Release Notes 6.4 (2605)
Version 6.4 (2605) of the platform has been released — see full details below.
Summary
CoreStack v6.4 (2605) brings AI spend into FinOps governance and gives multi-tier reseller networks a hierarchical view of their charges. It also moves security work into a single Cloud Security experience. AI-Native Service Discovery automatically finds AWS Bedrock and Anthropic's Claude API usage across accounts and API keys teams have already onboarded, and maps Claude API cost to the specific agent and API key that generated it. TokenOps adds token-based usage, cost, and rate analytics for AWS Bedrock, broken down by AI model. Cost widgets now support a Usage metric alongside Cost, and the Cost Trend widget adds a multi-axis combo chart that shows Cost, Usage, and Rate together, with drill-down from tenant to individual resource. Optimization Rate now covers Savings Plans for AWS Member Accounts, not just Master Accounts. A new Distributor / Indirect Partner Consolidated Charges report gives every tier of a reseller network a role-scoped view of its charges. On the Graphion side, SecOps Posture and SecOps Dashboard are now combined under the Cloud Security menu, and new AWS Inspector filters help teams find exploitable vulnerabilities in ECR images and Lambda functions. Graphion Threats now sync with ITSM tools on a regular schedule, and the rebuilt Compliance pages keep assessments current with every mapped policy run. The release also continues the move to CoreStack's current UI framework, with the Policies, Compliance, Templates, and Settings pages rebuilt on Angular.
FinOps
-
Added AI-Native Service Discovery — AWS Bedrock and Anthropic Claude API — Brings AWS Bedrock and Anthropic's Claude API into CoreStack's inventory, cost attribution, and governance workflows, using accounts and API keys customers have already onboarded, with Claude API cost mapped down to the specific agent and API key that generated it.
-
Added TokenOps — Token Usage, Cost, and Rate Analytics for AI Services — FinOps teams can now track AI token usage, cost, and rate for AWS Bedrock by setting a token-based Consumed Unit (Units, 1K Tokens, 1M Tokens) on a Platform Cost Trend (New) or Platform Summary widget, and group the data by AI Model Name to see which models drive spend and whether a cost change came from higher usage or a higher per-token rate.
-
Changed Cost Widgets — Usage Metric Support — Cost widgets across Summary, Trend, Forecast, and Measure by Dimension now support a selectable Usage metric alongside Cost, letting teams view resource consumption (vCPU-hours, GB, requests) side-by-side with spend to surface efficiency trends.
-
Changed Cost Trend Widget — Multi-Metric Combo Chart and Drill-Down — The Cost Trend widget now surfaces Cost, Usage, and Rate together in a single multi-axis combo chart with legend-based metric toggling and synchronized drill-down from account level down to individual resources across all three metrics.
-
Changed Optimization Rate — Savings Plan Support for AWS Member Accounts — Optimization Rate now covers Savings Plans for AWS Member Accounts, not just Master Accounts, so teams can see Savings Plan optimization for each Member Account and find accounts that aren't making full use of their commitments. This is turned on per customer through the Master Account-level configuration, because it uses additional AWS Cost Explorer API calls; contact CoreStack Support to request access.
Platform
- Changed Templates — Angular Migration — The Templates module (CloudOps → Orchestration → Templates) has been migrated to Angular, bringing the Templates list and detail views, Execute & Jobs, Schedules, and the Template Builder onto CoreStack's current UI framework, with existing template workflows preserved.
Graphion
-
Changed Governance UI — Policies Page Modernized — The Policies page under Governance has been rebuilt on Angular for a faster, more consistent experience, preserving full functional parity across policy list and detail views, execution, notifications, jobs, and schedules.
-
Changed Graphion UI — Compliance Pages Modernized — The Compliance Standards and Compliance Posture pages have been rebuilt on Angular. Assessments now stay In Progress until marked Complete, update automatically from any mapped policy run, and support manual control updates with comments and evidence. The update also adds a Continue Assessment view, policy mapping during control creation, single-CSV custom standard creation, and notifications sent only on meaningful events.
-
Added ITSM Integration for Graphion Threats — Regular Sync — Graphion Threats now integrates with ITSM tools on a regular sync schedule, so vulnerability groups can be tracked and resolved directly from the ITSM system as cloud provider data updates, reducing manual re-entry for security teams.
-
Changed Cloud Security — SecOps Posture and Dashboard Consolidation — The SecOps Posture and SecOps Dashboard menus are now unified under a single Cloud Security menu, with Infrastructure Issues by Severity and Accounts, single-screen issue review in the Infrastructure Explorer, Misconfiguration tab filters showing which policies have a remediation template mapped, and a Cloud Security Dashboard that carries forward the existing trend, severity, and region widgets, giving security teams a faster path from issue to remediation.
-
Added AWS Inspector Filters in Vulnerability Explorer — The Vulnerabilities tab in Infrastructure Explorer now offers AWS Inspector-specific filters, including Exploit Available, Inspector Fix Available, ECR image attributes, and Lambda function attributes. The filters appear when AWS is the selected Cloud Provider and Compute is the selected Resource Category, helping security teams prioritise exploitable vulnerabilities that have an available fix.
-
Changed Application Creation — Simplified BCS Question Answering — All BCS questions are now presented on a single screen during Application creation, and users can copy BCS responses from an existing Application instead of answering every question from scratch.
CloudOps
- Changed Settings Menu — Angular Upgrade — The Settings menu has been migrated to Angular, covering Resource Catalog, Account Management, Tenant Management, and Identity and Access Management, with existing settings configuration workflows preserved.
Reports
- Added Distributor / Indirect Partner Consolidated Charges Report — Gives every tier of a multi-tier reseller network — Distributor, Indirect Partner, and Customer — a role-scoped, hierarchical view of consolidated charges, replacing the flat list in the existing Consolidated Charges report.
Deprecation List
- Deprecated Recommendations Page — The Recommendations page under Governance has been deprecated. This page aggregated actionable recommendations across cost, security, and operational best practices.
- Deprecated SecOps Menu — The SecOps menu has been deprecated, and its functionality is now available under the Cloud Security menu. SecOps Posture issue counts and details are now in Infrastructure Issues by Severity and Accounts and the Infrastructure Explorers; skip or apply remediation for misconfigurations/guardrails is now in the Infrastructure Explorer (Misconfiguration tab); and SecOps Dashboard widgets are now in the Cloud Security Dashboard, with Compliance and Access dashboards moved to a separate dashboard.
External APIs
- To see the external APIs which have been added, modified, and removed in this release, refer to: External APIs 6.4 (2605)
- To see all the available external APIs, refer to: https://docs.corestack.io/reference/accesssummarycount