Skip to content
Notifications
Clear all

Showcase: Our monthly Orca review process (with templates).

4 Posts
4 Users
0 Reactions
7 Views
(@startup_founder_ops)
Eminent Member
Joined: 2 months ago
Posts: 11
Topic starter   [#671]

We've been using Orca for six months. The monthly review meeting was a mess until we templated it. Now it takes 30 minutes.

Here’s the flow. We run the Orca report on the last Friday of the month. The meeting has three sections: critical findings (must fix), compliance gaps (tracking), and asset drift (what's new in inventory). We assign one owner per item in the meeting doc. Next meeting starts by reviewing last month's owner list.

I can share the basic template. It's just a doc with those three sections and columns for finding, resource ID, owner, and status. No fluff. Keeps engineering and security aligned. What does your review process look like?



   
Quote
(@procurement_cynic_2)
Eminent Member
Joined: 4 months ago
Posts: 18
 

Thirty minutes is a nice target, but does that include the actual remediation work or just the talking? The danger with a clean owner list is it becomes a compliance theater checklist. Someone gets assigned, they mark it "in progress," and it rolls over six times. We started requiring the owner to state the exact single next action and its due date, not just a status. Stops the cycle of polite avoidance.

And "asset drift" is a generous term. Half of that is usually someone spinning up a test instance without a shutdown schedule. You're just documenting your own waste. Are you tracking the cloud spend impact of those "new" assets alongside the security finding? If not, you're only seeing half the problem.


Procurement Cynic


   
ReplyQuote
(@devops_barbarian_v2)
Estimable Member
Joined: 3 months ago
Posts: 123
 

Spot on about the checklist theater. Adding a due date just moves the goalpost for the same shrug.

The real fix? Tie owner KPIs to remediation closure rates. If their promo doc needs "reduced critical findings by X%," suddenly those due dates matter. Otherwise it's just calendar clutter.

And yeah, asset drift without a cost column is a joke. Orca flags a new S3 bucket, FinOps yells about the 3TB of unclassified data inside it. Same problem, two meetings.



   
ReplyQuote
(@cost_optimizer_88)
Estimable Member
Joined: 3 months ago
Posts: 95
 

Thirty minutes sounds efficient, but I'd bet a coffee the real waste is happening before the report even runs. "Asset drift" is just a polite term for uncontrolled provisioning. If you're not forcing a cost impact column next to every new finding, you're letting engineers rack up spend that security then politely asks them to clean up. That's two teams doing the same cleanup job.

Your template has columns for owner and status. Add one for "estimated monthly run-rate" and another for "savings from remediation." Then you'll see if your 30-minute meeting is saving thousands or just shuffling tickets. Otherwise you've built a great process for documenting waste, not stopping it.


pay for what you use, not what you reserve


   
ReplyQuote