Four steps from your cloud account to a verified saving.
Tallywyrmconnects to AWS, GCP and Azure through read-only OIDC trust roles in minutes, analyzes idle / oversized resources and unscheduled persistent volumes across providers, opens auto-generated rightsizing pull requests against your Terraform, Pulumi or Crossplane repo, and logs every verified saving to the audit trail — tied to the methodology finance signs off on.
- 01
Connect cloud + IaC via read-only roles in minutes
AWS, GCP and Azure are read through your existing OIDC trust. The agent opens scoped pull requests against your Terraform, Pulumi or Crossplane repo. Ten minutes from a README to a first run, no agent running in your account.
- 02
Analyze idle/oversized resources and unscheduled PVCs across providers
Compute, storage and managed services are reconciled against trailing usage, trailing spend and native cost signal every hour. Unscheduled persistent volumes across providers are surfaced separately so cleanup, not suspension, is the obvious next move.
- 03
Auto-generated rightsizing pull requests land in your repo for review
One small, reversible change per resource, opened as a pull request against your Terraform, Pulumi or Crossplane repo. Diff, rollback and post-deploy measurement written into the description so the reviewer signs with the same context they would have written themselves.
- 04
Verified savings logged to the audit trail and tied to a methodology
Every realized dollar ties back to a diff, a deploy timestamp and a post-deploy measurement, and lines up with the methodology on /methodology. The audit trail writes itself; finance signs the weekly report because every line carries the receipts.
A PR per resource, not a stateful agent running in your account.
Read-only cloud credentials are brokered through your OIDC trust. The agent’s only write path is the pull request into your Terraform, Pulumi or Crossplane repo. Reviewer signs; your CI reconciles; the audit trail carries the deploy timestamp.
Full credential model on /faq and /security-and-compliance.
The same four-step loop runs against Terraform, Pulumi and Crossplane. The shape of the diff changes; the merge loop, the credential model and the audit trail all stay the same.
Ready to see the loop run against your inventory?
A 30-minute read-only connector. First PR lands within an hour. First verified saving on the next weekly report, logged to the audit trail and tied to the methodology.