Illustrative figures for comparable deployments are provided for planning only. Actual results depend on the on-site baseline and acceptance findings.

SHEET 01 · HYBRID CLOUD CONTROL PLANE

Hybrid Cloud Governance Platform
Accounts, permissions and cost allocation

Yuqi Intelligent's enterprise hybrid cloud management platform brings distributedcloud accounts, resources, permissions and operational datainto a clear management process, helping enterprises move from provisioning resources tomanaging them sustainably. More resources require clearer ownership and rules. We make those rules work across your multi-cloud environment.

Accounts
Ownership inventory
Resources
Unified resource model
Policies
Approval boundaries
Costs
Allocation rules
PROVIDERS IN SCOPE / Clouds and infrastructure to assess
Alibaba Cloud Tencent Cloud Huawei Cloud AWS AZURE GCP VMware vSphere OpenStack Kubernetes Tianyi Cloud China Mobile Cloud Private data center
RESOURCE CONTROL PLANE SYNC 00:03:12
BUS·W BUS·E Public cloud A · East China Public cloud B · North China Public cloud C · South China SaaS / CDN Private cloud / domestic technology stack Private data center K8s / edge nodes Unified control plane OWNER · COST · POLICY CONTROL PLANE v4.2 0REGIONN LEGEND Public cloud connection Private / on-premises Control plane
Example
managed accounts baseline
Review
unowned-resource definition
Baseline
tag-compliance definition
ONBOARDED

Console values are simulated examples, not live customer telemetry. The scope link below distinguishes platform implementation from ongoing cloud resource operations.

SHEET 02 · WHY

Moving to the cloud is straightforward.
The challenge iskeeping it under control

Most enterprise cloud estates are not built all at once. They grow over years: new accounts for each project, temporary resources for each event, and unclaimed instances left behind when people leave. At scale, four problems emerge together.

BLIND 01
Where are our resources?

Accounts are spread across providers and subsidiaries. Test environments, temporary infrastructure and legacy project resources coexist without a reconciled asset inventory.

BLIND 02
Who is using them?

Access is granted faster than it is revoked. Subaccounts, access keys and temporary credentials accumulate. Without a named resource owner, there is no clear contact when an incident occurs.

BLIND 03
Where does the money go?

Bills are organized by account, while business costs are tracked by project. The two do not reconcile, and idle instances, orphaned disks and unused load balancers remain unreclaimed.

BLIND 04
Which changes are authorized?

Who may scale capacity, delete a database or make a change within a maintenance window is left to verbal agreement. Changes lack approval gates, and incident reviews lack evidence.

CRITICAL
More resources requireclear ownership and rules;
not more spreadsheets and meetings.

The platform turns these questions into four operational capabilities:a resource graphshows where assets are; ownership and permissionsshow who uses them; cost allocationshows where spend goes; and change controlsdetermine whether an action is allowed. Management then relies on executable rules rather than individual memory.

Earth at night, representing resources distributed across regions
GLOBAL FOOTPRINT
Resources can span multiple clouds and regions, but ownership, cost and policy need one consistent source of truth. Otherwise, operations will always be chasing the accounts.
SHEET 03 · ARCHITECTURE

A six-layer architecture:
onboard, model, then govern

This is not another cloud. It is a control plane above your existing clouds. Data flows upward into a unified resource model, while policies flow downward into each change. Automated feedback loops turn visibility into action.

LAYERED ARCHITECTURE
Connect Model Govern Execute Analyze Integrate
L6Delivery and open integrationPut capabilities in business users' hands
Unified console Mobile / WeCom notifications OpenAPI / SDK Webhook subscriptions ITSM / ticketing integration Dashboards and periodic reports

One dataset serves multiple channels: operations use the console, managers read reports, business systems call APIs, and approvals flow into tickets. Teams no longer query separate sources and reach conflicting conclusions.

L5Observability and insightsSee what happens and explain why
Monitoring and alerts Logs and distributed tracing Cost analysis and optimization Reporting and analytics Capacity and trend forecasting SLA reporting

Metrics, logs and billing data share the same tagging model. The cost and reliability of a machine can therefore be evaluated in the same view.

L4Automation and scheduling engineTurn rules into actions
Orchestration and job execution Intelligent scheduling Elastic scaling Automated recovery Scheduled and batch jobs Change rollback

A policy trigger does more than send a notification. It can scale, reclaim, rightsize, fail over, restart or roll back resources, with an audit record and recovery point at every step.

L3Governance and policy engineThe platform's policy decision layer
Cost policies Permissions and compliance Resource lifecycle Change windows and approval gates Quotas and budgets Approval workflows

Policies are expressed declaratively:who may act · on which resource · under what conditions · with which action · with whose approval. Define a rule once and apply it across clouds, without relying on people to remember it.

L2Unified resource modelCMDB · resource graph · ownership
Unified CMDB Resource graph Tagging and ownership Organizations / cost centers Asset inventory Change history

This is the platform's core: every resource, regardless of its cloud, receives three essential attributes: ownercost centerpolicy . Reporting, alerts and optimization all use this shared classification.

L1Connection and onboardingMulti-cloud · private cloud · containers · data centers
Public cloud API adapters Private cloud / OpenStack VMware / virtualization Kubernetes clusters Physical servers and data centers Storage / networking / CDN SaaS and account directories

Start discovery with read-only credentials and enable operational permissions incrementally. Collect resources across accounts, regions and subscriptions, and use agents for internal networks that cannot be reached directly.

Engineers validating a hybrid-cloud connection design in a lab
Validate credential scope, collection frequency and field mappings in a test environment before enabling production access.

What must the resource model capture?

IDENTA unique resource ID that can be correlated across clouds
OWNERA named owner or team, with unowned assets queued for assignment
COSTCost center and project codes for billing allocation
STATERunning / idle / pending reclamation / archived
POLICYApplicable policies, checked automatically at change time
TRACEA complete record of who changed what and when
OwnershipCostPolicy
SHEET 04 · CAPABILITIES

Eight modules,
one shared data modelthroughout

Modules can be introduced in phases, but they share the same resource model and tags. Whether you start with cost analysis or monitoring, subsequent modules do not require another asset inventory exercise.

Unified multi-cloud management

Public clouds, private clouds, containers and private data centers share one resource inventory and a cross-account, cross-region view, without switching between separate consoles.

  • Automatic discovery and incremental synchronization; inventory timing is measured against the agreed workflow
  • Automatically generated resource topology makes dependencies visible
  • Unowned resources are queued and routed for assignment
Examplecloud and infrastructure coverage to be confirmed

Cost analysis and optimization

Allocate bills by cost center, project, environment and team down to individual resources. Identify idle capacity, low utilization and sizing mismatches, then provide actionable recommendations.

  • Attribute cost to resources, not just account totals
  • Budget and quota thresholds warn before overspending
  • Model reserved-instance and Savings Plan combinations
Reviewcloud-spend comparison

Monitoring and alerts

Unify metrics, logs and events, then route alerts to resource owners. Deduplication consolidates notifications for the same incident to prevent alert storms.

  • S1/S2/S3 severity and escalation rules automatically escalate unacknowledged alerts
  • Link alerts to resource topology to accelerate fault isolation
  • Correlate alerts with recent changes to identify change-related incidents
Reviewreduction in non-actionable alerts

Automated operations

Capture routine responses as standard jobs: scaling, restarts, log cleanup, disk reclamation, failover and batch patching, triggered manually or automatically.

  • Parameterized job templates eliminate repeated manual commands
  • Validate before execution, verify afterward and roll back on failure
  • Require additional confirmation and permitted change windows for high-risk actions
Examplestandard job templates scoped per project

Reporting and analytics

Provide role-specific reports: cost and trends for management, availability and incidents for operations, and resource delivery efficiency for business teams.

  • Generate and distribute weekly and monthly reports automatically
  • Show year-on-year, period-on-period and budget performance together
  • Export data or retrieve it through APIs for your own BI platform
Examplereport templates confirmed by role and metric

Resource lifecycle management

Track requests, approvals, provisioning, changes, idle periods, reclamation and archiving. Each stage has a status, deadline and owner; temporary resources trigger expiry reminders or automatic reclamation.

  • Tag at request time and register assets when created
  • Configure idle-resource rules using CPU, network traffic and connection counts
  • Notify owners and retain snapshots before reclamation to prevent accidental deletion
Scopedlifecycle states confirmed per workflow

Intelligent scheduling

Place workloads according to load, cost, affinity and compliance constraints, choosing the most suitable location now rather than the most familiar one.

  • Autoscale for peak and off-peak demand and schedule flexible work outside peaks
  • Compare equivalent resources across clouds for cost-effective placement
  • Prioritize data affinity and regional compliance constraints
Reviewimprovement in resource utilization

Access and compliance governance

Grant least-privilege role-based access and revoke temporary permissions on expiry. Require approval for high-risk operations and retain audit evidence to support internal audits and MLPS requirements.

  • Review access periodically and identify dormant accounts automatically
  • Scan policy baselines and alert on configuration drift
  • Audit all operations with user- and resource-level traceability
Reviewof high-risk operations traceable
SHEET 05 · FINOPS

Understandwhere the money goes,
before cutting costs

Cost optimization is not simply a budget cut. It turns unknown spending into informed decisions. The platform breaks bills down to resources, then aggregates them by owner, environment and project, connecting each expense to an accountable person and a decision.

Cloud-spend trend and composition Unit: CNY 10,000 per month · illustrative data
140 130 120 110 100 90 80 CNY 10,000 / month Jan Apr Jul Oct Jan Apr Jul Oct Y1 · 2025 Y2 · 2026 Illustrative baseline Optimization begins · Y1 Jul Example Current month
Compute · ECS / CVM / nodesExample
Databases and middlewareExample
Storage · object / block / archiveExample
Network · bandwidth / NAT / CDNExample
Optimization opportunity: idle / mis-sizedExample
27%

Hypothetical model: a baseline of 100 and an optimized cost of 73 imply a 27% difference. This is not a measured customer saving; actual savings depend on bills, utilization, commitments and change costs.

01
Reclaim idle resources
Low utilization identifies candidates, not permission to delete. Confirm ownership, dependencies, retention, backup and recovery tests; release resources only after authorized approval.
Model review
02
Downsize and rightsize
Recommend target sizes from an agreed P95 observation window, generate change requests and execute after business-owner approval.
Model review
03
Optimize reservation commitments
Model the best reserved-instance and savings-plan mix for stable workloads, avoiding waste from overcommitment.
Model review
04
Storage tiering and lifecycle
Move cold data to infrequent-access or archive tiers and expire snapshots according to retention policy.
Model review
05
Off-peak and cross-cloud scheduling
Schedule non-real-time batch jobs in off-peak windows and lower-cost regions, comparing equivalent resources at current prices.
Model review
Cost allocation and billing reconciliation

Hypothetical cost model, not customer results or a savings commitment.

SHEET 06 · OBSERVABILITY

More alerts are not the answer.
Every alert needsan accountable owner

An alert is useful when it is necessary, reaches the right person and includes context. The platform links alerts to ownership, consolidates duplicates and includes related evidence, so the on-call engineer does not need three separate systems to understand the incident.

NOC / Live monitoring LIVE STREAM
Baseline
availability baseline
Example
managed-account scope
Review
open-alert example
Example
S1 severity example
TIMESEVEVENTSOURCE
Illustrative alert density · weekly view
Mon Tue Wed Thu Fri Sat Sun 0 4 8 12 16 20 23
Top 5 alert sources · this week
East China-1 / K8sExample
North China-2 / databaseExample
IDC-A / object storageExample
South China-3 / CDNExample
Global / IAMExample
Illustrative alert mix · consolidation measured per project; repeated alerts are shown only as a workflow example

Alert routing and escalation

S1 · Business unavailableTarget by agreement
S2 · Performance / capacityTarget by agreement
S3 · Configuration / complianceProcess-defined
Cost · Over budgetOwner policy scoped
Unowned resourcesCadence by agreement
Multi-screen network operations center
Response changes from whoever notices first to policy-based ownership. On-call handovers no longer depend on verbal explanations.

What each alert includes

Full resource pathCloud / account / region / instance
Ownership and costOwner · cost center
Recent changesIllustrative observation window
Related topologyUpstream / downstream impact
Recommended responseMatching historical jobs

Simulated monitoring events for interface illustration only.

SHEET 07 · AUTOMATION

Make rulesrun automatically,
not just sit in documentation

Monitoring detects an issue, policy determines whether action is permitted, orchestration defines the steps, and execution records the evidence. Closing this loop lets routine overnight alerts be handled without waking someone just to click a button.

Automated response loop EVENT → ACTION → AUDIT
Example
execution-volume baseline
Measured
success rate by scope
Measured
duration by workflow
Scoped
rollback rate by workflow
Detect Decide Orchestrate Execute Verify Audit Archive Monitoring / cost / compliance event Match policy and authorization Job template and sequence Execute with rollback points Health-check window by agreement Write audit record Update knowledge base
policy.yamlAUTO-REMEDIATION
# Low-utilization instances: notify the owner first, then adjust after the agreed observation window
policy: idle-instance-rightsize
match:
resource_type: [ecs, cvm, node]
cpu_p95_observation_window: "threshold agreed per project"
owner: assigned
action:
- notify(owner, "Resize only after the agreed observation window")
- snapshot() → rollback point
- resize(target=recommended)
- verify(health_check, verification_window)
- audit_log(change_id, operator)
EXECUTION LEDGER · Illustrative observation window
Example timeresize→ExampleExample resource · scope confirmed per workflowMeasured per workflow
Example timenotify→ExampleExample owner route · confirm in projectMeasured per workflow
Example timesnapshot→ExampleExample rollback point · verify per projectMeasured per workflow
Example timerestart→ExampleExample protected window · scope confirmedScoped
Example timescale_up→ExampleExample deployment path · confirm in projectMeasured per workflow
Example timeisolate→ExampleExample dependency conflict · verify per projectMeasured per workflow
Load-aware scaling

Scale ahead of demand using P95 and forecasts, rather than waiting for an alert. Scale down off-peak to avoid paying for idle capacity.

Example baselineForecast window scopedAutomatic
Cost-aware placement

Compare equivalent resources across zones and clouds in real time, selecting the best value within latency and compliance constraints.

Savings model reviewLatency threshold scopedCompare
Data-affinity scheduling

Keep compute close to data to reduce inter-region traffic. Pin workloads to approved regions where residency requirements apply.

Locality firstRegion constrainedAffinity
Spread failure domains

Distribute replicas across racks, availability zones and providers so a single cloud failure does not compromise overall availability.

Failure domains scopedAnti-affinityDistribute
Off-peak batch processing

Queue flexible workloads for off-peak execution and use spot instances to reduce cost.

Off-peak window scopedSpot instancesOff-peak
Capacity reservation and forecasting

Reserve capacity ahead of predictable peaks such as promotions and monthly settlement, avoiding last-minute shortages.

Reservation window scopedForecast accuracy measuredReserve
Automation scripts and job orchestration

Simulated execution statistics. Production automation requires tested approvals and recovery controls.

SHEET 08 · DELIVERY

Six delivery steps,
a tangible output at each stage

A hybrid cloud platform changes management processes; it is not just software to install. Delivery is organized around outputs you can use, accept and report on at the end of each stage.

Timing scoped per project

Inventory and discovery

Connect all cloud accounts with read-only credentials and perform a complete resource census. Align the organizational structure, project codes and cost-center definitions.

  • Cloud Resource Baseline Report
  • Account / region / resource inventory
  • Unowned and potentially idle resource list
Timing scoped per project

Connection and modeling

Establish a unified tagging scheme and resource model, map heterogeneous assets to consistent fields, and integrate the CMDB, organization directory and ticketing system.

  • Tagging standards and enforcement policies
  • Unified CMDB data model
  • Initial resource topology
Timing scoped per project

Policy definition

Agree cost-allocation rules, the access matrix, change windows and alert severities with business, finance and operations teams, then encode them in the policy engine.

  • Cost-center and allocation rules
  • Role-permission matrix
  • Change gates and approval workflows
Timing scoped per project

Pilot operation

Pilot one or two business domains to validate alert routing, reconcile cost reports and confirm safe automation.

  • Pilot operations report
  • Policy-tuning record
  • First production automation jobs
Ongoing support scoped

Full rollout

Bring all accounts under management, deliver reporting and OpenAPI capabilities, integrate existing BI and ticketing, and complete hands-on team training.

  • All resources onboarded
  • Reporting suite and API documentation
  • Administrator and on-call training
Ongoing

Continuous operation

Provide remote or on-site support, review costs and reliability on an agreed cadence, and adapt policies as the business evolves. Continue supporting new providers and resource types.

  • Operations review on an agreed cadence
  • Policy and template updates
  • Second-line technical support scoped per agreement
Delivery checklist review and sign-off
Every stage is independently verifiable
Agree deliverables at kickoff and review each item together at the end of the stage. Incomplete items are not signed off and do not advance to the next stage.

The sequence illustrates planning stages; actual duration and support follow the agreed scope.

SHEET 09 · TEAM

Platform delivery roles and capability review

Assign architecture, integration, data and operations responsibilities to the confirmed scope. Validate provider APIs, versions, permissions and operating constraints before production rollout.

Example
Delivery experience to confirm
Reference
Project count not asserted
Verify
Credentials checked per assignment
ARCH
Solution architects
Own architecture design and technology reviews, producing implementable layered designs and migration plans.
CLOUD
Cloud integration owner
Review the selected provider interfaces, authorization scope, licensing and support conditions. Verify any required credentials separately.
DEV
Platform engineering
Build the control plane, policy engine, orchestration executors and OpenAPI, keeping proprietary components maintainable and adaptable.
SRE
SRE and on-call engineers
Provide second-line support for alerts, incident response and supervised changes within the agreed service window.
DATA
Data and cost analysts
Model billing, define allocation rules and assess optimization opportunities to produce actionable recommendations.
SEC
Security and compliance consultants
Define access baselines, MLPS alignment, audit evidence and data-boundary controls.
Engineering team conducting a technical design review
Architects ×3 Developers ×8 SRE ×6
Architecture reviews bring engineering, SRE, cost and security specialists together. Implementation feasibility is challenged before work begins, not treated as a formality.
SHEET 10 · OUTCOME

A verifiable operating process for the enterprise

Launch is the starting point for consistent resource ownership, cost accounting and change rules. For Yuqi Intelligent, the immediate difference is discussing the cloud through one shared view rather than memories and screenshots.

One reconciled asset inventory

Resources from every account appear together with ownership, status and cost center. Audits, inventories and handovers no longer require last-minute manual consolidation.

Reviewresource traceability

Explain costs and act on them

Allocate bills to projects and environments to explain who spends what, why and where savings are possible. Recommendations become executable change requests.

Reviewspending comparison

Grant access and revoke it reliably

Apply least-privilege roles and expire temporary access automatically. Regular scans identify dormant accounts and expired access keys without relying on manual cleanup.

Reviewoverdue permissions

Controlled changes with rollback

High-risk operations require approval and an authorized window. Every step is logged, with a path back to the previous stable state if something goes wrong.

0unrecorded changes

A quieter on-call shift

Compare duplicate and actionable alerts against the agreed baseline. Automatic handling requires validated conditions, approval boundaries and a tested recovery path.

Reviewnon-actionable alerts

Evidence-based reporting

Weekly and monthly reports automatically supply cost trends, availability and provisioning efficiency, without a last-minute slide deck.

Scopedmonthly reporting preparation
Before launch→After launch
Teams self-report assets on an agreed cadence, and the inventory can become stale between checks
→
A synchronized inventory records new resources according to the agreed workflow and remains available for review
Account-based bills do not reconcile with project-based budgets, prompting repeated meetings
→
Tags allocate spend to projects, teams and environments using consistent reusable rules
Access is granted before revocation is considered; former employees may retain production permissions
→
Least privilege and automatic expiry, with weekly scans and notifications for overdue accounts
People discover incidents manually and struggle to prioritize a flood of alerts
→
Severity-based routing includes topology and recent-change context; routine incidents are automated
Uniform downsizing causes slowdowns, followed by capacity being added back
→
Recommend sizes per instance from actual utilization; reclaim idle capacity before downsizing
EXAMPLE FEEDBACK
"Example: a shared platform view can help teams reconcile resource ownership, cost definitions and optimization options without relying on separate spreadsheets."
Enterprise IT director Example role · no customer endorsement
Hybrid cloud platform acceptance model
Customer and engineering teams reviewing the design during delivery
FROM DELIVERY TO RUNNING TOGETHER
Launch puts the tools in the operations team's hands. Policy tuning, template improvements and incident response continue side by side with the customer's engineers.
SHEET 11 · INDUSTRY SOFTWARE

For industry software teams,
environments are part of productivity

For industry software companies such as Yuqi Intelligent, cloud infrastructure is part of delivery, not just an expense. Development, testing, demos, delivery and operations all need environments. Faster provisioning and disciplined cleanup improve project margins.

MULTI-TENANT

Multi-tenant delivery environments

Give each customer an isolated environment with its own domain, quota and cost center. Allocate post-delivery costs to the project for accurate margin reporting.

DEV / TEST

Self-service development and testing

Developers request standard environments from templates. Expiry reminders and reclamation prevent test systems from consuming budget indefinitely.

RELEASE

Standardized releases and rollback

Encode staged rollout, validation and rollback in job templates, retaining a complete history of version-to-environment mappings.

DEMO / POC

Demo and proof-of-concept environments

Create presales demo environments through an agreed workflow and destroy them when finished. Track POC resource use separately to measure presales costs.

SHEET 12 · BY THE NUMBERS

Five measurement areas for project acceptance

Establish a baseline and agree the measurement period, sample, owner and acceptance threshold for each area. The page does not report historical customer averages or guarantee improvement.

Measure
annual cloud-spend reduction
Measure
reduction in non-actionable alerts
Measure
resource-utilization improvement
Measure
overall availability
Measure
new-resource inventory delay
SHEET 13 · SECURITY

Managing more resources
requiresclear boundaries

Define platform permissions, data residency and the scope of audit logging during solution design, rather than relying on vague assurances.

Close-up of infrastructure hardware and circuitry
BELOW THE SURFACE
Governance boundaries must be enforced on every read and write, not merely described in documentation.
Least-privilege onboarding

Start with read-only credentials and enable individual operational permissions as needed. Centrally manage and rotate credentials without storing plaintext secrets.

Controlled data boundaries

Support private deployment and in-boundary data processing. Make collection scope and field lists auditable, and mask sensitive fields by default.

Comprehensive operation auditing

Record actor, time, parameters and result for each console or API operation, with queries by user, resource and time.

Compliance baseline scanning

Check configuration baselines aligned with MLPS and industry requirements. Alert on deviations, provide remediation items and retain the remediation history.

SHEET 14 · FAQ

Before implementation,
get clear answers

Q1Why add this platform when cloud providers already offer consoles?
A provider console manages one cloud; this platform governs all your clouds together. With multiple providers, accounts and teams, a single console cannot provide a unified asset view, consistent cost accounting, or shared access and change rules. The platform adds a governance layer rather than replacing provider consoles.
Q2Will onboarding affect existing operations?
The initial discovery and modeling phase uses read-only credentials and makes no changes. During the pilot, automation is validated in non-production and enabled gradually. Each action has a rollback point and a permitted execution window.
Q3Where is data stored, and is private deployment supported?
The control plane and data store can run in your own environment, keeping collected metadata within your boundary. In a managed deployment, data stays in an agreed region. The contract specifies collected fields, retention periods and access auditing.
Q4How long does implementation take?
The schedule is scoped after discovery: inventory, modeling, policy design, pilot and rollout are sequenced against the agreed scope, dependencies and acceptance criteria. Large or complex legacy estates may take longer.
Q5Could cost optimization reduce performance?
Start with clearly idle resources, then rightsize, and only then consider architectural changes. Recommendations use an agreed observation window and P95 definition, require business-owner confirmation, and are monitored after execution with rollback conditions defined in the acceptance record.
Q6How do you handle new providers or resource types?
Assess the provider API, resource model, permissions, compatibility and maintenance ownership before estimating a custom connector. Delivery time follows the validated scope.
SCOPE REVIEW SHEET 15 · NEXT STEP

Start witha scoped resource inventory,
then decide whether to adopt the platform

Using read-only credentials, we inventory your cloud estate and deliver a Resource Baseline Report covering total resources, unowned assets, potentially idle capacity and cost distribution. The report is yours regardless of whether you proceed, and provides the baseline for any subsequent proposal.

STEP 01
Submit an environment overview: providers, account count and scale
STEP 02
Sign an NDA and configure read-only credentials
STEP 03
Receive an inventory report and architecture recommendations after the agreed review window