Simulation Mode
Run any policy as a dry-run: Cumulus computes the whole decision and records what would happen, without executing. For a whole account or a single resource.
Cumulus reads usage metrics from your AWS accounts every ~1 minute via CloudWatch, estimates the cost and climbs a graduated enforcement ladder — from alert to stop — with simulation, an explanation for every decision and an audit trail. Tools that depend on the billing report (CUR) take hours to notice the same spend.
Born from one semester in production at a Brazilian college, with 49 student accounts governed.
You don't hand over the power to act on day one. First you watch what Cumulus would do; then you enable the ladder one rung at a time.
A cross-account role in your account gives Cumulus read access to CloudWatch metrics. In Edu, student accounts are created through AWS Organizations in a dedicated OU with protective SCPs.
Cumulus computes every full decision — tier, action, targets — and records what would happen, without executing. You see the explanation for each one before giving it the power to act.
Choose how high each environment may climb: prod stays at observe/alert, dev may reach throttle, sandbox may reach stop. Actions never skip rungs.
Five rungs, from no-action to stop. Each account's ceiling is configurable, and the effective action is always the lesser of what the tier asks for and what the mode allows.
Visibility and cost estimate. Zero action.
default in prod
Notifies the owner when the threshold is crossed.
default in prod
New spend above the limit needs approval before it proceeds.
suggested in staging
Selectively blocks the creation of expensive resources.
suggested in dev
Stops non-prod resources and applies DenyAll.
sandbox, explicit opt-in
effective action = min(requested tier, mode ceiling)
An account or resource tagged prod never receives an automatic throttle or stop: the action is downgraded to require-approval.
A global operator switch that suspends all enforcement. No per-resource override can turn it back on.
Every rung above Alert is enabled explicitly by you, per account, tag or environment.
Governance that reacts to the bill arrives after the spend. Cumulus reacts to usage.
Every decision can be simulated, explained and audited — and raw data never leaves your account.
Run any policy as a dry-run: Cumulus computes the whole decision and records what would happen, without executing. For a whole account or a single resource.
Every action ships with its why: which metric crossed which threshold, which tier resulted and which guardrail applied. Rendered in 12 languages.
Each record keeps who configured, who or what triggered and what was decided, hash-chained. Removing or editing a record mid-chain becomes evident — not even the actor can erase their own trace.
In the FinOps edition, collection and enforcement run inside your AWS account. Only aggregated metrics reach Outrun's control plane.
Same detection, estimation and enforcement engine. Different stakeholders and defaults.
For course coordinators, faculty and institutional IT
Each student gets their own AWS account, with a budget set by the institution and hard enforcement in the sandbox. Students learn cloud with the cost trail visible; the college is never surprised by the bill.
For platform, FinOps and security teams
Governance over the accounts you already have, with enforcement tiers per account, tag or environment, production guardrails and an audit trail. The data plane runs in your account.
To observe, a cross-account role with read access to CloudWatch metrics. You start in Observe or Simulation Mode with no action permissions at all. Enforcement permissions come in only for the tiers you explicitly enable, per account, tag or environment.
It doesn't. An account or resource tagged prod never receives an automatic throttle or stop: the action is downgraded to require-approval. There is a global break-glass that suspends all enforcement and that no per-resource override can turn back on. And the effective action is always the lesser of what the tier asks for and the ceiling configured for that environment.
In Edu, student accounts are created through AWS Organizations in a dedicated OU with protective SCPs, and Cumulus governs them from the institution's account. In FinOps, the data plane (collection and enforcement) is deployed into your account and only aggregated metrics reach the control plane. Onboarding details are agreed with you during early access.
In preparation. Today access is direct with Outrun, as early access.
Twelve languages, aligned with the AWS Console, with native PT-BR. That includes the explanation for each enforcement decision, not just the interface.
On request, as early access. Edu and FinOps are priced separately. Talk to us and get a proposal for your scenario.
A 30-minute demo with the real panel, in Simulation Mode, on a scenario close to yours.
Cumulus is an Outrun Data Solutions product. AWS and CloudWatch are trademarks of Amazon Web Services, Inc.