Platform teams define guardrails once, Kostavo enforces them automatically. Governance that enables innovation without constant oversight.
Everything Kostavo enforces is one of two policy types: what runs inside your workspaces, and how the workspaces themselves are set up.
Govern what runs
Checks on the resources inside your workspaces: clusters, SQL warehouses, jobs, pipelines, model serving endpoints, apps, and Lakebase. Catch idle compute, oversizing, missing auto-termination, and open permissions.
Example finding
Autoscale max workers (16) exceeds threshold of 8
Govern how workspaces are set up
A baseline for workspace settings: security options, preview features, token rules. Every scan compares each workspace against the baseline and flags drift the moment a setting changes.
Example finding
Setting 'enableIpAccessLists' has value 'false', expected 'true'
Define resource policies once and let Kostavo enforce them across all workspaces
Manage all your Databricks workspaces from a single platform. Define policies once, apply them everywhere, no need to configure each workspace individually.
Identify idle resources, enforce size limits, and clean up abandoned workloads, all automatically, every scan cycle. Catch waste and drift early, before anyone else has to.
Resource policies govern what runs inside workspaces. Configuration policies govern how workspaces themselves are set up.
Pick a workspace that is configured correctly, or manually set the expected values for security settings, preview features, and serverless compute.
Every scan cycle, Kostavo compares workspace settings against your baseline and flags any that have drifted.
Review exactly which settings changed and by how much per workspace, then decide how to bring them back in line.
Schedules define protected windows where automated actions are blocked. Checks keep running, but nothing acts until the window ends
Each workspace can have its own operating hours. Production, staging, and dev can all run on different schedules.
During a protected window Kostavo keeps scanning and reporting, but automated actions are blocked until the window ends.
Assign schedules via workspace tags. New workspaces inherit the right schedule automatically.
Choose how to nudge teams, from friendly reminders to automatic enforcement
Inform teams about policy suggestions without blocking their work. Build awareness before enforcement.
The resource owner gets an email describing the finding. Nothing is touched.
Automatically enforce policies while keeping changes reversible. Teams can restart resources instantly when needed.
The idle cluster is stopped; the owner is emailed and can restart it in one click.
Keep environments clean by removing truly abandoned resources. Protect teams from clutter and confusion.
A cluster abandoned for weeks is cleaned up; the owner is emailed beforehand.
Whichever mode you choose, actions respect your schedules: during protected windows checks still run, but nothing acts. Platform teams follow along via Slack, Teams, or webhook notification channels.
Tag rules turn the tags already on your workspaces into assignment logic. New workspaces get the right policies the moment they appear
Conditions run against cloud source tags (your Azure or AWS resource tags) and Kostavo custom tags. Combine them with ALL or ANY logic, and use exclusions like "environment is not production".
One rule can assign multiple resource and configuration profiles at once, and each profile can carry its own protected-window schedule.
A live preview shows exactly which workspaces match before you save. After that, new or re-tagged workspaces are picked up automatically on every sync.
A rule that sweeps costs on everything not tagged production: one condition, one profile, and a live preview of the workspaces it will cover.
Manage policies across all workspaces from a single platform
Mark specific resources as exempt from policies. Full audit trail of what's excluded and why.
Automatically apply the right policies based on team, environment, or workload type. No manual configuration per workspace.
Sign in via Microsoft Entra, Okta, or any OIDC/SAML provider. Use your existing identity infrastructure.
Resource owners are always notified by email. Notification channels keep the platform team in the loop
Pre-built policies for common scenarios, customize or use as-is
…and 75+ more across compute, jobs, pipelines, serving, Lakebase, and security.
Define policies once, enforce them everywhere. Start your free trial today.