Agent skill

Cloud Administration

by cbrock84 in cbrock84/headcount

Administers the cloud the company runs on rather than the one it sells — tenant and subscription structure, the SaaS estate and who owns each app, identity as the real perimeter, cloud spend that…

MITAuto-check passedDevOps & Cloud

Install Cloud Administration

skills CLI
$ npx skills add cbrock84/headcount --skill cloud-administration -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cbrock84/headcount cloud-administration --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cbrock84/headcount.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/it-operations/skills/cloud-administration .claude/skills/cloud-administration && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cloud-administration
GitHub stars
2k
Token cost
~1.5k tokens
SKILL.md length
830 words
Files
2 (incl. references)
Skills in repo
175
Repo updated
First seen
Licence
MIT

At a glance

Administers the cloud the company runs on rather than the one it sells — tenant and subscription structure, the SaaS estate and who owns each app, identity as the real perimeter, cloud spend that…

  • Tasks that involve Cloud cost optimization
  • SKILL.md covers Structure the tenant before…, The SaaS estate is the part…, Identity is the perimeter, so… and Cloud spend surprises are…, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Cloud Administration is an agent skill from cbrock84/headcount. Administers the cloud the company runs on rather than the one it sells — tenant and subscription structure, the SaaS estate and who owns each app, identity as the real perimeter, cloud spend that arrives as a surprise, and what the provider does not do for you. Use this to structure subscriptions or tenants, get control of sprawling SaaS, cut a cloud bill, work out who owns an application nobody admits to buying, or decide what corporate workloads belong in cloud at all.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/sources.md`).

It sits in DevOps & Cloud, covering Cloud cost optimization. The repository describes itself as: An agent organization structured as a company — 15+ departments, 125+ skills, each independently installable, citing the standards and regulators that settle the question. Runs… The licence is MIT.

When your agent uses it

  • Tasks that involve Cloud cost optimization

Example prompts

  • “Use the cloud-administration skill to administer the cloud the company runs on rather than the one it sells — tenant and subscription structure, the…”
  • “/cloud-administration”

What it can do on your machine

Read from SKILL.md and the folder at commit 98d1c17. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cloud Administration loads about 1.5k tokens when it runs, and up to ~2.1k if it reads all its reference files. Until then it costs about 124 tokens; SKILL.md has 830 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~124
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from cbrock84/headcount at commit 98d1c17, republished under its MIT licence (© cbrock84). 830 words, ~1,524 tokens.

Download SKILL.mdSave it as .claude/skills/cloud-administration/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
cloud-administration
description
Administers the cloud the company runs on rather than the one it sells — tenant and subscription structure, the SaaS estate and who owns each app, identity as the real perimeter, cloud spend that arrives as a surprise, and what the provider does not do for you. Use this to structure subscriptions or tenants, get control of sprawling SaaS, cut a cloud bill, work out who owns an application nobody admits to buying, or decide what corporate workloads belong in cloud at all.

Cloud administration

Corporate cloud is bought, not architected. Someone needed a tool, expensed it, and it entered the estate without a review, an owner, or an offboarding path. The characteristic failure is not a bad design — it is discovering the estate years later, one invoice at a time.

This is the cloud the business runs on. For the cloud a product is built on — environments, infrastructure as code, scaling, region failure — see technology:cloud-infrastructure. The two follow different rules and the boundary is worth keeping sharp.

Structure the tenant before you need to

Subscription and account structure encodes what you can later separate: billing, access, policy, and blast radius. Retrofitting it means moving live workloads, so the cheap moment is the first one.

A workable default is to separate by what you would want to bill, govern, or lose independently — production corporate services, non-production, and anything with a distinct compliance obligation. Resist a subscription per team; teams reorganize, and the structure outlives them.

Tag at creation with owner, cost center, and environment, and enforce it with policy rather than documentation. Untagged resources become unattributable spend within a quarter, and nobody volunteers to claim them.

The SaaS estate is the part nobody is managing

Most companies underestimate their application count by a wide margin, because the ones they know about were bought by IT and the rest were bought by everyone else. The discovery methods that actually work are financial, not technical: expense reports, corporate card statements, and the identity provider's sign-in logs. Network monitoring finds less than the accounting system does.

Every application needs a named business owner, a renewal date, and a data classification. Without the owner there is nobody to ask at renewal. Without the renewal date the negotiation happens after auto-renewal. Without the classification, nobody knows which breach notification obligations apply when the vendor is compromised.

An application that stores customer or employee data belongs in the review that legal-risk:privacy-and-data-protection describes, and a departing employee's access to it is it-operations:identity-lifecycle-administration's problem — which it cannot solve for an application it does not know exists.

Identity is the perimeter, so treat it as infrastructure

Once the estate is cloud, network location protects nothing and the identity provider is the only consistent control point. Single sign-on is therefore not a convenience feature; it is what makes deprovisioning possible in one place instead of forty.

The practical rule is to refuse applications that cannot federate, or to accept them knowingly with a documented manual offboarding step. Vendors that charge extra for SSO are charging for the security baseline, and that cost belongs in the purchase decision rather than being discovered later.

Conditional access, MFA, and privileged role activation are the controls worth the effort. See security:access-and-identity for the design; this skill owns operating it across a real estate.

Show full SKILL.md (364 more words)Show less

Cloud spend surprises are structural

Cloud bills grow because nothing in the system stops them. Resources are easy to create, nobody is billed personally, and consumption is invisible until the invoice.

Three habits catch most of it: a budget alert on every subscription before workloads land, a monthly review of the largest movers rather than the whole bill, and a scheduled look at anything running that nobody has logged into. Reserved and committed pricing is real money for steady workloads, but it is a bet on a run rate — commit only where the load is genuinely predictable.

Non-production environments running overnight and at weekends are the most common single line of waste, and shutting them on a schedule is a change nobody notices.

Shared responsibility is narrower than people assume

The provider keeps the platform available. Almost everything else — configuration, access, and in most cases the data itself — stays yours.

The one that catches organizations out is backup. A major SaaS suite protects itself against its own failures, not against a user deleting a mailbox or a ransomware event propagating through sync. Retention settings are not backups, and the recycle bin is not a recovery point. Decide deliberately what needs independent protection under it-operations:backup-and-recovery rather than assuming the vendor's durability promise covers your mistakes.

Sources

references/sources.md in this skill lists the outside authorities that settle the questions here — what each one is authoritative for, and what you may do with it. Check them before answering on anything they cover, and cite what you used. Most are free to read and not free to reproduce; the use note on each is binding.

Tooling

Platforms: AWS, Microsoft Azure, Google Cloud, and similar.

Infrastructure as code: Terraform, OpenTofu, Pulumi, Bicep, CloudFormation, and similar.

Cost visibility: the native cost tools, or CloudZero, Vantage, Finout, and similar. Guardrails: AWS Control Tower, Azure Policy, Wiz, and similar.

Console changes nobody can reproduce in code become the outage you cannot rebuild from.

Never

  • Buy an application that cannot federate without recording the manual offboarding step.
  • Let a resource exist without an owner tag and a cost center.
  • Treat vendor retention settings as a backup.
  • Structure subscriptions around the current org chart.

© cbrock84, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in plugins/it-operations/skills/cloud-administration of cbrock84/headcount.

  • SKILL.md
  • references/sources.md

Open the folder on GitHubat commit 98d1c17

Compare with similar skills

Cloud Administration next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cloud Administration compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cloud Administration this skillcbrock84/headcount2k—~1.5kAutomated safety check: PassMIT
Capacity And Cost Engineeringmagnus919/agent-skills113—~4.7kAutomated safety check: PassMIT
Vercel Optimize Auditvercel-labs/agent-skills32k9 repos~4.3kAutomated safety check: PassNone
Cloud Cost Optimizationwshobson/agents40k14 repos~1.7kAutomated safety check: PassMIT
Trigger.dev Cost Savings Auditpapermark/papermark9.2k—~1.3kAutomated safety check: PassCustom licence
Kubernetes SpecialistJeffallan/claude-skills12k1 repos~2.1kAutomated safety check: PassMIT

Similar skills

  • Capacity And Cost Engineering

    magnus919/agent-skills

    Model technical capacity, unit cost, and budget constraints connected to demand, performance, and reliability decisions.

    113 GitHub stars~4.7k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Vercel Optimize Audit

    vercel-labs/agent-skills

    Official

    Runs a metrics-first audit of a deployed Vercel project, gating investigations on real signals to produce ranked, citation-backed cost and performance recommendations.

    32k GitHub starsUsed in 9 repos~4.3k tokens
    DevOps & CloudAuto-check passed
  • Cuts cloud spend across AWS, Azure, GCP and OCI with cost tagging, rightsizing, commitment and spot pricing models, and architecture changes.

    40k GitHub starsUsed in 14 repos~1.7k tokens
    DevOps & CloudAuto-check passed
  • Audits Trigger.dev tasks, schedules and run history for wasteful machine sizes, retries, polling and cron frequency to cut spend.

    9.2k GitHub stars~1.3k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Kubernetes Specialist

    Jeffallan/claude-skills

    Creates and checks Kubernetes manifests, Helm charts, RBAC and network policies, and helps debug pod problems, with kubectl checks and rollback steps.

    12k GitHub starsUsed in 1 repo~2.1k tokens
    DevOps & CloudAuto-check passed
  • Axiom Cost Control

    openclaw/clawhub

    Finds unused data in Axiom by analyzing query patterns, then deploys a cost dashboard and ingest monitors to keep spend under the contract limit.

    9.5k GitHub stars~1.7k tokensUpdated today
    DevOps & CloudAuto-check passed

More from cbrock84/headcount

All 175 skills in this repo
  • Agent Hierarchy

    cbrock84/headcount

    Designs orchestrator-and-subagent hierarchies for a repository — splitting agents by exclusive write surface, pairing every producer with an independent auditor, and enforcing the split with a…

    2k GitHub stars~1.2k tokensUpdated 20 days ago
    Auto-check passed
  • Access And Identity

    cbrock84/headcount

    Designs and audits who can reach what — authentication, authorization models, privileged access, service credentials, and joiner-mover-leaver process.

    2k GitHub stars~1.1k tokensUpdated 20 days ago
    Auto-check passed
  • Account Based Marketing

    cbrock84/headcount

    Concentrates marketing and sales effort on a named set of accounts rather than on volume — qualifying whether the model fits your economics at all, building the account list and the buying group…

    2k GitHub stars~1.2k tokensUpdated 20 days ago
    Auto-check passed
  • Activation

    cbrock84/headcount

    Gets new users from signup to first real value — signup flow, onboarding, time-to-value, and the early experience that determines whether someone becomes a user or a lapsed account.

    2k GitHub stars~865 tokensUpdated 20 days ago
    Auto-check passed
  • AI Research Analyst

    cbrock84/headcount

    Produces executive-level research — market sizing, competitor mapping, trend analysis, and strategic intelligence — grounded in cited sources with the confidence in each claim made explicit.

    2k GitHub stars~916 tokensUpdated 20 days ago
    Auto-check passed
  • AI Search Optimization

    cbrock84/headcount

    Optimizes for AI assistants and AI-generated answers — being retrievable, being cited, and being represented accurately when a model answers on your behalf.

    2k GitHub stars~829 tokensUpdated 20 days ago
    Auto-check passed

Questions about Cloud Administration

What does Cloud Administration do?

Administers the cloud the company runs on rather than the one it sells — tenant and subscription structure, the SaaS estate and who owns each app, identity as the real perimeter, cloud spend that…. Cloud Administration is an agent skill from cbrock84/headcount. Administers the cloud the company runs on rather than the one it sells — tenant and subscription structure, the SaaS estate and who owns each app, identity as the real perimeter, cloud spend that arrives as a surprise, and what the provider does not do for you.

When should I use Cloud Administration?

Cloud Administration fits situations like: tasks that involve Cloud cost optimization.

How do I install Cloud Administration in Claude Code?

Run `npx skills add cbrock84/headcount --skill cloud-administration -a claude-code`. Or copy the skill folder (plugins/it-operations/skills/cloud-administration in cbrock84/headcount) into .claude/skills/cloud-administration in your project. Claude Code loads it when a task matches its description.

How do I install Cloud Administration in Codex?

Run `npx skills add cbrock84/headcount --skill cloud-administration -a codex`. Or copy the skill folder (plugins/it-operations/skills/cloud-administration in cbrock84/headcount) into .agents/skills/cloud-administration in your project. Codex loads it when a task matches its description.

Can I use Cloud Administration in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cbrock84/headcount --skill cloud-administration -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cloud-administration, .gemini/skills/cloud-administration, .github/skills/cloud-administration and .opencode/skills/cloud-administration in your project.

What does Cloud Administration need to run?

SKILL.md names no scripts, command-line tools or credentials: Cloud Administration is instructions for the agent only.

Does Cloud Administration access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Cloud Administration safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cloud Administration use?

Cloud Administration is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cloud Administration use?

About 1.5k tokens (SKILL.md is roughly 6.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 626 tokens, read only when the agent opens those files.

What are the alternatives to Cloud Administration?

Skills that share tags, products or a category with Cloud Administration: Capacity And Cost Engineering (magnus919/agent-skills, 113 stars), Vercel Optimize Audit (vercel-labs/agent-skills, 32k stars), Cloud Cost Optimization (wshobson/agents, 40k stars) and Trigger.dev Cost Savings Audit (papermark/papermark, 9.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cloud Administration?

cbrock84 (a GitHub user) maintains it in cbrock84/headcount, which has 2,007 GitHub stars. The repository holds 175 skills in this directory. The repository was last updated on September 17, 2026.

Source: cbrock84/headcount on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.