1. Source intake, parsing & safety boundary
The Engine begins by turning heterogeneous source material into a safe, attributable assessment pack before any FinOps judgment is allowed.
PDFOpen logicInput preparationMulti-format local parsing
Normalizes PDFs, HTML, tables, JSON, screenshots, and other uploaded artifacts before model analysis.
Local extractionPage markersTable rows
“A policy statement on page 12 and a cost table on row 8 must remain independently traceable; they cannot become one blended contextual impression.”DLPOpen logicSafety controlDLP & sensitive-data review
Scans the source pack for secrets and sensitive identifiers before model calls and report generation.
SecretsRedactionDistributed scan
“Use the existence of a budget-control gap as evidence; do not echo account numbers, customer names, access tokens, or unnecessary exact spend values.”PQOpen logicInput qualityParse quality & visual evidence
Identifies sparse pages, weak extraction, and dashboard-like content that may require visual evidence handling.
Sparse-page warningVisual sourceQuality metadata
“A cost-allocation dashboard may prove role-based visibility even when its labels are embedded in an image rather than extractable text.”KBOpen logicClean-room ruleCustomer evidence vs. reference KB
Separates witness evidence from methodology, definitions, false-positive checks, and solution knowledge.
Source of truthReference onlyNo proof leakage
“The KB defines what mature tagging looks like. It does not prove that the assessed organization has implemented it.”2. Source registry, chunking & domain packetization
The complete source pack is converted into traceable chunks and routed into six bounded FinOps domain packets before parallel audit begins.
IDOpen logicTraceability layerSource registry & provenance
Assigns stable source, page, chunk, row, and image identifiers to the assessment material.
Source IDChunk IDManifest
“The evidence verifier should be able to point to src-003, page 007, chunk 2—not only to a generic document title.”A–FOpen logicDeterministic routingDomain relevance classification
Scores each source chunk against domain-specific terms before the LLM receives its packet.
High / medium / lowKeyword reasonsPre-routing
“Token-routing evidence belongs primarily in Domain F; a governance policy may also route to C, but it should not dominate right-sizing analysis in B.”POpen logicBounded evidence packetPacket construction & weak coverage
Selects the highest-value chunks for each domain and marks thin coverage explicitly.
Bounded packetGap signalsWeak-coverage flag
“A Domain E packet with only one generic culture reference is not enough to certify engineering cost accountability; broad-source fallback remains visibly marked.”RTOpen logicExecution controlTask-fit model routing & fallback
Maps each LLM task to a controlled primary profile and ordered fallback chain.
Stage IDsTask fitRun trace
“A targeted rescan is routed differently from initial extraction because it must challenge a disputed finding rather than repeat the same first-pass behavior.”3. Six parallel forensic domain audits
Each domain audits five maturity criteria and five corresponding anti-patterns. The two streams remain separate: capability evidence does not erase harmful patterns, and silence does not become maturity.
AOpen logicForensic domainCost Visibility & Allocation
Tests whether cloud spend is attributable, timely, role-visible, and connected to business unit economics.
TaggingShowbackUnit economicsExpanded sample model
“A monthly finance export proves some reporting. It does not prove near-real-time anomaly response, engineering self-service, or reliable product-level allocation.”BOpen logicForensic domainRate & Usage Optimization
Tests continuous commitment, right-sizing, waste, spot, and storage-lifecycle optimization.
CommitmentsRight-sizingWaste
“A right-sizing report without ownership or completed actions is evidence of opportunity visibility, not evidence of embedded optimization.”COpen logicForensic domainGovernance & Policy
Tests policy, budgeting, operating model, procurement, and compliance-cost controls.
PolicyForecastingRACI
“A cloud policy can establish intent; exception logs, budget decisions, and enforcement mechanisms establish operating proof.”DOpen logicForensic domainArchitecture & Engineering
Tests whether cost is embedded in design, IaC, scaling, cloud strategy, and platform choices.
Cost-aware designIaC guardrailsScaling
“Autoscaling exists, but without upper bounds or cost alarms it may strengthen performance while preserving a scaling-without-limits anti-pattern.”EOpen logicForensic domainCulture & Organization
Tests ownership, executive sponsorship, engineering accountability, collaboration, and continuous improvement.
OwnershipCollaborationBehavior change
“A FinOps community of practice is useful, but it does not prove engineering cost accountability unless teams carry measurable ownership.”FOpen logicForensic domainGenAI & AI Cost Management
Tests token visibility, AI allocation, routing efficiency, guardrails, forecasting, and value realization.
Token spendModel routingAI unit economicsCurrent sixth domain
“A premium model used everywhere may increase quality, but without routing policy and task-level unit economics it can indicate premium-model overuse rather than deliberate optimization.”4. Independent evidence check, anti-pattern semantics & targeted rescan
The first audit is provisional. A separate verification layer checks whether forwarded scores and quotations are genuinely supported before any metric is calculated.
VOpen logicIndependent verifierClaim and score verification
Tests each forwarded criterion against the raw source packet and exact evidence location.
SupportedWeakUnsupported / missing
“The source mentions monthly cost review, but the scanner scored continuous optimization at 3. Reclassify as weak and lower the verified count.”ØOpen logicAbsence semanticsAnti-pattern adjudication
Separates harmful findings, partial signals, tested absence, and unassessed silence.
Confirmed presentPartially presentTested / unknown absenceExpanded reliability model
“No mention of commitment avoidance is not tested absence. A detailed commitment-management review showing rational coverage decisions can support tested absence.”↺Open logicSecond opinionTargeted rescan
Re-examines only weak, unsupported, or missing scored criteria instead of rerunning the whole domain blindly.
Disputed criteriaFocused promptHigher-value review
“Re-open only B2 and B4 because the verifier found related material but insufficient proof; do not regenerate all ten Domain B judgments.”↓Open logicDeterministic correctionApply verified counts
Writes evidence-check outcomes back into the audit logs before Phase 2 sees them.
Original vs. verifiedAdjustment reasonNo optimism carryover
“Scanner score 3, verifier score 1, targeted rescan still weak: Phase 2 receives 1 and the report retains the downgrade trail.”5. Deterministic metric firewall & confidence bracket
AI does not decide the headline maturity result. Arithmetic converts the verified audit into bounded metrics, classification, and permission for later synthesis.
ΣOpen logicMetric firewallEvidence-gated FinOps readiness
Calculates maturity, burden, clearance, coverage, integrity, density, and domain scores from verified audit data.
Deterministic math0–100Traceable inputs
“Strong policy maturity with entrenched manual optimization and weak evidence density cannot become a high readiness score through narrative synthesis.”C/W/ROpen logicClassificationCrawl / Walk / Run
Translates the capped readiness score and burden into an evidence-aware maturity classification.
InsufficientCrawl / WalkRun
“A 55 readiness score with burden above 50 becomes ‘Walk with significant friction,’ not a clean Walk.”CAPOpen logicEvidence capEvidence density & readiness ceiling
Caps optimistic readiness when too few criteria have verified source coverage.
<30 BLOCK floor<60 warning capCoverage matters
“A polished cloud strategy covering only eight of sixty evidence surfaces cannot justify a high enterprise FinOps readiness result.”H/M/LOpen logicSynthesis permissionConfidence bracket
Converts density, delivery integrity, and silent areas into HIGH, MEDIUM, or LOW synthesis behavior.
HIGH directiveMEDIUM cautiousLOW findings-onlyPermission model
“The organization may have real gaps, but if the source pack cannot ground them deeply, the correct output is a validation plan—not confident implementation directives.”6. Evidence summary, diagnosis & persona lenses
The Engine first establishes a facts-and-metrics summary, then interprets root causes, and only then translates the same evidence through three executive lenses.
ESOpen logicFacts-first synthesisAssessment evidence summary
Creates the non-prescriptive synopsis of classification, metrics, strengths, gaps, anti-patterns, and missing evidence.
Evidence onlyNo tactic IDsNo directives
“The report may state that evidence density is 58% and anti-pattern coverage is 42%; it cannot translate those values into invented annual savings.”DOpen logicInterpretive layerFinOps diagnosis
Explains the primary bottleneck, root causes, domain implications, and confidence without yet prescribing the roadmap.
Primary bottleneckRoot causesA–F diagnosisExpanded sample model
“Weak allocation, finance-engineering separation, and manual optimization may jointly indicate an accountability bottleneck—but the diagnosis must retain uncertainty when ownership evidence is sparse.”FLOpen logicPersona lensFinOps Lead
Reads the evidence through operational maturity, optimization flow, tooling, and cross-team enablement.
OperationalMaturity gapsTeam enablement
“Emphasize ownership cadence, optimization backlog flow, and evidence gaps—not an invented tooling shopping list.”CFOOpen logicPersona lensCFO / Finance Director
Reads the same diagnosis through financial control, risk exposure, budgeting, and investment confidence.
FinancialRiskInvestment logic
“Explain cost predictability and governance risk; do not claim a €2M savings opportunity unless a validated source and calculation support it.”CTOOpen logicPersona lensEngineering Lead / CTO
Reads the evidence through architecture, engineering workflow, technical debt, and cost-performance trade-offs.
ArchitectureWorkflowCost-performance
“Describe the evidenced absence of cost guardrails in IaC; do not assume Terraform, Kubernetes, or a specific cloud provider unless the source establishes it.”↟Open logicAdaptive routingSynthesis escalation
Routes especially complex or high-friction diagnoses to a deeper synthesis stage using deterministic triggers or explicit deep mode.
Complexity triggersDeep modeRecorded reason
“A low-readiness estate with widespread anti-patterns may justify deeper causal synthesis, but it still cannot bypass the LOW confidence findings-only boundary.”7. Planning decision, roadmap synthesis & tactic permissioning
Recommendations are created only after diagnosis and only in the form permitted by the confidence bracket. The roadmap must remain linked to verified findings and approved tactic identifiers.
H/M/LOpen logicRoadmap modeDirective, cautious, or findings-only
Changes the shape of Phase 3 output according to evidence permission.
HIGH roadmapMEDIUM assumptionsLOW validation plan
“When evidence is LOW, ask for commitment coverage, allocation accuracy, and ownership records before prescribing implementation.”GO?Open logicActionability gatePlanning decision
States whether the roadmap is safe to use, conditionally usable, or blocked pending evidence.
GOCONDITIONAL_GONO_GO
“Safe now: collect allocation and commitment evidence. Unsafe now: launch a chargeback redesign before ownership and allocation quality are validated.”TACOpen logicTactic permissioningVerified tactic ID contract
Requires exact approved tactic IDs for prescriptive mechanisms and rejects invented or modified identifiers.
Exact IDsLookup tableRegenerate on invalidExpanded control model
“If a roadmap action cites a non-existent TAC-CUL shortcut or a tactic unrelated to the locked findings, regenerate or remove it.”GNDOpen logicFinding-to-action controlRoadmap grounding sanitation
Removes unsupported actions and tactic citations after generation if they do not match both the action and the locked findings.
Finding corpusReplace / removeWarning trail
“A commitment-purchase tactic cannot remain in the roadmap if the source shows no stable workload pattern or commitment-management gap.”8. Fact-check, sanitation, Quality Gate & audit trail
The complete report is treated as another artifact to verify. Unsupported claims are challenged, corrected, removed, or blocked before the final publication state is assigned.
FCOpen logicIndependent verificationSummary & roadmap fact-check
Reviews narrative claims and planning claims separately against sources, metrics, and approved tactic knowledge.
Separate checksBounded retriesHigh-reasoning escalation
“The diagnosis may be valid while one roadmap action remains unsupported. Check and repair them independently.”SANOpen logicActive correctionStrategy sanitation
Removes, rewrites, or quarantines unsupported content while preserving an appendix trail.
RemoveRewriteQuarantine
“Rewrite ‘anti-pattern burden equals share of cloud spend’ into the correct interpretation: a validated severity index, not a spend allocation metric.”QGOpen logicPublication controlGO / WARN / BLOCK Quality Gate
Aggregates evidence density, traceability, verification, fact-check, silence, and sanitation into a visible final decision.
GOWARNBLOCKFinal authority
“Evidence density 28% triggers BLOCK even when the generated prose is excellent. The system chooses evidence sufficiency over presentation quality.”TRACEOpen logicAssurance layerRun trace, diagnostics & drift corpus
Records the actual pipeline path and supports repeatability testing against bundled golden maturity profiles.
Model traceDiagnosticsGolden fixtures
“After changing a model or rubric, rerun the known Crawl, Walk, and Run corpus and compare score and criterion behavior before production use.”Evidence Summary
Facts, metrics, strengths, gaps, anti-patterns, and missing evidence.
FinOps Diagnosis
Primary bottleneck, root causes, and A–F domain interpretation.
Persona Views
FinOps Lead, CFO, and Engineering Lead lenses on the same evidence.
Roadmap or Findings Mode
Directive, cautious, or validation-first output according to confidence.
Quality Appendix
Evidence checks, sanitation, model trace, source gaps, and GO / WARN / BLOCK state.