For Platform Engineering Teams

Self-Service Guardrails
for Data Teams

Your data team needs freedom to move fast. Your finance team needs cost control. Give everyone what they need with automated guardrails that enforce policies without blocking work.

The Platform Team Dilemma

Caught in the Middle

Data teams blame you for restrictions. Finance blames you for costs. You can't win with manual enforcement.

No Visibility

You can't see what's running across 50+ workspaces right now. Problems surface weeks after they start, when they're expensive to unwind.

Inconsistent Policies

Different rules in different workspaces. No central governance. Tribal knowledge instead of automation.

Governance That Runs Itself

Policy Profiles

Configure which policies run per workspace, with what settings and action modes. One profile can cover many workspaces.

  • 100+ built-in resource policies
  • Per-workspace configuration
  • Notify, Fix, or Remove modes

Continuous Enforcement

Policies run continuously on a scan cadence. When a violation is found, Kostavo emails the resource owner and workspace admins, or stops the resource automatically.

  • Continuous scheduled scans
  • Configurable action modes
  • Owner + admin notifications

Tag-Based Targeting

Policies can target resources by tag. Apply stricter rules to production, lighter rules to dev, based on tags already on your resources.

  • Filter by resource tags
  • Environment-aware rules
  • Multi-workspace findings view

Policy profiles bundle checks into reusable guardrails you assign per workspace or tag.

What Platform Teams Configure

Cluster Governance

Size limits, autotermination, runtime versions, access modes, SSH, env var secrets

Warehouse Governance

Warehouse size, auto-stop settings, channel, serverless usage, permissions

Cost Hygiene

Missing cost tags, idle resources, abandoned clusters, and after-hours compute in dev/test

Notification Channels

Route findings to email, Slack, Microsoft Teams, or webhooks by severity

Security Policies

IP access lists, service principal hygiene, open permissions, token expiry

Configuration Baselines

Define expected workspace settings (preview features, serverless, security) and detect drift across all workspaces

Tag rules do the assigning for you: match workspaces on cloud or custom tags (with exclusions) and they inherit the right profiles and schedules automatically.

How It Works

1

Connect Workspaces

Link all your Databricks workspaces to a single Kostavo organization. Kostavo becomes a workspace admin with a minimal service principal on Azure or AWS.

2

Configure Policy Profiles

Choose which policies to enable, set thresholds, and pick action modes (Notify, Fix, or Remove) per workspace or group of workspaces.

3

Policies Run Continuously

Kostavo scans on a schedule. Findings surface in the multi-workspace dashboard and trigger notifications to resource owners and workspace admins.

Governance That Scales

Connect your first workspace and see what the first scan turns up.

Start Free Trial