Flagship product · lifecycle governanceFor SREs & solution architects

Stop being
your own
cloud janitor.

Tag Manager turns AWS tags into a workflow engine. Apply and audit tags across accounts, then attach business processes — TTL, ownership, approval, archival — directly to them. The custodial work that used to eat your sprints just runs itself.

Runs in your account · Terraform / CDK / CLI · Slack · PagerDuty · JIRA hooks
~/infra · tagmworkflow: ttl · dry-run
$ tagm workflow run ttl --dry-run
Loaded workflow ttl.v3.yaml · matching 4,612 resources…
Stage 1 · Discover
4,612 resources scanned · 218 missing ttl tag
Stage 2 · Notify
94 owners pinged · 3 escalations to @platform-team
Stage 3 · Archive
142 idle resources → snapshot + tombstone · saves $8.4k / mo
Stage 4 · Delete
26 confirmed for delete · awaiting approval in #cloud-cleanup
Projected monthly$8,420 saved · 0 engineer-hours
How it works

Built for terminal speed and board-level context.

The CLI workflow, dashboard evidence, and governance data stay aligned so every recommendation has an owner and a next step.

01

Lifecycle ownership

TTL, owner, environment, service, and exception tags become workflow triggers.

React route · clean URL
02

Cost cleanup

Find idle, orphaned, oversized, or expired resources before they become spend drift.

React route · clean URL
03

CLI plus web

Platform teams can enforce policies from terminal workflows and review evidence in the dashboard.

React route · clean URL
0%
Resources with known owner after rollout
0% of AWS bill
Recoverable unmanaged spend
0
Manual cleanup spreadsheets required
0 hr
Default review window before expiration
Install

Start from your terminal.

brew install bluearchio/tap/tag-manager-cli
Read-only first. Expand permissions only when your team approves write workflows.Self-hosted. Designed for your account, your data, and your operating cadence.
FAQ

Common questions.

Do we need perfect tags first?+
No. Tag Manager is built to discover gaps, propose owners, and create the policy trail.
Can it run read-only?+
Yes. Discovery can run read-only, then write workflows can be enabled only where your team approves them.
Can it pair with BlueArch CLI?+
Yes. Tag Manager handles lifecycle governance while BlueArch CLI prioritizes risk and operations.

Want help wiring this into your AWS operating model?

Book a short review and we will map the first workflow from scan to action.