reads a pull request the way a senior engineer would: flags security patterns, architectural drift, and the stuff a linter can’t catch, as a real review comment.

TOUCHES The PR’s diff and repo context — read-only
ON APPROVAL Posts as a review; never merges, never blocks CI on its own
CAPABILITY·04GROWTH+

Legacy Code & Infrastructure Migration

Takes a file or module you name — a Flask route, a Terraform 0.12 module, a Python 2.7 script — and drafts the migrated version with a step-by-step plan attached.

TOUCHES One file or module at a time, on request
ON APPROVAL Opens a PR with the migrated code, or files a tracking issue with the plan
CAPABILITY·05GROWTH+

IAM Policy Minimization

Diffs what a role actually used against what it’s allowed to do, and proposes the tightened policy — the least-privilege cleanup nobody has time to do by hand.

TOUCHES AWS IAM / Azure RBAC / GCP IAM, read for analysis, write only on approval
ON APPROVAL Opens a PR against your IaC, or applies directly if you’ve enabled that
CAPABILITY·06GROWTH+

FinOps Cost Optimization

Reads your actual billing export, finds the idle resources and the waste, and ranks fixes by real monthly savings — not a generic "right-size everything" report.

TOUCHES Cost Explorer / Azure Cost Management exports, idle-resource inventory
ON APPROVAL Stop/delete the specific idle resources it found, or just get the report
CAPABILITY·07GROWTH+

Interactive Runbook Automation

Turns a written runbook into an executable, step-gated workflow — each step runs, reports back, and waits before the next one fires.

TOUCHES Whatever the runbook itself touches — shell, HTTP, or infra steps
ON APPROVAL Runs step by step with a stop-on-failure gate, never all-at-once
CAPABILITY·08GROWTH+

Drift Detection & Auto-Correction

Compares live state against Terraform, CloudFormation, or a Kubernetes manifest, and proposes the correction — never applies IaC changes without a PR to review.

TOUCHES Terraform state, CloudFormation stacks, K8s live resources — read for detection
ON APPROVAL Remediation PR (always), or kubectl apply directly for K8s if you’ve enabled that
CAPABILITY·09GROWTH+

Context-Aware Onboarding & On-Call Buddy

Answers "how does this actually work" and "what do I do about this page" using your real runbooks and incident history — not a generic wiki search.

TOUCHES Your knowledge base and incident history — read-only
ON APPROVAL Answers in chat; never takes an action on its own
CAPABILITY·10GROWTH+

Dependency & Vulnerability Patching

Scans your manifest (npm, pip, go, maven, ruby, or cargo) against OSV.dev, and proposes the patched manifest with a severity-ranked vulnerability summary.

TOUCHES One dependency manifest at a time, on request or schedule
ON APPROVAL Patch PR, a tracking issue, or both — your choice per finding
CAPABILITY·11GROWTH+

Cloud Resource Health Monitoring

Catches a resource going down, a threshold breach, or a security finding the moment your cloud provider fires the alert — the runtime counterpart to CI/CD triage and drift detection.

TOUCHES Azure Monitor Action Groups, AWS SNS/CloudWatch alarms — push-driven, no polling
ON APPROVAL Remediation PR, or a tracking issue — never a live restart/scale call on its own

Starter gets you three. Growth+ gets you all eleven.

CI/CD triage, Kubernetes alerts, and PR review ship on every plan. The other eight — migration, IAM, FinOps, runbooks, drift, on-call knowledge, dependency patching, and resource health monitoring — come with Growth and Enterprise.

Start free trial