Cloud operations and cost

Explore your AWS, GCP, and Azure resources and surface wasted spend through read-only queries, without leaving a Praxis conversation.

Praxis can query your cloud accounts on your behalf. You ask a question in a chat session, and it runs read-only commands against your organization's connected AWS, GCP, and Azure accounts, then summarizes the result instead of returning raw output. Two built-in capabilities sit behind it: one explores what you are running, and the other flags resources that cost money but do little work. You get answers across all three clouds from one conversation, and neither capability can change anything in your cloud.

Before either capability can run, connect the relevant integration to your organization, a cloud account or New Relic, and enable its MCP on your Praxis agent.


Explore your infrastructure

Ask Praxis about a resource in plain language, for example "show the running instances in our production AWS account" or "list the databases in our GCP project," and it finds your connected cloud accounts, uses the one you named (or asks which to use when you have several), runs the query, and returns the answer as a table or a count rather than raw output.

It reads across compute instances, networks and disks, object storage, managed databases and caches, Kubernetes clusters and container registries, serverless functions, identity and permissions, metrics and logs, DNS, and messaging queues. Praxis selects the right command for each account's provider, so you do not need to remember whether an account is AWS, GCP, or Azure, or how each provider's command line is spelled. Because each request is part of a conversation, you can follow up to narrow a result or move to the next question without repeating context.

If your organization connects New Relic, Praxis can query it the same conversational way: it runs NRQL queries and pulls application performance (APM) data, entities, logs, alerts, synthetics, and workloads into the conversation. Unlike the AWS, GCP, and Azure explorer, the New Relic integration is not confined to read-only: it can run commands that change your observability data and configuration, not only read them.

🚧

Because the New Relic integration can make changes, give any New Relic action the same review and approval you would give a change to production, and confirm what it will do before you run it.

You reach all of this in a Praxis chat session, or from your terminal with the Praxis CLI.


Find wasted spend

The second capability scans the same accounts for resources that keep billing while doing little or no work, then returns a ranked report of what you could save. Point it at one account, or let it scan every connected account and total the savings across them.

Findings are grouped by confidence. High-confidence items are the ones almost always safe to remove: disks left unattached, static IP addresses reserved but not associated with anything, and orphaned snapshots whose source volume no longer exists. Medium-confidence items need a human eye, because they can have good reasons to look idle: snapshots that are merely old but whose source volume still exists, databases with no connections, compute instances running at almost no CPU, instances stopped long ago that still bill for their attached disks, load balancers with no healthy targets or traffic, and idle NAT gateways. "Idle" is measured over a 14-day window by default, so a resource has to stay quiet for a while before it appears.

The scan also points out one easy optimization that is not waste: AWS gp2 disks that would cost about 20% less on gp3. It reports these separately, because the disk is still in use.

Each finding carries an approximate monthly saving, and the report totals them. A single scan might surface, for instance, several unattached disks, a stopped instance still paying for its storage, and an idle load balancer, each line showing its estimated monthly cost with the running total at the top. Every figure is an estimate, and the report says so. It also reasons about false positives rather than declaring a resource dead: a database with zero connections might be a warm standby kept for disaster recovery, so the report explains why it flagged something and leaves the judgment to you.

📘

This capability is report-only. It reads your accounts and ranks what looks wasteful, but it never deletes, stops, or changes anything. Deciding what to act on, and acting, stays with you.


How access works

The AWS, GCP, and Azure explorer and the waste finder are read-only. Praxis runs their queries server-side against your organization's stored credentials, so the credentials resolve at the server and never reach the model. Commands that would change or delete a resource are blocked at the system level, not merely discouraged, which is why these two capabilities need no approval step. Because they have no write path, you can run them against production without staging or a dry run.

The New Relic integration works differently. It is not restricted to read-only, so none of those guarantees apply to it: it can run commands that change your observability setup, and it needs your review and approval before it acts. Its credentials are still resolved server-side and never reach the model, the same as the cloud integrations.

For how Praxis runs under your credentials and audits every call, see How Praxis works.