Guides
Software operations guides for startups
Operations at a software startup has two halves: running the company (people, finance, legal) and running the software (CI, cloud, security, dependencies). These guides focus on the second half, for teams of about 2 to 30 engineers on GitHub and AWS with no ops hire yet.
On this page
What operations covers at a software startup
Before the first ops hire, each area falls to someone by default.
| Area | Usual owner before an ops hire | Guide |
|---|---|---|
| Company operations: hiring, payroll, finance, legal | The founders, later an operations manager or COO | Startup COO |
| CI and deploys | The CTO or lead engineer | DevOps for startups |
| Cloud cost | The CTO | AWS cost monitoring |
| Runtime health | The CTO or the engineer on call | DevOps for startups |
| Security alerts | The CTO | Security alert triage |
| Dependencies and deprecations | Nobody in particular | Dependency breaking changes |
Since.dev covers software operations only. People, finance and legal need other tools and people; the COO guide explains when that work needs its own leader.
A weekly operations checklist
Give the list one owner and a fixed day. With alerts in place, 30 minutes is a realistic target (our suggestion). The weekly operations review guide turns it into an agenda with a decision log.
CI and deploys
- Is
maingreen? Which workflows failed this week? - Which runs needed a rerun (
run_attemptabove 1)? A rerun that passes usually means a flaky test.
Guide: DevOps for startups
Cloud cost
- Which services changed most against last week in Cost Explorer? Sort by the change, not the total.
- Did Cost Anomaly Detection flag anything? AWS offers it at no additional cost.
Guide: AWS cost monitoring
Runtime health
- Which CloudWatch alarms fired: EC2 status checks, Lambda errors and throttles, RDS free storage?
- Which metrics stopped reporting? A missing metric is unknown, not healthy: a Lambda function with zero invocations may have a broken trigger.
Guide: DevOps for startups
Security alerts
- Which Dependabot and code scanning alerts are new? Which Security Hub findings are labelled CRITICAL or HIGH?
- Is any new CVE in CISA's Known Exploited Vulnerabilities catalog (confirmed exploitation)? A listed CVE goes first, whatever its severity.
Guide: Security alert triage
Dependencies and deprecations
- Did CI logs show new deprecation warnings, such as
npm warn deprecated(older npm versions print it in capitals)? - Which runtimes reach end of life in the next 90 days? AWS lists a deprecation date for each Lambda runtime, for example April 30, 2027 for
nodejs22.xand June 30, 2027 forpython3.11(AWS runtime policy).
Guide: Dependency breaking changes
All guides
- DevOps for startups without a DevOps teamSet up four things once, then check five every week. A practical DevOps checklist for startups on GitHub and AWS that have no DevOps engineer yet.
- What does a COO do at a startup?What a startup COO owns, when companies add one, how the role differs from CTO and VP of Engineering, and who runs software operations before then.
- Weekly operations review: a template for small software teamsA 30-minute weekly operations review for small software teams: the agenda, the checks for CI, AWS, security and dependencies, and a decision log to copy.
- When to hire your first DevOps engineerThe signs you need a DevOps engineer, what the first one should own, and how a full-time hire compares with a contractor, a managed platform or software.
- AWS cost monitoring for startups: a 15-minute weekly reviewTurn on free AWS cost alerts, read Cost Explorer by service each week and check the common leaks: NAT gateways, idle volumes, log retention and idle RDS.
- How to triage Dependabot, code scanning and Security Hub alertsA 20-minute weekly routine to triage Dependabot, code scanning and AWS Security Hub alerts: known exploitation first, then exposure, then severity.
- How to track breaking changes and deprecations in your dependenciesDependabot flags vulnerable and outdated versions, not announced breaking changes. Where deprecation and end-of-life notices appear, and how to catch them.
Where Grant fits







Grant is the COO for your software operations. He and his team are AI agents built by Since.dev, not people. On a schedule, Maya reads GitHub Actions runs, Liz reads AWS costs, Noah reads CloudWatch metrics, Priya reads existing security alerts and findings, and David and Owen check compatibility, configuration and lifecycle. Check-ins run daily on Pro and every six hours on Studio, plus on GitHub events. Grant answers in Slack, the dashboard or MCP.
Check-ins only read the sources you connect, except Vera's tests of your own agents, and nothing merges or deploys. Supported compatibility repairs arrive as pull requests for your review.
Questions
Which guide should I read first?
If CI, deploys and alarms aren't set up, start with DevOps for startups. If they are but nobody checks them weekly, start with the weekly operations review. If you're deciding whether to hire, read the startup COO or first DevOps engineer guide.
Do the guides apply if we don't use GitHub or AWS?
The checks do, since every CI system keeps run history and every cloud has cost, metric and security views. The steps name GitHub and AWS tools, and Grant's team reads CI and cloud evidence from GitHub and AWS.