Skip to main content
Reference / Glossary

Every term,
in one place.

1109 terms across 279 lessons, each with a definition pulled verbatim from the lesson that first uses it. Click any term to land there.

105 terms
Absent-series signal A metric series that does not exist, treated as evidence of zero activity rather than as missing data. 1 Abstain A rule or probe declining to produce a verdict because no honest one is available. 1 Account consolidation Merging two or more cloud accounts of similar purpose into one when maintenance overhead exceeds the isolation benefit, compliance allows it, or an account is forgotten with low… 1 Account filter A platform engineer scoped to team=platform sees their team's resources across the 3 accounts that hold platform infrastructure. 1 Account id Jira's opaque identifier for a user, used in place of an email address for privacy reasons. 1 Account isolation Separating production, non-production, and compliance-scoped workloads into distinct cloud accounts so that a breach, misconfiguration, or runaway script in one account cannot… 1 Account proliferation The growth in cloud account count that follows from isolating by team crossed with environment. 1 Account split Dividing one cloud account's resources across multiple accounts when the account grows too large for cloud quotas, blast radius grows too big, distinct teams emerge, or compliance… 1 ACCOUNT_USAGE The Snowflake schema of account-level usage views that ZopNight reads for discovery and cost. 1 ACS URL The Assertion Consumer Service endpoint, where a SAML identity provider posts its assertion after authenticating a user. 1 Action default The conservative predefined action ZopNight recommends per rule category (for example Terminate with snapshot for idle, Downsize during maintenance for rightsizing, Attach to… 1 Action item A named owner, a specific change and a date. 1 Action item tracking The formal tracking of postmortem action items, where each item has a single owner, a specific deliverable, a due date, a status of open, in-progress, done, or cancelled, and a… 1 Action status The state of a scheduled or remediated action: pending, running, succeeded or failed. 1 Action translation The middle tier of the IAM import translation staircase, where a custom cloud role with no curated mapping is translated by reading its actions and deriving an approximate… 1 Actionable visibility Inform is the first phase of the FinOps lifecycle. 1 Active bytes The storage a Snowflake table actually occupies, including the overhead of Time Travel and Fail-safe retention. 1 Active-active vs warm standby Two disaster-recovery tiers, where active-active keeps synchronous multi-region writes with RTO under one minute and RPO of zero, while warm standby keeps a secondary replica… 1 Activity-sync The Recent Activity tab in the evidence panel shows operations against the resource, pulled from CloudTrail (AWS) / Cloud Logging (GCP) / Azure Activity Log via the daily… 1 Actual cost Cost as charged by the cloud provider's billing API, held in the `actual_cost_usd` column and available where billing sync has landed. 1 Adaptive batching Anomaly detection that scales its batch size to organization resource count (25 at 5,000 resources or fewer, 5 at 20,000 or fewer, and 1 at a time above 20,000) so larger estates… 1 Adjacency graph The server-side graph of one-hop relationships between resources, built from resource metadata such as shared security groups, routing targets, attachments, triggers and parentage. 1 Admin ZopNight ships with three system roles: Viewer, Editor and Admin. 1 AdministratorAccess The AWS managed policy granting unrestricted access within an account. 1 Adopt flow The path from a surfaced recommendation to an applied change: review, check blast radius, apply or open a ticket, then let verification confirm it. 1 Adopt-or-promote The one-way transition where editing an adopted, observation-only autoscaler policy automatically promotes it to a recommended, ZopNight-managed policy, so adopted policies should… 1 Adopt-or-replace Pattern where ZopNight detects existing cloud scaling and asks the user whether to adopt (observe) or replace (manage). 1 Advanced mode Quick Setup is a streamlined flow for the most common autoscaler scenario: pick a target, accept smart defaults, save. 1 Advisory category A rule category carrying no recoverable dollar figure by design, used where the artifact itself is free and the spend lives elsewhere. 1 Advisory demotion Downgrading a finding from an actionable, priced recommendation to an advisory one when a concrete saving cannot be computed or the action cannot be proven safe. 1 AES-256-GCM The authenticated encryption used for stored cloud credentials and provider secrets. 1 Agent helps, human writes The operating model at MCP write tier `none`: the agent researches, correlates and drafts, and a person executes the change through a surface designed for it. 1 Agent-friendly workflow Work that fits an agent's strengths because it is multi-step, multi-source, produces written output, requires non-trivial synthesis, and repeats often enough to be worth a recipe,… 1 Agent-helps-human-writes loop The operating pattern where an agent investigates via read-only MCP tools and recommends an action with justification, but a human reviews and executes the change through the… 0 AI bolt-on A cost tool where the AI is a chat box added on top of an existing dashboard, rather than something an engineer can reach from the tool they already work in. 1 AI Gateway ZopNight's LLM cost governance capability: virtual keys, provider and model management, budgets and spend reporting, built by reusing Config integrations, budgets, RBAC and… 1 ai-model policy The RBAC capability governing AI model registration, with the standard view, create, update and delete verbs. 1 ai-usage:view The RBAC policy granting read access to AI cost and usage data. 1 Alert fatigue Severity tuning is iterative. 4× All-of decision A watch policy decision mode requiring every signal to fire before a finding is produced. 1 Allocation Assigning a cost to the team, product or environment responsible for it. 1 Allocation dimension The primary axis (Organisation, Teams, or Tags) along which showback and chargeback cost is grouped and presented in Reports, each with its own sweet spot. 1 Allocation rule A documented policy specifying how a shared or indirect cost is distributed across teams or cost centers, recording what it allocates, why, how (formula or fixed percentage), when… 1 Allocation rule audit A quarterly review that retires allocation rules unused for six or more months or with under $100 per month of impact, targeting a roughly 10 percent reduction in rule count per… 1 Allowed value list The enumeration a tagging policy accepts for a key. 1 allResources flag The RBAC scope field indicating a policy applies without resource filtering. 2× Always-on exception A resource explicitly run 24/7 even in non-production because business need justifies it, such as office-hours-only B2B SaaS or regional shutdowns where no customers exist in that… 1 Amortized cost The cost of an upfront commitment (RI, Savings Plan, CUD) spread across the hours it covers, so each resource shows its true effective daily cost. 2× Annotation In forecasting, a documented note attached to a projection that records the assumptions, drivers, and risks behind it, such as a planned feature launch, an assumed growth rate, or… 1 Annual account review Annual account review (2-3 weeks of focused work). 1 Annual freeze calendar A calendar, agreed once a year, of the periods when schedules must not fire and changes must not ship. 1 Annual run-rate The projection of savings across a full 12 months extrapolated from realized short-term savings, for example scaling roughly $4,800 of weekly savings into a $250K annual figure… 1 Anomaly A cost deviation large enough to be flagged against its own baseline rather than against a fixed threshold. 1 Anomaly detection The daily job flagging cost deviations across several dimensions at once, rather than on a single total. 1 Anomaly dimension One of the five levels (org, cloud account, resource group, resource, and team) across which ZopNight detects cost anomalies, each catching a different kind of event and used as a… 1 Anomaly root-cause analysis The ranked identification of what drove a cost anomaly, across instance resizes, new resources, reservation expiry, schedule failures and unscheduled usage increases. 1 Anomaly severity bands Three anomaly severity bands. 1 Anomaly signature The shape of a cost deviation: which dimension moved, how fast, and whether it stepped or ramped. 1 Anti-pattern A practice that recurs because it looks reasonable and reliably produces a worse outcome. 2× API request charge A per-call cloud bill line item for services that bill by request volume rather than running time, such as Lambda invocations, S3 GET, PUT, and LIST, and DynamoDB capacity units,… 1 API-driven schedule A schedule started and stopped by API calls from a test pipeline rather than a fixed cron, typically paired with a backup schedule that force-stops the environment if the pipeline… 1 App registration The Azure AD application whose service principal ZopNight uses as its runtime identity, paired with a client secret. 1 Apply / dismiss / snooze Recommendations is the canonical triage surface. 1 Apply to cloud The explicit, on-demand action that writes accepted Smart Tags to the cloud provider as real tags. 1 apply_tag job The remediation job that writes an accepted Smart Tag onto the real cloud resource. 1 Approval decline rate The share of approval requests that are declined, where a near-zero rate under 5 percent means the approval gate is friction without value and a healthy 15 to 30 percent means it… 1 Approval gate A pause in the remediation workflow where a change waits for a person to approve it before it reaches your cloud. 2× Approval SLA The maximum time window, often 24 hours, within which an approval-gated remediation must be responded to, after which the action auto-cancels rather than executing without approval. 1 Architect-design lever The fourth and highest-ceiling optimization lever, changing the workload's architecture to cost less (for example replacing a 24/7 service with a serverless equivalent), applied… 1 Architectural boundary A limit enforced by design rather than configuration, as with ZopNight's read-only MCP layer where writes are simply not implemented so there is no toggle to flip or scope to… 0 Architectural ceiling The structural cost base of a workload that remains after operational optimizations such as scheduling, rightsizing, and rate optimization are exhausted, and which stays with… 1 Architectural differentiation A competitive edge that comes from structural design choices rather than feature lists, such as being MCP-native, read-only by design, recipe-driven, and built on an open protocol. 1 Archive tier Audit retention; right-size per tier; configure lifecycle policies. 1 Assertion Consumer Service The SAML endpoint URL on ZopNight's side (for example https://zop.dev/zopnight/app/auth/saml/<domain>/callback) where the identity provider posts the signed SAML assertion after… 0 Assume-role ZopNight connects to AWS via an IAM role with cross-account assume-role trust. 2× Asymmetric risk A situation where the downside cost far exceeds the upside benefit, as with database writes where a failed change can cost six figures in downtime and trust, justifying the… 1 Async export A long-running export that runs as a background job so the HTTP request returns immediately. 1 At-least-once delivery A messaging guarantee where a consumer may receive the same event more than once and must therefore be idempotent. 1 attached_to A blast-radius edge type detected from a volume or disk's own attachment metadata. 1 Attribute mapping The configuration of which identity-provider user attributes map to ZopNight fields, requiring at least email, recommending name, and enabling automatic team assignment when… 1 Audience mismatch A SAML validation failure caused by metadata drift where the Audience URI in the assertion does not match the Entity ID configured in ZopNight, fixed by making the two values… 1 Audience translation Converting engineering terminology into language a non-technical audience understands, such as rendering technical detail as business terms like access control or cost flow when… 1 Audit log The per-organisation record of every mutating API call: who, what, when, and from where. 2× Audit log vs notifications The distinction that the audit log is the immutable source of truth recording every event regardless of notification settings, while notifications are only a delivery mechanism… 1 Audit-log integrity The guarantee that audit entries are append-only and tamper-resistant, enforced by an INSERT-only MySQL table with no UPDATE permission and per-entry hashes chained to the… 1 Authority bounds The limits on what a responder may do without escalating, set per severity level. 1 Authorization code flow The OAuth 2.0 flow in which a client receives a short-lived code at a redirect endpoint and exchanges it server-side for tokens. 1 Auto-escalation The rule that raises an anomaly's severity by itself when it keeps recurring, on the basis that a spike nobody has dealt with after several days is a different problem from a… 2× Auto-expiry The auto-expiry is critical: manual cleanup gets forgotten and freezes drift. 1 Auto-promote Auto-promote makes the transition explicit. 2× Auto-remediation The workflow that executes a recommendation's fix as a precondition, an optional approval, a cloud action and a validation. 1 Auto-remediation trigger A state-history trigger type indicating a recommendation rule fired and executed auto-remediation, shown in a format like auto-rem:RC-001 (Idle EC2) that links through to the… 1 Auto-remediation workflow The ordered three or four step process (Precondition, optional Approval, Action, and Validate) that runs each auto-remediation, where every step has a defined success or failure… 1 Auto-sequencing Auto-sequencing covers 80% of cases. 1 Auto-suspend The Snowflake setting that stops a warehouse after a period of no queries. 1 Auto-tag The retired heuristic tagger that guessed tag values with a confidence score. 1 Auto-tagger The retired heuristic component that predicted a resource's owner and environment with a confidence score. 0 Autopilot mode The autoscaling mode in which the autoscaler manages capacity automatically without per-action approval, adopted per policy as teams progress from monitor to recommend to… 1 Autoterm vs schedule In Databricks SQL Warehouse cost control, the choice between autoterm (auto-pause after a few minutes of inactivity, suited to always-available workloads) and an explicit schedule… 1 Avoidable spend Spend on resources a rule has flagged as idle, orphaned or over-provisioned. 2× AWS Organizations AWS's multi-account management service, providing the account hierarchy, consolidated billing and SCPs. 2× Azure Hybrid Benefit Layer 5, Azure Hybrid Benefit. 2× Azure Management Group Azure's hierarchical grouping of subscriptions with inheritable policies, analogous to AWS Organizations or GCP Folders, sitting above the subscription which is the billing and… 1 Azure Reservation Azure's commitment to a specific resource configuration for one or three years. 2× Azure Resource Graph Azure's canonical inventory query API. ZopNight runs one expanded query returning 86 keys that resolve to 85 unique canonical types, which is what makes Azure discovery a single… 1
36 terms
Backfill A one-off pass that applies a new definition to existing data rather than only to data arriving afterwards. 1 Backup retention The length of time backups are kept, a direct driver of monthly storage cost, disciplined so that retention matches RTO, RPO, and compliance requirements and no more rather than… 1 Batch API Bedrock offers batch API at ~50% of on-demand pricing. 1 Batch latency The delay introduced by accumulating work before processing it. 1 Bearer credential PAT management is covered in detail in M6.3. For now: read-only is the only scope option (architectural; see M6.1.L2 and M6.6); the token is bearer credential (treat like a password). 2× Bedrock pricing AWS Bedrock charges per input token and again per output token, at rates that differ enormously between models. 1 Bedrock rule One of the ten ML and Bedrock recommendation rules (RC-1601 through RC-1610) that each target a specific cost pattern such as model selection optimization, provisioned throughput… 0 Belt-and-suspenders cron A redundant stop cron added to a schedule (such as a weekend midnight stop on a weekday-only schedule) that is harmless during normal operation but catches the edge case of a… 1 Bias factor A deliberate adjustment applied to a computed figure to make it conservative. 1 BigQuery billing export GCP BigQuery billing export. 1 BigQuery slots GCP BigQuery's reserved query capacity purchased as a flat-rate commitment for predictable workloads, offering an alternative to on-demand per-terabyte pricing where a single… 1 Billed cost The amount the provider actually charged, as distinct from rack rate. 1 BilledCost The FOCUS column for the amount actually invoiced, after discounts and commitments. 0 Blameless culture A blameless culture is essential. 1 Blameless postmortem A written account of an incident that explains what happened and what will change, without assigning fault to a person. 1 Blast radius The math: a single-account org has a blast radius equal to its entire estate. 4× Body capture By default, the full request body and response body are stored. 2× Bookmark The default is the org's primary landing; each user's bookmark is their personal landing. 1 Bottom-up forecast A forecast built by summing individual resource and workload projections. 1 Breadcrumb The path trail shown when viewing a nested resource, such as a cluster's node pool or a group's members. 2× Break-even coverage The commitment coverage level at which the discount captured exactly offsets the cost of unused commitment. 1 Break-glass path The documented route to act when the normal control surface is unavailable, usually the cloud console. 1 Break-glass procedure Even ZopNight engineers cannot read a customer's credential. 1 Breakeven calculation A reliability investment analysis that invests only when downtime hours avoided times cost per hour exceeds the annual reliability cost, for example Multi-AZ RDS at $4,800 per… 1 Budget A spend limit set against an organisation, cloud account, resource group, resource set or AI entity, with threshold notifications. 1 Budget conversation The recurring discussion where a team's spend is reviewed against its budget by the people who can change it. 1 Budget pyramid The budget pyramid is a layered budget structure where each level rolls up to the level above. 1 Budget scope The entity a budget is measured against: an organisation, a cloud account, a resource group, a resource set or an AI entity. 1 Bulk accept Bulk accept on high-confidence predictions is the fastest path to coverage. --- [All glossary terms](/resources/university/glossary) 0 Bulk action A multi-resource start, stop or attach operation, executed through a bounded worker pool. 1 Bulk membership Adding or removing many resources from a resource group in one operation by reusing the filter machinery to construct a filter, multi-select the matches, and add hundreds of… 1 Business Hours preset The shipped schedule covering a standard working week, with a start, a stop and a redundant weekend stop. 1 By Resource layout One of the five Cost Flow Sankey layouts, cascading Account to Service to Resource to Team, used for deep diagnosis and anomaly investigation to find which specific resources… 1 By Service layout One of the five Cost Flow Sankey layouts, cascading Provider to Account to Service to Team, used to identify which cloud services dominate spend, for example whether cost is… 1 Byte-accurate restore Putting an autoscaling policy back exactly as it was found, byte for byte, when ZopNight is removed. 1 Byte-accurate rollback Restoring a previous configuration exactly as it was, from an opaque specification captured before the change. 1
140 terms
Cadence Inform fails when one report tries to serve three audiences. 1 CAGR Compound Annual Growth Rate, used as a calibration check on the growth-rate input to top-down forecasting, where a historical CAGR anchors and validates a synthesized forward… 1 Calibration Checking a model's or a rule's output against measured reality and adjusting. 1 Calibration loop The quarterly iterative process of measuring historical forecast variance, identifying systematic bias, applying a correction factor to future forecasts, and verifying the result,… 1 Cancel override Terminate an active override before its scheduled expiry to resume normal resource operation when the situation it addressed resolves early. 1 Canonical tag set The minimal starting set of mandatory and recommended organizational tags, typically environment, team, owner, and cost-center, enforced and maintained as code to reduce tag debt. 1 Canvas overlay The blast-radius view layered onto the architecture canvas, colouring the target blue, affected neighbours red, warnings amber and proven-safe neighbours green, and dimming… 1 Capability catalog The YAML-driven definition set behind the V2 recommendation engine, under `providers/`. 1 Carbon Aware SDK An open-source library that answers one question at runtime: is the electricity feeding this region clean right now? Schedulers use the answer to decide whether to run flexible… 1 Carbon intensity Cloud workloads consume electricity. 1 Carbon intensity metric The measurement of carbon emissions in grams of CO2 per kilowatt-hour from electricity generation, which varies by grid region and time of day. 1 Carbon reporting cadence The frequency and structure for reporting cloud carbon footprint to leadership, typically quarterly or annually, following trend, breakdown, intensity, and comparison. 1 Carbon-aware computing Carbon-aware computing is the practice of scheduling compute to align with low-carbon energy availability. 1 Carbon-aware scheduling Scheduling compute workloads to align with low-carbon energy availability on the grid, since carbon intensity varies throughout the day. 1 Cardinality The number of distinct values a dimension produces. 1 Cascade 3 layout switches in 90 seconds. 1 Cascade filter A filter chain where each selection narrows the options available in the next. 1 Cascade investigation Investigating cost anomalies by drilling from the broadest dimension down through progressively narrower ones, org to cloud account to team to resource group to resource, to… 1 Cascading savings Cascading savings are a feature, not a bug. 1 Catastrophic protection A reliability investment justified by the potential cost of trust damage and organizational impact that a failure on a critical business system would cause. 1 Categorical exclusion Ruling a whole class out by policy rather than case by case. 1 Cause probability The probabilistic ranking of potential root causes for a cost anomaly, expressed as a percentage indicating how likely each cause explains the observed deviation. 1 CDCR Continuous Detect, Continuous Remediation: the operating model where finding waste and acting on it are one recurring loop rather than two separate projects. 1 CDCR boundaries The four explicit limits of Continuous Detect, Continuous Remediation: it is not autopilot for everything, not a bypass for change management, not a substitute for cost ownership,… 1 Centralized monitoring A shared-services architecture where monitoring, logging, and observability run in a dedicated platform-team account rather than being duplicated across team-owned accounts. 1 Certified rule Shorthand for a recommendation rule on the auto-remediation allowlist (validated end-to-end on real cloud). 1 Change management integration Wiring CDCR approval-gated remediation into existing change-management processes to preserve audit trails, cross-team awareness, and rollback playbooks. 1 Chaos engineering Deliberately introducing failures such as killing components into production or test environments to verify reliability assumptions. 1 Chargeback Moving cloud cost onto a team's own budget so it competes with their other spending. 2× Chargeback anti-pattern The condition where chargeback complexity grows until maintaining it costs more than the savings or accountability it enables, warranting simplification or rollback to showback. 1 Cheap tier The lower-cost model tier a complexity router serves trivial prompts from. 1 Claude Code Claude Code is Anthropic's CLI agent. 1 Client credentials The OAuth grant type in which a service authenticates as itself rather than on behalf of a user. 1 Client ID / Secret The credential pair an OAuth provider such as Google, GitHub, or Azure issues to authenticate an application and authorize users on its behalf. --- [All glossary… 0 Clock skew Disagreement between two systems' clocks. 1 Clone Presets are immutable templates. 1 Closure reason The recorded cause of a recommendation closing. 1 Cloud Asset Inventory GCP's canonical inventory API, queried with `ContentType_RESOURCE`. 1 Cloud Identity Google's directory service. 1 Cloud-native scheduled action A provider's own scheduled scaling action, such as an AWS Auto Scaling scheduled action. 1 CloudFormation StackSet An AWS mechanism deploying one template across many accounts and regions. 1 cloudId Atlassian's identifier for a Jira site, resolved during connection when a scoped API token is rejected at the site URL. The resolved gateway base is stored for REST calls while… 1 CloudWatch agent The AWS agent publishing in-guest metrics such as memory and disk. 1 Cluster autoscaler The Kubernetes component that adds and removes nodes in response to unschedulable pods and under-used nodes. 1 Cluster scheduling layer ZopNight's daily lifecycle management of start and stop times for Databricks clusters, working alongside Databricks native autotermination to cut compute cost. 1 cluster-admins The OpenShift group granting cluster-wide administrative rights. 1 COALESCE pattern The COALESCE pattern gives the best-available-answer per day: actual where available, calculated where not. 1 Codex MCP A Model Context Protocol integration that lets OpenAI's Codex tool read ZopNight cost data inline during development. 1 Cold-start latency The delay before a scaled-to-zero or newly-started resource can serve traffic. 2× Combined business case A scheduling justification that weighs both cost savings and carbon impact as complementary reasons to manage a resource. 1 Combined optimization Applying more than one lever to the same resource. 1 Commander authority The decision-making power granted to a single incident commander during a cost SEV-1 or SEV-2 to coordinate response, approve actions, and communicate outcomes. 1 Commitment portfolio The major clouds offer four commitment-style instruments that trade flexibility for discount. 1 Commitment utilization The percentage of purchased Reserved Instances, Savings Plans, or Committed Use Discounts actually consumed during their term, tracked as an Operate KPI. 1 Committed Use Discount Google Cloud's version of a commitment: promise a year or three of usage and pay less for it. 2× Communication templates Standardized message formats for different audiences such as engineering, finance, leadership, and security during a cost incident to keep detail appropriate per stakeholder. 1 Complexity drift The accumulation of allocation rules and special cases in a chargeback system until the effort to maintain it exceeds its cost-savings or accountability value. 1 Complexity router The AI Gateway classifier that routes a prompt to a cheap or strong model tier using length, max-tokens and keyword rules. 1 Compliance framework tag A label on an IaC governance rule naming the standard it supports, such as CIS, PCI, SOC 2, HIPAA, NIST, ISO or FinOps. 1 Composite budget A budget structure combining scopes, typically an organisation ceiling with per-team budgets beneath it. 1 Composite scoring The composite scoring is robust to confused naming. --- [All glossary terms](/resources/university/glossary) 0 Compound optimization Two savings that multiply rather than overlap, because they act on different things. 1 Compounding savings Cost reductions that persist quarter over quarter and build on prior gains, enabled by a consistent weekly Operate cadence and governance. 1 Compromise response The immediate actions taken when credentials are leaked: revoke the credential, rotate replacements via a secret manager, audit affected resources, and contain the blast radius. 1 Compromise-driven cost incident A cost spike caused by compromised cloud credentials that launch unauthorized workloads, classified as SEV-1 because of its security implications. --- [All glossary… 0 Compromised credentials A credential in the hands of someone it was not issued to. 1 Concept metric A canonical metric name in a watch policy that resolves to the correct provider-native metric on each cloud, so one policy works across AWS, GCP and Azure. 1 Concrete-or-abstain The rule-engine discipline of emitting either a real, priced finding or nothing at all. 1 Concurrency policy The rule for what happens when a job is triggered while a previous run is still going. 1 Concurrent event constraint A limit on how many event-readiness scaling actions can run simultaneously across cloud targets to avoid overloading infrastructure during coordinated events. 1 Confidence band Event Readiness shows a cost estimate before commit. 5× Confidence band communication Presenting forecasts to non-engineering audiences as a range rather than a single point to reflect the underlying uncertainty. 1 Confidence score Each prediction has a confidence score. 0 Confirmation fatigue The degradation of approval workflows where frequent prompts get rubber-stamped, turning thoughtful review into automatic acceptance. --- [All glossary… 0 Confirmation modal The confirmation modal is intentional friction. 1 Confused deputy The external ID is mandatory. 2× Connection pool exhaustion The state where all database connections are held and new requests queue. 1 Connection-pool math The calculation of whether available database connections will exhaust under load, the primary diagnostic for database bottlenecks during traffic spikes rather than CPU saturation. 1 Connector interface The provider-neutral abstraction behind ITSM ticket execution, exposing a neutral status category, assignee resolution and assignment. 1 Content path The route a customer's LLM request and response actually travel. 1 ContractRevision The optional rule interface an author increments when a rule's behaviour changes: a threshold, a lookback window, or an added or removed condition. 1 Control mapping The link between a technical rule and the compliance control it evidences. 1 Conversation breakdown If conversation breakdown signals are present, plan an off-site or facilitated session to reset. 1 Cooldown The minimum interval a scaling policy waits before acting again. 1 Cost allocation method A strategy for distributing shared infrastructure cost back to consuming teams based on usage, headcount, or another proportional metric. 1 Cost approval threshold A spend limit configured in CI/CD that requires extra review or sign-off when an infrastructure change would exceed it, preventing ungated cost growth. 1 Cost Breakdown card The dashboard card that shows cost split several ways within one widget, switched by a toggle rather than by moving between reports. 1 Cost commander handoff The transition of the cost-incident commander role from one person to another to prevent decision fatigue during a long incident. 1 Cost estimate Event Readiness shows a cost estimate before commit. 1 Cost Explorer AWS Cost Explorer. 1 Cost flow The movement of spend between two groupings, shown as a Sankey. 1 Cost incident compromise The bounded trade a cost incident commander makes between killing a runaway immediately and investigating first. 1 Cost isolation A reporting view that keeps per-account or per-resource costs distinct and visible rather than aggregated into one number. 1 Cost of detect-only The money that keeps billing between a finding being made and somebody acting on it. 1 Cost of downtime The financial impact per unit of time, usually per hour, when a service is unavailable, combining lost revenue and other business impact. 1 Cost ownership Cost ownership lives with the team that uses the resource. 2× Cost rollup The aggregation of costs across multiple accounts or resources into a single total, typically for org-wide financial reporting. 1 Cost runaway A sudden, unexplained increase in cloud spend that signals a potential incident requiring immediate investigation and possible remediation. 1 Cost SEV A cost problem serious enough to be run as an incident rather than as FinOps work. 1 Cost shape The pattern or trajectory of cost over time for a workload or initiative, used in forecasting and capacity planning. 1 Cost source Which of the two cost columns a figure came from: rack rate `cost_usd` or billing `actual_cost_usd`. 1 Cost source label A report indicator showing whether the underlying cost data is post-discount billing from cloud APIs or calculated rack rate. 1 Cost trend The direction and rate of change in spend over a period. 1 cost_allocation_daily Internally, ZopNight computes daily allocations into a single cost_allocation_daily table with a dimension_type column. 1 Cost-per-X Unit economics is the practice of dividing cost by a business denominator: Monthly Active Users (MAU), orders, requests, tenants, anything that scales with revenue or value, to… 2× Cost-recovery vs quality category The distinction between rules that directly cut spend, cost-recovery, and rules addressing governance, security, or reliability debt, quality, which pay back through avoided incidents. 1 costColumn The resolved cost expression that prefers billing cost where a row exists and falls back to rack rate where it does not. 1 Coverage The share of eligible usage a commitment applies to. 2× Coverage trend The tracking of tag-coverage percentages over weeks or quarters to show whether tagging discipline is improving or declining. 1 CrashLoopBackOff The Kubernetes state where a container repeatedly starts and fails, with growing delays. 1 Crawl stage The first maturity level, where the organization has cost visibility through dashboards and reports but lacks team-level cost ownership and action. 1 Crawl-Walk-Run A three-stage FinOps maturity model where Crawl is visibility only, Walk is optimization that decays, and Run is sustained operational cadence. 1 Credential rotation The periodic renewal or replacement of long-lived cloud access credentials, favoring modern patterns such as assume-role and Workload Identity Federation. 1 Critical severity A finding level indicating security risk or major cost waste that requires same-day response. 1 Cron expression The five-field pattern defining when a schedule fires. 2× CronJob suspend The Kubernetes action of pausing a CronJob's schedule to prevent workload runs during specific windows. 1 Cronstrue The preview is generated by the cronstrue library (the industry standard for cron-to-prose conversion). 1 cross_region A blast-radius edge type derived from connection resources carrying both a source and a target resource id. 1 Cross-account credential A role another account may assume, used instead of handing over long-lived keys. 1 Cross-account dependency A relationship where a workload in one cloud account relies on a service in another, requiring coordinated scheduling. 1 Cross-account group A resource group whose members span more than one cloud account, with a single schedule attached. 1 Cross-AZ traffic Network traffic between availability zones, which is billed. 2× Cross-cluster group A resource group spanning multiple Kubernetes clusters so one schedule applies across cluster boundaries without per-cluster duplication. 1 Cross-region egress Network traffic leaving one cloud region for another, incurring per-GB charges that compound significantly at scale. 1 Cross-stage anti-pattern A structural FinOps problem that can appear at any maturity stage and tends to worsen as the organization advances. 1 Cross-team role An RBAC role with allResources set true that grants access across the entire organization rather than to a single team's resources. 1 CSV upload One of the three ways to get your own business numbers into ZopNight: you upload a file. 1 CUD The usual abbreviation for **Committed Use Discount**, Google Cloud's commitment mechanism. 1 CUR AWS Cost and Usage Report (CUR). 1 CUR 2.0 AWS Data Exports' Cost and Usage Report version 2, an opt-in per-resource billing source read from the customer's S3 bucket instead of Cost Explorer. 1 Curated mapping The top tier of the IAM import translation staircase, where a known cloud managed policy or predefined role maps to a deliberately chosen ZopNight policy set. 1 Currency reconciliation Converting cloud bills from multiple currencies into one reporting currency using date-specific exchange rates so totals match the invoices. 1 Cursor command A reusable AI-agent instruction file saved in the .cursor/commands/ format that teams invoke by name to run a consistent workflow. 1 Cursor MCP Connecting ZopNight's MCP server to the Cursor editor so an agent can query cost, recommendation, and audit data, with the PAT supplied through an environment variable reference… 1 Cursor pagination Paging with an opaque marker rather than an offset. 1 Custom role The system-role design is a deliberate trade. 2× Custom sequence The custom sequence runs strictly in order. 1 custom_recommendation The table holding findings produced by user-authored watch policies, separate from the built-in `recommendations` table. 1 Customer-execution rule A recommendation, such as the Bedrock rules, that ZopNight can only surface and quantify because the actual fix requires customer-side code or config changes; ZopNight stays… 0 Customization Changing a shipped preset for local needs. 1
59 terms
Daily billing Actual cost pulled from the provider's billing APIs, lagged roughly 24 hours. 1 Data residency A regulatory or compliance requirement that data for certain customers stay in a specific region or cloud, which is a common reason orgs run a tactical second cloud or split accounts. 1 Database denylist The hardcoded set of resource types ZopNight refuses to auto-mutate regardless of configuration. 2× Databricks auto-termination Databricks' own idle timeout, which terminates a cluster after a quiet period. 1 Databricks Cluster A Spark compute cluster inside a Databricks Workspace that runs jobs and interactive notebooks, discovered by ZopNight as a schedulable target and usually the main Databricks cost… 1 Databricks Job A Databricks scheduler that runs work on a cluster. 1 Databricks Workspace The top-level Databricks tenant, per region with its own URL and authentication, that contains Clusters, Instance Pools, and SQL Warehouses as schedulable child resources. 1 Date-specific exchange rate The FX rate as of the specific date of a charge, used to convert a non-USD cloud bill to USD, because there is no single exchange rate and using today's rate for a past charge… 1 Day 90 review The 45-minute assessment at the end of a 90-day maturity move-up plan that checks whether the plan's specific, measurable goals were met, and which doubles as the kickoff for the… 1 Day card The unit of the recommendation History drawer: one card per day, down a continuous spine, each carrying its own activity feed. 1 Day-of-week field The cron field that sets which days a schedule fires, numbered 0 to 6 with Sunday as 0. 1 DB event readiness The monitor-only mode for databases during a traffic event, where ZopNight surfaces recommendations (raise connection limits, add read replicas, pre-warm caches) for a DBA to… 1 db_access edge A blast-radius edge inferred from a shared security group on AWS, a shared network on GCP or a shared subnet on Azure. 1 Deallocate The Azure VM state in which compute billing stops. 1 Decision matrix The 'right path' depends on context. 0 Decision tree The exception applies when steps 1-3 of the decision tree have already been done. 1 Decomposition The decomposition is what makes the response proportionate. 1 Dedicated bot user A purpose-created account whose credential a system uses, rather than a person's. 1 Deep link A URL landing on a specific filtered view rather than a page's default. 1 Default dashboard The one dashboard every organisation designates as its landing page. 1 Default tags A provider or IaC feature applying a tag set to every resource a stack creates. 1 Default-deny The policy model is default-deny. 1 Defense in depth Layering multiple independent controls so no single failure grants unauthorized access, for example gateway-level RBAC enforcement that blocks a request before the backend sees… 0 Degraded status A connection or discovery status indicating a cloud account or discovery process is partially failing rather than fully working, typically routed as a WARNING-severity notification. 1 Demo-env audit ZopNight schedule per demo environment. 1 Demo-prod environment A production-like environment kept for sales demos, customer showcases, training, and investor pitches, scheduled for business hours plus on-demand start because its audience is… 1 Denominator Unit economics is the practice of dividing cost by a business denominator: Monthly Active Users (MAU), orders, requests, tenants, anything that scales with revenue or value, to… 2× Denylist A list of what is forbidden, with everything else permitted. 1 Dependency warning The alert ZopNight raises when you attach a schedule to a resource that something else depends on, such as a Databricks cluster with jobs due to run in the off-hours you just chose. 1 Deployment (AI Gateway) A registered model instance on the hosted LLM fleet. 1 DeploymentConfig OpenShift's older deployment primitive, predating Kubernetes Deployments. 1 Derived tag A virtual tag whose value a tagging policy computes from the resource's own fields. 3× Detach Detaching does NOT change the resource's current state. 1 Diffuse responsibility The state where a cost is everyone's and therefore nobody's. 1 Diffusion of responsibility The state where an alert reaches several people and each assumes another is handling it. 1 dimension_source The field on a tag recording where its value came from: a real cloud tag, a ZopNight assignment, or a tagging policy derivation. 2× Dimensional cascade Investigating a cost anomaly by moving from the broadest dimension to the narrowest (org-level, cloud-account, resource-group, resource) to find the specific resource driving the spike. 1 Dimensional redundancy The pattern where a cost shift between teams nets to no org-level change, so ZopNight suppresses the offsetting team-level anomalies as noise while still firing org-level and… 1 Direct attribution Assigning a cost to an owner from the resource's own tags, without a split rule. 1 Discount stack The layers of price reduction applied to a line item: enterprise agreement, commitment, sustained use and credits. 1 Discovery cron The scheduled sweep that re-reads a cloud account's inventory. 1 Dispute resolution Chargeback systems often start simple and become Byzantine. 1 Domain allowlist The trade-off: OAuth has no built-in domain restriction. 2× Double-lever scheduling Scheduling cuts compute hours, and fewer hours means both less cost and less carbon. 1 DR drill A rehearsed failover to a disaster-recovery environment. 1 Drafting vs executing The distinction between using an AI agent to draft artifacts like memos, tickets, and incident comms (where agents win) versus taking action, which the read-only agent does not do. 1 Drift A cloud-side state change ZopNight detected but did not initiate. 1 Drift detection Watching for tags in the cloud drifting away from what your policy or your code says they should be. 1 Drift detection cadence The 6-hour discovery cron cadence at which ZopNight catches tag drift within the day, paired with a weekly review to keep drift from accumulating and hold tag coverage at 95%+. 1 Drift rate How often cloud state diverges from what was declared or expected, measured over a period. 1 Drift resolution Reconciling detected tag drift between the cloud's tags and ZopNight's expected values via one of three paths: trust cloud, trust ZopNight, or re-evaluate. --- [All glossary… 0 Drift response pattern The appropriate remediation for an IaC drift event once it is classified by source, whether intentional, accidental, or unauthorized manual changes that diverge from Terraform,… 1 Drift trigger A state-history trigger value (drift: cloud-side) indicating the cloud resource's state changed outside ZopNight, distinguishing it from schedule, manual, override, and… 1 Drill-down Navigating from a broad cost view into a specific resource, for example clicking a Sankey node in Cost Flow and using the breadcrumb to answer a question in under 60 seconds. 1 Driver analysis Explaining what factors would push a forecast higher or lower (feature launches, growth-rate variance, one-time projects) so a forecast band is communicated honestly rather than… 1 Driver-based forecasting Forecasting from the business quantities that actually cause spend, such as orders or active tenants, rather than extrapolating the spend curve. 1 Dry-run evaluation A stateless routing check that reports which tier and model a prompt would reach without calling anything or incurring cost. 1 DST handling ZopNight interpreting crons in the schedule's IANA timezone so a cron fires at the same local clock time year-round, automatically absorbing daylight saving transitions without… 1 Duty cycle The fraction of time a resource actually runs. 1
43 terms
EC2-Other The AWS bill line item absorbing EBS volumes, snapshots, NAT Gateway data processing, elastic IPs and data transfer. 1 Edge type The kind of relationship between two resources in the blast-radius graph: db_access, routes_to, attached_to, triggers, member_of or cross_region. 1 editable=false The flag marking a policy the UI will not let a customer change, used for the categories where a change would be unsafe rather than merely unusual. 1 Edition rate The per-credit price for a Snowflake account, which varies by edition. 1 Editor ZopNight ships with three system roles: Viewer, Editor and Admin. 1 Effective discount The discount an organisation actually captures, not the one on the rate card. 5× EffectiveCost The FOCUS column, and the AWS CUR equivalent, expressing amortized cost with upfront commitment fees spread across the hours they cover. 1 Egress Network traffic leaving a cloud or crossing a zone boundary, which is billed. 1 Elastic IP AWS charges $0.005 per hour ($3.60 per month) for any Elastic IP that is not attached to a running instance. 1 Eliminate waste The first and fastest optimization lever: stop paying for things nobody uses, such as scheduling non-prod off-hours, terminating idle resources, releasing orphan storage, and… 1 Enforce One of the two available responses to a budget overrun: bring the spending back inside the budget, by stopping resources or blocking actions. 1 Engineering preset A ZopNight dashboard preset for day-to-day platform team use, featuring resource health, schedule execution status, recommendations to triage, and anomaly detection. 1 Enterprise Discount Program Layer 6, Enterprise Discount Program (EDP). 1 Entity ID The SAML config is stored in the customer's tenant database, encrypted at rest. 1 Env-var loading Passing a secret such as a ZopNight token to an assistant through a shell environment variable, written in the config as a reference like ${env:VAR} rather than as the value itself. 1 Environment prediction The retired auto-tagger's inference of a resource's environment (dev, test, stage, prod), returned with a confidence score for the customer to accept or reject. 0 Environment schedule A schedule pattern defined per environment type (dev, test, stage, prod), based on when each environment is actually used, then rolled out, monitored, and refined. 1 Ephemeral demo environment A demo environment provisioned per demo and torn down after use, distinct from a persistent demo-prod environment that runs on a business-hours plus on-demand schedule. 1 Equal split Dividing a shared resource's cost evenly across its owning teams, using shareCount. 1 Error class triage Classifying a failed auto-remediation into one of three classes, user_action (customer self-fixes, e.g. missing IAM permission), transient (wait and retry), or system (escalate),… 1 Escalation chain Each budget can have multiple thresholds: percentage levels of the budget that trigger a notification when spend crosses them. 2× Escalation matrix The mapping from severity to who is contacted and how fast. 1 ESG narrative A carbon report framed for leadership and investors that turns the cloud carbon footprint into a tracked KPI, adapted per audience (CEO, sustainability team, investors) rather… 1 ESG reporting Reporting a company's environmental, social and governance performance, of which cloud carbon is one input. 1 Evaluate Running a policy against an input to produce a decision without applying it. 1 Event catalogue The static set of subscribable notification event types, surfaced to the Alerts matrix as key, label and category across eight categories. 1 Event lifecycle The defined states an event-readiness plan moves through, from draft to scheduled, executing, complete and rolled back. 1 Event log The record every autoscaler policy keeps of what happened to it and what it did. 1 Event log retention The per-policy event log an autoscaler maintains of all lifecycle and scaling actions, which serves as the diagnostic surface for explaining why scaling behaved a certain way. 1 Event readiness Pre-scaling infrastructure ahead of a known traffic event and returning it afterwards. 1 Evidence panel The composite score balances multiple signals; the evidence panel exposes the math. 1 Exclusive membership A resource can be attached to at most one schedule at a time. 2× Executive preset A ZopNight dashboard preset for leadership and finance, showing high-level cost trend, top costly resources, budget health versus forecast, and savings over time, with no… 1 Exit clause A contract term governing how an org can leave a share-of-savings commitment vendor arrangement, evaluated when deciding whether such a vendor fits. 1 Expected event A cost anomaly with a known, documented cause such as a marketing campaign or planned launch, which the severity-times-expectedness matrix treats as an event rather than an… 1 Expected requests model The demand model an event-readiness plan sizes against. 1 Expired override An override that has passed its expiry time and no longer suspends the schedule, shown on the Overrides page with a relative-time display such as 'expired 30m ago.' 1 Expiry Overrides are for time-bounded exceptions. 1 export.ready The notification event fired when a cost-report, audit-log or recommendation export completes, carrying the signed download link. 1 ExpressRoute Azure's dedicated private network connection between on-premises and Azure that bypasses the public internet, with its own pricing model. 1 External authentication An OpenShift cluster configuration that replaces the built-in OAuth server with an external identity provider. 1 External ID The external ID is mandatory. 2× ExternalId A shared secret included in a cross-account role's trust policy. 0
30 terms
Fail closed Defaulting to the restrictive outcome when evidence is absent or ambiguous. 2× False positive guards Design choices that reduce false alarms, such as requiring multiple signals before flagging a resource as abandoned, or using soft budget alerts instead of hard enforcement… 1 False precision Reporting a figure to more accuracy than its inputs support. 1 Filter dimension One of the audit log's queryable fields (user, path, status, date, and similar) that lets an investigator narrow thousands of entries to the few directly relevant to a forensic or… 1 FindingObservable The single resource key a posture rule declares its finding fired on, re-read at verification time. 1 Fingerprint The stable identifier for a problem, composed of organisation, resource and rule type, used to de-duplicate tickets. 1 FinOps Foundation The cross-vendor industry body publishing the FinOps Framework, its capability model and the FOCUS billing specification. 2× FinOps lifecycle The FinOps Foundation's three iterative phases of cloud financial management: Inform, Optimize, and Operate. 1 FinOps preset A ZopNight dashboard preset for the dedicated FinOps practitioner, featuring the cost flow Sankey, team-level showback, budget versus spend per team, tag coverage trend, anomaly… 1 Floor A minimum threshold below which findings are suppressed, such as the low-savings floor on non-orphan recommendations. 1 Floor commit The commitment strategy of buying reservations or savings plans to cover only the predictable steady-state floor of usage, while covering peaks with on-demand or spot capacity. 1 FOCUS FinOps Open Cost and Usage Specification. 1 Force off A manual override stopping a scheduled resource outside its schedule. 1 Force on A manual override starting a scheduled resource outside its schedule. 1 Force on / force off The two override types that suspend a schedule's firing in one direction. 1 Force-on override An override (override_type=1) that keeps a resource or group ON during a window, causing the schedule's stop crons to be ignored; its counterpart is force-off. 1 Forecast Conflating them produces dysfunction: people argue about budget when they should be discussing forecast; alerts get treated as enforcement when they are notifications; forecasts… 2× Forecast accuracy How close a forecast turned out to be, measured after the period ends by comparing what was predicted against what was spent. 2× Forecast log Run hybrid forecasting quarterly. 1 Forecast template A structured per-team form used in bottom-up forecasting, where each team forecasts resource by resource, accounts for planned events, and submits to FinOps for aggregation. 1 Forensic query An audit log query, enabled by full request and response body capture, that answers a specific investigation question with complete detail rather than just noting that an action… 1 Forgotten account A low-usage cloud account with no clear owner, often created for a past experiment, that is a candidate for consolidation into a parent account. 1 Forgotten resource A long-running resource nobody remembers, the single most common cause of cost anomalies (around 25%), showing up as gradual cost drift over weeks with no new resources. 1 Four-layer compliance The four independent controls a security team can point at for assistant access: the organisation-level switch, which is off by default, the write tier, the user's own role, and… 1 Freeze window A defined period during which schedules do not fire and resources stay in whatever state they are in, usually running. 1 Frontend gate If a frontend gate were to disagree with the gateway (e.g., frontend cached an old policy set), the worst case is a 403 from the gateway and a corresponding 'Access restricted'… 1 Frozen baseline The before-picture of a resource captured when a recommendation is emitted and never recomputed. 1 Full response logging An optional audit setting that captures full MCP response bodies for compliance; it is off by default because it increases audit log volume 10-50x and puts sensitive cost data… 1 Functional tagging Reorg-proof tagging that labels a resource by what it does or which business function it serves rather than by the team that currently owns it, so tags survive org-chart changes. 1 FX rate The currency conversion rate applied to a cost figure. 1
23 terms
Gap (schedule) An uncovered time window in a schedule, spotted on the 24-hour weekly grid before saving, that would otherwise leave resources running or stopped against the intended coverage. 1 Gateway The v3 consolidation merged the table to a small set of stable, user-facing core entities. 1 Gateway check The authorisation decision made at the API gateway, which is the authoritative one. 1 Gateway enforcement The pattern of resolving every authorisation decision at the single ingress that already owns authentication, RBAC and routing. 2× Gating criteria The conditions a write capability must satisfy before it is exposed over MCP: reversibility, a bounded blast radius, an audit trail, and no path to widening access. 0 GCP Folder A grouping node in the GCP resource hierarchy (Organization to Folder to Project) that holds projects and enables policy inheritance, the GCP counterpart to an AWS Organizational… 1 Geographic shift Moving a workload to a different region. 1 Global search The cross-surface search over resources, recommendations and settings. 1 Governed override An audited exception to an IaC policy decision. 1 gp3 A bill row is not the same as a 'resource.' A single EC2 instance generates compute rows (EC2-Instance), storage rows (EBS:VolumeUsage.gp3, EBS:SnapshotUsage), network rows… 1 GPU scheduling Pausing GPU instances during off-hours when training jobs are intermittent rather than running them 24/7, typically capturing 60 to 90 percent of cost savings for ML training workloads. 1 Graduated authority CDCR's act layer expressed as a ladder rather than a switch: notify, then propose, then act on an allowlist, then act with a resource-aware gate. 1 Granted / denied / unknown The three permission states the discoverer reports. 1 Graviton AWS's ARM-based instance family, cheaper per unit of compute than comparable x86. The migration cost is architecture compatibility rather than price, which is why the decision is… 1 Grid intensity API A real-time or forecast API (such as electricitymaps.com or WattTime) that reports the carbon intensity of a region's electrical grid, enabling carbon-aware scheduling of flexible… 1 Grid mix Cloud workloads consume electricity. 1 Group attachment Assigning a schedule, budget, or notification rule to a resource group so every member inherits it automatically, instead of re-attaching per resource. 2× Group metadata The descriptive fields (name, description, budget, tags) that organize a resource group so future engineers understand its purpose and cross-group policies can apply. 1 Group-read grant The optional directory permission, Cloud Identity on GCP or Microsoft Graph on Azure, that lets IAM import read group membership rather than only group existence. 1 Grouped Account dropdown A multi-select filter on the Resources page that organizes cloud accounts by provider (AWS, GCP, Azure) so a large multi-cloud estate stays navigable past the point a flat… 1 Grouped Type dropdown The resource-type filter organised into nine categories: compute, Kubernetes, serverless, database, storage, networking, data and analytics, ML and AI, and messaging. 1 Growth rate The percentage a company's spending is expected to grow over the forecast period. 1 Guardrail signal A recommendation whose value is a loss that has not happened yet, so it carries no savings figure. 1
25 terms
Habit formation Turning a practice into something that happens without being scheduled. 1 Half measure A partial change that carries most of the risk and little of the benefit. 1 Hallucination An agent answering from its own reasoning instead of calling the available MCP tools, producing made-up numbers that do not match the actual data, which trust-but-verify… 1 Hardcoded safety A safety mechanism such as the database denylist embedded directly in application code rather than configuration, making it non-bypassable and auditable to guarantee protection… 1 Headline number The single key metric presented first in a report to leadership (for example cost-per-paying-user), followed by drivers and forecast, so the message lands in about a minute rather… 1 Headroom factor A safety multiplier (typically 1.3 to 1.5x for event capacity planning) applied over the calculated minimum capacity to buffer for scaling delays and demand spikes, set higher for… 1 Hidden costs Bottom-up forecasting reverses the top-down approach: each team forecasts their own needs, and the FinOps function aggregates the results into the org total. 1 Hide vs Placeholder The split: ZopNight defines the security policy per widget; customer chooses how to render denied widgets (hide vs placeholder). 1 Higher-severity-wins The anomaly-detection rule that when percent-deviation and z-score methods disagree on severity, the higher level is reported, so no anomaly gets downgraded. 1 Historical accuracy How close past forecasts turned out to be, tracked over time. 1 Historical proportions Top-down forecasting starts with the org's total trajectory and allocates down to BUs and teams using historical proportions. 1 History drawer The per-recommendation timeline showing generated, viewed, bookmarked, applied, dismissed, reopened and closed events as day cards. 1 HMAC verification Authenticating an inbound webhook by checking a keyed hash of its body against a shared secret. 1 Host network mode A Kubernetes configuration where pods use the host's network namespace directly instead of an isolated interface, a legacy pattern often correlated with older workloads and cost waste. 1 Hosted control plane A ROSA topology in which Red Hat manages the control plane outside the customer's account. 1 HPA The Kubernetes Horizontal Pod Autoscaler. 1 HPA (Horizontal Pod Autoscaler) HPA (Horizontal Pod Autoscaler) automatically scales pod replicas based on CPU, memory, or custom metrics. 0 HPA pause/resume The mechanism where ZopNight pauses a Horizontal Pod Autoscaler during a scheduled off-period so scale-to-zero can drop replicas, then restores the HPA's active state on resume. 1 HPA stabilization window A Kubernetes parameter controlling the time window over which the Horizontal Pod Autoscaler averages metrics before scaling, preventing rapid oscillation between min and max… 1 HPA target The utilization percentage (typically 65 to 70 percent for CPU) the Horizontal Pod Autoscaler aims to hold by scaling replicas, where a target set too high causes latency during… 1 htpasswd identity A username-and-password identity provider on an OpenShift cluster. 1 Hybrid account structure A cloud account layout that splits resources by both team and environment (for example team-A-prod, team-A-stage), giving the strongest isolation at the highest operational… 1 Hybrid forecast A cost forecast that combines top-down projections from the growth plan with bottom-up team estimates, reconciles the gap through discussion to surface assumptions, and commits to… 1 Hybrid model A commercial arrangement that combines two approaches, such as a FinOps team handling optimization breadth while a share-of-savings vendor specializes in commitment management. 1 Hybrid pattern A scheduling approach combining a fixed window with a demand signal, used where a workload is neither reliably idle nor reliably busy. 1
27 terms
IaC drift The gap that opens when somebody changes something in the cloud console instead of in the code. 1 IaC tag enforcement Validation rules built into Infrastructure-as-Code CI pipelines that reject resource definitions missing required tags before deployment. 1 IAM import The capability that reads AWS, GCP or Azure IAM principals and proposes equivalent ZopNight users, teams and roles. 1 IAM role ZopNight connects to AWS via an IAM role with cross-account assume-role trust. 1 IANA timezone The named timezone a schedule's cron is evaluated in, such as `Europe/London` or `Asia/Kolkata`. 1 Idempotency A property of an operation where running it many times has the same effect as running it once. 2× Idempotent import Re-running IAM import without duplicating anything, because the same principals resolve to the same entities. 1 Idempotent remove The Remove lifecycle operation that safely repeats on failure, restoring cloud-side state to its pre-ZopNight configuration without partial corruption. 1 Identity Provider Single Sign-On lets users authenticate once against a trusted identity provider (IdP) and access ZopNight without managing a separate password. 1 Idle workload shape One of seven distinct Kubernetes idle patterns distinguished by replica state, traffic, CPU usage, pod state, suspension status, or endpoint backend presence. 1 ImageStream OpenShift's abstraction over container image references. 1 Immutable template A preset dashboard configuration that cannot be edited directly; customization requires cloning it into a new saved dashboard before making changes. 1 Inbound webhook The Jira-to-ZopNight direction of ITSM sync, registered automatically on connect where the token permits. 1 Incident commander Cost incident commander: a single person responsible for coordinating response during a cost SEV-1 or SEV-2 incident. 1 Incident communication cadence The structured message schedule during a cost incident, balancing urgency against noise through initial acknowledgment, periodic updates, resolution, and postmortem. 1 Indefinite-override hazard The risk that a time-bounded override forgotten after creation keeps running indefinitely, accumulating cost until someone notices quarters later. 1 Industry benchmark Comparable cost or carbon figures from peer companies or published averages that give context for judging whether an organization's position is favorable. 1 Inference profile An AWS Bedrock construct routing inference across regions or model versions. 1 Inform Inform is the first phase of the FinOps lifecycle. 1 Infracost Infracost (or equivalent) is the pre-merge equivalent of drift detection: it catches cost surprises early. 2× Infrastructure of infrastructure The supporting systems a team needs before it can run anything of its own: monitoring, logging, CI, secrets. 1 Instance Pool Pre-warmed compute that reduces cluster cold-start latency from 3 to 5 minutes down to 1 to 2 minutes by keeping ready-to-attach nodes available. 1 Inter-region transfer Data movement between geographically separate cloud regions that incurs bandwidth charges and must be counted in the total cost of a workload migration. 1 Internal billing The finance process that moves cloud cost onto a team's ledger. 1 Inventory scan The IaC governance mode that reads declared state and links it to discovered inventory, producing a managed-versus-orphan split. 1 isEstimated badge A confidence indicator on Event Readiness cost figures showing whether the number is calculated from pricing data (badge off) or a best-effort estimate given uncertain inputs… 1 ISO 27001 The international standard for information security management systems. 1
5 terms
18 terms
Label A key-value pair on a Kubernetes or GCP object. 1 Last Discovery timestamp A manual refresh takes 1-3 minutes for typical estates. 1 Last human operation The timestamp of the most recent manual change to a resource, drawn from CloudTrail or Activity Log, used to confirm that a stopped or idle resource is truly abandoned. 1 Layout The Cost Flow Sankey supports five preconfigured layouts, each cascading cost through different dimensions. 1 Layout JSON The serialized structure storing a dashboard's widget arrangement, configuration, and sizing, which enables layout persistence and sharing across users via URL. 1 Layout switch reset The automatic clearing of drill-down navigation when the Cost Flow layout is changed, since drill paths depend on the cascade structure being switched. 1 LCU ELB. Per LB-hour ($0.0225 ALB, $0.0225 NLB) plus per-LCU (load balancer capacity unit) for traffic processed. 1 Leavers report The set of principals present in ZopNight and absent from cloud IAM, surfaced by a quarterly re-import diff. 1 Legitimate growth The share of a cost increase explained by more business happening. 1 LeverAware The rule interface declaring what a recommendation's prescribed action actually changes. 1 Lifecycle email A one-time, customer-facing email sent once per organisation ever, through the notification service but not the alerting policy. 1 Lifecycle policy A rule that deletes backups and snapshots automatically once they reach a given age. 2× List cost Cost at published rates before any discount, the same quantity as rack rate. 1 List price A provider's published rate before any discount. 1 ListCost The FOCUS column for undiscounted list price. 0 Live calculated cost A cost figure computed now from rack-rate cards rather than read from a billing export. 1 Live computation Computing an aggregate at query time rather than serving a pre-built rollup. 1 Loop guard The mechanism preventing two systems that write to each other from ping-ponging. 1
57 terms
M&A tag collision The state after an acquisition where two organisations' tag taxonomies use the same key for different meanings, or different keys for the same meaning. 1 Machine pool A group of worker nodes in a ROSA cluster. 1 Managed vs orphan The split an IaC inventory scan produces: resources both declared in IaC and present in the cloud, versus resources present and undeclared. 1 Management Group Azure organizes by Management Groups at the top, then Subscriptions under them. 1 Manual action An immediate one-off start or stop that bypasses any attached schedule and requires explicit confirmation, used for incidents, ad-hoc demos, or unexpected capacity changes. 1 Manual refresh An on-demand re-read of a cloud account outside the discovery cron. 2× MANUAL trigger The state-history entry recording a change a person made by hand rather than one a schedule or policy made. 1 Mark applied The 'Mark Applied' button lets the customer note they've completed the action manually, so savings tracking works correctly. 1 Maturity model The FinOps Foundation uses a three-stage maturity model (Crawl, Walk, Run) to describe how a practice evolves. 1 MAU Unit economics is cost per unit of business value. 1 Max override duration The Max Override Duration is a per-resource and per-resource-group setting (max_override_duration_minutes) that caps how long any single override on that resource or group can be… 1 max_cost_delta An IaC cost guardrail bounding the *change* a plan makes rather than its absolute cost. 1 maxNodesTotal A cluster-autoscaler setting capping total node count, and one of the four editable on a ROSA hosted control plane alongside maxPodGracePeriod, podPriorityThreshold and… 1 MCP Model Context Protocol: the open standard letting AI clients call tools. 1 MCP audit log The record of every MCP tool call in ZopNight, capturing user identity, PAT used, tool name, filters, response metadata, and status. 1 MCP configuration Setting up the ZopNight MCP server for Claude Desktop involves three steps: create a PAT in ZopNight, edit Claude Desktop's MCP configuration file, restart Claude Desktop. 1 MCP_DISABLED error The error returned when a PAT attempts an MCP connection while the organization's MCP toggle is switched off by an admin, rejecting all such attempts. 1 MCP-native By 2026, every cloud cost vendor claims 'AI.' Differentiation is in the specifics: MCP-native (engineer's own AI tool), read-only by design (CISO-friendly), recipes for real… 1 Member list The set of principals attached to a team or organisation. 1 member_of A blast-radius edge derived from a resource's parent identifier. 1 Meta-audit Audit-log queries that track who is accessing the audit logs themselves, used for security monitoring and compliance to detect unauthorized access to sensitive records. 1 Metadata enrichment The discovery step where per-service API calls pull detailed metadata (instance type, tags, IOPS, Multi-AZ status) to supplement the initial resource inventory. 1 Metric catalog The aggregator's record of which metrics each resource type actually emits. 1 Metrics drawer The panel on a recommendation card showing the cloud monitoring data the rule actually read, from CloudWatch, Cloud Monitoring or Azure Monitor. 1 MetricsAware One of the interfaces a recommendation rule can implement, declaring that it reads cloud monitoring data as well as resource state. 1 Migration pilot An initial migration of a non-critical workload, typically 1 to 2 weeks, that validates latency, cost, and carbon impact before committing to a production migration. 1 Migration prompt A surfaced suggestion to move from a deprecated mechanism to its replacement, such as from the retired auto-tagger to Smart Tags. 1 Milestone Each milestone needs a single owner. 1 Minimum viable tag set The smallest tag set that makes attribution work, conventionally four keys: owner, environment, cost centre and application. 1 Mixed routing Sending each request to the cheapest model that can handle it, rather than sending everything to the most capable one. 1 ML cost driver A major cost contributor in ML workloads such as Bedrock inference, training compute, GPU instances, or provisioned throughput, each with its own optimization lever. 1 Mode auto-derivation Setting the autoscaling mode (monitor, recommend, or autopilot) automatically from the IAM credential's permission level, without manual configuration. 1 Model alias A per-key mapping from a friendly model name onto a specific org's deployment, applied by the gateway after the key's model check. 1 Model allow-list The set of models a virtual key may call. 1 Model Context Protocol MCP, Model Context Protocol, is an open protocol that connects AI assistants (Claude Desktop, Cursor, Codex, Claude Code) to data sources and tools. 1 Model routing Choosing which model answers a request. 0 Model selection Choosing the cheapest model that still meets the quality bar for a task, and routing simpler prompts to cheaper models. 1 Model selection lever The optimization technique of routing each inference query to the right model tier by complexity (Haiku for simple, Sonnet for medium, Opus for complex) to cut per-token cost. 1 Model unit The capacity unit for AWS Bedrock provisioned throughput, billed per hour. 1 Modernization path The suggested route from an old service or instance family to a current one, given alongside the cost difference. 1 Monitor mode In monitor mode, any existing cloud-side autoscaler continues to do its own native scaling; ZopNight just doesn't touch it. 1 Monitor-only database A database that Event Readiness does not auto-scale; instead it surfaces connection-pool and capacity recommendations for manual DBA action, given the higher risk of mutations. 1 Monthly close The 'monthly close' rhythm is what gives the chargeback its operational shape. 1 Monthly cost review The recurring month-end meeting among team lead, finance partner, and FinOps lead covering variance, top drivers, forecast, and budget adjustments. 1 Monthly settled Monthly settled. 1 Move-up action The single change that advances an organisation one maturity rung. 1 Multi-account Multi-account architecture is the practice of running workloads across several distinct cloud accounts (AWS accounts, GCP projects, Azure subscriptions) rather than one big shared… 1 Multi-approver pattern An approval-gate configuration requiring more than one approval before remediation runs, such as a two-person rule, any-of-team, or escalation chain for high-stakes changes. 1 Multi-cloud governance Keeping one set of cost rules across every cloud a company runs on, without building and staffing a separate version of it for each. 1 Multi-cluster permission scoping Configuring IAM credentials per cluster so ZopNight cannot modify a cluster it lacks credentials for, preventing silent cross-cluster access. 1 Multi-org config A single AI tool (Cursor, Codex) configured to connect via MCP to multiple ZopNight organizations using different PATs and organization IDs. 1 Multi-org setup An AI tool such as Claude Desktop configured with multiple MCP server entries, each pointing to a different ZopNight organization with its own PAT and org ID. 1 Multi-source synthesis An AI agent's ability to chain several MCP tool calls across audit logs, costs, and recommendations, then combine the findings into one coherent answer. 1 Multiplier model The multiplier model is simpler. 1 Mutating action ZopNight's audit log captures every mutating action (POST, PUT, PATCH, DELETE) performed through the API or the UI (the UI sends API calls under the hood, so the distinction does… 1 MVT (Minimum Viable Tag set) The core set of four mandatory tags (team, environment, cost_center, owner) that enable attribution, policy routing, and chargeback without fragmenting governance. --- [All… 0 MVT (Minimum Viable Tags) The core set of four mandatory tags (team, environment, cost_center, owner) that enable attribution, policy routing, and chargeback without fragmenting governance. --- [All… 0
22 terms
Name-confirmation Deleting a schedule requires name-confirmation (typing the schedule name into a confirmation field) to prevent accidents. 2× Namespace boundary The grouping layer inside a Kubernetes cluster, sitting between the cluster and the workloads, which you filter by and attach schedules and recommendations to. 1 NAT Gateway NAT Gateway on AWS is $0.045 per hour ($32.40 per month per gateway) plus $0.045 per GB data processed. 3× Native-first loading Loading a heavier engine only when it is genuinely needed. 1 Needs Attention The bottom tier of the IAM import translation staircase, holding grants the importer could not translate cleanly. 2× Net change threshold The percentage the combined cost across affected teams has to move before team-level anomaly alerts are allowed to fire, set to 20% by default. 1 Net of credits Cost with provider credits already applied. 1 Net-zero commitment An organization-wide sustainability goal to reach net-zero carbon emissions by a target year, which cloud scheduling and carbon-aware decisions contribute toward and which anchors… 1 Neutral status category A provider-independent classification of an issue's state, used instead of its display label. 1 Never-exposed list The capabilities no MCP write tier unlocks: RBAC, user management, organisation and cloud-account deletion, credential access and bulk actions. 1 Nine type categories The grouping of resource types in the Grouped Type dropdown: compute, Kubernetes, serverless, database, storage, networking, data and analytics, ML and AI, and messaging. 1 No backfill The K8s scheduler simply checks suspend before firing. 1 No clear cause The honest outcome the anomaly root-cause engine surfaces when it cannot attribute a cost spike to a confident single cause, instead of fabricating one, leaving the operator to… 1 No-fire A watch policy signal declining to fire because its metric series is absent or entirely gapped. 1 Non-prod fallacy The non-prod fallacy is a specific commitment-design mistake that recurs at almost every organization in the first FinOps year: buying reservations or Savings Plans for… 1 noStop prediction An auto-tagging output that predicts, with a confidence score, whether a resource can be safely stopped, serving as the critical 'is this safe to act on' signal that prevents… 0 not_observable A verification abstention reason for recommendations whose adoption nothing in the data can show, such as a request to write a policy document. 1 Notification channel A webhook-based destination (Slack, Microsoft Teams, Google Chat, or any URL that accepts a JSON POST) configured under Settings to receive ZopNight notifications on schedule… 1 Notification routing The practice of subscribing each notification channel to a chosen subset of event types and severities, so the right alerts reach the right channel and alert fatigue is avoided. 1 Notification suppression The lever for tuning notification volume down without losing signal, using rules such as suppressing routine auto-remediation events by resource so that only events warranting… 1 Numerator The denominator (M4.3.L1) tells you what unit of value you are dividing by. 1 Numerator change log A dated record documenting any change to a unit-economics cost numerator definition, including the old and new scope and the recomputation of prior periods, so that cost-per-unit… 1
45 terms
OAuth An authorization framework, frequently used as the basis for sign-in. 2× OAuth 2.0 An authorization framework (it grants access to resources), not an authentication protocol; the authentication layer built on top of it is OIDC. ZopNight supports OAuth-based… 0 OCM OpenShift Cluster Manager, Red Hat's control service for ROSA clusters. 1 Off-hours recovery The spend reclaimed by shutting non-production resources down outside working hours on a schedule, while keeping an on-demand or on-call wake-up path so the environment can be… 1 On-demand vs provisioned The choice between paying per-request on-demand pricing (scales with traffic, can spike) versus reserving provisioned capacity billed per hour (predictable, but over-pays during… 1 One-click apply A rule is only wired for one-click Apply once these checks pass; until then it stays advisory or guided. 1 One-hop traversal Blast radius's deliberate scope: direct neighbours only. 1 onlineModify The blast-radius behaviour family for resource types that update live without interruption, so all their connections classify as safe. 1 OPA Open Policy Agent, the engine evaluating custom Rego policies in IaC governance. 1 Open protocol A specification anyone can implement, as opposed to a vendor interface. 1 Open recommendation A recommendation that has been surfaced but not yet acted on, representing reclaimable spend that ZopNight sums into 'reclaimable' savings figures and highlights in views such as… 1 open_ticket effect A recommendation policy action that opens a ticket automatically when a matching finding is newly surfaced. 1 Operate Operate is the third phase of the FinOps lifecycle and the one that separates organizations that get FinOps from organizations that ran a FinOps sprint once. 1 Operate cadence The recurring rhythm in which findings are reviewed, assigned and closed. 3× Operate-led A FinOps practice organised around a recurring cadence rather than periodic projects. 1 Operate-led optimization An optimization model where cost work is sustained through a continuous weekly Operate cadence with clear ownership, contrasted with project-led sprints that end and leave savings… 0 Operating cadence ZopNight's onboarding includes a maturity self-assessment. 1 Operational floor The correct framing: CDCR handles the operational floor. 1 Optimize Optimize is the second phase of the FinOps lifecycle. 1 Ordered scaling Starting or stopping group members in a defined sequence, so dependencies come up before what depends on them. 1 Org ceiling A hard cap on total AI spend across an organisation's virtual keys, enforced by the gateway on the org's own minted team. 1 Org overhead Shared or unallocated infrastructure cost that sits at the organization level in the budget pyramid, rolled into the org budget alongside the sum of business-unit budgets rather… 1 Org settings The organization-level configuration surface where admins tune platform-wide behavior such as notification severity routing and the default dashboard, with values cascading down… 1 Org Tree A ZopNight Reports view that visualizes the cloud estate's provider-side hierarchy (AWS Organizations, GCP folders/projects, Azure management groups/subscriptions) as a tree with… 1 org-ai-skills repo A shared repository holding a team's reusable prompts, so that something one engineer worked out becomes something everyone can run. 1 Org-bound token A token tied to a specific organisation, required in addition to write tier 3 before irreversible MCP operations are reachable. 2× Org-level toggle A single admin-controlled switch (Settings, Org, API) that enables or disables MCP access org-wide, whose blast radius is bounded to MCP activity so disabling it leaves non-MCP… 1 Org-management grant A permission over roles, users, assignments or the organisation itself. 1 Org-shared dashboard The V1 dashboard model where every saved dashboard is visible to anyone in the org, with no per-user private dashboards, and per-user flexibility limited to bookmarking a… 1 Organizational unit A grouping container in a cloud provider's account hierarchy, such as an AWS Organizations OU. Hierarchy enables policy inheritance, which is what makes governance tractable at scale. 1 Orphan evidence The authoritative control-plane facts the Safety Gate accepts as proof a resource is unused: an explicitly false association flag, an unattached flag with a real detach dwell, a… 1 Orphan resource A resource present in the cloud and not declared in IaC. Orphans drift freely, are disproportionately likely to be untagged, and are not reconciled by the next apply, which is why… 1 Orphan storage Disks, snapshots and volumes that nothing uses any more and that nobody deleted. 1 Oscillation pattern Rapid back-and-forth scale-up then scale-down of an autoscaler caused by too short a cooldown reacting to transient metric spikes, fixed by setting a cooldown (typically 120 to… 1 Over-allocation Requesting more capacity than a workload uses. 1 Over-commitment The 'disaster' case is Scenario C. An RI bought for a workload that gets re-architected or migrated mid-term keeps billing the committed rate until expiry, on capacity nobody uses. 3× Overlap (schedule) A condition, visible on the 24-hour weekly grid, where redundant crons issue duplicate ON or OFF triggers for the same resource, which is non-destructive but noisy in the action… 1 Overlap rotation Minting a replacement credential before revoking the old one, so clients can be updated without a window in which nothing works. 1 Override A time-bounded suspension of a schedule's normal behaviour on specific resources. 1 Override + cluster The pattern of using the Override system to force-on a cluster (for example a Databricks cluster) for a few hours to handle an edge case, after which the schedule resumes when the… 1 Override archive The Overrides page 'Expired' tab, a convenience record of historical overrides useful for audit, pattern detection, and cost reconciliation, distinct from the Audit Log which is… 1 Override expiry The date after which a governance override stops applying. 1 Override scope The implicit fourth field of an override, determined by where it is set (an individual resource or a resource group), which governs the set of resources the override applies to. 1 Ownership spread The blast-radius risk component counting the teams and schedules touching the affected set. 1 Ownership sync Keeping a recommendation's owner and its linked ticket's assignee in agreement in both directions. 1
97 terms
P95 / P99 The 95th and 99th percentile of a metric's historical values, the 'typical-high' aggregations that capture recurring peaks that averages miss and single spikes (max) overweight. 1 P95 target The autoscaling smart-default target value set at P95 minus 5 percent, chosen so scaling triggers before saturation but not during normal load, avoiding both latency risk from… 1 Parametrized skill A reusable prompt written with placeholders for the team and the time window instead of hardcoded values. 1 Parent-child hierarchy A containment relationship between resources, such as a cluster and its node pools. 1 PAT A personal access token: a long-lived credential carrying the issuing user's identity, used for API and MCP access. 4× PAT description The free-text label on a personal access token. 1 PAT rotation Replacing a personal access token before it is compromised or expires. 1 Pattern analysis SMART action items. 1 Peak Hours preset The shipped schedule keeping capacity up only through a defined busy window. 1 Per-account sync Per-account sync status is in the Cloud Accounts page; if one account is failing while others are succeeding, only the failing account's resources are stale. 1 Per-audience framing Presenting the same cost data through the lens a specific audience can act on, such as ZopNight's Executive, Engineering, and FinOps dashboard presets, each a curated widget set… 1 Per-capability assessment Evaluating cloud permissions feature by feature rather than as a single pass or fail. 1 Per-env account structure A multi-account model that splits cloud accounts by environment (dev, stage, prod) regardless of team, which suits smaller orgs and strong environment-level compliance but blurs… 0 Per-environment account A multi-account axis isolating by deployment stage rather than by ownership. 1 Per-group budget A budget scoped to a resource group of multiple resources with coordinated ownership and lifecycle, whose threshold alerts land on the group's owner (often a team's tech lead). 1 Per-hour peak The maximum within each hour, over which watch-policy percentile and extreme aggregations are computed. 1 Per-instance capacity The resource ceiling of a single instance. 1 Per-key coverage A breakdown of commitment coverage by individual commitment rather than in total. 1 Per-org isolation The security property that each customer organization has a distinct credential namespace so one org's credentials cannot be queried, decrypted, or used by another org under any… 1 Per-problem dedup De-duplicating tickets on the stable problem identity rather than on the recommendation id. 1 Per-region pattern Organising accounts, schedules or policies by region. 1 Per-resource attribution Direct assignment of a cost to the single resource that incurred it, the simplest allocation case that anchors per-resource budgets on the owner who chose the resource's sizing. 1 Per-resource budget A budget scoped to specific resources rather than to an account or organisation. 1 Per-resource exception An exemption applying to one resource rather than to a rule. 1 Per-step delay Per-step delay specifies how long ZopNight waits after the previous resource is confirmed-started before starting the next. 1 Per-team account A multi-account axis isolating by ownership rather than by deployment stage. 1 Per-team account structure A multi-account model that splits cloud accounts by team across all environments, giving each team its own account for isolation and accountability at the cost of duplicating… 0 Per-team budget The total is the same spend; different budgets watch different slices. 1 Per-widget RBAC Some dashboard widgets surface data that not all users should see: audit logs, RBAC configuration, raw cost data scoped to other teams. 1 Percent deviation method A magnitude-based anomaly detection method that computes how far a day's cost sits from its 7-day rolling average as (X minus Y) divided by Y times 100, mapping the result to… 1 Periodic-workload pattern A usage shape where a resource sits mostly idle but spikes on a recurring schedule (monthly batch jobs, weekly reports, quarterly runs), which average-based right-sizing rules… 1 Permission visibility Showing which cloud permissions are granted, denied or unknown and what each unlocks. 2× permission.denied The notification event emitted by the discoverer when a cloud permission newly transitions to denied. 1 Persistent disk GCP's block storage volume charged per GB-month across SSD and HDD tiers, and one option (as regional persistent disks) for replicating at the storage layer to avoid cross-zone… 1 PersistentVolume A cluster-level storage resource in Kubernetes. 1 PersistentVolumeClaim A workload's request for storage in Kubernetes. 1 Phased rollout A speculative approach to enabling write actions where capability is introduced in risk-ordered phases (starting from today's read-only Phase 0) only once pre-conditions and… 0 Pickup rate The percentage of surfaced recommendations that actually get remediated rather than closed as won't-fix, a core measure of the cost of detect-only tooling that rises sharply under… 1 Placeholder pattern Some widgets (Audit Log, RBAC Summary, Cloud Accounts) are typically Admin-only; PAT Inventory is SuperAdmin-only. 1 Pod anti-affinity The Kubernetes scheduling constraint keeping replicas of a workload on separate nodes. 1 Pod-hours vs instance-hours Two clocks that run independently in Kubernetes. 1 Pod-level attribution Rolling up pod resource usage to per-team or per-app cost via Kubernetes labels, so cluster-level cost can be assigned to the workloads that actually drive it. 1 Policy Decision Point A component that emits an authorisation or compliance verdict without enforcing it. 1 Policy domain A namespace within the shared policy engine. 1 Policy entity One of the 15 fixed authorization objects in ZopNight's RBAC table that every protected endpoint maps to, where a role is a set of (entity, action) pairs the gateway enforces on… 2× Policy guardrail A configurable org-wide limit such as Max Override Duration that catches the canonical mistake, forever-overrides, without micromanaging legitimate ones, and serves as a… 1 Policy inheritance The model in which a Personal Access Token is user-scoped and carries exactly the user's RBAC policies, no more and no less, so the token can never do what its owner cannot. 1 Policy lifecycle The four idempotent, reversible operations on an autoscaler policy, Apply, Pause, Resume, and Remove, each mapping to specific cloud API calls under the hood. 1 Policy resolver The component selecting which policy applies to a finding, returning a single most-specific winner. 1 poolModify The blast-radius behaviour family for node pools, scaling groups and managed instance groups, where a modify recreates child nodes. 1 Postmortem A postmortem is a written record of an incident, its root cause, and the action items that prevent recurrence. 1 PR cost comment The output of a pre-merge cost estimation tool, posted on the pull request so reviewers see the monthly cost delta of an IaC change alongside the code diff, making cost a… 1 Pre-computed recommendations Recommendations evaluated on a cron cadence and stored in the database so the UI reads them instantly, trading roughly six-hour freshness for a sub-500ms read path that scales to… 1 Pre-destruction checklist Pre-destruction checklist for every destroy. 1 Pre-merge cost estimation Working out what an infrastructure change will cost before it is merged, and posting the figure on the pull request. 1 Pre-scaling Adding capacity before demand arrives rather than reacting to it. 1 Pre-warmed demo A demo-prod scheduling pattern that starts a demo environment about 24 hours before a scheduled demo and shuts it off afterward, recovering near-total cost between demos for… 1 Precondition A state that must hold before an action is allowed to run. 1 Predictable event A traffic spike with a known time and magnitude, such as Black Friday or a product launch, for which Event Readiness can pre-scale infrastructure beforehand instead of relying on… 1 Predictive scaling refusal ZopNight's refusal to Replace a PredictiveScaling policy, because the raw spec captures the configuration but not the trained predictor model, so a restore would create a… 1 Preset A ready-made schedule shipped with the product, covering one of the three patterns nearly every schedule turns out to be. 2× Preventive enforcement A team with 4 MVT tags and preventive enforcement spends ~10 hours/year on tag governance. 2× previous_config The prior cloud-side configuration saved on the policy event row during Apply, which ZopNight reads back to perform a safe rollback when a policy is removed. 2× previousConfig.existingPolicies The captured pre-existing cloud scaling configuration stored when an autoscaler policy is replaced, held as an opaque per-policy specification so Remove can restore it byte-accurately. 1 Priced plan A Terraform or OpenTofu plan with a cost figure attached to the resources it declares. 1 Pricing API The provider interface supplying rate cards. 1 Pricing gap DLQ The dead-letter queue holding cost records that could not be priced. 1 Pricing sync The refresh of provider rate cards. 1 PricingAware The capability that attaches a dollar figure to a recommendation by pricing its target against SKU and tier rates. 1 Primary plus tactical A multi-cloud pattern where one provider carries 60 to 90 percent of spend and hosts new workloads while a smaller secondary cloud (10 to 40 percent) serves a specific driver such… 1 Principal An identity in a cloud IAM system: a user, group, role or service account. 1 PrivateLink Quarterly network audit. 2× Privilege escalation Gaining permissions beyond those intended. 1 Privileged container A container running with elevated host access. 1 Progressive autonomy Widening what a system may do on its own as evidence accumulates, rather than granting it all at once. 1 Project-scoped MCP An MCP server defined in a repository's own .claude/mcp.json rather than in the global config. 1 Promotion Raising an imported user to a higher ZopNight role, done by hand from Settings as a separate audit-logged action. 1 Prompt caching A Bedrock technique that caches long repeated context such as system prompts or RAG templates across calls to cut input token cost by roughly 90 percent on the cached portion,… 0 Prompt injection An attempt to redirect an AI agent by planting instructions in content it reads. 2× Prompt scope The first required component of a team-specific prompt, stating exactly which resources, accounts, or tags apply (for example team=payment-team, accounts=prod-us, prod-eu) to fix… 1 Prompt-injection escalation An attempt to make an AI agent perform an action beyond what the requester is authorised for, by planting instructions in content the agent reads. 0 ProsperOps Share-of-savings vendors (ProsperOps, Spot.io, etc.) manage cloud commitments and charge a percentage of the verified savings they produce. 1 Proven floor The 'equivalent 24/7 instances' is what you commit on. 1 Provider default tags Tags applied automatically by an IaC provider block (such as Terraform default_tags or CDK Tags.of()) to every resource it creates, removing per-resource tagging boilerplate and… 1 Provider scoping A third policy segment narrowing an AI capability to one provider, generalising the resource-type scoping used elsewhere. 1 Provider weighting By provider weight. 1 Provisioned IOPS A cost added beyond baseline storage when I/O throughput is reserved in advance, measured in operations per second and common on RDS and io2 volumes, which can add significant… 1 Provisioned throughput Reserved model capacity on Bedrock, billed at a fixed hourly rate whether or not you use it, in exchange for a much lower price per request. 2× Provisioned vs consumption cost The distinction between cost incurred by capacity existing and cost incurred by usage. 1 Provisioner The ZopNight backend component that orchestrates cloud API calls when an autoscaling policy is applied, handling auth, error mapping, and retries while preserving the previous… 1 Published vs realized discount The gap between a commitment's headline discount and what an organisation actually captures after coverage and utilization. 1 PUE Power Usage Effectiveness, the ratio of total facility power to IT equipment power, used in carbon math to account for cooling and infrastructure overhead beyond raw compute draw. 1 Pull API In practice: most customers start with CSV for backfill, then Push API for ongoing. 1 Push API In practice: most customers start with CSV for backfill, then Push API for ongoing. 1 PV (PersistentVolume) The actual persistent storage resource allocated in a Kubernetes cluster, which sits in Bound, Released, or Failed state and can be orphaned to keep accruing storage cost if not… 0 PVC (PersistentVolumeClaim) A request for persistent storage in Kubernetes that binds to a PersistentVolume, and which can be orphaned with no pod using it while still incurring storage cost until detected… 0 PVC preservation The behavior where PersistentVolumeClaims stay bound and their data persists when a StatefulSet scales to zero or is paused, so storage cost continues even though compute is stopped. 1
7 terms
90 terms
Rack rate The public, undiscounted unit price from a provider's rate card, carried in the `cost_usd` column. 2× Raise One of the two available responses to a budget overrun: accept the spending and move the budget up, because the growth behind it was justified. 1 Rate optimize The third of four optimization levers, using commitments (Reserved Instances, Savings Plans, Committed Use Discounts, Spot) or negotiated discounts to pay less per unit, sequenced… 1 Rate-as-of A USD/INR exchange rate today is 83.20. A year ago it was 79.50. Six months ago it was 81.10. A cloud bill in INR converted to USD using 'today's rate' gives one answer; converted… 1 RBAC Role-based access control, expressed in ZopNight over a policy table of 15 core entities plus one for every capability that ships its own surface. 1 Reactive autoscaling gap The roughly 5-minute window where a reactive autoscaler lags a traffic spike (traffic arrives, autoscaler triggers, instances launch, instances become ready) leaving customers… 1 Read-only contract The guarantee that an assistant connected to ZopNight can read the estate and change nothing, which is the default state of every organisation. 1 Read-only contract verification Testing a destructive query like delete resource X against the MCP connection to confirm the agent refuses and redirects to the ZopNight UI, proving the connection is genuinely… 1 Read-only MCP An MCP surface exposing only reads, which is the default and the boundary most organisations should keep. 0 Read-only safety model The design where an agent reads freely and writes only through separately-gated tiers. 1 Realism discount A multiplier applied to a theoretical scheduling saving to account for overrides, exceptions and resources nobody attaches. 1 Realism factor The numbers are computed from the schedule's crons (active hours per week), the attached resources' rack-rate cost (from the pricing API, live), and a configurable realism factor. 2× Realization rate The share of estimated savings that verification confirms was actually captured. 1 Realized savings The saving verification confirms was actually captured, as opposed to the estimate. 2× Reason field Treat the reason field like a commit message. 2× Recent Activity tab The Recent Activity tab in the evidence panel shows operations against the resource, pulled from CloudTrail (AWS) / Cloud Logging (GCP) / Azure Activity Log via the daily… 1 Recipe A recorded prompt-and-tool sequence that produced a useful result, kept so it can be re-run rather than reconstructed. 0 Recipe library The set of ready-made prompts an assistant offers, so somebody meeting it for the first time has somewhere to start. 0 Recipe vs skill A recipe is a raw MCP tool-call pattern that chains calls and synthesizes output, while a skill is a reusable markdown wrapper that invokes recipes via a named slash command such… 0 Reclaim policy The Kubernetes setting deciding what happens to a PersistentVolume when its claim is deleted. 1 Reclaimable The Cost Flow Sankey has an optional savings overlay that highlights flows with reclaimable spend (open recommendations) and a separate unattributed teams overlay that highlights… 1 Recommend mode The middle tier of autoscaling autonomy where ZopNight surfaces scaling suggestions in the UI and the customer clicks Apply on each one, adding an approval gate before any scaling… 1 Recommendation card The unit a recommendation is read and acted on as. 2× Reconciliation Checking a number against a second source before acting on it. 3× Reconstructibility check The test run before ZopNight offers to replace an existing autoscaling policy: can this be restored exactly if it is removed later? Where the answer is no, Replace is refused… 1 Reconstructibility refusal ZopNight's refusal to Replace an autoscaling policy when byte-accurate restoration on Remove cannot be guaranteed, specifically policies with predictive scaling, step adjustments… 1 RecoverableFraction The measured share of a resource's hours that a recurring schedule could remove, used to price schedule-outcome findings. 1 Red diagnosis The investigation path for an overrun budget: open the budget detail, find the inflection point in Cost Trend, cross-reference the Cost Flow Sankey for the dominant dimension,… 1 Redacted field A sensitive audit log value replaced at storage time with a mask such as [REDACTED] or a partial like 1234 for tokens or jane@example.com for email, applied irreversibly for… 1 Redaction Before any body is written to the audit log, a redaction middleware scans for known-sensitive fields and replaces them with [REDACTED] (or a partial-mask equivalent). 1 Redirect URI The URL registered with an OAuth provider such as Google or GitHub where the provider sends the user back after authentication (for example… 1 Redis Stream A per-organization ordered log transport that captures mutating API calls in real time with microsecond precision, buffers them for about a minute, then syncs to MySQL for durable… 1 Redistribution suppression Staying quiet when one team's cost rises because another team's fell by the same amount. 1 Redundancy awareness Knowing how much spare capacity sits behind a resource. 1 Region carbon intensity The grams of CO2 emitted per kilowatt-hour of a cloud region's grid, ranging from around 30 in hydro-powered regions to roughly 700 in coal or gas regions, used to pick… 1 Rego The policy language used for custom IaC governance rules, evaluated by OPA in a sandbox with no network and no clock access. 1 Relative time display Rendering a timestamp as '3 hours ago' rather than as a clock time. 1 Reliability theatre Spending that looks like resilience and does nothing when it is needed. 1 Reliability tier A workload classification (typically Tier 0 revenue-critical through Tier 3 dev/test) that maps to SLO targets and decides whether reliability investments like multi-AZ,… 1 REMEDIATION_NOTIFY_TERMINAL The setting sending a notification on every terminal remediation outcome rather than only on failures. 1 Reorg-proof tag A tag value that abstracts away from org structure, such as team=marketing-acquisition for the function rather than a dated or person-named value, so it survives reorganizations… 1 Replace flow The Replace flow is safe in practice. 1 Replay Re-processing a delivered message. 1 Replica count math The reliability exponential where one pod gives about 99.9 percent uptime, two independent pods reach about 99.9999 percent for roughly 2x cost, and a third pod adds diminishing… 1 Report and ticket The pattern CDCR replaces: generate a findings report, file tickets, wait. 1 Request body capture Recording the full JSON request payload of a POST, PUT, or PATCH call in the audit log for forensic reconstruction, with sensitive fields redacted before the body is persisted. 1 Required check A CI status that branch protection treats as blocking. 1 Required policy The widget registry is in code; each widget exports its required policy. 1 Reserved Instance An AWS commitment to a specific instance configuration for one or three years, in exchange for a discount. 2× resolution_state The measured verdict on whether a recommendation was actually adopted, independent of the customer-set status. 1 Resource drill-down Navigating the Kubernetes hierarchy in ZopNight from cluster to namespace to workload type to a specific workload, typically three clicks from the estate-wide view to a single… 1 Resource Explorer 2 AWS's canonical multi-region, multi-service inventory API, and ZopNight's primary AWS discovery source. 1 Resource group A resource group is a named bundle of cloud resources. 1 Resource limit The maximum CPU or memory a Kubernetes pod may consume, above which it is CPU-throttled or OOM-killed, and which should sit near p99 actual usage plus a 30 to 50 percent buffer to… 1 Resource request The minimum CPU or memory reserved for a pod when it is scheduled, guaranteed to the pod and setting how many pods fit per node, making it the primary lever for Kubernetes cost… 1 resourceIds The RBAC scope field listing the specific resources a policy applies to. 2× Response body capture Storing the full JSON response returned by a mutating API call (POST, PUT, PATCH, DELETE) in the audit log with sensitive fields redacted at storage time, enabling forensic… 1 restartModify The blast-radius behaviour family for resource types that reboot on modification. 1 Restore window The 30-day period after a resource group is soft-deleted during which it can be recovered with members and attachments intact, after which the group is permanently purged. 1 Review cadence The data refreshes daily; the review cadence is weekly/monthly. 1 Revoke Returning an accepted Smart Tag to pending. 1 RI distribution columns The CUR fields describing how a reservation's benefit was spread across accounts. 1 RI exchange AWS's ability to swap a Reserved Instance of one type for another, such as m5.large to m6i.large, to recover value when architecture changes leave the original RI mismatched to… 1 RI marketplace AWS's resale platform where customers can sell unused Reserved Instances mid-term, typically at a 10 to 20 percent loss, rather than holding stranded capacity until expiry. 1 Right-sizing Changing a resource's allocated capacity to match measured demand. 1 Right-sizing throughput Tuning Bedrock provisioned throughput to match actual usage, typically sized at average load rather than peak and paired with on-demand for bursts, to minimize cost while holding… 1 Rightsize Changing a resource's size to match its measured demand. 1 Risk score The 0-100 blast-radius figure composed of impact severity ratio, environment weight and ownership spread. 1 ROI framing Presenting Event Readiness cost next to expected revenue impact, for example $5K cost against $80K of protected revenue for 16x ROI, to justify approval to Finance on value rather… 1 Role consolidation Periodically merging near-duplicate roles back into a maintained set. 1 Role description A one-paragraph field on a custom role that records the job to be done, the policies included, and the rationale, so a future reviewer understands intent and role proliferation is… 1 Rollback trigger A specific observation, written down in advance, that would cause a configuration change to be reverted. 1 Rolling test environment A test environment that exists only while a test runs, starting when the run starts and disappearing when it finishes. 1 Rollout pattern The sequence in which a change reaches an estate: a pilot, then a widening set, then everything. 1 Rollup Cost aggregation from the leaf level (account, project, or subscription) upward through a cloud hierarchy such as an AWS OU, GCP Folder, or Azure Management Group, producing… 1 Root cause The condition whose removal stops a problem recurring, as opposed to the symptom that surfaced it. 1 Root cause analysis Working from a symptom back to the condition whose removal stops it recurring. 0 Root cause vs symptom The postmortem distinction between the underlying system failure (root cause, such as a cleanup script that hid its failures) and the surface event (symptom, such as an engineer… 1 ROSA Red Hat OpenShift Service on AWS. It connects against an OCM organisation rather than the AWS account hosting it, carries its own provider value, and has nothing schedulable… 1 Route OpenShift's ingress abstraction, predating and parallel to Kubernetes Ingress. 1 Routing rule A rule mapping an event to the channels that should receive it. 2× RPO DR (Disaster Recovery) cost scales steeply with how fast you must recover and how little data you can lose. 1 RTO DR (Disaster Recovery) cost scales steeply with how fast you must recover and how little data you can lose. 1 RTO / RPO Recovery Time Objective, how fast recovery must happen, and Recovery Point Objective, the maximum tolerable data loss, which together set backup frequency and retention (tighter… 1 Rule category One of eight groupings of ZopNight's rule library (idle, rightsizing, schedule, orphan, compliance, discount, security, reliability, governance) that cluster findings by… 1 Rule version A record of a rule's behavioural revision, stamped onto recommendations raised under it. 1 rule_retired The status given to a recommendation withdrawn because its rule changed, hidden from the customer's own tab row and visible internally as Withdrawn. 2× rule_superseded The closure reason for an applied recommendation transitioned after a rule version change. 1 Rule-based prediction The retired auto-tagger's deterministic approach: combining signals such as naming patterns, existing tags, instance configuration, group membership and account context into a… 0 Run stage The FinOps maturity level where a weekly Operate cadence drives continuous incremental optimization so savings compound quarter over quarter instead of decaying. 1
147 terms
Safe rotation order The five-step PAT rotation sequence of generate new, update client config, restart client, verify new works, then revoke old, so the agent does not break if the new credential is bad. 1 Safe-to-auto A classification in the CDCR (Continuous Detect, Continuous Remediation) graduated authority model marking findings such as idle resources, orphans, and scheduled operations as… 1 Safety Gate The resource-aware check deciding whether an allowlisted lever may run automatically on a specific resource. 1 Safety margin The safety margin absorbs uncertainty. 1 SAML Security Assertion Markup Language, the assertion-based standard behind most enterprise SSO. ZopNight stores configuration per email domain with the certificate held separately,… 1 SAML 2.0 The assertion-based federation standard used for enterprise SSO. ZopNight stores the configuration per email domain in the customer's tenant database with the certificate held… 1 Sanity band The clamp holding a computed savings fraction inside a plausible range. 1 Sankey diagram An interactive multi-column cascade that visualizes cost composition flowing from one dimension to another (for example Provider to Account to Type to Team), where node size… 1 Sankey node A stage in a cost-flow diagram, where band width is proportional to spend. 1 Save on stop Capturing the pre-change configuration at the moment a change is applied, so it can be restored exactly. 1 Saved search A named, reusable audit-log query saved in ZopNight so a recurring forensic or compliance question (such as 'all RBAC changes this week') can be re-run against live data with one… 1 Savings decay The defining feature of Walk is savings decay: gains achieved in a sprint silently erode in the months that follow. 1 Savings estimator After resources are attached to a schedule, the schedule detail page displays a savings estimator. 1 Savings overlay The Cost Flow Sankey has an optional savings overlay that highlights flows with reclaimable spend (open recommendations) and a separate unattributed teams overlay that highlights… 1 Savings Plan An AWS commitment to a dollar-per-hour spend level rather than to a specific instance shape. 2× Scale to minimum Reducing a scaling group to its floor rather than terminating it. 1 Scale to zero Reducing a resource to no running capacity while keeping its configuration. 2× Scale-to-one Leaving a single small instance running instead of stopping a workload entirely. 1 Scaling action A recorded autoscaler decision, carrying the metric value that triggered it and the target it was compared against. 1 Scaling policy A scaling policy tells the cloud's autoscaler when to add or remove capacity. 1 ScalingLimited The HPA condition indicating the autoscaler wants to scale beyond a configured bound. 1 ScalingLimited condition The HPA state where the autoscaler wants to add replicas but cannot, typically because it has hit its configured max, which is the strongest signal that a workload is… 0 Scenarios ZopNight's Unit Economics report includes a forecast overlay using driver-based methodology by default. 1 Schedulable A property marking a resource type as capable of being attached to a start/stop schedule. 1 Schedulable resource A resource whose runtime does not need to be continuous (such as non-prod compute) and can therefore be started and stopped on an environment schedule, where most teams find 50 to… 1 Schedule A cron-based rule starting and stopping resources on a repeating window. 1 Schedule attachment Binding resources or a resource group to a schedule. 1 Schedule trigger A history-log entry showing a state change (Stopped to Running or the reverse) caused by an automated ZopNight schedule rather than a person, and the expected dominant pattern for… 1 Schedule-aware provisioned capacity Provisioned capacity whose sizing accounts for a known start/stop schedule. 1 Schedule-eligibility Whether a given workload can be put on a schedule at all. 1 Scheduling Stopping resources when nobody needs them and starting them again when somebody does. 1 SCIM The provisioning protocol, well-supported over SAML, that lets an enterprise IdP automatically create, update, and deactivate ZopNight users so account lifecycle is managed centrally. 1 Scope drift The gradual, undocumented change in how a unit-economics numerator is defined over time, which invalidates trend analysis because a percentage improvement is only meaningful if… 1 Scope selector The expression choosing which resources a watch policy applies to. 1 Scope state Which of the three RBAC scoping conditions a policy is in: no resource filter, an explicit resource list, or an empty list. 1 Scoped filter A dashboard or view filter constrained to a specific team or slice of the estate, used to give each cloned per-team dashboard its own team-bounded data. 1 Scoped scan token The narrow credential minted by IaC CI onboarding for a repository's scans. 1 Scoped token An Atlassian granular API token. 1 Scoped write A narrow, auditable, opt-in write action (like start or stop a VM, terminate a specific orphan) that does exactly one thing and nothing else even if the underlying credentials… 1 Secrets manager integration Storing agent and MCP credentials such as PATs in a dedicated secret store and having clients pull them from there, enabling automated rotation instead of hardcoded tokens. 1 Security-cost correlation The observation that some Kubernetes security configurations correlate with cost and reliability problems, so auditing security signals surfaces workloads that are both a risk and… 1 Sentinel resource id The synthetic identifier under which billing line items that match no discovered resource are stored. 1 Sequence rule The commitment-design discipline that says schedule first, then observe the post-schedule baseline, and only commit to that reduced floor, so you do not over-commit to capacity… 1 Sequenced execution Sequenced execution lets a group specify an ordering: storage tier first, compute tier second, app tier third (for start); reverse for stop. 2× Service account A non-human identity used by software. 1 Service Account (GCP) A GCP identity granted the organization-viewer role at the org level so ZopNight can discover all projects automatically, authenticated via Workload Identity Federation… 1 Service Control Policy An AWS guardrail attached at an Organizational Unit level that applies to every account beneath it, for example forbidding a region across all accounts in a production OU. 1 Service dependency handling The practice of preventing breakage when a scheduled resource is depended on by another service, resolved either by scheduling the dependent services together as a group or by… 1 Service principal An Azure AD application identity used to authenticate a non-human client, granted a role at the tenant or management-group level so ZopNight can discover the subscriptions in… 1 Service Principal (Azure) The Azure AD application registered with Reader role at the tenant or root management-group level, connected to ZopNight with tenant_id plus app_id plus secret, so ZopNight… 1 Service-specific cost Spend attributed to one cloud service rather than to a resource. 1 ServiceAccount token A Kubernetes-issued credential for a ServiceAccount. 1 ServiceName A FOCUS column naming the cloud service a line item belongs to. 1 Session permissions The resource scope worked out when a user logs in and held for the session, typically 8 hours. 1 Session token The ZopNight frontend uses a single hook, usePermission(), to decide whether to render an action. 1 Severity Severity is the lever for routing notifications correctly. 1 Severity ladder Five severity levels, each tied to an action timeline. 1 Severity override A per-event-class setting that replaces the default severity for a specific case, for example downgrading a dev-environment cost anomaly to warning or escalating a… 1 Severity ratio The dominant blast-radius risk component, computed as a ratio of affected and warning neighbours to the neighbour set rather than as a count. 1 Severity routing Using an event's severity, INFO, WARNING or CRITICAL, to decide where it goes, whether it wakes anybody, and how often it should arrive at all. 1 Severity tuning Adjusting the severity assigned to a rule or finding to reduce noise, so that only findings warranting real attention are escalated and low-impact ones stay quiet. 1 Severity-vs-urgency The distinction between severity, ZopNight's classification of an anomaly's magnitude, and urgency, the team's interpretation of business impact, which is why the same severity… 1 Shape 2 (no traffic) The idle-workload shape where Kubernetes pods are running with replicas but receive no inbound traffic, meaning they are costing money while doing no work, including stale pods… 1 Share-of-savings Share-of-savings vendors (ProsperOps, Spot.io, etc.) manage cloud commitments and charge a percentage of the verified savings they produce. 1 shareCount The divisor used to split a shared resource's cost equally across its owning teams. 1 Shared services account A cloud account holding the infrastructure several teams share, run by the platform team. 2× Shared services team A team owning infrastructure other teams consume. 1 Shared tagging module A reusable IaC module (for example a Terraform tagged_resource module) that larger orgs adopt to enforce consistent required tags across resources rather than tagging each… 1 Shared-services allocation The chargeback approach for costs that benefit multiple teams (such as shared DNS or overhead accounts), commonly charged to a shared-services team that owns the overhead and then… 1 Showback Reporting each team's cloud cost to that team without moving money. 3× SIEM A security information and event management system. 1 SIEM export Weekly MCP audit review (10 minutes). 2× SIEM integration Forwarding ZopNight's audit log to a security information and event management platform such as Splunk, Datadog, or Sumo Logic, typically via a scheduled job that pulls the… 1 SIEM webhook A notification route that mirrors the full audit log to a SIEM for compliance evidence collection, used by regulated organizations that need a complete record of remediation activity. 1 Signal weight A concept from the retired auto-tagger: the confidence value it assigned to each individual signal (naming patterns, existing tags, configuration, resource group, account context)… 0 Signed download URL A short-lived link to a completed export in object storage, surfaced on the originating page and emailed for long jobs. 1 Silent adoption A recommendation the customer acted on without telling the platform, showing as optimised with a verified-adopted verdict. 1 Silent overwrite When ZopNight encounters a target (ASG, VMSS, MIG, ECS service) that already has cloud-side autoscaling configured, two paths exist: adopt the existing configuration as-is, or… 1 Simplification sprint Run a quarterly chargeback complexity audit. 1 Single ownership SMART action items. 1 Single-fire-per-period The single-fire-per-period rule prevents alert spam. 1 Single-replica deployment A workload running as one copy with no spare. 1 Single-vendor lock Dependence on one provider to the point where leaving is impractical. 1 Size-scaling pattern A Databricks SQL warehouse schedule that runs a larger size during business hours and scales down to a smaller size overnight for occasional queries, best for prod with diurnal… 1 Skeleton crew The off-hours pattern of scaling a service down to a single replica (not zero) to keep it warm and reachable at minimal cost. 1 Skill A reusable, versioned prompt packaged as a file the AI client loads, parametrised so one definition serves several teams or windows. 3× Skill (Claude Code) A markdown file that Claude Code loads as a named command, letting a team invoke an embedded prompt by name so the same instructions run consistently every time, shifting prompts… 0 Skill changelog The dated list of version entries kept in a shared skill's metadata that records what changed in each release, including breaking changes, so users can see how the skill has evolved. 1 Skill deprecation The graceful retirement of a shared skill that has become obsolete (for example after an MCP tool is renamed or an output format changes), done deliberately rather than by silent… 1 Skill discovery How team members find shared skills to use, best served by a central, discoverable location (such as an org skill repo) so there is one place to look and duplication is reduced. 1 Skill frontmatter The YAML metadata block at the top of a skill file, delimited by triple dashes, holding fields like the one-line description shown in the menu and any parametrized args with their… 1 Skill maturity model The Level 0 to 6 roadmap for a team's skill library, from ad-hoc prompts (0) through personal, project-scoped, team-scoped, and org-wide repos (1 to 4) to CI testing with drift… 1 Skill quality gate The review a shared skill passes before anybody else adopts it: does it do what it says, is the description clear, are the parameters documented, is the output consistent, are the… 1 Skill sharing Choosing the right distribution mode for a skill, project-scoped in a repo, team-scoped in a per-team library, or org-wide in a single source of truth, and migrating from personal… 1 Skill versioning Tracking a shared skill's revisions with metadata and a dated changelog (including breaking-change markers) plus a quarterly review cadence, so users know what changed and can… 1 Skills (Claude Code) Claude Code's feature of custom reusable command files that, combined with the ZopNight MCP server, turn recurring cost workflows into parameterized team commands invoked by name.… 0 SKU ladder The catalog-diff pricing path (SKURates) the recommender uses when savings come from changing what you use rather than how you pay, as opposed to the commitment math path (TierRates). 1 skuRates The per-SKU rate structure used when pricing a finding. 1 SLA A service level agreement: a committed availability or latency target, usually with a consequence attached. 2× SMART action item A cost-postmortem follow-up written to be specific, owned by a single named person, and due-dated, since vague items rot while SMART items get done and prevent the same incident… 1 Smart defaults Statistically-derived starting values for a policy or autoscaler, computed from observed behaviour. 1 Smart Tag A virtual tag derived by a tagging policy from a resource's own fields, counting toward attribution inside ZopNight once accepted. 2× Smoke test A failing smoke test means: don't use agent-reported numbers in leadership presentations this week until fixed. 1 Snapshot The Idle EC2 rule (RC-001) computes savings using the full cost (compute plus storage plus snapshot), not just the EC2 row. 1 Snowflake credit The consumption unit for Snowflake compute, billed at a per-edition rate and consumed only while a warehouse runs. 1 Snowpipe Snowflake's continuous ingestion service. 1 SOC 2 An attestation report on a service organisation's controls. 1 Soft delete The recoverable delete lifecycle operation for a resource group, one of create, edit, soft-delete, and restore, so a removed group can be brought back rather than being… 1 Software Assurance A discount that the other clouds do not have. 1 Source field The wizard's adopt-or-replace prompt is on every Create flow for an autoscaler policy. 1 Spot Interruptible capacity sold at a steep discount, typically 50 to 90% off on-demand, that the provider may reclaim with little notice. 1 Spot burst A hybrid capacity pattern that commits to a base floor and uses spot or preemptible instances for stateless work above that floor, chosen when there is bursty demand and the… 1 Spot instance Deeply discounted compute (50 to 90 percent off) offered without a commitment but subject to eviction on about two minutes notice, fit only for stateless or interruption-tolerant… 1 Sprint-led An optimization practice organised around periodic projects rather than a recurring cadence. 1 Sprint-led optimization The Walk-stage operating pattern where a team runs one or two optimization sprints a year and achieves real savings that then decay over the following 6 to 12 months, contrasted… 0 SQL Warehouse Databricks' managed compute for SQL workloads. 2× SSO failure categories The four root-cause buckets that account for about 95 percent of SSO login failures (certificate, metadata drift, clock or timing, and user-side), which you classify first and fix… 1 SSRF guard The SSRF guard means customer endpoints must be on the public internet (or behind a public load balancer or API gateway). 2× Stable membership The property a resource group gives a schedule: the group is what the schedule is attached to, so resources can be added and removed underneath without anyone re-attaching anything. 1 Stale data Data explicitly known to be older than the current state. 1 Stale lock A heartbeat that has stopped advancing, indicating the owning process likely crashed. 1 Stale payload A response explicitly labelled as last-known data during a brief upstream outage, used instead of reporting zero. 1 Standalone connection A provider connected on its own credentials rather than riding an existing cloud account. 1 State history The per-resource record of state changes and who or what caused them. 1 State surgery Direct manipulation of IaC state (such as terraform state mv or import) that changes tracking without touching cloud resources, a moderate-risk operation where you must verify it… 1 Stateful classification The Safety Gate's test for whether a resource holds data, based on a managed data-service type, a non-empty engine specification, or a data tier. 1 StatefulSet StatefulSets are like Deployments but with pod identity guarantees: pods are ordered (sts-0, sts-1, sts-2) and bound to persistent storage via VolumeClaimTemplates. 1 StatefulSet checklist The safety checklist for scheduling a StatefulSet, which requires confirming that PVCs are non-critical or backed up and accounting for pod ordinal identity and per-pod persistent… 1 Stddev-based cooldown The autoscaling default derived from Welford's online standard-deviation computation over a target's historical metrics, part of the smart-defaults recommendation for min, max,… 1 Step adjustment limit The Replace-flow refusal threshold that blocks migration of a step-scaling policy with more than two step adjustments, because that raw spec does not reliably round-trip. 1 Step scaling A scaling policy applying different adjustments at different breach sizes. 1 Storytelling structure The four-section narrative (What happened, Why, What's next, and the Ask) used to translate unit economics for non-engineering audiences, leading with a single headline number and… 1 Stranded commitment A cloud commitment that no longer matches usage and has become a sunk cost rather than a saving, remediated where possible by exchanging it, selling it on, or letting it expire. 1 Structural fix A permanent, one-time change to process, data model, cadence, or ownership that resolves an anti-pattern at its root, as opposed to exhortation ('try harder') which produces brief… 1 Structural gap A persistent pricing-data gap that will not auto-resolve, typically caused by an unusual region and SKU combination missing from public price endpoints, requiring engineering… 1 Stuck job A process that consumes resources continuously on a single machine without completing (roughly 7 percent of cost anomalies), diagnosed by steady high consumption from one resource… 1 Sum of max De-duplicating savings per resource by taking the largest applicable lever rather than adding them. 1 Sunk-cost trap The cognitive bias where over-commitment on reservations creates stranded costs that are hard to unwind, leading teams to keep paying for unused committed capacity instead of… 1 SUSPEND / RESUME The Snowflake warehouse stop and start operations. 1 Suspend pattern A Kubernetes-native way to pause a CronJob by setting spec.suspend=true, which is non-destructive and instantly reversible, skipping scheduled executions while preserving… 1 Suspended CronJob A Kubernetes CronJob with spec.suspend=true that will not fire on its schedule, one of the idle workload shapes, which may be intentional (scheduled off by ZopNight) or forgotten… 1 Sustainable practice The compounding FinOps operating model achieved at the Run maturity stage, where a weekly Operate cadence makes savings build on prior quarters rather than decay, verified by… 1 Sustained use discount Google Cloud's automatic discount for compute that runs a large share of the month. 2× Sync-back Default: sync-back ON. Most teams want consistency between ZopNight and cloud. --- [All glossary terms](/resources/university/glossary) 0 system error A remediation failure class where a cloud API returned an unanticipated or unsupported state (for example a cluster requiring manual console deletion), flagged as a red alert with… 1 System role A user with the Editor system role can still be team-scoped so they only have Editor permissions within a specific team. 1 Systematic bias Bottom-up forecasting reverses the top-down approach: each team forecasts their own needs, and the FinOps function aggregates the results into the org total. 1
61 terms
Tabletop exercise Run a tabletop exercise monthly: pick a recent anomaly, walk through the matrix step-by-step, identify gaps, revise. 2× Tag The fix is tag policy as code, enforced at provision time (Terraform / CDK / Pulumi pre-commit hook) and audited continuously (the Auto-Tagging service flags drift; see T2.M2.8). 1 Tag attribution Tag attribution is the flexible attribution dimension. 1 Tag coverage The share of resources carrying a required tag key. 4× Tag Coverage widget The dashboard tile showing the share of resources carrying each required tag key. 0 Tag debt Tags accumulate over time. 1 Tag drift The gap that opens between a tag's expected value and its value in the cloud, once someone edits it outside IaC. A rising drift rate is a process signal rather than a tagging one:… 2× Tag inheritance Tags set high in a hierarchy being picked up automatically by everything beneath. 1 Tag migration pattern A process for updating tag values during reorgs, mergers, or structural changes while preserving cost attribution, covering rename (1:1 value mapping) and split (one value becomes… 1 Tag precedence The priority order applied when tag values are inherited from multiple scopes, where a resource-level tag overrides provider defaults and parent-inherited values, allowing… 1 Tag provenance The record of where a tag value came from: applied in IaC, set by hand, or derived by a tagging policy. 0 Tag taxonomy The documented set of allowed tag keys and the value patterns each accepts. 2× Tag-based membership A grouping pattern where resource-group membership is determined by matching resource tags (for example team=payment-api), letting a single schedule apply across multiple clusters… 1 Tag-selector group A resource group that spans multiple cloud accounts and is defined by tag selectors, so a single schedule attached to the group applies coordinated scheduling across those accounts. 1 Tagging policy A rule that enforces one tag key and derives its value from a resource's own fields. 2× Tags-as-code Treating tag policy as versioned code (for example tag-policy.yaml) with CI enforcement, review cycles, and automated drift detection, preventing tag debt the same way… 1 Target tracking A scaling policy holding a metric near a set point, with the adjustment computed by the provider. 1 target_spec The shape a resize recommendation asked for, stamped at emission and never recomputed. 1 Team authority Whether a team can actually decide how its own money is spent. 1 Team scope A role answers the question 'what actions is this user allowed to take?' A team scope answers a separate question: 'which resources are those actions allowed on?' The two are… 1 Team scoping Restricting a policy's effect to the resources a team owns. 1 Team-level anomaly A cost anomaly detected at the team dimension, subject to redistribution suppression so that cost merely shifting between teams without a net org-level change does not generate noise. 1 Team-level ownership Recording which team owns a resource, in ZopNight rather than only in a tag. 1 Team-specific prompt A prompt that carries your team's own context: which resources are yours, what to exclude, what you usually ask. 1 Tenant cascade The cascading edge-case handling for dashboard ownership, where deleting an org clears its default_dashboard_id, deleting a default dashboard forces reassignment first, and a… 1 terraform destroy A destructive Terraform command that deletes cloud infrastructure (optionally scoped with -target), carrying extreme production blast radius and requiring a pre-destruction… 1 Terraform plan A zero-risk, dry-run Terraform command that previews the changes an apply or destroy would make without touching cloud state, used to map blast radius before acting. 1 Test utilization The percentage of hours per week a test environment is actively running tests, where low utilization (under about 30 percent) signals strong fit for rolling test environments that… 1 The five components The parts of a well-formed recommendation: what, why, how much, how, and what it will affect. 1 The three showback tests The diagnostic checks for whether showback alone produces accountability, or whether chargeback's friction is warranted. 1 The three tests The checks for whether showback alone produces accountability: does the owning team see the number, can they change it, and do they discuss it on a cadence. 0 Theoretical savings The sum of every finding's estimate, before de-duplication, adoption and verification. 2× Threshold Each threshold fires once per period; the next threshold is the next conversation. 1 Threshold alert A budget alert that fires when spend crosses a configured percentage (50, 75, 90, 100, 110), acting as a conversation trigger that notifies humans to decide a response rather than… 1 Ticket link The stored association between a recommendation and its external ticket, carrying the state that drives bi-directional sync. 1 Tier (resource) A classification level in sequenced resource-group execution (Tier 1 storage and databases, Tier 2 compute, Tier 3 application and orchestration) that sets start order and the… 1 Tiered reliability A framework that matches reliability spending to business impact by assigning services to distinct SLO tiers (single-region 99 percent through active-active 99.999 percent), each… 1 tierRates The tiered rate structure for services priced in bands. 1 Time decay The gradual loss of savings after a one-off optimization project. 1 Time shift Moving work to a cheaper or quieter window rather than removing it. 1 Time Travel Snowflake's retention window allowing historical queries and restores. 1 Time-of-day filter A per-channel notification routing filter that limits delivery to specified windows (for example business hours on one channel, 24/7 for on-call), reducing alert fatigue by… 1 Time-to-remediation How long passes between waste being found and waste being fixed. 1 Tool call A single MCP invocation by an AI agent against ZopNight's API, logged in full in the audit trail (tool name, filters and parameters, result) to enable security monitoring and… 1 Top 10 cap A noise-reduction limit that caps anomaly notifications at the top 10 resources per org, per dimension, per detection run, while additional anomalies stay visible in the feed… 1 Top-down forecast The growth rate is the most-leveraged input to a top-down forecast. 1 Trace ID The identifier carried through every part of a single request, so one action can be followed across services. 2× Traffic-light signal Budget health surfaces as a traffic-light signal (green, yellow, red) visible at a glance on dashboards and reports. 1 transient error A temporary cloud API error (rate limit, 5xx, eventual consistency) that resolves on retry, which ZopNight auto-retries with exponential backoff up to three times with no customer… 1 Transit Gateway Quarterly network audit. 1 Transition A change in a resource's state, recorded with when it happened, what it changed from, what it changed to, and what caused it. 1 Triage The first pass over a fired anomaly, deciding whether it is an incident needing a response or an event to record and close. 1 Triage cadence The regular, typically weekly schedule on which recommendations are reviewed and sorted into apply, dismiss, or snooze decisions, preventing backlog accumulation. 1 Triage SLA The time a team agrees to take before somebody looks at a new alert. 1 Trigger column The trigger column on the state-history timeline answers the operational question 'who or what caused this transition?' Every transition carries one of five trigger types, with… 1 Trigger source Everything that changes a resource's state is recorded. 1 Truncation marker An explicit indication that a result set was cut short. 1 Trust but verify Treating an agent's numeric claims as a starting point to be checked against the source surface. 1 Trust cloud vs trust ZopNight The two resolution paths for tag drift, where trust cloud treats cloud-side values as the corrected source of truth and trust ZopNight reverts unauthorized cloud changes back to… 1 Trust domain The boundary within which a credential is meaningful. 1 Two-source cost model The two-source cost model is the architectural pattern ZopNight uses for cost data, and the recommended pattern for any FinOps practice: maintain both a live calculated cost (rack… 1
19 terms
Unattributed With tags, attribution flows from the resource. 1 Unattributed bucket The share of spend that reaches no owner: data transfer, taxes, fees, rows with no resource id and undiscovered services. 1 Unattributed overlay The view that marks, on the cost flow diagram, the spending that carries no team tag. 1 Unattributed spend Billing line items that match no discovered resource: data transfer, taxes, fees, rows with no resource id and undiscovered services. 1 Unblended cost The rate the account actually paid, without averaging across a consolidated family. 2× Unblended Cost label A cost-source label shown on report headers indicating that post-discount billing data is the active source, in contrast to the Rack Rate label which indicates costs calculated… 1 Under-allocation Requesting less capacity than a workload needs. 1 Unit economics Cost expressed per business unit, such as per order, per active user or per tenant. 1 Unit economics dashboard The surface where cost per business unit becomes visible and discussable, turning 'we have a metric' into a number a team sees on a cadence. 1 Unit economics overlay A cost-per-unit series drawn against a spend chart. 1 Unit metric A business quantity, such as orders or active tenants, that spend is divided by. 1 Update job The asynchronous mechanism applying a cluster configuration change, used for ROSA pool resizes and autoscaler edits through OCM. It works even on a cluster whose Kubernetes API is… 1 Uptime fold Rescaling a calculated cost to the hours a resource actually ran before pricing a finding against it. 1 URL persistence The property that drill and filter state is encoded in the URL, making a view shareable (paste the link and a teammate sees the same state), bookmarkable, and reload-safe. 1 Usage-based attribution Equal split is the default for three reasons. 1 usePermission() The frontend hook gating UI on a policy. 1 user_action error A remediation failure caused by a customer-fixable condition (missing permission, exceeded quota, resource in use, policy violation) that does not auto-retry and requires the… 1 User-Defined tab The Recommendations surface where watch-policy findings appear, separate from built-in recommendations. 1 Utilization The discount published on a commitment ('save up to 40%!') is the best case. 1
24 terms
V2 engine The catalog-driven recommendation engine, defined in capability YAML rather than Go rule code. 1 Validation The post-action check confirming a remediation achieved what it intended. 1 Vanity metric A metric that measures activity rather than business impact (for example 'reviewed 200 recommendations' or 'spent 40K') with no denominator or outcome context, making it non-actionable. 1 Vanity metrics Figures that look like progress and predict nothing. 0 Variable cost The cloud is variable cost. 1 Variable validation A Terraform feature that rejects a plan when a variable does not meet the rules you set, used to refuse a deployment that is missing its tags. 1 Variance analysis Notification routing per-threshold is configured in the budget itself: different audiences get different alerts (covered in L3). 1 Variance direction Whether a forecast miss was an over-forecast or an under-forecast, a distinction that matters because each has different business implications and calls for different calibration… 1 Variance review A period-end (typically quarterly) meeting that compares forecast against actual cost, quantifies the delta and accuracy, and analyzes drivers to feed the calibration loop for the… 1 Vault Where ZopNight keeps the credentials for connected cloud accounts. 1 Velocity How quickly findings move from surfaced to resolved. 1 Vendor lock-in The risk that leaving a share-of-savings vendor incurs high switching costs from knowledge transfer and setup overhead, mitigated by negotiating exit clauses (commonly a 90-day… 1 Verification bucket One of the seven signal classes verification routes a recommendation to, six observable and one that always abstains. 1 Verification checklist The fixed set of checks run against an assistant's connection before trusting it with real work. 1 verified_adopted The verdict recorded when the estate changed to match what a recommendation asked for. 1 verified_diverged The verdict recorded when the customer acted, differently from what was asked. 1 Viewer ZopNight ships with three system roles: Viewer, Editor and Admin. 1 Virtual key An org-issued API key pointing at the AI gateway rather than at a vendor, carrying a hard USD budget and a model allow-list. 2× Virtual warehouse Snowflake's compute unit, and the only schedulable Snowflake resource type. 2× virtual-key policy The RBAC capability governing AI virtual keys. 1 Visibility to accountability The progression showback is meant to produce: making spend visible to the team that owns it until the team acts without money changing hands. 1 Visibility-driven accountability The mechanism where cost visibility alone (per-team dashboards shown to leadership) changes team behavior without formal chargeback, working when teams care about cost, leadership… 0 Volume estimate The live count of recommendations a policy's conditions would match, shown before the policy is saved. 1 VPC endpoint A private route from a VPC to a cloud service, avoiding the NAT Gateway and its data-processing charges. 1
23 terms
Wake-for-job pattern A Databricks scheduling pattern where a cluster is configured to start just before a dependent job runs and stop afterward (for example waking 1:30 to 4 AM for a 2 AM nightly… 1 Walk stage The middle FinOps maturity stage of action without rhythm, where orgs run optimization sprints and achieve savings but watch those gains erode over 6 to 12 months for lack of a… 1 Warehouse sizing Selecting the right Databricks SQL Warehouse size (2X-Small to 4X-Large, roughly 1 to 256 nodes) based on concurrency and workload, which drives both cost factor and query… 1 Warn-only mode Running a gate so its decision is visible without blocking. 1 Wasteful overrun A budget overrun driven by waste (forgotten resources, runaway processes, unauthorized spend) rather than legitimate growth, which warrants enforcement such as killing resources… 1 Watch policy A user-authored metric-threshold recommendation, running on a separate engine from the built-in rules and surfacing on the User-Defined tab. 1 Webhook ZopNight notifications fire on schedule actions, override events, anomalies, and failures. 1 Weekend Scale-Down preset A preset schedule that stops resources for the weekend (midnight Saturday to Monday 8 AM) while running weekdays, yielding about 33.3 percent theoretical savings and suiting teams… 1 Welford's algorithm A one-pass method for computing running mean and variance. 1 Well-architected framework The AWS Well-Architected Framework, a review methodology built on six pillars: operational excellence, security, reliability, performance efficiency, cost optimization, and… 1 Widget config The stored specification of a dashboard tile: its query, grouping and visualisation. 1 Widget registry The widget registry is in code; each widget exports its required policy. 1 windowDays The observation period of a watch policy signal, from one to ninety days. 1 Won't-fix attrition The steady loss of findings that are never actioned and eventually stop being read. 1 Worker pool The bulk path uses a 4-worker pool to prevent burst load on the cloud provider's APIs. 2× Workload identity federation Federated authentication that exchanges a trusted identity for short-lived cloud credentials, removing the long-lived key. 2× Workload schedulability Whether a Kubernetes workload can be scaled to zero or suspended for cost, where Deployments, StatefulSets, and CronJobs are schedulable but DaemonSets, ReplicaSets, Jobs, and… 1 Workload-level scheduling The workload-level scheduling preserves the cluster while saving cost on non-prod. 1 WORM storage Write-once, read-many storage, used where records must be provably unaltered. 1 Write surface The UI is the highest-confidence write surface. 1 Write surface decision matrix The mapping from an intended change to the surface that should own it: the UI for one-offs, the API for scripted work, auto-remediation for allowlisted fixes, IaC for anything… 1 Write tier The per-organisation setting bounding which class of MCP mutations is reachable: none, metadata-only, reversible or irreversible. 3× Write-with-approval Mental model: agent reads, human writes. 0
3 terms

Start with the bill.

Foundations takes about five hours. The first lesson is nine minutes.

Open curriculum. No login. No paywall. 290 lessons across 7 courses, three publicly verifiable credentials. Read it on the train, take the exam on a Saturday, list the credential on your résumé Monday.

5h median time to finish Foundations
0 logins, paywalls, or marketing forms
open curriculum, public credential verifier
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·