Most maturity models are marketing with rungs. This one is meant to be used: four stages of cloud cost and operations governance, each defined by observable characteristics — what you would see if you sat with the team for a week — and by explicit promotion criteria. The stages are Manual, Assisted, Automated, and Autonomous. The urgency behind the climb is not abstract: Flexera's 2026 State of the Cloud Report puts wasted cloud spend at 29%, the first rise in five years, and the FinOps Foundation's 2025 survey finds 50% of practitioners ranking waste reduction as their top priority while 63% now manage AI spend on top of everything else. The gap between the estate and the operating model is widening. This is the ladder out.
Stage 1 — Manual
Cost governance is a person, not a process. One or two specialists own a set of spreadsheets and a console habit. Waste is found when someone goes looking, and someone goes looking when the bill surprises. Observable characteristics: optimization work is triggered by invoices rather than signals; analysis is bespoke every time; findings travel by email and die in ticket queues; the departure of one named individual would halt the practice entirely. Coverage is whatever that individual had time for. Most organizations recognize this stage immediately, usually with a wince.
Stage 2 — Assisted
The organization has tooling — dashboards, anomaly alerts, sometimes an agent that answers questions conversationally. The decisive change is who can interrogate cost: not just the specialist, but any engineer who owns a workload. Time-to-insight drops from days to minutes. Observable characteristics: engineers query spend directly instead of filing requests; anomalies are investigated within days of occurring; findings arrive with resource-level evidence; the specialist's role shifts from performing analysis to curating standards. What has not changed: every action is still initiated, decided, and executed by a human. The tooling extends reach; it does not yet carry load.
Stage 3 — Automated
Recurring analysis stops depending on anyone remembering to run it. Scheduled interrogations sweep the estate on a standing cadence; anomalies open their own investigations; recommendations arrive with generated remediation — parameterized infrastructure-as-code, ready for review — rather than as prose suggestions. Observable characteristics: a standing rhythm of machine-produced findings with human approval as the only manual step; right-sizing and cleanup proposals that ship with rollback paths; a measurable, falling time-from-detection-to-remediation. Humans have moved from doing the work to judging the work.
Stage 4 — Autonomous
For a narrow, policy-defined class of actions — high confidence, low blast radius, fully reversible — the system executes without waiting for a human, and every action lands in an audit trail with its evidence attached. Observable characteristics: a written policy that defines exactly which actions qualify; automatic rollback on regression; a human-override rate that is tracked and reviewed; regular audits of autonomous actions against outcomes. Autonomy is never estate-wide. It is a scoped privilege for proven action classes, expanded one class at a time as each earns its record.
| Stage | Who finds waste | Who acts | Typical latency |
|---|---|---|---|
| Manual | A specialist, when prompted by the bill | Humans, via tickets | Weeks to months |
| Assisted | Any engineer, conversationally | Humans, directly | Days |
| Automated | The system, on a standing cadence | Humans approve; machines execute | Hours |
| Autonomous | The system, continuously | Machines, within written policy | Minutes |
Promotion is earned with evidence, not enthusiasm
The failure mode of every maturity model is self-assessment by aspiration. Promotion between these stages should require records, not intentions.
- Manual to Assisted: engineers outside the FinOps team are demonstrably querying cost themselves — measured by usage, not by license count.
- Assisted to Automated: a sustained period in which machine-generated findings were accurate enough that owners stopped disputing them; a false-positive rate you can state with a number.
- Automated to Autonomous: a specific action class with a long approval history in which humans approved without modification, plus tested rollback and a written scope policy. The record justifies removing the approval step for that class — and nothing else.
A stage is not where your tooling says you are. It is what your audit trail proves you have been doing for months.
Where enterprises actually sit, and the anti-patterns
Honestly assessed, most enterprises sit at stage 1 or early stage 2 — including many that own stage 3 tooling, because a purchased capability nobody wired into the operating rhythm is still stage 1 with better invoices. Two anti-patterns account for most stalled climbs. The first is jumping to autonomy: granting write access to automation that has no evidentiary track record. The first bad automated action destroys organizational trust, and the program regresses further than it started. The second is tool sprawl: buying a new point product for each pain — one for anomalies, one for right-sizing, one for commitments — until the FinOps team spends its time reconciling tools instead of reducing waste. Maturity is one loop deepening, not many tools accumulating.
Running the climb is unglamorous: pick the stage the evidence says you are in; wire the current stage into the weekly operating rhythm until it is boring; instrument the promotion criteria; then advance one stage, in one scope, at a time. Teams that do this reach automation in quarters. Teams that skip steps tend to reach it never.
Caelion Meridian is built as this ladder: deployed read-only and assisted on day one, with automated cadences and policy-scoped autonomy earned stage by stage — every step evidenced in the audit trail. Find out which stage your estate is really in with a private briefing.