Enable self-service with confidence

Features built for platform teams

Platform teams define guardrails once, Kostavo enforces them automatically. Governance that enables innovation without constant oversight.

The Policy Model

Two kinds of policies, one platform

Everything Kostavo enforces is one of two policy types: what runs inside your workspaces, and how the workspaces themselves are set up.

Resource Policies

Govern what runs

Checks on the resources inside your workspaces: clusters, SQL warehouses, jobs, pipelines, model serving endpoints, apps, and Lakebase. Catch idle compute, oversizing, missing auto-termination, and open permissions.

Example finding

Autoscale max workers (16) exceeds threshold of 8

See resource policies

Configuration Policies

Govern how workspaces are set up

A baseline for workspace settings: security options, preview features, token rules. Every scan compares each workspace against the baseline and flags drift the moment a setting changes.

Example finding

Setting 'enableIpAccessLists' has value 'false', expected 'true'

See configuration policies
Resource Policies

Visibility without micromanagement

Define resource policies once and let Kostavo enforce them across all workspaces

Cross-Workspace Governance

Manage all your Databricks workspaces from a single platform. Define policies once, apply them everywhere, no need to configure each workspace individually.

Automatic Lifecycle Management

Identify idle resources, enforce size limits, and clean up abandoned workloads, all automatically, every scan cycle. Catch waste and drift early, before anyone else has to.

Configuration Policies

Enforce workspace consistency

Resource policies govern what runs inside workspaces. Configuration policies govern how workspaces themselves are set up.

1

Define baseline

Pick a workspace that is configured correctly, or manually set the expected values for security settings, preview features, and serverless compute.

2

Auto-detect drift

Every scan cycle, Kostavo compares workspace settings against your baseline and flags any that have drifted.

3

Resolve & align

Review exactly which settings changed and by how much per workspace, then decide how to bring them back in line.

Smart Scheduling

Policies that respect working hours

Schedules define protected windows where automated actions are blocked. Checks keep running, but nothing acts until the window ends

Per-workspace schedules

Each workspace can have its own operating hours. Production, staging, and dev can all run on different schedules.

Checks run, actions wait

During a protected window Kostavo keeps scanning and reporting, but automated actions are blocked until the window ends.

Tag-driven assignment

Assign schedules via workspace tags. New workspaces inherit the right schedule automatically.

Remediation

Guardrails, not roadblocks

Choose how to nudge teams, from friendly reminders to automatic enforcement

Gentle

NOTIFY

Inform teams about policy suggestions without blocking their work. Build awareness before enforcement.

The resource owner gets an email describing the finding. Nothing is touched.

Teams stay in control
Build compliance culture
Recommended

FIX

Automatically enforce policies while keeping changes reversible. Teams can restart resources instantly when needed.

The idle cluster is stopped; the owner is emailed and can restart it in one click.

Zero friction restarts
Teams stay productive
Strict

REMOVE

Keep environments clean by removing truly abandoned resources. Protect teams from clutter and confusion.

A cluster abandoned for weeks is cleaned up; the owner is emailed beforehand.

Cleaner workspaces
Reduce cognitive load

Whichever mode you choose, actions respect your schedules: during protected windows checks still run, but nothing acts. Platform teams follow along via Slack, Teams, or webhook notification channels.

Tag Automation

Governance that assigns itself

Tag rules turn the tags already on your workspaces into assignment logic. New workspaces get the right policies the moment they appear

Match on tags you already have

Conditions run against cloud source tags (your Azure or AWS resource tags) and Kostavo custom tags. Combine them with ALL or ANY logic, and use exclusions like "environment is not production".

Assign whole baselines

One rule can assign multiple resource and configuration profiles at once, and each profile can carry its own protected-window schedule.

Preview, then stay in sync

A live preview shows exactly which workspaces match before you save. After that, new or re-tagged workspaces are picked up automatically on every sync.

A rule that sweeps costs on everything not tagged production: one condition, one profile, and a live preview of the workspaces it will cover.

Enterprise Controls

Governance that scales

Manage policies across all workspaces from a single platform

Exception Lists

Mark specific resources as exempt from policies. Full audit trail of what's excluded and why.

Tag-Based Policies

Automatically apply the right policies based on team, environment, or workload type. No manual configuration per workspace.

SSO Integration

Sign in via Microsoft Entra, Okta, or any OIDC/SAML provider. Use your existing identity infrastructure.

Integrations

Stay informed everywhere

Resource owners are always notified by email. Notification channels keep the platform team in the loop

Slack
Real-time alerts in your channels
Microsoft Teams
Real-time alerts in your channels
Email Digests
Daily or weekly summaries
Webhooks & API
Custom integrations
100+ Built-in Policies

Ready-to-use governance

Pre-built policies for common scenarios, customize or use as-is

Running ComputeCompute
Oversized ClustersCompute
Long-Running ClustersCompute
Abandoned ClustersCompute
Cluster Auto-TerminationCompute
Warehouse RunningSQL
Warehouse Auto-StopSQL
Serverless MigrationSQL
Warehouse SizingSQL
Failing JobsJobs
Job Retry PolicyJobs
Job TimeoutsJobs
Long-Running JobsJobs
Failed PipelinesPipelines
Continuous PipelinesPipelines
Scale-to-Zero ServingML Serving
Provisioned ThroughputML Serving
Serving Workload SizeML Serving
Idle Vector SearchML Serving
Branch ExpiryLakebase
Endpoint SuspensionLakebase
Open Cluster PermissionsSecurity
IP Access ListsSecurity
Token ExpirySecurity
Secret ScopesSecurity
Workspace AdminsSecurity
Resource TagsGovernance
Stale DashboardsGovernance

…and 75+ more across compute, jobs, pipelines, serving, Lakebase, and security.

Ready to streamline
Databricks governance?

Define policies once, enforce them everywhere. Start your free trial today.