> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cloudthinker.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Keepers

> Enable autonomous keepers that catch cost, security, and performance drift and turn findings into tracked recommendations.

CloudKeepers are autonomous monitors that enforce cost, security, and performance guardrails across every connected cloud account and Kubernetes cluster. The app sidebar shows them as **Keepers** under **Infrastructure**.

## How keepers are organized

Keepers form a **3 × 3 matrix** of providers and pillars:

| Provider       | Cost     | Security | Performance |
| -------------- | -------- | -------- | ----------- |
| **AWS**        | AWS-COST | AWS-SEC  | AWS-PERF    |
| **GCP**        | GCP-COST | GCP-SEC  | GCP-PERF    |
| **Kubernetes** | K8S-COST | K8S-SEC  | K8S-PERF    |

Each keeper monitors one provider–pillar combination. Enable only the keepers you need — for example, AWS-COST and K8S-SEC — or all nine for full coverage.

Each keeper contains multiple **detection rules** (40+ rules total) that you toggle and tune individually:

* **Cost rules**: idle compute instances, unattached storage, old snapshots, unused static IPs, oversized databases, idle load balancers, over-requested pod resources, and more
* **Security rules**: public S3 buckets, unused IAM roles, MFA disabled on root, open security groups, secrets in parameter store, and more
* **Performance rules**: RDS connection limits, missing health probes, CrashLooping pods, throttled resources, and more

## Autonomy

Every detection rule runs in one of two modes:

| Mode       | What happens                                                                       |
| ---------- | ---------------------------------------------------------------------------------- |
| **Manual** | The agent proposes the action and waits for a person to approve it before running. |
| **Auto**   | The agent runs the action on its own and reports the result.                       |

Autonomy is set per rule, so most rules can stay in Manual while well-understood cost rules — like cleaning up unattached volumes — run in [Auto](/guide/auto-mode).

## Prerequisites

* At least one cloud account or Kubernetes cluster connected with read/monitoring permissions and, optionally, remediation permissions.
* [Slack](/guide/slack-integration), Microsoft Teams, or email destinations configured if you want alerts beyond in-app [notifications](/guide/notifications).
* Optional: tags or filters ready if you plan to scope findings to specific environments.

## Set up your first keepers

<Steps>
  <Step title="Open Keepers">
    Go to **Infrastructure → Keepers** to see the onboarding view. It walks you through three steps: connect a cloud account, enable keepers, and run your first detection scan. Click **Enable Your First Keepers** to begin.

    <Frame>
      <img src="https://mintcdn.com/cloudthinker/OJRahgLXUPDmURsx/images/infrastructure/cloudkeepers/01-onboarding-landing.jpg?fit=max&auto=format&n=OJRahgLXUPDmURsx&q=85&s=96e8a4bd7a1b639eb3437a4d7335b3b2" alt="CloudKeepers onboarding page with Enable Your First Keepers CTA, three-step how-it-works timeline, and cost, security, and performance value cards" width="4590" height="2764" data-path="images/infrastructure/cloudkeepers/01-onboarding-landing.jpg" />
    </Frame>
  </Step>

  <Step title="Select and configure keepers">
    The setup wizard has two steps. In **Select Keepers**, choose which keepers to activate — filter by provider (AWS, Kubernetes) or pillar (Cost, Security, Performance). In **Review & Configure**, fine-tune detection rules per keeper, set each rule to Manual or Auto, and adjust which rules are enabled.

    <Frame>
      <img src="https://mintcdn.com/cloudthinker/OJRahgLXUPDmURsx/images/infrastructure/cloudkeepers/02-setup-wizard.jpg?fit=max&auto=format&n=OJRahgLXUPDmURsx&q=85&s=0058539cc8bb9ee7c514dd3cb481491b" alt="Two-step setup wizard showing keeper selection grid on the left and per-keeper rule review with autonomy level toggles on the right" width="4776" height="2086" data-path="images/infrastructure/cloudkeepers/02-setup-wizard.jpg" />
    </Frame>
  </Step>

  <Step title="Review the dashboard">
    Once keepers are enabled, select one from the sidebar to see its **Dashboard** tab. Four stat cards — **Open Findings**, **Critical & High**, **Potential Savings**, and **This Week** — give you a quick pulse. The **Findings Over Time** chart breaks down trends by severity.

    <Frame>
      <img src="https://mintcdn.com/cloudthinker/OJRahgLXUPDmURsx/images/infrastructure/cloudkeepers/03-keeper-dashboard.jpg?fit=max&auto=format&n=OJRahgLXUPDmURsx&q=85&s=299025a7004c4a91280dd61775178c42" alt="AWS Cost Optimization dashboard with stat cards for open findings, critical and high, potential savings, and this week count, plus a findings over time chart" width="4572" height="2766" data-path="images/infrastructure/cloudkeepers/03-keeper-dashboard.jpg" />
    </Frame>
  </Step>

  <Step title="Triage findings">
    Switch to the **Findings** tab to see a board with a column for each finding status. Each finding card shows the title, estimated savings, effort level, and risk severity. Click a card to drill into details, or drag it between columns to update its status.

    <Frame>
      <img src="https://mintcdn.com/cloudthinker/OJRahgLXUPDmURsx/images/infrastructure/cloudkeepers/04-keeper-findings.jpg?fit=max&auto=format&n=OJRahgLXUPDmURsx&q=85&s=e62b71ccdae9a203917ca363f34bf1fb" alt="Findings Kanban board with a pending finding card showing 30 unattached EBS volumes, $55.20 savings, effort low, risk medium" width="4572" height="2766" data-path="images/infrastructure/cloudkeepers/04-keeper-findings.jpg" />
    </Frame>
  </Step>

  <Step title="Review detection runs">
    The **Runs** tab shows every detection run with its status, summary, duration, and how many findings were created or updated. Use this as an audit trail to verify keepers are running on schedule.

    <Frame>
      <img src="https://mintcdn.com/cloudthinker/OJRahgLXUPDmURsx/images/infrastructure/cloudkeepers/05-keeper-runs.jpg?fit=max&auto=format&n=OJRahgLXUPDmURsx&q=85&s=028371683a439f72d4315896d8e5d402" alt="Runs tab showing a completed detection run with 30 detections from 6 rules, 57-second duration, and 1 new finding" width="4572" height="2766" data-path="images/infrastructure/cloudkeepers/05-keeper-runs.jpg" />
    </Frame>
  </Step>

  <Step title="Configure keeper settings">
    In the **Settings** tab, set the cron schedule (default: daily at 07:00 UTC), and toggle individual detection rules on or off. Each rule shows a description of what it detects and supports per-rule autonomy and threshold configuration.

    <Frame>
      <img src="https://mintcdn.com/cloudthinker/OJRahgLXUPDmURsx/images/infrastructure/cloudkeepers/06-keeper-settings.jpg?fit=max&auto=format&n=OJRahgLXUPDmURsx&q=85&s=edaadcf521459188e46c732ffacf4f35" alt="Settings tab showing cron schedule editor and a list of 10 detection rules with toggle switches for idle compute, unattached storage, old snapshots, and more" width="4572" height="2766" data-path="images/infrastructure/cloudkeepers/06-keeper-settings.jpg" />
    </Frame>
  </Step>
</Steps>

## From finding to recommendation

Keepers turn raw detections into tracked, governed work:

1. **Detect** — each keeper runs on its cron schedule (default: daily at 07:00 UTC) or on demand, scanning all permitted resources — not just the ones you previously discovered. Every run leaves an audit trail in the **Runs** tab.

2. **Triage** — each finding is tagged with pillar, severity, effort, and estimated savings so you can prioritize the highest-value fixes. Move findings through their statuses as you work:

   | Status           | Meaning                                                    |
   | ---------------- | ---------------------------------------------------------- |
   | **New**          | Just detected; nobody has looked at it yet.                |
   | **Acknowledged** | A team member has seen the finding and owns the follow-up. |
   | **Active**       | Work on the finding is underway.                           |
   | **Resolved**     | The underlying issue is fixed and verified.                |
   | **Dismissed**    | Reviewed and intentionally not acted on.                   |

3. **Promote** — findings start as drafts; promote the ones worth acting on into active recommendations. Every recommendation includes an impact analysis with before/after estimates and a step-by-step playbook. From the detail view, use **Impact Analytics** for deeper analysis, **Generate Guidelines** for shareable runbooks, **Custom Prompt** to explore edge cases, or **Implement** to execute the change.

4. **Track** — save recommendations to [Plan](/guide/infrastructure/plan) for approvals, scheduling, and execution tracking, so governance, FinOps, and security teams share the same source of truth.

<Note>
  Keepers are your daily operational guardrail. [Assessment](/guide/infrastructure/assessment) is a deeper, periodic evaluation and is not meant for day-to-day runs.
</Note>

## Keeper settings

Each keeper has a dedicated **Settings** tab where you can configure:

* **Schedule**: a cron expression for automated runs (minimum 1-hour interval).
* **Detection rules**: toggle individual rules, set each rule to Manual or Auto, and adjust per-rule thresholds (idle CPU %, lookback days, snapshot max age).
* **Commands & permissions**: manage which cloud commands each rule is allowed to execute, with per-command effects (Allow / Require Approval / Deny).
* **Notifications**: Email, Slack, and Teams channels with per-channel minimum severity thresholds. In-app [notifications](/guide/notifications) are always delivered regardless of channel settings.

## Examples

### Cost guardrails

Infrastructure that grew organically hides waste that manual audits rarely catch. AWS-COST flags idle EC2 instances, unattached EBS volumes, aging snapshots, and underused NAT gateways — and it reads context: a volume tagged for daily backups serves a purpose, while an untagged test volume from last year is genuinely orphaned. Review findings on the dashboard, promote the high-confidence ones, and save them to [Plan](/guide/infrastructure/plan) for approval and execution.

<Frame>
  <img src="https://mintcdn.com/cloudthinker/0IKJjKZJEIROke98/images/use-cases/continuous-cloud-guardrails/03-cost-optimization-recommendations.jpg?fit=max&auto=format&n=0IKJjKZJEIROke98&q=85&s=f128fe6aef813a4a19a8c59ab7198369" alt="Cost optimization analysis with resource utilization and savings recommendations" width="1676" height="946" data-path="images/use-cases/continuous-cloud-guardrails/03-cost-optimization-recommendations.jpg" />
</Frame>

### Security guardrails

Security drift accumulates between audits: overly broad IAM roles, public S3 buckets, unencrypted volumes, and security groups open to 0.0.0.0/0. AWS-SEC scans continuously and weighs operational context — HTTP from anywhere is normal for a load balancer but dangerous for a database, and a root account access key outranks an unused read-only role. Route critical findings to Slack for immediate triage and track multi-team fixes in Plan.

<Frame>
  <img src="https://mintcdn.com/cloudthinker/0IKJjKZJEIROke98/images/use-cases/continuous-cloud-guardrails/02-security-recommendations.jpg?fit=max&auto=format&n=0IKJjKZJEIROke98&q=85&s=59fa0785d0bfbcf833e1209fd32c8e1d" alt="Security audit recommendations with remediation steps" width="1676" height="946" data-path="images/use-cases/continuous-cloud-guardrails/02-security-recommendations.jpg" />
</Frame>

## Related

<CardGroup cols={2}>
  <Card title="Plan" icon="list-check" href="/guide/infrastructure/plan">
    Save findings to Plan for approvals, scheduling, and execution tracking
  </Card>

  <Card title="Assessment" icon="clipboard-check" href="/guide/infrastructure/assessment">
    Run deeper periodic Well-Architected assessments alongside daily keeper runs
  </Card>

  <Card title="Slack integration" icon="slack" href="/guide/slack-integration">
    Route keeper alerts to Slack channels for real-time triage
  </Card>

  <Card title="Tasks" icon="calendar-check" href="/guide/automation/tasks">
    Schedule additional recurring analysis to complement keepers
  </Card>
</CardGroup>
