City skyline beneath fully visible cumulus clouds

Cloud teams are under increasing pressure to keep infrastructure aligned with security, cost, availability and performance policies while the volume and pace of change rise. Infrastructure as code (IaC) establishes an intended configuration, but it does not by itself account for changes made through cloud consoles, emergency fixes, automated pipelines or AI agents.

Those gaps can leave operations teams with a familiar but labor-intensive workflow: identify a configuration or policy violation, determine the affected resource’s owner and dependencies, decide whether the change was deliberate, then either correct the live environment or update the source code. The work is made harder when inventory, policy and remediation processes sit in separate tools.

env zero has introduced EZ Control, an early-access SaaS cloud control plane intended to bring those activities into a continuous, governed loop. The company says the product reconciles the state described in IaC and other enterprise policies with the resources actually running across cloud environments, then can act within boundaries set by the customer.

EZ Control follows env zero’s March merger with CloudQuery. It combines cloud and SaaS resource discovery with IaC governance and organizes the resulting information in a continuously updated ontology, according to the company. The product is designed to associate each resource with its declaring code, owner, cost, dependencies, applicable policies and related risks or insights.

That contextual model is central to the product’s case for automated remediation. Rather than treating drift as an alert for an engineer to investigate, EZ Control is designed to identify the relevant policy and remediation path. The company says it supports nearly 2,300 resource types across Amazon Web Services, Microsoft Azure, Google Cloud and Kubernetes, and connects to more than 80 cloud and SaaS integrations.

The scope extends beyond IaC drift. env zero said EZ Control can ingest policies maintained in sources such as cloud security posture management platforms, policy-as-code repositories and cloud-provider guardrails. It can apply those policies against the same inventory to address compliance, maintenance, cost, availability and performance gaps, the company said.

Customers determine the level of autonomy for each resource class. The available modes range from observation to proposed fixes, approval-gated actions and autonomous remediation within defined guardrails. For unintentional configuration drift, the product can reapply IaC; when it identifies a deliberate change, the company says it can create a pull request against the owning repository or flag a defect in source code. Each action is intended to follow the repository and review process assigned to that resource, followed by a scan to verify the issue has been resolved.

“The cloud is already being changed autonomously, by pipelines, by automation and now by AI agents,” said Steve Corndell, CEO of env zero. “What is missing is a control plane that can respond at the same speed, inside the guardrails the enterprise has already set.”

The product also addresses a governance concern created by infrastructure-provisioning agents: allowing automated systems to make changes without broadly distributing cloud credentials. env zero said actions routed through EZ Control use the same policies, approvals and audit trail that apply to human engineers.

EZ Control initially connects in an agentless, read-only mode, allowing organizations to discover resources and governance gaps before allowing changes. Teams can then increase the permitted level of autonomy one resource class at a time.

For platform and cloud-operations teams, the practical promise is a shorter path from identifying divergent infrastructure to a documented, policy-controlled correction. The value of that approach will depend on the accuracy of an organization’s policies and ownership data, but it directly addresses the operational bottleneck that remains after cloud drift is detected: making and verifying a safe change.

Leave a Reply

Your email address will not be published. Required fields are marked *

Latest News