DEVOPS
Attribute daily cloud-spend spikes to the owning team and file a Linear ticket
Each morning it scans yesterday's BigQuery billing export for cost spikes per service, maps the offending service to its owning team via a label lookup.
How it runs
The automated pipeline, trigger to output.
- TriggerDaily schedule after billing export loads
- ActionQuery per-service spend vs 14-day baselineBigQuery
- LogicKeep spikes above % and $ thresholds
- ActionLook up owning team for each flagged serviceBigQuery
- OutputFile Linear ticket assigned to owning teamLinear
What it does
Runs a scheduled scan of your GCP/cloud billing export in BigQuery, finds services whose spend jumped sharply versus their trailing baseline, attributes each spike to the team that owns the service, and files a Linear ticket so the cost has a clear owner instead of disappearing into the monthly bill.
When to use it
Use it when cloud cost overruns keep getting noticed too late and nobody is sure which team caused them. Best for orgs with a BigQuery billing export and per-service ownership labels (cost-center or team tags).
How it works
- 1A daily schedule fires after the billing export lands.
- 2A BigQuery query computes per-service cost for yesterday and the trailing 14-day daily average.
- 3A logic step keeps only services where yesterday exceeded the baseline by both a percentage and an absolute-dollar floor (filters out noisy tiny services).
- 4A second BigQuery lookup joins each flagged service to its owning team from the ownership/labels table.
- 5For each attributed spike, a Linear ticket is created, assigned to the owning team, with the delta, baseline, and top contributing SKU in the body.
Set it up
What you configure once, before turning it on.
- 1Connect BigQueryDatasets, queries, schemas.
- 2Connect LinearIssues, projects, cycles, triage.
- 3Set each agent's modelWe leave models unset so you pick the tier — fast + cheap, or top-quality.
- 4Tune it to your dataEdit the prompts, filters, and field mappings so it matches how your team works.
- 5Test, then turn it onRun once against a sample, confirm the output, then enable the trigger.
More DevOps workflows
Slack-approved pause for idle Hugging Face Spaces
On a daily scan it finds idle paid Spaces and posts an interactive Slack approval; on approve it pauses the Space and logs the decision to a GitHub issue audit trail.
Block costly Hugging Face Space hardware upgrades in PR review
When a pull request changes a Space's hardware config, it estimates the new monthly cost and posts a GitHub PR comment that flags upgrades crossing a budget ceiling.
Hugging Face Spaces idle-runtime sweep with auto-pause
On a schedule, scans all Hugging Face Spaces for ones running idle past a threshold, pauses them to stop billing, and posts a Slack summary with the estimated monthly savings.
Open a Zoom war-room from a Datadog multi-alert storm
When a Datadog monitor crosses a critical threshold, this workflow dedupes against active incidents, and only for a genuinely new outage it creates a Zoom bridge.
Auto-spin a Zoom war-room when PagerDuty hits SEV-1
When a PagerDuty incident escalates to a critical severity, this workflow creates a dedicated Zoom meeting and posts the bridge link to the incident's Slack channel so responders…
Spin up a war-room on demand from a Slack slash command
When an engineer runs a Slack command, this workflow creates a Zoom bridge, opens a tracking Sentry-linked incident, files a Linear issue for follow-up.
Run it inside a business
This workflow drops into a full company template. Import the org, and this is one of the playbooks its agents run.

Run this workflow in your colony.
14-day trial. No DevOps. No Sales call. Provisioned in under a minute.
