RosettaHub™ for Scaleups

Governance that arrives on time

You outgrew the phase
where nobody had to ask.

Fifty people ago the cloud bill was small enough to ignore and everyone knew what everyone was running. Neither is true now, and the usual fix is a hiring plan you do not have. This is the other fix.

Five reasons people
arrive on this page

Almost nobody adopts governance because it seemed like a good idea in the abstract. Something happens first.

The AI bill arrived and nobody recognised it

A model endpoint or a GPU fleet costs several times what was assumed, and the invoice is the first place it shows up as one number with no owner.

An enterprise customer asked for the audit

SOC 2, ISO 27001, HIPAA or PCI DSS, wanted this quarter, with the evidence gathered by a team that has never had to produce it before.

A second cloud arrived with an acquisition

Two consoles, two permission models, two cost pictures, and nobody who knows both.

A new engineering leader wants one platform

Five point tools with five bills and five integrations, and a mandate to consolidate them.

Non-production is quietly enormous

Development and test environments outnumber production and nobody switches them off, because it has never been anyone’s job.

Nobody here is going
to police this by hand

At this size there is rarely a dedicated FinOps function, and there is never a spare platform team. Anything that depends on somebody watching a dashboard will quietly stop happening within a month.

The budget refuses the launch

Checked when a resource is created, enforced by the cloud’s own API. Nothing to notice, chase or approve.

Waste switches itself off

Twenty eight kinds of idle and orphaned resource, found continuously, reported first and then stopped when you say so.

Compliance runs whether or not you do

Continuous scanning against ten standards, with every finding mapped to the control it breaks, so audit preparation is a report rather than a month.

The people who live with it

Engineers have to want
this too

Governance bought over the heads of the people it lands on gets worked around, and the fastest way to lose a team is to make the platform the reason things take longer.

So the trade has to be worth taking. What engineers get back is the thing they usually wait on somebody else for.

Environments without a ticket

Machines, notebooks, clusters and stacks launched by the person who needs one, in seconds, without an account request or a platform team in the middle.

Budgets you can see and move

Spend is visible while the work happens rather than at month end, and running low is a request an administrator can answer in a minute.

Restrict nothing, if you prefer

Narrowing which services and regions a team can reach is a separate switch from enforcing the budget. Leave the catalogue wide open and the spending limit still holds.

A limit on what a team can spend is a very different thing from a limit on what they are allowed to try.

One platform, rather than
five that each do a third of it

Cost visibility from one vendor, compliance scanning from another, account provisioning from a third, an identity bridge from a fourth, and something for AI spend that does not exist yet. Each with its own bill, its own integration and its own view of who owns what.

Cost, compliance, accounts, permissions, AI spend and self-service run through the same gate here, which is also why a budget can act on a compliance finding and a permission can act on a budget.

Start read-only,
and keep it that way if you like

The first level grants no administrative access at all: live cost estimates, allocation, idle detection and compliance scanning, deployed into your own accounts in about fifteen minutes. Your data stays in your accounts, there is no agent on a host and no proxy in your network.

Enforcement and remediation are separate levels, granted per account, and withdrawn by removing the stack. Nobody has to decide everything on the first call.

Common questions

We already have a cloud cost tool. What does this add?

Cost tools report what happened. The budget here is checked when a resource is created, so an over-budget launch is refused by the cloud’s own API rather than appearing on next month’s invoice. Add continuous compliance, drift remediation and per-person AI limits and it usually replaces several separate tools rather than joining them.

Our AI bill came in several times higher than expected. Where does that come from?

Usually from not knowing whose it is until the invoice arrives. Token cost is attributed to the person who incurred it within about five minutes, and which models a role may call is a permission, so a limit can restrict access as it is approached instead of describing the overrun afterwards.

How much work is it to connect, and what access do you need?

The first level is read-only and takes about fifteen minutes. It deploys into your own accounts, your data stays there, there is no agent on a host and no proxy in your network. Enforcement and remediation are separate levels you switch on per account when you want them.

We just picked up a second cloud through an acquisition. Does that mean two of everything?

No. The same budgets, quotas, roles and compliance policies apply across AWS, Azure and Google Cloud from one place, and the same operations work on each. That is usually the point at which a governance decision stops being optional.