TodaySix consoles, six CLIs, six APIs. Every automation is rebuilt per provider.
One model for every provider
A single resource graph and API across all six clouds. Write automation once; it runs everywhere.
Early access is open for multi-cloud teams
Paco is the control plane between AI agents and your infrastructure. One interface across six providers, your rules on every action, and approvals in your pocket.
Teams run on several providers for resilience, regulation and regional reach, then spend their days stitching them together by hand. AI agents could help, if they could be trusted.
TodaySix consoles, six CLIs, six APIs. Every automation is rebuilt per provider.
A single resource graph and API across all six clouds. Write automation once; it runs everywhere.
TodayGiving an agent cloud keys means it can do anything, so it does nothing.
Agents never hold cloud credentials. Every request is checked by policy, risky ones wait for a person, and all of it is logged.
TodayAlerts at 2 a.m. with no context. Which cloud, which service, which change?
Paco correlates health, events and recent changes across providers, explains the likely cause and proposes a fix.
TodayEach cloud has its own release process, so rollouts are slow and rollbacks are scary.
Roll out in waves across providers with health gates, then pause or roll back everywhere with a single action.
TodayLeadership asks engineers for status, usually in a meeting after the fact.
An executive view of availability, open risks and spend across every cloud, written for people who don't read dashboards.
TodayHuawei Cloud, Alibaba Cloud and Oracle Cloud are partial or missing in most tools.
The same monitoring, actions, pipelines and cost tracking on every supported provider from the first release.
Whether an agent, a pipeline or a person starts it. Pick a step, or watch a real-world incident play through.
Paco sits between everything that wants to change your infrastructure and the clouds themselves. Agents never hold cloud keys.
Agents get scoped Paco tokens. Only Paco reaches providers, through short-lived roles.
Every change, from any source, is checked against your rules before it reaches a cloud.
Start with visibility. Grant write access per action type and per environment.
A standard MCP server lets Claude and other agents use Paco without glue code.
Engineers on call, team leads and executives open the same app and see what matters to them. Design previews with sample data.
Availability, last 30 days
99.97%
Overnight
One incident on Google Cloud, resolved by an agent with on-call approval in 6 minutes. No customer impact.
Spend
$48.2k81% of budget
Releases
14This week
Google Cloud, europe-west1
Checkout latency p95 812 ms
Likely cause
Checkout node pool hit its CPU quota 3 minutes after release v2.4.1.
Timeline
Requested by
On-call agent, via MCP
Change
Shift 30% of checkout traffic to AWS eu-central-1
Why it needs you
Production traffic changes need on-call approval. Estimated cost +$14 per hour.
Health gate
Error rate 0.2%, latency normal. Next wave starts automatically.
$48.2k
of $60k monthly budget
Unusual spend
Alibaba Cloud data transfer is up 38% this week.
We're building Paco with a small group of teams that run on more than one cloud. If that's you, or you just want to talk about the problem, we'd like to hear from you.