What is built, and what is not

Most roadmaps are a wish list with the failures deleted. This one comes from the codebase, including the part where our provider adapters are still simulated.

Last reviewed 18 August 2026

How to read this. Everything under “in the console today” is running code you can be shown in a demo. Everything under “next” and “later” is not built yet, and we have not attached dates because we would only be guessing. The build log records what actually landed and when.

In the console today3

You can open these screens right now. Nothing here is a promise.

The four-domain control plane

Cloud and Kubernetes inventory. GPU waste reporting. Agent token metering with guardrails. Anomaly detection with remediation playbooks. All of it is in the console today.

Alerting across 26 metrics

One rule builder over infrastructure, cost, security, GPU utilisation and agent spend. You can page on recoverable GPU dollars the way you page on CPU.

Cost, carbon and audit reporting

Spend and CO₂e reporting. Team and role management. API keys. A complete audit log of everything the platform did.

Next2

Being built now. These two stand between early access and general availability.

Live provider adapters

Discovery synthesises inventory from a catalog today. Everything downstream runs for real: normalisation, diffing, cost rollups, alerting, remediation. Swapping in live SDK clients is the largest job in front of us, and it touches one function per domain.

GCP to parity with AWS and Azure

GCP already connects. Getting its resource coverage and cost model to the depth AWS and Azure have is next. Two clouds done properly beats five done badly.

Later2

Real intent, no date. Better undated than an invented quarter.

Self-serve onboarding

Connect an account, see your own number, skip the sales call. This waits on the live adapters. Self-serve reporting synthesised inventory would be worse than no self-serve at all.

SOC 2 programme

We are not certified and will not imply otherwise. What the platform already produces supports your audit: policy enforced on every apply, full change history, exportable artefacts. Eventually it supports ours.

Deliberately never1

Not a gap. A boundary, and the reason the rest is safe to adopt.

Hosting your workloads

This is a boundary, not a gap. CoverOps is a control plane, not a host. The moment we run your workloads, leaving us stops being easy. That property is worth more to you than the revenue is to us.

What would change our order

This is our current read, not a commitment. What moves an item up is hearing it is the reason a team cannot adopt us. If your blocker is GCP depth, or self-serve, or a certification we do not hold, say so. Knowing which gap costs us the most conversations is how we decide what to build next.

Tell us what is blocking you, or read the platform overview for what the four domains do today.