For the complete documentation index, see llms.txt. This page is also available as Markdown.

Governance Recommendations

This topic describes how to optimize cloud costs using asset governance.

Recommendations help kickstart your journey with governance. Essentially, Harness run certain policies behind the scenes to generate recommendations for your governance-enabled AWS accounts. These policies not only help to cut costs but also increase the efficiency of your system. On the Governance Overview page, Harness showcases recommendations that will benefit you to save costs on associated resources. You can click on any recommendation to view its details.

Recommendations By Harness

Cloud Asset Governance provides valuable recommendations, but when it comes to operationalizing them at scale, it might become challenging. Additionally, when using shared cloud accounts across teams, project-level recommendations might not work out. With Granular Recommendations, Governance recommendations will now be generated at the individual resource level, ensuring greater granularity and actionable insights for both custom and out-of-the-box (OOTB) recommendations. This enhancement simplifies implementation and tracking, allowing customers to take more effective action on governance recommendations at scale.

Recommendation: delete-unattached-aws-ebs

Description: Delete all ebs volumes which are unattached

Policy Used:

policies:
  - name: delete-unattached-aws-ebs
    resource: ebs
    filters:
      - Attachments: []
      - State: available
    actions:
      - delete

Savings Computed: The policy identifies a list of resources on which potential savings are calculated by summing up cost of each resource for last 30 days.

Permissions Required:

  • Dry Run:

    • ec2:DetachVolume

    • ec2:DescribeVolumes

  • Run Once:

    • ec2:DetachVolume

    • ec2:DeleteVolume

    • ec2:DescribeVolumes


Recommendation: list-low-request-count-aws-elb

Description: List ELBs with low request count

Policy Used:

policies:
  - name: list-low-request-count-aws-elb
    resource: elb
    description: List ELBs with low request count
    filters:
      - type: metrics
        name: RequestCount
        statistics: Sum
        days: 7
        value: 7
        missing-value: 0
        op: less-than

Savings Computed: The policy identifies a list of resources on which potential savings are calculated by summing up cost of each resource for last 30 days.

Permissions Required:

  • Dry Run:

    • cloudwatch:GetMetricData

    • elasticloadbalancing:DescribeLoadBalancers

  • Run Once:

    • cloudwatch:GetMetricData

    • elasticloadbalancing:DescribeLoadBalancers


Recommendation: migrate-gp2-to-gp3-aws-ebs

Description: Migrate gp2 volumes to gp3

Policy Used:

policies:
 - name: migrate-gp2-to-gp3-aws-ebs
   resource: ebs
   filters:
    - VolumeType: gp2
    - modifyable
   actions:
    - type: modify
      volume-type: gp3

Savings Computed: The policy identifies a list of resources on which potential savings are calculated by summing up cost of each resource for last 30 days. Then, 20% of that sum is taken as the savings.

Ref: https://aws.amazon.com/blogs/storage/migrate-your-amazon-ebs-volumes-from-gp2-to-gp3-and-save-up-to-20-on-costs/

Permissions Required:

  • Dry Run:

    • ec2:DescribeVolumeAttribute

    • ec2:DescribeVolumesModifications

  • Run Once:

    • ec2:DescribeVolumeAttribute

    • ec2:ModifyVolumeAttribute

    • ec2:DescribeVolumesModifications


Recommendation: delete-volume-absent-aws-ebs-snapshot

Description: Delete snapshots with no volumes

Policy Used:

policies:
  - name: delete-volume-absent-aws-ebs-snapshot
    description: Find any snapshots that do not have a corresponding volume.
    resource: aws.ebs-snapshot
    filters:
      - type: volume
        key: VolumeId
        value: absent
    actions:
      - delete

Savings Computed: The policy identifies a list of resources on which potential savings are calculated by summing up cost of each resource for last 30 days.

Permissions Required:

  • Dry Run:

    • ec2:DescribeVolumes

  • Run Once:

    • ec2:DescribeVolumes

    • ec2:DeleteSnapshot


Recommendation: stop-unused-aws-rds

Description: Stop unused RDS database

Policy Used:

 policies:
  - name: stop-unused-aws-rds
    resource: rds
    description: Stop unused RDS database
    filters:
      - type: value
        key: DBInstanceStatus
        value: available
      - type: metrics
        name: DatabaseConnections
        statistics: Sum
        days: 7
        value: 0
        op: equal
    actions:
      - stop

Savings Computed: The policy identifies a list of resources on which potential savings are calculated by summing up cost of each resource for last 30 days.

Permissions Required:

  • Dry Run:

    • rds:DescribeDBInstances

  • Run Once:

    • rds:DescribeDBInstances

    • rds:StopDBInstance


Recommendation: delete-unused-aws-elb

Description: Delete unused ELB

Policy Used:

policies:
  - name: delete-unused-aws-elb
    resource: elb
    filters:
      - Instances: []
    actions:
      - delete

Savings Computed: The policy identifies a list of resources on which potential savings are calculated by summing up cost of each resource for last 30 days.

Permissions Required:

  • Dry Run:

    • elasticloadbalancing:DescribeLoadBalancers

  • Run Once:

    • elasticloadbalancing:DescribeLoadBalancers

    • elasticloadbalancing:DeleteLoadBalancer


Recommendation: release-unattached-aws-elastic-ip

Description: Release unattached Elastic IPs

Policy Used:

Savings Computed: The policy identifies a list of resources on which potential savings are calculated by summing up cost of each resource for last 30 days.

Permissions Required:

  • Dry Run:

    • ec2:DescribeAddresses

  • Run Once:

    • ec2:DescribeAddresses

    • ec2:ReleaseAddress


Recommendation: delete-underutilized-aws-cache-cluster

Description: Delete underutilized cache cluster with CPU utilization less than 5% in the last 7 days.

Policy Used:

Savings Computed: The policy identifies a list of resources on which potential savings are calculated by summing up the cost of each resource for the last 30 days.

Permissions Required:

  • Dry Run:

    • elasticache:DescribeCacheClusters

  • Run Once:

    • elasticache:DescribeCacheClusters

    • elasticache:DeleteCacheCluster

    • elasticache:DeleteReplicationGroup

Recommendation: configure-lifecycle-aws-s3

Description: Configure lifecycle for S3 buckets wherever it is absent which would help to reduce storage spend

Policy Used:

Savings Computed: To estimate the percentage cost savings from the given S3 lifecycle policies, we need to look at the specific actions and apply some reasonable assumptions. Here's a step-by-step approach:

  1. Abort Incomplete Multipart Uploads after 7 days:

  • Assumption: 5% of all uploads are incomplete and are not cleaned up without this policy.

  • Cost Impact: Each incomplete multipart upload that is aborted saves the storage cost of the data uploaded so far.

  1. Expire Noncurrent Versions after 30 days (keeping 6 versions):

  • Assumption: Each object has, on average, 10 noncurrent versions stored. Expiring noncurrent versions after 30 days, keeping only the latest 6, will delete 4 out of every 10 noncurrent versions.

  • Cost Impact: Deleting 40% of noncurrent versions reduces the total storage used by these versions.

Example Calculation

Let's assume the following for a single S3 bucket:

Total Storage Used: 1 TB (1,024 GB) in the S3 Standard storage class.

Storage Distribution:

  • Current versions: 50% (512 GB)

  • Noncurrent versions: 40% (410 GB)

  • Incomplete multipart uploads: 10% (102 GB)

Calculations:

Click to view full size image

Total Savings

Click to view full size image

References:

Permissions Required:

  • Dry Run:

    • s3:GetLifecycleConfiguration

  • Run Once:

    • s3:GetLifecycleConfiguration

    • s3:PutLifecycleConfiguration

Recommendation: set-intelligent-tiering-aws-s3

Description: Configure intelligent tiering for S3 buckets wherever it is disabled which would help to reduce storage spend.

Policy Used:

Savings Computed:

  • Frequent Access Tier: This tier is equivalent in cost to the standard S3 storage, so no savings here.

  • Infrequent Access Tier: Data not accessed for 30 days moves here, saving approximately 45% compared to standard S3 storage​.

  • Archive Instant Access Tier: Data not accessed for 90 days moves here, with savings of up to 68% compared to standard storage​.

  • Archive Access Tier: If configured, data not accessed for 90 days can move here, offering around 71% savings​.

  • Deep Archive Access Tier: Data not accessed for 180 days can be moved to this tier, providing up to 95% savings.

Example Calculation

Assume you have 1 TB of data stored in S3 standard storage:

Click to view full size image

Example Scenario

If 20% of your data transitions to the Infrequent Access tier after 30 days, 20% moves to Archive Access after 90 days, and 10% moves to Deep Archive Access after 180 days, your costs might look like this:

Click to view full size image

This results in a cost savings of approximately 32.76% compared to keeping all data in standard S3 storage ($23.00 per month vs. $15.463 per month).

References:

Permissions Required:

  • Dry Run:

    • s3:GetBucketIntelligentTieringConfiguration

  • Run Once:

    • s3:GetBucketIntelligentTieringConfiguration

    • s3:PutIntelligentTieringConfiguration

Recommendation: delete-underutilized-aws-redshift

Description: Delete any Amazon Redshift cluster where CPU Utilization has been less than 5% for the last 7 days

Policy Used:

Savings Computed: The policy identifies a list of resources on which potential savings are calculated by summing up the cost of each resource for the last 30 days.

Permissions Required:

  • Dry Run:

    • redshift:DescribeClusters

  • Run Once:

    • redshift:DescribeClusters

    • redshift:DeleteCluster

Recommendation: delete-old-manual-aws-redshift-snapshot

Description: Delete all redshift snapshots older than 35 days with a lifetime retention period

Policy Used:

Savings Computed: The policy identifies a list of resources on which potential savings are calculated by summing up the cost of each resource for the last 30 days.

Permissions Required:

  • Dry Run:

    • redshift:DescribeClusterSnapshots

  • Run Once:

    • redshift:DeleteClusterSnapshot

    • redshift:DescribeClusterSnapshots

Recommendation: delete-empty-aws-dynamodb-table

Description: Delete DyanmoDB tables which are empty

Policy Used:

Savings Computed: The policy identifies a list of resources on which potential savings are calculated by summing up the cost of each resource for the last 30 days.

Recommendation: delete-stale-aws-log-group

Description: Delete stale cloud watch log groups

Policy Used:

Savings Computed: The policy identifies a list of resources on which potential savings are calculated by summing up the cost of each resource for the last 30 days.

Recommendation: delete-stale-aws-rds-snapshot

Description: Delete all stale(older than 28 days) RDS snapshots

Policy Used:

Savings Computed: The policy identifies a list of resources on which potential savings are calculated by summing up the cost of each resource for the last 30 days.

Recommendation: delete-unencrypted-aws-firehose

Description: Delete Firehose which are not encrypted

Policy Used:

Savings Computed: The policy identifies a list of resources on which potential savings are calculated by summing up the cost of each resource for the last 30 days.

Recommendation: delete-unencrypted-aws-sqs

Description: Delete SQS which are not encrypted

Policy Used:

Savings Computed: The policy identifies a list of resources on which potential savings are calculated by summing up the cost of each resource for the last 30 days.

Recommendation: delete-unused-aws-nat-gateway

Description: Delete unused NAT Gateways based on no associated traffic in past 7 days.

Policy Used:

Savings Computed: The policy identifies a list of resources on which potential savings are calculated by summing up the cost of each resource for the last 30 days.

Recommendation: delete-idle-gcp-image

Description: Delete GCP recommended idle images

Policy Used:

Savings Computed: The policy identifies a list of resources on which potential savings are calculated by summing up cost of each resource for last 30 days.

Permissions Required:

  • Dry Run: recommender.computeImageIdleResourceRecommendations.list

  • Run Once:

    • recommender.computeImageIdleResourceRecommendations.list

    • compute.images.delete


Recommendation: delete-never-attached-gcp-disk

Description: Delete GCP recommended idle persistent disks which were never attached to a VM and is blank

Policy Used:

Savings Computed: The policy identifies a list of resources on which potential savings are calculated by summing up cost of each resource for last 30 days.

Permissions Required:

  • Dry Run: recommender.computeDiskIdleResourceRecommendations.list

  • Run Once:

    • recommender.computeDiskIdleResourceRecommendations.list

    • compute.disks.delete


Recommendation: stop-forever-running-gcp-instance

Description: Stop the gcp instances that have an uptime greater than 30 days.

Policy Used:

Savings Computed: The policy identifies a list of resources on which potential savings are calculated by summing up cost of each resource for last 30 days.

Permissions Required:

  • Dry Run:

    • compute.instances.list

    • monitoring.timeSeries.list

  • Run Once:

    • compute.instances.list

    • monitoring.timeSeries.list

    • compute.instances.stop


Recommendation: delete-old-gcp-snapshot

Description: Delete gcp snapshots older than 14 days.

Policy Used:

Savings Computed: The policy identifies a list of resources on which potential savings are calculated by summing up cost of each resource for last 30 days.

Permissions Required:

  • Dry Run:

    • compute.snapshots.list

  • Run Once:

    • compute.snapshots.list

    • compute.snapshots.delete


Recommendation: stop-underutilized-gcp-instance

Description: Stop underutilised instances with average CPU utilisation less than 5% in last 3 days.

Policy Used:

Savings Computed: The policy identifies a list of resources on which potential savings are calculated by summing up cost of each resource for last 30 days.

Permissions Required:

  • Dry Run:

    • compute.instances.list

    • monitoring.timeSeries.list

  • Run Once:

    • compute.instances.list

    • monitoring.timeSeries.list

    • compute.instances.stop


Recommendation: stop-underutilized-gcp-sql-instance

Description: Stop underutilised sql instances with average CPU utilisation less than 5% in last 3 days

Policy Used:

Savings Computed: The policy identifies a list of resources on which potential savings are calculated by summing up cost of each resource for last 30 days.

Permissions Required:

  • Dry Run:

    • cloudsql.instances.list

    • monitoring.timeSeries.list

  • Run Once:

    • cloudsql.instances.list

    • monitoring.timeSeries.list

    • cloudsql.instances.update


Recommendation: snapshot-and-delete-unattached-gcp-disk

Description: Snapshot and delete GCP recommended idle persistent disks which are unattached

Policy Used:

Savings Computed: Savings are considered as 35% of the total cost. Implementing this recommendation would result in 35% to 92% reduction in the maintenance cost of that disk. Thus, we have considered the minimum savings achievable, which is 35%. Ref: https://cloud.google.com/compute/docs/viewing-and-applying-idle-resources-recommendations

Permissions Required:

  • Dry Run:

    • recommender.computeDiskIdleResourceRecommendations.list

  • Run Once:

    • recommender.computeDiskIdleResourceRecommendations.list

    • compute.disks.delete


Recommendation: delete-idle-gcp-gke-cluster

Description: List GCP Idle GKE Clusters Recommendations

Policy Used:

Savings Computed: The policy identifies a list of resources on which potential savings are calculated by summing up the cost of each resource for the last 30 days.

Permissions Required:

  • Dry Run:

    • recommender.containerDiagnosisInsights.list

    • container.clusters.list

  • Run Once:

    • recommender.containerDiagnosisInsights.list

    • container.clusters.list

    • container.clusters.delete


Recommendation: list-cost-recommendations-gcp-cloud-run-service

Description:

Policy Used:

Savings Computed: The policy identifies a list of resources on which potential savings are calculated by summing up the cost of each resource for the last 30 days.

Permissions Required:

  • Dry Run:

    • recommender.runServiceCostRecommendations.list

    • run.services.list

  • Run Once:

    • recommender.runServiceCostRecommendations.list

    • run.services.list


Recommendation: list-unused-gcp-bq-dataset

Description: List BigQuery datasets that haven't been accessed in the last 7 days.

Policy Used:

Savings Computed: The policy identifies a list of resources on which potential savings are calculated by summing up cost of each resource for the last 30 days.

Permissions Required:

  • Dry Run:

    • bigquery.datasets.get

  • Run Once:

    • bigquery.datasets.get


Recommendation: delete-unused-gcp-function

Description: Delete Cloud Functions that haven't been invoked in the last 7 days to reduce costs.

Policy Used:

Savings Computed: The policy identifies a list of resources on which potential savings are calculated by summing up cost of each resource for last 30 days.

Permissions Required:

  • Dry Run:

    • monitoring.timeSeries.list

    • cloudfunctions.functions.list

  • Run Once:

    • monitoring.timeSeries.list

    • cloudfunctions.functions.list

    • cloudfunctions.functions.delete


Recommendation: list-under-utilized-gcp-bucket

Description: List low utilized gcp buckets in last 7 days.

Policy Used:

Savings Computed: The policy identifies a list of resources on which potential savings are calculated by summing up the cost of each resource for last 30 days.

Permissions Required:

  • Dry Run:

    • monitoring.timeSeries.list

    • storage.buckets.list

  • Run Once:

    • monitoring.timeSeries.list

    • storage.buckets.list


Recommendation: list-hanged-gcp-dataflow-job

Description: List Dataflow jobs that have been in an hanged state for more than 1 day.

Policy Used:

Savings Computed: The policy identifies a list of resources on which potential savings are calculated by summing up cost of each resource for last 30 days.

Permissions Required:

  • Dry Run:

    • dataflow.jobs.list

  • Run Once:

    • dataflow.jobs.list


Recommendation: delete-under-utilized-gcp-loadbalancer-address

Description: Delete all load balancers with low utilizations, where packet count is less than 1000 in the last 72 hours.

Policy Used:

Savings Computed: The policy identifies a list of resources on which potential savings are calculated by summing up the cost of each resource for the last 30 days.

Permissions Required:

  • Dry Run:

    • monitoring.timeSeries.list

    • compute.addresses.list

  • Run Once:

    • monitoring.timeSeries.list

    • compute.addresses.list

    • compute.addresses.delete


Recommendation: list-under-utilized-gcp-redis

Description: List Redis instances with less than 5% CPU utilization over the last 7 days.

Policy Used:

Savings Computed: The policy identifies a list of resources on which potential savings are calculated by summing up cost of each resource for the last 30 days.

Permissions Required:

  • Dry Run:

    • monitoring.timeSeries.list

    • redis.instances.list

  • Run Once:

    • monitoring.timeSeries.list

    • redis.instances.list


GCP Resource Coverage (Examples)

  • Compute Engine instances

  • Cloud Storage buckets

  • App Engine applications

  • Cloud SQL instances

  • Cloud IAM policies

For a comprehensive list of all supported GCP resources, refer to the GCP Resource Reference — Cloud Custodian documentation.

Recommendation: delete-low-utilized-azure-cosmodb

Description: Delete low utilised CosmosDB based on total requests in last 72 hours.

Policy Used:

Savings Computed: The policy identifies a list of resources on which potential savings are calculated by summing up cost of each resource for last 30 days.

Permissions Required: To execute the action section of the custodian policy, the Contributor Role is required, whereas the Reader Role suffices for generating recommendations.


Recommendation: delete-unattached-azure-disk

**Description:** Delete all unattached disks.

Policy Used:

Savings Computed: The recommendation identifies a list of resources; to calculate potential savings, the costs of all resources over the last 30 days are summed together and that is shown as the potential savings.

Permissions Required: To execute the action section of the custodian policy, the Contributor Role is required, whereas the Reader Role suffices for generating recommendations.


Recommendation: delete-low-utilized-azure-load-balancer

**Description:** Delete all low utilised load balancers where packet count is less than 1000 in last 72 hours.

Policy Used:

Savings Computed: The policy identifies a list of resources on which potential savings are calculated by summing up cost of each resource for last 30 days.

Permissions Required: To execute the action section of the custodian policy, the Contributor Role is required, whereas the Reader Role suffices for generating recommendations.


Recommendation: delete-orphaned-azure-networkinterface

**Description:** Delete network interface which are not attached to virtual machine.

Policy Used:

Savings Computed: The policy identifies a list of resources on which potential savings are calculated by summing up cost of each resource for last 30 days.

Permissions Required: To execute the action section of the custodian policy, the Contributor Role is required, whereas the Reader Role suffices for generating recommendations.


Recommendation: stop-underutilized-azure-vm

**Description:** Stop underutilised virtual machines with average CPU utilisation less than 5% in last 72 hours.

Policy Used:

Savings Computed: The policy identifies a list of resources on which potential savings are calculated by summing up cost of each resource for last 30 days.

Permissions Required: To execute the action section of the custodian policy, the Contributor Role is required, whereas the Reader Role suffices for generating recommendations.


Recommendation: delete-low-utilized-azure-keyvault

**Description:** Delete KeyVaults with less than 10 API hits in last 72 hours.

Policy Used:

Savings Computed: The policy identifies a list of resources on which potential savings are calculated by summing up cost of each resource for last 30 days.

Permissions Required: To execute the action section of the custodian policy, the Contributor Role is required, whereas the Reader Role suffices for generating recommendations.


Recommendation: delete-low-utilized-azure-sqlserver

**Description:** Delete SQL servers with less than 10% average DTU consumption over last 72 hours.

Policy Used:

Savings Computed: The policy identifies a list of resources on which potential savings are calculated by summing up cost of each resource for last 30 days.

Permissions Required: To execute the action section of the custodian policy, the Contributor Role is required, whereas the Reader Role suffices for generating recommendations.


Recommendation: delete-unattached-azure-publicip

**Description:** Delete public ip which are not attached to any network interface.

Policy Used:

Savings Computed: The policy identifies a list of resources on which potential savings are calculated by summing up cost of each resource for last 30 days.

Permissions Required: To execute the action section of the custodian policy, the Contributor Role is required, whereas the Reader Role suffices for generating recommendations.


Recommendation: delete-low-utilized-azure-datalake

**Description:** Delete all Datalake Stores with less than 1000 read requests or 1000 write requests in the last 72 hours.

Policy Used:

Savings Computed: The policy identifies a list of resources on which potential savings are calculated by summing up cost of each resource for last 30 days.

Permissions Required: To execute the action section of the custodian policy, the Contributor Role is required, whereas the Reader Role suffices for generating recommendations.


Recommendation: delete-unused-azure-postgresql-server

**Description:** Delete PostgreSQL Servers that have had zero active connections in the last 72 hours.

Policy Used:

Savings Computed: The policy identifies a list of resources on which potential savings are calculated by summing up cost of each resource for last 30 days.

Permissions Required: To execute the action section of the custodian policy, the Contributor Role is required, whereas the Reader Role suffices for generating recommendations.


Recommendation: delete-orphaned-azure-appserviceplan

**Description:** Delete orphaned(numberOfSites=0) application service plan

Policy Used:

Savings Computed: The recommendation identifies a list of resources; to calculate potential savings, the costs of all resources over the last 30 days are summed together and that is shown as the potential savings.

Permissions Required: To execute the action section of the custodian policy, the Contributor Role is required, whereas the Reader Role suffices for generating recommendations.



Rules Generating Recommendations

The "Rules Generating Recommendations" tab shows all the rules you’ve turned on to generate recommendations. Every day, our system runs these rules across your main accounts and regions. The results are shown as recommendations, so you can track their full lifecycle from when they’re created to when they’re addressed. The tab also gives you insights into the rules you’ve enabled. You can see a breakdown by account and region, including whether the rule ran successfully, had an error, or found resources that don’t have any savings attached.

Using Rules Generating Recommendations

  1. Navigate to the Rules Generating Recommendations > +New Rule to begin the process

  2. Select a governance rule to generate recommendations

  3. Configure the rule's scope:

    • All Accounts: Apply the rule across your entire cloud infrastructure

    • Specific Accounts: Target only selected cloud accounts for evaluation

  4. Click Generate Recommendations to initiate the evaluation process

Click to view full size image

After this, all the rules generating recommendations can be seen in the Rules Generating Recommendations tab alongwith last evaluation, recommendations, potential savings and success rate. If any connector and region combination encounters an issue, the system flags it with a Failed status. The UI displays a detailed error message to assist in resolving the issue quickly.

Status Breakdown:

  1. Failed Status : A failed status indicates one of the following scenarios:

  • Missing Permissions: The necessary permissions required for Harness to get or list resources are not provided.

  • Harness Internal Error: A system-level issue occurred during processing.

  1. Ignored Status : An ignored status indicates one of the following scenarios:

  • No Cost Data Available: Billing connector setup at Harness is missing cost data for the target cloud account.

  • Cost Threshold Not Met: Cost is less than $300 for the GCP project.

  • Invalid Region: The regions found in cost data is not valid to run against Governance Rule.

  1. Success Status : A successful status indicates one of the following scenarios:

  • Recommendation Generated: The system successfully evaluated the rule and created a recommendation.

  • No Resources in Evaluation: The rule was evaluated, but there were no resources found.

  • Savings Below Threshold: A recommendation was generated, but the potential savings were calculated to be less than $10.


Granular Recommendations

Cloud Asset Governance provides valuable recommendations, but when it comes to operationalizing them at scale, it might become challenging. Additionally, when using shared cloud accounts across teams, project-level recommendations might not work out. With Granular Recommendations, Governance recommendations will now be generated at the individual resource level, ensuring greater granularity and actionable insights for both custom and out-of-the-box (OOTB) recommendations. This enhancement simplifies implementation and tracking, allowing customers to take more effective action on governance recommendations at scale.

Enabling Granular Recommendations

Owing to this, now, while adding a recommendation to Ignore List, users have the option to specify the scope at which the users want to ignore the recommendation. The scope can be either at:

  • Rule-level

  • Rule-level + Project-level

  • Rule-level + Project-level + Resource-level.

Last updated

Was this helpful?