Waste scans

What we scan on each cloud

Detailed catalog of every waste check SpendPilot runs for AWS, Azure, and GCP — by service, how it works, and whether Approve & delete is available.

What a waste scan does

A waste scan inventories cloud resources and billing signals, then opens savings actions for likely idle or oversized spend. Scans are read-only by default — they never change your cloud until an engineer opts into approve-then-delete and confirms.

Findings land on Actions (and roll into Can save /mo on Services). After you fix waste, mark verified so Savings reflects confirmed monthly savings.

  1. 1. Connect

    Link AWS / Azure / GCP under Cloud accounts with read access.

  2. 2. Sync costs

    Pull Cost Explorer / Cost Management / billing export for MTD spend.

  3. 3. Scan waste

    Run per account. Findings become open actions with estimated $/mo.

  4. 4. Act

    Approve → fix manually, or Approve & delete when remediable + opted in.

Run scans from your dashboard (log in). Review findings on Actions and service rollups on Services.

Amazon Web Services

Amazon Web Services

Uses Cost Explorer, CloudWatch, EC2/RDS/ELB APIs, and Compute Optimizer where available.

Scope Account-level checks once (anomaly, commitments). All other scanners run per selected waste-scan region.

21 checks · 3 remediable

Org / Other

CheckDetectsConfidenceDelete

Spend anomaly

anomaly

Yesterday’s spend ≥ ~25% above a recent daily baselineMediumNo

RIs & Savings Plans

CheckDetectsConfidenceDelete

Low RI / Savings Plans coverage

commitment_coverage

Low Reserved Instance hour coverage and/or Savings Plans coverageMediumNo

EBS Storage

CheckDetectsConfidenceDelete

Unattached EBS volume

unattached_ebs

EBS volumes in available (not attached) stateHighYes*

Old EBS snapshots

old_snapshots

Owned snapshots older than 90 daysMediumYes*

gp2 → gp3 opportunity

gp2_to_gp3

gp2 volumes that can move to gp3 in placeMediumNo

Unused old AMIs

old_ami

Owned AMIs >90 days not used by running/stopped instancesMediumNo

EC2 Compute

CheckDetectsConfidenceDelete

Idle EC2 instance

idle_ec2

Running instances with very low average CPU over 14 daysMediumNo

Compute Optimizer rightsizing

compute_optimizer

Overprovisioned EC2 / EBS recommendations from AWSMediumNo

Idle EKS node group

idle_eks

EKS node groups with low CPU — scale-down candidateMediumNo

Oversized Auto Scaling group

oversized_asg

ASGs with low average CPU over 14 daysMediumNo

EC2 Other

CheckDetectsConfidenceDelete

Idle Elastic IP

idle_eip

EIPs not associated with an instance or ENIHighYes*

Idle NAT Gateway

idle_nat

NAT Gateways with ~0 ActiveConnectionCount over 14 daysMediumNo

Unused network interface

unused_eni

Available ENIs (excluding AWS-managed interfaces)MediumNo

RDS

CheckDetectsConfidenceDelete

Oversized RDS

oversized_rds

Provisioned RDS with low CPU (skips Aurora Serverless)MediumNo

Load Balancing

CheckDetectsConfidenceDelete

Unused load balancer

unused_elb

ALB/NLB with no targets, or ALB with ~0 requests over 14 daysMediumNo

ElastiCache

CheckDetectsConfidenceDelete

Idle ElastiCache

idle_elasticache

Cache nodes with low CPU over 14 daysMediumNo

VPC / Endpoints

CheckDetectsConfidenceDelete

Unused VPC interface endpoint

unused_vpc_endpoint

Interface endpoints with near-zero ActiveConnectionsMediumNo

S3

CheckDetectsConfidenceDelete

Orphaned S3 multipart uploads

s3_multipart

Incomplete multipart uploads older than 7 daysHighNo

OpenSearch

CheckDetectsConfidenceDelete

Idle OpenSearch domain

idle_opensearch

Domains with low CPU over 14 daysMediumNo

MSK Kafka

CheckDetectsConfidenceDelete

Idle MSK cluster

idle_msk

Clusters with near-zero BytesInPerSec over 14 daysMediumNo

API Gateway

CheckDetectsConfidenceDelete

Unused API Gateway

unused_apigateway

REST/HTTP stages with near-zero traffic over 14 daysMediumNo
Microsoft Azure

Microsoft Azure

Combines resource inventory (Resource Graph) with optional Monitor metrics for idle VMs and Cost Management for anomalies.

Scope Subscription-scoped via Azure Resource Graph, ARM, and Cost Management. One pass covers the whole subscription.

12 checks · 2 remediable

Org / Other

CheckDetectsConfidenceDelete

Spend anomaly

anomaly

Yesterday’s spend spike vs ~7-day Cost Management baselineMediumNo

Virtual Machines

CheckDetectsConfidenceDelete

Idle virtual machine

idle_vm

Running VMs with very low average CPU over 14 daysMediumNo

Storage

CheckDetectsConfidenceDelete

Unattached managed disk

unattached_disk

Managed disks in Unattached stateHighYes*

Old disk snapshots

old_disk_snapshot

Managed disk snapshots older than 90 daysMediumNo

Networking

CheckDetectsConfidenceDelete

Unused public IP

unused_public_ip

Public IPs not associated with NIC / LB / NAT / etc.HighYes*

Unused load balancer

unused_lb

Load balancers with no backend pools or rulesMediumNo

Unused network interface

unused_nic

NICs not attached to a VMMediumNo

Azure SQL

CheckDetectsConfidenceDelete

Oversized Azure SQL

oversized_sql

Databases on Premium / high-capacity SKUs (rightsizing candidates)MediumNo

Kubernetes (AKS)

CheckDetectsConfidenceDelete

Idle AKS cluster

idle_aks

AKS clusters with zero agent nodes (empty / stopped pools)MediumNo

API Management

CheckDetectsConfidenceDelete

Unused API Management

unused_apim

APIM with no APIs, or leftover Developer SKU gatewaysMixedNo

Cosmos DB

CheckDetectsConfidenceDelete

Empty Cosmos DB account

idle_cosmos

Cosmos accounts with no databases or containersHighNo

Monitor & Logs

CheckDetectsConfidenceDelete

Long Monitor & Logs retention

idle_log_analytics

Log Analytics workspaces or Application Insights with retention ≥ 90 daysMediumNo
Google Cloud

Google Cloud

Uses Compute Engine, Cloud SQL, and BigQuery billing export APIs. Idle GKE is reserved in the product model but not scanned yet.

Scope Project-scoped. Compute/network/disk checks respect selected scan regions (or all enabled). Anomaly needs BigQuery billing export configured on the account.

9 checks · 2 remediable

Cloud Monitoring metrics for low-CPU running VMs are not scanned yet — idle_gce today flags stopped/terminated VMs only.

Org / Other

CheckDetectsConfidenceDelete

Spend anomaly

anomaly

Yesterday’s GCP spend spike vs recent baselineMediumNo

Compute Engine

CheckDetectsConfidenceDelete

Stopped / terminated GCE VM

idle_gce

VMs that are stopped or terminated but still hold disks & IPsMediumNo

Old custom machine images

old_gcp_image

Project custom images older than 90 daysMediumNo

Cloud Storage / Disk

CheckDetectsConfidenceDelete

Unattached persistent disk

unattached_pd

Persistent disks with no attached usersHighYes*

Old disk snapshots

old_disk_snapshot

Global disk snapshots older than 90 daysMediumNo

Networking

CheckDetectsConfidenceDelete

Unused static external IP

unused_static_ip

External static IPs in RESERVED stateHighYes*

Unused load balancer / target pool

unused_gcp_lb

Forwarding rules with no backend/target, or empty legacy target poolsMixedNo

Cloud SQL / AlloyDB

CheckDetectsConfidenceDelete

Stopped Cloud SQL

oversized_cloudsql

Cloud SQL instances left in STOPPED state (still billable)HighNo

Kubernetes (GKE)

CheckDetectsConfidenceDelete

Idle GKE cluster

idle_gke

GKE clusters with zero nodes (empty / scaled to zero)MixedNo

Approve & delete (optional)

Only the checks marked Yes*can be deleted from SpendPilot. You must enable remediation on the cloud account and an engineer must confirm Approve & delete. Everything else is fix manually, then mark fixed / verified.

AWS

  • Delete EBS volume

    unattached_ebs

  • Release Elastic IP

    idle_eip

  • Delete EBS snapshot

    old_snapshots

Azure

  • Delete managed disk

    unattached_disk

  • Delete public IP

    unused_public_ip

GCP

  • Delete persistent disk

    unattached_pd

  • Release static IP

    unused_static_ip

IAM / role setup for read-only and optional delete: Cloud access setup →

What scans do not do

  • Purchase Reserved Instances or Savings Plans
  • Automatically rightsize or stop idle compute (manual workflow)
  • Change Monitor retention or APIM SKUs without your action
  • Run delete without account opt-in and engineer confirmation