
AIdeas: Cirrondly - The first autonomous FinOps agent for AWS
No more fear when using AWS. The first AI agent that detects AWS cost waste in real-time and executes optimisations with your approval. No dashboards. Just chat, approve, and save money.
For many people, the cloud is something unsafe, complicated, and hard to understand. There are enormous amounts of cloud services that are super necessary to scale your company and innovate without worrying about infrastructure. But this knowledge gap has created terror and insecurity around using them. Today, with AI, writing code isn't a problem anymore but I still see founders terrified of cloud services. AWS offers excellent services with global reach. But for non-experts without cloud knowledge, the barrier to entry is high, despite the generous free tier. Then add the horror stories: a simple Google search for "surprise cloud bills" returns 50+ posts, articles, and comments from people who suffered. The supervision companies aren't accessible to indie founders or small startups. There's no circuit breaker to disconnect services easily, no simple alerting system, no tool that feels right for the cloud. That's why Cirrondly exists.
SolutionsTag: #aideas-2025 #commercial-solutions #EMEA
App Category
Commercial Solutions
My Vision
Cirrondly is the bridge between simplicity and cloud services.
It detects cost anomalies in real time with an agent that speaks your language. Write naturally: "show me my costs," "what if we scale 20x?", "which services are we not using?" and Cirrondly answers, no FinOps expertise required, no DevOps knowledge needed.
You can:
- Detect anomalies the moment they happen (minutes, not months)
- Understand why costs changed (in plain English, not AWS jargon)
- Optimize your account without hiring a DevOps engineer
- Cancel abandoned services with a single message
- Project costs with growth scenarios ("what does 20x look like?")
- See your AWS spending clearly, for the first time
Target users:
Startups, founders, indie hackers, CTO teams, vibecoders, anyone building on AWS without a dedicated FinOps person.
Why This Matters
I validated the problem myself. Searched for cloud cost horror stories. Found dozens.
70% of teams discover cloud cost problems too late, when the bill arrives or when leadership asks "why did we spend $50,000 this month?" By then, damage is done. Root cause analysis becomes forensics.
Real cost of waiting:
A startup's deployment bug floods S3 with uncompressed logs. Undetected for 48 hours: $2,400 in extra costs. The founder didn't check, priorities were features, not cost details. These details hurt when they explode.
With Cirrondly: the spike is flagged in minutes with a clear recommendation: "Enable log compression or pause this feature."
The deeper problem:
Most founders or indie hackers aren't AWS experts. They know parts of it, or they're guided by an LLM because it's the best and most economical cloud provider. But this experience gap and fear means they forget to enable alerts or check costs. As a founder, your priority is value generation and distribution, not cost management. Until those costs explode.
Impact of real-time anomaly detection:
- Faster incident response (hours ā minutes)
- Prevention, not reaction (stop the bleeding before the bill)
- Confidence to scale (ship features without hidden cost fears)
This matters most for early-stage companies where every dollar counts and engineering speed is a competitive advantage. Cirrondly lets teams optimise without slowing down.
How I Built This
The hardest problem wasn't detection. It was trust.
How do you let an AI execute actions inside someone's AWS account without terrifying them? That single question shaped every architectural decision in Cirrondly.
Zero Setup by Design
Most AWS tools require SDK configuration, config files, access keys, or CLI installation. That creates instant friction and friction is the enemy of adoption for the audience I'm building for.
The solution: CloudFormation-based onboarding. Users click one link, deploy a stack, and Cirrondly receives a cross-account IAM role ARN. No credentials stored. No SDK installed. No CLI commands. The connection is verified through STS AssumeRole, if the role assumption fails, onboarding doesn't proceed. Zero false positives, zero silent failures.
This decision forced a constraint that made the product better: if it can't be zero-setup, it doesn't ship.
Conversational Approval as a Safety Primitive
Most AWS cost tools show a table of resources with checkboxes. You select, you click "Apply." You've approved something, but you haven't necessarily understood it.
Cirrondly takes a different approach: the agent explains findings in natural language first, then renders a structured approval card directly in the chat, resource ID, region, estimated savings, and a rollback plan link, before any action executes. The user isn't approving a row in a table. They're approving a specific action they've just read about, with full context visible at the moment of decision.
Behind this, the safety model is layered:
- Destructive actions (instance stops, volume deletions) always require explicit card approval. Never auto-executed
- Low-risk actions (S3 lifecycle policies, snapshot cleanup) can be pre-authorized on a schedule via Agent Controls
- Every execution is logged with pre-execution state and a rollback window for reversible actions
The result: users feel in control because they are in control.
Event-Driven Everything
There are no servers running 24/7 in Cirrondly. Every component is triggered on-demand.
The watchdog runs on EventBridge schedules. Detection modules execute as Lambda functions invoked by user actions or scheduled jobs. The Bedrock Agent responds to API calls. Cost Explorer data is fetched at query time, not cached in a background process.
The practical outcome: the architecture scales from 1 workspace to 1,000 with zero infrastructure changes. The cost implication: the entire MVP was built and tested within AWS Free Tier. Total infrastructure cost: under $50.
Event-driven wasn't just a cost decision, it was a correctness decision. Polling-based architectures drift. Event-driven architectures stay current.
Multi-Tenant Security From Day One
Each customer workspace operates in complete isolation. Cirrondly never stores AWS credentials, only an IAM role ARN per workspace, used for temporary STS assumptions. One customer's breach cannot affect another's data or account access.
The workspace model is embedded in every data access pattern. DynamoDB queries always include a
workspace_id filter. Lambda functions receive workspace context on every invocation. The Bedrock Agent maintains conversation history scoped to a session, not a global state.Building this correctly on day one cost time. Retrofitting it later would have cost the product.
Kiro as Co-Pilot
Kiro (AWS's agentic IDE) handled backend module implementation in parallel while I built the frontend. But the real value wasn't the code, it was the spec-first workflow.
Before writing any Lambda function, I wrote the requirement: what inputs does it receive, what outputs does it produce, what edge cases must it handle, what should it never do. Kiro translated those specs into implementation. When the implementation drifted from the spec, the tests caught it. When the tests caught it, the spec was clarified.
This forced clarity on product decisions that would otherwise be deferred to implementation time which is the worst time to make product decisions.
The result: 800+ passing tests across unit, property-based, and integration layers. Every detection module covered before it touches a real AWS account.
AWS Services
Built entirely on AWS serverless infrastructure: Bedrock for AI orchestration and conversational agent, Lambda for all compute (ARM64, Python), DynamoDB for multi-tenant storage, EventBridge for scheduling, API Gateway for REST endpoints, Cost Explorer API for real spending data, SES for email notifications, S3 for static assets, CloudFormation for customer account onboarding, STS for cross-account role assumption, CloudWatch for observability.
No EC2. No containers. No always-on services. Every component scales to zero when not in use.
Demo
See it live:
š Beta: agent.cirrondly.comĀ
š Landing: cirrondly.comĀ (waitlist open)

Home The interface: no dashboard, no menus. Just a chat prompt and four suggested actions.

Onboarding Zero-setup connection: CloudFormation verifies the AWS role in seconds. No SDK, no credentials stored.

Diagnosis card "Give me a diagnosis of my account" ā Projected spend, potential savings in green, findings by service. One message, full picture.

6-month projection "What is my 6 months projection?" ā Trend chart with month-by-month breakdown. No FinOps expertise required.

Scaling scenario "What if I scale to 10x users?" ā Variable vs fixed cost breakdown by service. The answer a founder actually needs before scaling.
What I Learned
The spec comes before the code
I spent a year over-engineering a previous version of this product. More services, more complexity, more features nobody asked for. When I restarted for this competition, I forced myself to write requirements before writing code. What does this function receive, what does it return, what should it never do.
Kiro translated those specs into implementation. The 800+ tests didn't come from discipline, they came from having clear specs. When the spec is wrong, the test fails. When the test fails, you fix the spec, not just the code. That loop prevented entire categories of bugs before they touched a real AWS account.
The lesson: clarity about what you're building is more valuable than speed of building it.
Trust is an architecture decision, not a UX detail
The hardest thing about building a tool that executes actions in someone's cloud account isn't the detection. It's convincing the user that nothing will happen without their knowledge.
Trust has to be built into the system at the architecture level, not added as a disclaimer. Cross-account IAM with no stored credentials, approval cards with full context before execution, rollback windows for reversible actions, workspace isolation at every data access layer. None of these are features. They're the foundation.
If you build a product that touches real infrastructure and real money, the safety model is the product.
Market validation
The pain of misunderstanding cloud services and fear of costs has created entire platforms: Vercel, Render, Railway, Fly.ioĀ exist because they simplify this fear.
Yet many still want AWS it's #1 on LLM recommendations for starting any project.
The deeper insight: people suffer with costs. Small teams deprioritise cost monitoring because they're focused on building. Until it's too late. That's the gap Cirrondly fills.
Betting 100%
I posted every stage on Reddit before and after becoming a semifinalist. Before this competition, I almost abandoned it all. Then something clicked.
Everyone lives their competition differently. Everyone has their own path, their own will. Many told me to get a job. I bet 100% on this project. I hope you enjoy it and see the utility I'm proposing.
Team
Built by: Jose (@josemarin18 on Reddit, @josermarinr on LinkedIn, @CirrondlyLog on X)
Full-stack engineer, 9 years experience, Lyon, France.
Former CTO. Betting 100% on this.
š Beta: agent.cirrondly.comĀ
š Landing: cirrondly.comĀ
Don't hesitate to vote. Don't hesitate to follow my journey.
š Reddit: https://www.reddit.com/user/josemarin18/Ā
š LinkedIn: https://www.linkedin.com/in/josermarinr/Ā
š X: https://x.com/CirrondlyLogĀ
# aideas-2025# cost-savings# commercial-solutions# europe-middle-east-africa# cost-control-automation
Any opinions in this article are those of the individual author and may not reflect the opinions of AWS.Enjoyed reading this content? Let the author know!
Your likes, comments, shares, and saves help creators reach more builders.
Loading recommendations
Loading article