DEVOPS
Daily AWS cost-spike digest from the Cost and Usage Report
Each morning this workflow scans yesterday's AWS Cost and Usage Report in BigQuery for per-service spend spikes versus a trailing baseline.
How it runs
The automated pipeline, trigger to output.
- TriggerDaily schedule after CUR partition loads
- ActionQuery per-service spend deltas vs trailing baselineBigQuery
- LogicKeep lines over percent and dollar floors
- LogicMap each spike to its owning team via tags
- OutputPost ranked spend-spike digest to SlackSlack
What it does
Runs a scheduled sweep over the AWS Cost and Usage Report (CUR) loaded into BigQuery. For each service-and-account line, it compares yesterday's spend to a trailing 14-day median, flags statistically meaningful jumps, maps each to its owning team via a tag lookup, and ships a single ranked digest.
When to use it
Use it when you want a proactive daily pulse on cloud spend instead of reacting to pages. Ideal for FinOps or platform teams who already export CUR into BigQuery and tag resources by team.
How it works
- 1A daily schedule fires after the previous day's CUR partition has loaded.
- 2A BigQuery query computes per-service spend deltas against the trailing baseline.
- 3A logic step keeps only lines exceeding both a percentage and absolute-dollar floor.
- 4Each flagged line is joined to an owning-team mapping pulled from cost-allocation tags.
- 5The digest is sorted by dollar impact, biggest first.
- 6The ranked digest posts to the FinOps Slack channel with per-team callouts.
Set it up
What you configure once, before turning it on.
- 1Connect BigQueryDatasets, queries, schemas.
- 2Connect SlackChannels, DMs, threads, mentions.
- 3Set each agent's modelWe leave models unset so you pick the tier — fast + cheap, or top-quality.
- 4Tune it to your dataEdit the prompts, filters, and field mappings so it matches how your team works.
- 5Test, then turn it onRun once against a sample, confirm the output, then enable the trigger.
More DevOps workflows
Slack-approved pause for idle Hugging Face Spaces
On a daily scan it finds idle paid Spaces and posts an interactive Slack approval; on approve it pauses the Space and logs the decision to a GitHub issue audit trail.
Block costly Hugging Face Space hardware upgrades in PR review
When a pull request changes a Space's hardware config, it estimates the new monthly cost and posts a GitHub PR comment that flags upgrades crossing a budget ceiling.
Hugging Face Spaces idle-runtime sweep with auto-pause
On a schedule, scans all Hugging Face Spaces for ones running idle past a threshold, pauses them to stop billing, and posts a Slack summary with the estimated monthly savings.
Open a Zoom war-room from a Datadog multi-alert storm
When a Datadog monitor crosses a critical threshold, this workflow dedupes against active incidents, and only for a genuinely new outage it creates a Zoom bridge.
Auto-spin a Zoom war-room when PagerDuty hits SEV-1
When a PagerDuty incident escalates to a critical severity, this workflow creates a dedicated Zoom meeting and posts the bridge link to the incident's Slack channel so responders…
Spin up a war-room on demand from a Slack slash command
When an engineer runs a Slack command, this workflow creates a Zoom bridge, opens a tracking Sentry-linked incident, files a Linear issue for follow-up.
Run it inside a business
This workflow drops into a full company template. Import the org, and this is one of the playbooks its agents run.

Run this workflow in your colony.
14-day trial. No DevOps. No Sales call. Provisioned in under a minute.
