// Cloud Intelligence

Migration, optimization, and rationalization intelligence.

Built vendor-neutral. Delivered inside Barrier engagements.

5
cloud + on-prem cost scenarios, one comparable basis
184 wks
a hand-built assessment, compressed into a structured run
6R × 50+
disposition per app across a dependency-mapped portfolio
100%
exportable: branded PDF, CSV, Excel round-trip, REST API
Migration to cloud Cloud-to-cloud arbitrage In-cloud rationalization M&A diligence
// See it run

A narrated tour of the live engine.

Real screens from a live assessment - multi-cloud TCO, the dependency graph, and a computed wave plan - the same output we hand you inside an engagement.

Narrated walkthrough (sound on). Live product, recorded on an illustrative sample portfolio (StackForge Cloud Inc.). No client data shown.

// What it does

Three capabilities. One assessment workflow.

Multi-cloud TCO, dependency mapping, wave planning. Used in every Barrier engagement.

01 / TCO

Multi-cloud TCO

AWS, Azure, GCP, OCI, and on-prem comparison with itemized run-rate, migration cost, and decommission savings. Every dollar traceable to a formula.

02 / Graph

Visual dependency mapping

Interactive graph with business overlays (criticality, 6R, initiative band, cost), what-if migration simulation, AI narrative explanation, drift mode, and trust-boundary overlays.

03 / Waves

Wave planner

Topological dependency-ordered migration waves with capacity caps, cycle detection, and within-wave priority by criticality + effort + fan-out. Drag-and-drop adjustments preserved across re-runs.

// Inside the product

The three modules, on real data.

Every screen below is the live tool, run on a 50-application sample portfolio. The same workflow scales from a 50-app carve-out to a 5,000-app migration.

01 / Multi-cloud TCO

Five cost scenarios, every dollar traceable.

Per-application monthly run-rate and 3-year TCO across AWS, Azure, GCP, OCI and on-prem - priced from live AWS and Azure rate cards, cached and refreshed weekly. A CFO ledger itemizes every number against its formula, and the whole model round-trips to Excel.

5scenarios compared
$3.1M3-yr on-prem baseline
50apps priced individually
client.barrierconsulting.tech / cost
Multi-cloud TCO comparison: per-application monthly run-rate and 3-year TCO across AWS, Azure, GCP, OCI and on-prem
02 / Dependency graph

Every dependency, every disposition.

An interactive app-to-app map with business overlays - criticality, 6R verdict, initiative band, cost. Switch layouts, recolor by any dimension, simulate a what-if migration, isolate the critical path, and export to PNG, SVG, or JSON.

50×60apps × edges mapped
6Rdisposition per node
3export formats
client.barrierconsulting.tech / dependencies / graph
Visual dependency graph of 50 applications and 60 dependency edges with 6R and criticality overlays
03 / Wave planner

A migration sequence, computed - not guessed.

Topological, dependency-ordered waves with capacity caps and cycle detection. Foundation apps go first; the critical core lands last and is flagged as the schedule risk. Cyclic or over-capacity apps are surfaced instead of silently mis-sequenced, and manual drag-and-drop moves survive a re-run.

5dependency-ordered waves
17cycle/overflow apps flagged
6R + coston every card
client.barrierconsulting.tech / migration / waves
Wave plan: five dependency-ordered migration waves across 50 applications with 6R, line-of-business, effort and monthly cost on every card
// What the output looks like

Boardroom-ready exhibits, generated - not drawn.

The before-and-after, a portfolio value map, and a looping recap. Sample data is illustrative; the format is what lands in the report.

Value proposition · before / after

Eighteen-plus weeks of assessment, delivered in four.

One vendor-neutral platform replaces scattered spreadsheets, discovery scripts, and slideware - across all four engagement scenarios.

TODAY - FRAGMENTED, ~18+ WEEKS Discovery scripts TCO spreadsheets Dependency hunts Wave slideware Manual re-keying Static PDFs Cloud Intelligence CLOUD INTELLIGENCE - ONE PLATFORM, ~4 WEEKS 01 TCOMulti-cloud costAWS / Azure / GCPOCI / on-prem 02 GraphDependency map6R + criticalityAI narrative 03 WavesTopological planCapacity-awareDrag-and-drop Four scenarios: Migration to cloud  ·  Cloud-to-cloud arbitrage  ·  In-cloud rationalization (6R)  ·  M&A IT diligence & separation So what: the same diligence a team needs months to assemble by hand, produced in one vendor-neutral engine - with exportable, defensible numbers.
Portfolio value map

Quick wins vs. the long haul, at a glance.

Every application plotted by migration fitness against effort, auto-bucketed into Quick Win, Mid-term, Long-term, and Consider-alternatives.

client.barrierconsulting.tech / visuals
Value map plotting 50 applications by migration fitness against effort, bucketed into quick wins, mid-term, long-term and consider-alternatives
Animated · the workflow in a loop

Four scenarios, three modules, one engine.

A short looping recap of how a fragmented, multi-month assessment collapses into a single structured run.

Animated loop summarizing the Cloud Intelligence workflow: from 18-plus weeks of fragmented assessment to a 4-week run across TCO, dependency graph and wave planning
// Scenarios

Four scenarios. One workspace.

Migration is the most common destination but not the only one. The same questionnaire, dependency graph, and cost engine answer four distinct engagement types.

01 / Migration

Migration to cloud

Move from on-prem (or co-lo, or hosted) to a public cloud. Multi-cloud cost modeling, dependency-ordered wave plan, 6R disposition per app.

02 / Arbitrage

Cloud-to-cloud arbitrage

Already in AWS or Azure? The same engine compares all four clouds. Includes egress and re-architecture costs.

03 / Rationalize

In-cloud rationalization

For orgs already cloud-native: which apps to keep, kill, modernize, or replace. Same 6R framework, no migration required. Most common follow-up to a cost overrun.

04 / M&A

M&A / carve-out diligence

IT portfolio diligence pre-deal, separation planning during integration, post-merger rationalization. Fortune 500 carve-out case study below.

Gartner classifies the underlying capability as Application Discovery and Dependency Mapping (ADDM), a $4B+ market. Barrier delivers it inside the Public Cloud IT Transformation Services engagement model.

// In engagements

What we deliver inside an engagement.

Mid-market and Fortune 500 organizations running migration, optimization, or rationalization engagements with Barrier. Engagements typically run four to eight weeks.

Fortune 50 retail

4 months → 4 weeks

Migration assessment for a Fortune 50 retailer's app portfolio. Replaced an 18-week external assessment with a 4-week structured run using the multi-cloud TCO module and the wave planner.

Fortune 500 carve-out

240 apps mapped in 9 days

Day-1 IT separation for a tech-heavy carve-out. The dependency graph plus AI narrative resolved 90% of the application disentanglement question set inside the first sprint.

Engagement summaries anonymized. Read the full case-study catalog →

// Built right

How your data is protected.

  • Each engagement is isolated at the database layer. Cross-engagement reads return zero rows by policy.
  • Access tokens are per-engagement, rotatable and revocable.
  • Nightly backups, weekly recovery test that restores into a scratch database.
  • Rate-limited logins and API endpoints.
  • Content-Security-Policy restricts the page to Barrier-served scripts only.
  • TLS 1.3 in flight. Storage-layer encryption at rest.
  • No third-party analytics, marketing pixels, or telemetry.
  • Every byte exportable as PDF, CSV, Excel, or REST API.
// FAQ

Common questions.

How does this differ from CloudHealth, Apptio, or Flexera?

Those are FinOps tools for ongoing cloud spend management once you are already in cloud. Cloud Intelligence is an assessment platform for migration, arbitrage, rationalization, and M&A diligence, the work that happens before workloads move (or before they get cut). Different buyer, different workflow, different output (a wave plan and a defensible TCO model, not a monthly chargeback report).

Do you replace AWS Transform or Azure Copilot Migration Agent, or sit alongside them?

We sit alongside, and we are explicitly neutral. AWS Transform shipped September 2025 and optimizes for AWS landing zones. Azure Copilot Migration Agent shipped the same month and optimizes for Azure. Both are useful inside their respective clouds. Neither will tell you to pick the other. Cloud Intelligence scores AWS, Azure, GCP, and OCI on the same matrix, weighted by your scenario, we have no landing-zone quota.

Can I import from ServiceNow, a CMDB, or another inventory tool?

CSV import works today and is the path most engagements use. ServiceNow and Device42 connectors are on the roadmap. The XLSX round-trip with the v5.1 Excel template covers the cases where your client gives you a spreadsheet and wants the answer back in the same format.

How is my data protected?

Each engagement runs in its own isolated workspace. The database itself refuses to return one client’s data to a different client’s session, this is enforced at the database layer, not just in the application code, so even a software bug cannot leak data across engagements.

Specifically:

  • In flight: All traffic uses TLS 1.3, the same encryption standard banks and payment networks use. The connection negotiates TLS 1.3 with modern ciphers; older protocols are refused.
  • At rest: The storage layer is encrypted by the cloud provider (Oracle Cloud Infrastructure block-volume encryption). A physically removed disk reveals nothing readable.
  • Authentication: Access is gated by per-engagement Bearer tokens. Tokens are stored as salted SHA-256 hashes, the database does not retain the raw token. Each token can be rotated or revoked instantly without affecting other engagements.
  • Authorization: Postgres Row-Level Security policies are FORCED on every table that holds engagement data (15 tables verified). A query without engagement context returns zero rows by policy; the database, not the app, is the boundary.
  • Brute-force protection: Login attempts and authenticated API calls are rate-limited per IP and per engagement. Repeated failed logins lock out the source within seconds.
  • Browser hardening: Strict Content-Security-Policy (CSP) blocks script injection. HSTS forces HTTPS. X-Frame-Options blocks click-jacking. Permissions-Policy disables camera, microphone, geolocation, and FLoC tracking.
  • Backups and recovery: A full database dump runs every night with 30-day retention. A weekly restore test actually restores the most recent dump into a scratch database and verifies row counts, if a backup is silently broken, the next weekly test catches it.
  • Tracking: No Google Analytics, no Facebook pixel, no HubSpot, no Segment, no Amplitude, no telemetry of any kind. Your engagement data is never sent to a third party. Only library code (Chart.js, Cytoscape, html2canvas) loads from public CDNs, and the CSP restricts even those origins.
  • Export rights: Every byte you put in is exportable at any time as branded PDF, CSV, Excel, or REST API. Your data is yours, irrevocably.

Need to hand this answer to your security team for review? Get the long-form security brief.

Can I export everything?

Yes. Branded PDF report, CSV of every table, XLSX round-trip with the v5.1 Excel template, and REST API. Your assessment outputs are yours; we never gate the export.

How does scope work?

Scope is set per engagement, not per tier. There is no hardcoded app or server cap. Whether the engagement covers 50 apps for a mid-market carve-out or 5,000 apps for a Fortune 500 multi-year migration, the tool runs at the size of the work. The shape of the engagement is something we agree before we start; talk to us about the assessment in front of you.

Used in Barrier Consulting engagements.

To see it run on your migration, arbitrage, rationalization, or M&A engagement, get in touch.