Release Notes 6.4 (2605)

September 2026

Summary

CoreStack v6.4 brings AI spend into FinOps governance and gives multi-tier reseller networks a hierarchical view of their charges. It also moves security work into a single Cloud Security experience. The release continues the platform's move to CoreStack's current UI framework, with the Policies, Compliance, Templates, and Settings pages rebuilt on Angular.

On the FinOps side, AI-Native Service Discovery automatically finds AWS Bedrock and Anthropic's Claude API usage across accounts and API keys teams have already onboarded. It maps Claude API cost to the specific agent and API key that generated it. TokenOps builds on this with token-based usage, cost, and rate analytics for AWS Bedrock, broken down by AI model. This shows whether a spend change came from higher usage or a higher per-token rate. Cost widgets now support a Usage metric alongside Cost. The Cost Trend widget adds a multi-axis combo chart that shows Cost, Usage, and Rate together, with drill-down from tenant to individual resource. Optimization Rate now covers Savings Plans for AWS Member Accounts, not just Master Accounts. A new Distributor / Indirect Partner Consolidated Charges report gives every tier of a reseller network a role-scoped view of its consolidated charges.

On the Graphion side, SecOps Posture and SecOps Dashboard are now combined under the Cloud Security menu. There, Infrastructure Explorer shows detailed findings on one screen, and new AWS Inspector filters help teams find exploitable vulnerabilities in ECR images and Lambda functions. Graphion Threats now sync with ITSM tools on a regular schedule, so tickets stay current without manual re-entry. The rebuilt Compliance pages keep assessments open and update them automatically from any mapped policy run. During Application creation, all BCS questions now appear on a single screen, and responses can be copied from an existing Application.

This release also deprecates the Recommendations page and the SecOps menu. See the Deprecation List for details.

Release Highlights

  • Distributor / Indirect Partner Consolidated Charges Report — new report gives every tier of a multi-tier reseller network a role-scoped, hierarchical view of consolidated charges
  • TokenOps token usage, cost, and rate analytics for AWS Bedrock, broken down by AI model
  • Multi-Metric Cost, Usage, and Rate Analysis — cost widgets across the platform now support Usage and Rate alongside Cost, including a new Cost Trend multi-axis combo chart
  • AI-Native Service Discovery — automatic visibility into AWS Bedrock and Anthropic's Claude API, with cost mapped to the agent and API key that generated it
  • New Distributor / Indirect Partner Consolidated Charges report with role-scoped hierarchy views
  • A single Cloud Security menu replacing SecOps Posture and SecOps Dashboard, with AWS Inspector filters in Vulnerability Explorer
  • Automatic ITSM sync for Graphion Threats
  • Modernized Policies, Compliance, Templates, and Settings pages, with compliance assessments that stay up to date

FinOps

AI-Native Service Discovery

Description: AI-Native Service Discovery brings AWS Bedrock and Anthropic's Claude API into CoreStack's inventory, cost attribution, and governance workflows, using accounts and API keys customers have already onboarded. Bedrock gets automated discovery and cost visibility; Claude API usage is mapped down to the specific agent and API key that generated it.

Key Capabilities:

  • Auto-discovers Bedrock and Claude API usage within 24 hours — no new connector, IAM role, or manual onboarding for Bedrock
  • Maps Claude API cost to the Agent and API key that generated it (including shared/multi-key cases), rolling into existing chargeback/showback Dimensions
  • Captures Claude API usage detail — requests, tokens, rate limits, searchable invocation logs, and key/agent lifecycle events
  • Exports AI inventory as CSV or scheduled digests

Key Benefits:

  • Surfaces AI shadow-spend across Bedrock and Claude API in one inventory — 90% within 24 hours, 100% within 7 days
  • Cuts cost-spike investigation from hours to a few clicks
  • Reduces manual AI inventory effort from 8+ hours/quarter to under 30 minutes

Supported Providers: AWS (Bedrock), Anthropic (Claude API)


TokenOps — Token Usage, Cost, and Rate Analytics for AI Services

Description: TokenOps lets FinOps teams track AI token usage, cost, and rate in CoreStack and analyze spend by AI model. Users set a token-based Consumed Unit on a Platform Cost Trend (New) or Platform Summary widget bound to AI Service data. AWS Bedrock usage is auto-discovered, so no additional connector or onboarding is needed.

Key Capabilities:

  • Supports token-based Consumed Units (Units, 1K Tokens, 1M Tokens) for AWS Bedrock, set through Override Filters on the widget's Data Binding tab
  • Shows Cost, Usage, and Rate together on the Cost Trend (New) widget
  • Groups data by AI Model Name to isolate each model's consumption, cost, or rate
  • Calculates Rate as the average cost per 1K or 1M tokens for the selected Time Range and Granularity

Key Benefits:

  • Shows which AI models drive spend and consumption, instead of only a total AI cost
  • Shows whether a cost change came from higher usage or a higher per-token rate
  • Needs no new connector for AWS Bedrock, because usage is auto-discovered within 24 hours

Usage Metric Support Across Cost Widgets

Description: Cost widgets across CoreStack — Summary, Forecast, and Measure by Dimension — now support a selectable "Usage" metric alongside Cost, so teams can view resource consumption (vCPU-hours, GB, requests) rather than just spend. When Usage is selected, a Consumed Unit filter lets users focus on a specific unit of measure.

Key Capabilities:

  • Adds a selectable Usage metric to the Summary, Trend, Forecast, and Measure by Dimension widgets
  • Applies a mandatory Consumed Unit filter (e.g., GB, Hrs, vCPU-Hours) when Usage is selected
  • Shows Cost and Usage side-by-side in the group-by-None view to surface efficiency trends
  • Adjusts forecasting logic to follow the usage trendline when the Usage metric is selected
  • Automatically disables groupbys or drill-downs not yet supported for usage-based data

Key Benefits:

  • Lets teams correlate usage patterns with cost trends to spot optimization opportunities directly in existing widgets
  • Surfaces unit-cost efficiency signals — usage up with cost down (or vice versa) — without building a separate report

Cost Trend Widget — Multi-Metric Combo Chart & Drill-Down

Description: The Cost Trend widget now surfaces Cost, Usage, and Rate together in a single interactive multi-axis chart, so FinOps analysts and platform teams can see why costs changed, not just that they changed. Configuring a Consumed Unit filter unlocks a combo chart with legend-based metric toggling and drill-down from account level all the way to individual resources across all three metrics.

Key Capabilities:

  • Visualizes Cost, Usage, and Rate together in a multi-axis combo chart once a Pricing Unit/Consumed Unit filter is applied
  • Toggles metrics and Group By items on or off via legend click or Shift+Click, without reconfiguring the widget
  • Drills down from Tenant → Cloud Account → Service → Usage Type → Region → Resource, with all three metrics drilling together
  • Groups by 25+ business dimensions (cloud account, region, tags, instance type, purchase option, and more) for chargeback and allocation
  • Exports PNG or CSV reflecting the current legend selection and Group By state

Key Benefits:

  • Cuts monthly cost analysis time by up to 50% by replacing manual cross-referencing of cost, usage, and pricing reports with one widget
  • Traces cost spikes to the root resource in under 5 minutes using synchronized drill-down across all three metrics
  • Eliminates 2+ hours of manual Excel chargeback work per month by combining dimension-based Group By with Usage and Rate breakdowns

📘

Note: Visible and Primary metric selection is not supported in the Budget Cost Trend Forecast widget.


Savings Plan Support in Optimization Rate for AWS Member Accounts

Description: The Optimization Rate feature now covers Savings Plans for AWS Member Accounts. Before this release, it supported Savings Plans only at the Master Account level. Support is turned on in the backend through the Master Account-level configuration, because it relies on AWS Cost Explorer API calls that add to AWS costs.

Key Capabilities:

  • Extends Savings Plan coverage in Optimization Rate from AWS Master Accounts to their Member Accounts
  • Turns on Member Account support through the Master Account-level configuration
  • Fetches Savings Plan data through AWS Cost Explorer API calls

Key Benefits:

  • Shows Savings Plan optimization for each Member Account, not just a consolidated view at the Master Account level
  • Helps teams find Member Accounts that aren't making full use of their Savings Plan commitments
📘

Note: This feature is turned on per customer in the backend, because the extra AWS Cost Explorer API calls add to AWS costs. Contact CoreStack Support to request access.


Platform

Angular Migration for Templates

Description: The Templates module (CloudOps → Orchestration → Templates) has been migrated to Angular, bringing the Templates list and detail views, Execute & Jobs, Schedules, and the Template Builder onto CoreStack's current UI framework.

Key Capabilities:

  • Templates List and Detail views
  • Template Execute & Jobs
  • Template Schedules
  • Template Builder (components, variables, constraints)

Key Benefits:

  • Delivers a faster, more consistent Templates experience in line with the rest of the modernized platform
  • Preserves existing template creation, execution, and scheduling workflows — no retraining required

Graphion

Governance UI Modernization — Policies Pages

Description: The Policies page under Governance has been rebuilt on Angular, delivering a faster, more consistent experience while preserving full functional parity with the previous version.

Key Capabilities:

  • Policies page: list and filter policies, view policy detail, pre-execute and execute policies, trigger activity, configure default notifications, and manage policy jobs, schedules, and per-policy configuration

Key Benefits:

  • Brings Governance pages onto CoreStack's current UI framework for a more consistent experience across the platform
  • Preserves every existing policy and compliance workflow — no retraining required

Governance UI Modernization — Compliance Pages

Description: The Compliance pages under Graphion — Compliance Standards and Compliance Posture — have been rebuilt on Angular. All existing workflows carry over, and assessments now stay open, update automatically from policy runs, and support manual control updates.

Key Capabilities:

  • Marketplace Standards: Browse system standards, view controls and their details, and run on-demand assessments at the standard or control level
  • My Standards: Create, update, and delete custom standards, and manage their controls through a form or a CSV/XLSX upload
  • Assessment History: View past assessment jobs with status, job number, cloud account, audit trail, and error details
  • Schedules and Notifications: Create, edit, and delete assessment schedules, and create and update compliance notifications
  • Compliance Posture: View the latest assessment details by cloud account, six-month trends by standard and service account with a summary graph, and violated policies with affected resources and remediation actions

What's New and Improved:

  • Ongoing assessments: An assessment stays In Progress until you mark it Complete; when re-running a standard, you can complete the current assessment first. This lets you track improvements within the same assessment over time
  • Always up-to-date results: Any policy run — including runs started outside Compliance — now updates the in-progress assessments the policy is mapped to, and control statuses update to match
  • Manual control updates: Manual controls start as Open and can be set to Success or Violation, with comments and evidence attached; automated control statuses can also be overridden
  • Continue Assessment: A new control-by-control view to answer controls, add comments and attachments, and re-scan at the standard or control level
  • Built-in policy mapping: Map policies while creating or editing a control, with no separate step
  • One-step custom standards: Create a custom standard and all its controls in a single CSV upload, with validation checks before a standard is updated or deleted
  • Smarter notifications: Sent only when a full automated policy scan finishes or an assessment is marked Complete; each notification states the triggering event and includes the control status

Key Benefits:

  • Brings Governance pages onto CoreStack's current UI framework for a more consistent experience across the platform

  • Preserves every existing policy and compliance workflow — no retraining required


ITSM Integration for Graphion Threats (Regular Sync)

Description: Graphion Threats now integrates with ITSM tools on a regular sync schedule, so vulnerability groups can be tracked and resolved directly from the ITSM system as cloud provider data updates.

Key Capabilities:

  • Integrates ITSM tools with Graphion Threats
  • Adds configurable attributes for the Threat Domain during ITSM tool onboarding, including grouping, filters, and exceptions
  • Groups vulnerabilities and tracks them in the ITSM tool, updating and resolving them based on periodic sync with cloud providers

Key Benefits:

  • Keeps ITSM tickets current with the latest cloud provider threat data without manual re-entry
  • Lets security teams manage vulnerability grouping and exceptions from within their existing ITSM workflow

Cloud Security — SecOps Posture and Dashboard Consolidation

Description: The SecOps Posture and SecOps Dashboard menus are now unified under a single Cloud Security menu, giving you a consolidated view of infrastructure security issues and a faster path from issue to remediation.

Key Capabilities:

  • Infrastructure Issues by Severity and Accounts — an aggregated view of threats, vulnerabilities, and misconfiguration/guardrails findings
  • Infrastructure Explorer — reviews detailed issue data in a single screen instead of the previous multi-screen navigation
  • Misconfiguration tab filters showing which policies already have a remediation template mapped, alongside the existing skip/apply remediation actions on Guardrails findings
  • Cloud Security Dashboard — carries forward the existing threat, vulnerability, and misconfiguration trend, severity, and region widgets

Key Benefits:

  • Resolves security issues faster by reviewing detailed findings in one screen instead of navigating across multiple pages
  • Speeds up remediation planning by showing which policies already have a remediation template mapped before you act
  • Keeps existing security dashboard visibility intact under the new Cloud Security Dashboard, with Compliance and Access dashboards still available separately

AWS Inspector Filters in Vulnerability Explorer

Description: The Vulnerabilities tab in Infrastructure Explorer now offers AWS Inspector-specific filters, so users can filter findings more deeply. Filters such as Exploit Available, Inspector Fix Available, ECR Image Repository, and Lambda Runtime appear once AWS is selected as the Cloud Provider and Compute is selected as the Resource Category.

Key Capabilities:

  • Exploitability and fix filters: Narrow findings by whether an exploit is available or an Inspector fix is available
  • Container image filters: Filter ECR findings by image repository, tags, hash, and architecture
  • Lambda filters: Filter Lambda findings by function name, runtime, and architecture
  • Context-aware display: Inspector filters appear only when AWS is selected as the Cloud Provider and Compute as the Resource Category, keeping the default filter list uncluttered

Key Benefits:

  • Helps security teams prioritise remediation by isolating exploitable vulnerabilities with an available fix
  • Speeds up investigation of container and serverless vulnerabilities by filtering directly on ECR and Lambda attributes

Simplified BCS Question Answering During Application Creation

Description: All BCS questions are now presented on a single screen during Application creation, so users can answer them without navigating across multiple screens. Users can also copy BCS responses from an existing Application instead of answering every question from scratch.

Key Capabilities:

  • Single-screen BCS questionnaire: View and answer all BCS questions on one screen during Application creation
  • Copy from existing Application: Select an existing Application and copy its BCS question responses into the new Application

Key Benefits:

  • Speeds up Application creation by removing multi-screen navigation for BCS questions
  • Reduces repetitive data entry and keeps BCS responses consistent across similar Applications

CloudOps

Settings Menu — Angular Upgrade

Description: The Settings menu has been migrated to Angular, covering Resource Catalog, Account Management, Tenant Management, and Identity and Access Management, along with corresponding backend updates.

Key Capabilities:

  • Resource Catalog (self-service; flagged for future deprecation)
  • Account Management: Account Info, Account Configuration, Account Hierarchy
  • Tenant Management
  • Identity and Access Management: Users, User Groups, User Delegation, Roles, Authorization, Cost Metrics

Key Benefits:

  • Brings account, tenant, and identity/access management settings onto CoreStack's current UI framework for a more consistent experience
  • Preserves existing settings configuration workflows across account, tenant, and IAM areas

Reports

Distributor / Indirect Partner Consolidated Charges Report

Description: A new report gives every tier of a multi-tier reseller network — Distributor, Indirect Partner, and Customer — a role-scoped, hierarchical view of consolidated charges, replacing the flat list in the existing Consolidated Charges report.

Key Metrics: Commercial hierarchy (Distributor → Partner → Customer → Subscription, scoped by role), the same filters and Group By options as the existing Consolidated Charges report, hierarchy search by account, reseller/partner name, MPN ID, customer, or subscription, and a collapsible tree down to Meter Subcategory and Consumed Quantity.


Deprecation List

Recommendations Page Deprecation

The Recommendations page under Governance will be deprecated. This page aggregated actionable recommendations across cost, security, and operational best practices.

SecOps Menu Deprecation

The SecOps menu will be deprecated. Its functionality is now available under the Cloud Security menu, as mapped in the following table.


Existing MenuExisting FunctionalityNew MenuNew Functionality
SecOps Posture

Aggregated counts of security issues (threats, vulnerabilities, and misconfigurations/guardrails)

Details of the security issues

Cloud Security

Infrastructure Issues by Severity and Accounts

Infrastructure Explorers

This also provides the detailed issues in one shot rather than the multi-screen navigation used earlier

SecOps PostureSkip or apply remediation to misconfigurations/guardrailsCloud Security

Available in the Infrastructure Explorer (Misconfiguration tab)

Additional filters to see which policies have remediation templates mapped

SecOps DashboardMultiple widgets showing security issues (threat, vulnerability, and misconfiguration) trend, severity, and regionCloud Security

Equivalent widgets available in the Cloud Security Dashboard

Compliance and Access dashboards are moved to a separate dashboard


External APIs


Did this page help you?