AI Tag Strategy
Guardian Pro's AI Tag Strategy analyses your infrastructure and generates a tailored tagging strategy -- recommending which tags to enforce, in what order, and at what scope. Instead of guessing which tags matter, you get recommendations grounded in what you actually run.
Generating a Strategy
- Navigate to Governance and expand the AI Tag Strategy section.
- Click Generate Tag Strategy.
- Guardian Pro analyses your discovered resources, existing tags, and organisational structure.
- Once complete, the strategy appears with a narrative summary and detailed recommendations.
You can regenerate the strategy at any time by clicking Regenerate. This is useful after significant infrastructure changes or after you have implemented earlier recommendations.
Strategy generation analyses your current resource inventory. For the most accurate recommendations, ensure a recent resource discovery scan has completed.
Understanding Your Strategy
Summary
The strategy opens with an AI-generated narrative explaining the overall approach. This includes context about your environment (resource types, existing tagging patterns) and the rationale behind the recommendations. A badge indicates whether the strategy was AI-generated or based on rule-based analysis.
Recommended Tags
The recommendations table lists each suggested tag with:
| Field | Description |
|---|---|
| Tag Key | The recommended tag key (e.g., Environment, Owner, CostCenter) |
| Enforcement | How strictly the tag should be enforced: Required (must be present), Recommended (should be present), or Optional (nice to have) |
| Phase | When to implement: Foundation (implement first), Expansion (implement second), or Optimisation (implement last) |
Use the phase filter buttons to focus on one implementation phase at a time.
Expand any row to see additional detail:
- Description -- What the tag is for.
- Rationale -- Why this tag was recommended for your environment.
- Allowed values -- Suggested values to standardise on.
- Scope -- Whether the tag should apply at the root, OU, or account level.
- Target -- Specific OUs or accounts where the tag is most relevant.
Coverage Indicator
If your existing tag policies already cover some of the recommended tags, Guardian Pro shows how many recommendations are already enforced. Tags already covered are excluded from the recommendations table to avoid duplication.
OU Strategy
For AWS Organisation setups, an OU Strategy tab provides per-OU recommendations:
- OU name and its inferred purpose (e.g., production workloads, development environments).
- Top resource types in that OU.
- Required and recommended tags specific to that OU's workload pattern.
- Enforcement mechanism -- Whether to enforce via tag policies, SCPs, or Guardian Pro's built-in compliance.
- Restructuring notes -- Suggestions for OU organisation improvements, if any.
Acting on Recommendations
You can turn recommendations into enforceable policies directly from the strategy view.
Adding Tags to an Existing Policy
- Select one or more recommended tags using the checkboxes.
- Click Add to [Policy Name].
- Guardian Pro adds the selected tag rules to your best-matching existing policy.
Creating a New Policy
- Select one or more recommended tags.
- Click Create New Policy.
- A pre-populated policy form opens with:
- A suggested policy name based on the selected phase (e.g., "Foundation Policy").
- Rules derived from your selected recommendations (tag keys, enforcement levels, allowed values).
- Review and adjust the policy as needed.
- Assign targets (OUs, accounts, or root).
- Click Save.
A practical rollout approach: start with Foundation-phase required tags as your first policy. Once compliance reaches a healthy level, create a second policy for Expansion-phase tags. This avoids overwhelming teams with too many new requirements at once.
Strategy History
Guardian Pro retains your strategy history so you can compare how recommendations have evolved as your infrastructure changes. Access history from the strategy section.
Next Steps
- Tag Governance -- Monitor compliance against the policies you create from your strategy.
- SCP Management -- Enforce tagging requirements at the AWS level.
- Maturity Assessment -- See how your tag strategy contributes to governance maturity.