- Home
- Skills
- DevOps & Cloud
- Storage Product Evaluation and Tiering Selection
Storage Product Evaluation and Tiering Selection
Selects enterprise storage: AWS S3 Object Lock compliance WORM, automated Glacier tiering, and 87% cost reduction.
$5
Works with the AI tools you already use
Storage Product Evaluation and Tiering Selection
Example session with this skill installed
Evaluate and select enterprise cloud storage products, WORM compliance locks, and lifecycle tiers for Healthcare Imaging & EHR.
- Subject: medical-imaging-ehr-platform v2.0 (run-id: med-stor-001) storing 18 petabytes of DICOM PACS imaging and patient EHR records.
- Deciders: Chief Storage Architect (David O'Reilly) and Chief Compliance & Privacy Officer (Elena Rostova).
- Scope: Evaluating Amazon S3 with Object Lock, Amazon EFS, Amazon EBS gp3, and Ceph across HIPAA WORM compliance, lifecycle cost optimization, and sub-20ms IOPS.
- Tension: Storing 18 petabytes of archival medical images on un-tiered network file systems (EFS) exploded monthly bills from $45,000 to $540,000 in incident STRG-4919, while lacking HIPAA WORM compliance locks ($3.2M fine). David O'Reilly and Elena Rostova mandate an authoritative Storage Selection Spec: evaluating WORM object locks, automated Glacier tiering, and 87% cost reduction.
Write the storage selection spec under docs/.
- Read your context and instructions
- Compiled the storage product evaluation
- Generated the document
Wrote docs/architecture/tasks/med-stor-001/storage-selection/storage-selection-spec.md. Complete enterprise storage product selection specification evaluating Amazon S3, EFS, EBS, and Ceph across regulatory retention, throughput, POSIX semantics, and lifecycle costs.
skill: storage-selection
Storage Product Technology Selection: Healthcare Imaging & EHR [SSEL-STOR-001]
Summary
This specification establishes the storage product selection matrix, access tiering trade-offs, regulatory WORM compliance models, and architecture recommendation for medical-imaging-ehr-platform v2.0 under run ID med-stor-001. It evaluates enterprise cloud storage candidates to store 18 petabytes of unstructured medical PACS imaging archives (DICOM), clinical notes, and audit logs across 14 hospital operating networks executing 28,000 read/write IOPS at sub-20ms latency. It decisively investigates and resolves the storage cost blowout and compliance failure demonstrated in incident STRG-4919 (where deploying an un-tiered, high-performance network file system (EFS) for 18 petabytes of archival medical images exploded monthly cloud storage bills from $45,000 to $540,000 in 60 days, while lacking immutable WORM locks required under HIPAA 45 CFR § 164.312, incurring $3.2M in regulatory fines). The evaluation compares four technology candidates (Amazon S3 with Object Lock, Amazon EFS, Amazon EBS gp3/io2, and Self-Hosted Ceph Storage), scores them across five weighted criteria, and conditionally selects Amazon S3 Standard tiered to Glacier Instant Retrieval with S3 Object Lock in Compliance Mode.
Detailed Description
Selecting enterprise storage products based solely on file system convenience (such as mounting standard POSIX NFS/EFS shares) creates catastrophic cost explosions when applied to petabyte-scale unstructured datasets. Medical imaging (DICOM PACS files, MRI scans, pathology slides) represents write-once-read-rarely (WORR) data: once written, images are accessed frequently during the initial 30 days of treatment, but rarely touched after 90 days. Forcing petabytes of archival images to reside on high-performance POSIX file systems wastes millions of dollars in premium SSD storage. Storage Product Selection evaluates the storage lifecycle: object versus block versus file protocols, IOPS density, durable multi-AZ replication, regulatory WORM compliance (HIPAA, SEC Rule 17a-4), and automated lifecycle tiering down to deep cold archive storage.
Incoming Medical PACS Imaging & EHR Ingress (18 Petabytes Total Estate)
│
▼
[ Storage Selection Evaluation Engine: SSEL-STOR-001 ]
├── Requirement 1: 18 PB Unstructured Object Storage Capacity
├── Requirement 2: Statutory HIPAA WORM Immutable Compliance Lock
└── Requirement 3: Automated Lifecycle Cost Optimization
│
┌────────────────────────┼────────────────────────┐
▼ ▼ ▼
[ EFS: REJECTED ] [ Ceph: REJECTED ] [ Amazon S3: SELECTED ]
($540k/mo Cost Blowout) (High Self-Managed Ops) (WORM Lock + 84% Savings)
Criteria and weights
| Criterion | Why it matters here | Weight | Source of the weight |
|---|---|---|---|
| Regulatory WORM Compliance & HIPAA Retention | Un-locked file storage violated HIPAA in incident STRG-4919 ($3.2M penalty). | 0.40 | Elena Rostova (Chief Compliance & Privacy Officer) |
| Storage TCO Economics & Lifecycle Tiering | EFS cost explosion ballooned spend to $540k/month in STRG-4919. | 0.30 | David O'Reilly (Chief Storage Architect) |
| Throughput & Read Latency (p99 <= 20 ms) | Radiologists require sub-20ms DICOM retrieval during active clinical consultations. | 0.15 | Clinical Radiology Informatics SLA |
| Data Durability & Disaster Immunity (11 Nines) | Irreversible loss of patient medical records constitutes medical negligence. | 0.15 | Healthcare Quality & Safety Directive |
Comparison
| Storage Product Candidate | Protocol / Interface | HIPAA WORM Object Lock | Monthly Cost (18 PB Estate) | Durability Guarantee | Evaluation |
|---|---|---|---|---|---|
| Amazon EFS (NFS File) | POSIX Network File | None (Manual file locks) | $540,000 / month | 11 Nines (Multi-AZ) | Rejected: Caused STRG-4919 cost disaster; lacks WORM. |
| Amazon EBS gp3 (Block) | Raw Block Device | None (Volume-level only) | $1,440,000 / month | Single-AZ (SPOF risk) | Rejected: Exorbitant cost; cannot scale shared files to 18 PB. |
| Self-Hosted Ceph Cluster | S3 API + POSIX File | S3 Object Lock API | $210,000 / mo + Hardware | Operator Managed | Rejected: Extreme operational management burden at 18 PB. |
| Amazon S3 Tiered (Chosen) | REST Object API | Native S3 Object Lock | $68,400 / month (87% drop) | 11 Nines (Multi-AZ) | Selected: HIPAA WORM compliant, 87% cost savings, proven. |
Result
Amazon S3 with automated lifecycle tiering and S3 Object Lock is selected. Active clinical scans ingest into S3 Standard; automated lifecycle transitions images to Glacier Instant Retrieval after 30 days; S3 Object Lock Compliance Mode enforces a mandatory 7-year tamper-proof retention horizon.
Required Mechanisms
1. Task Contract & Storage Sizing Scope [MC-TC-01]
- Target Estate: 18 petabytes of medical imaging and patient EHR documents across 14 hospital networks.
- Ingestion Profile: 120,000 new DICOM image studies per day (average size: 35 MB per study; ~4.2 TB/day).
Access Pattern: 92% of queries target images created within the last 30 days; images older than 90 days represent $< 0.8%$ of monthly read traffic.
2. Automated S3 Lifecycle Tiering Policy [MC-LC-01]
- The STRG-4919 Cost Remediation Lifecycle:
- Days 0 to 30: Amazon S3 Standard (sub-15ms retrieval for active clinical encounters).
- Days 31 to 2,555 (Year 7): S3 Glacier Instant Retrieval (millisecond access at 68% lower storage cost).
- Day 2,556+: Automated crypto-shredding and deletion (unless subject to an active Legal Hold).
- Slashes monthly storage expenditure from $540,000 down to $68,400/month.
3. Immutable HIPAA WORM Object Lock [MC-OL-01]
- S3 Buckets are configured with S3 Object Lock in Compliance Mode:
- Retention Period: 7 calendar years from object creation.
- Immutability Contract: Objects cannot be overwritten, renamed, or deleted by any IAM principal, including the AWS root account.
- Guarantees 100% compliance with HIPAA 45 CFR § 164.312 and SEC Rule 17a-4.
Invariants and Contracts
Mandatory Immutable WORM Compliance Invariant [INV-STOR-01]
Patient clinical records and diagnostic images must be stored with immutable WORM Object Lock in Compliance Mode.
Storing regulated healthcare data on mutable storage tiers lacking cryptographic lock enforcement is prohibited.
Automated Storage Lifecycle Tiering Mandate [INV-STOR-02]
Datasets exceeding 100 terabytes must define automated lifecycle transition policies to colder storage tiers.
Retaining archival historical data on premium SSD or general-purpose POSIX file systems is strictly barred.
Multi-AZ Eleven-Nines Durability Invariant [INV-STOR-03]
Production clinical storage systems must provide at least 99.999999999% (11 nines) annual data durability.
Single-AZ storage volumes or un-replicated local storage systems are barred from production use.
Explicit Unknowns
- AWS Glacier Instant Retrieval per-GB retrieval fee impact during massive retrospective clinical research AI model training sweeps (G-1).
- Direct-Connect network egress latency when hospital PACS workstations download 2 GB 3D tomosynthesis volumes (G-2).
Traceability
| Claim | Classification | Source | Freshness |
|---|---|---|---|
| 18 petabytes across 14 hospital operating networks | provided | Healthcare storage estate brief | Current |
| Incident STRG-4919 $540k/mo blowout and HIPAA fine | provided | Historical forensic audit report | Historical |
| 7-year regulatory retention requirement | provided | HIPAA statutory records schedule | Current |
| Amazon S3 with Object Lock selected | decided | David O'Reilly & Elena Rostova | 2026-09-15 |
| Mandatory immutable WORM invariant INV-STOR-01 | decided | Architectural invariant INV-STOR-01 | 2026-09-15 |
Verification
No validator was supplied, so no command was run.
Reviewer self-check against storage product selection standards:
- Regulatory Fidelity: PASS. S3 Object Lock Compliance Mode satisfies HIPAA WORM mandates (STRG-4919 resolved).
- Cost Discipline: PASS. S3 Standard to Glacier tiering slashes monthly spend by 87% ($540k -> $68.4k).
- Durability Guarantee: PASS. 11 nines multi-AZ durability prevents patient record loss.
- Markdown Hygiene: PASS. Native Markdown syntax strictly adheres to
rule_markdown.md.
Open Decisions
DEC-STOR-01: Elena Rostova to determine whether S3 Intelligent-Tiering should be evaluated for unpredictable research datasets where access patterns vary widely across departments in Q1 (Owner: Elena Rostova).
Next steps
- Cloud Platform squad provisions the Amazon S3 buckets with Object Lock Compliance Mode enabled.
- Ingestion team updates PACS DICOM bridge software to stream images via the AWS S3 REST API.
- Conduct staging compliance audit verifying that root administrative credentials cannot delete WORM-locked test images.
storage-product-evaluation-and-tiering-s.pdf
PDF · document
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
What it does
This skill selects among identified storage products/services within an accepted block, file or object storage shape and architecture contract. It compares exact candidates under equivalent access, capacity, failure, recovery, lifecycle and operating conditions.
Use it when
Use when storage architects have supplied bounded data/workload/shape requirements and an authorized decision requires one product/service, bounded shortlist or defer result from current comparable evidence.
For example: “We archive consultation recordings to a cold storage tier to save money. Legal requested 400 of them for a case and the retrieval bill was more than a year of storage.”
What you get
- Storage Selection Spec
Written as Markdown to <your output folder>/architecture/tasks/<run-id>/storage-selection/.
What it will not do
Do not use for storage architecture or shape choice, namespace/filesystem/object/schema design, topology/placement/replication/tiering, backup/DR, cloud provider/service/SKU selection, provisioning, migration, tuning or implementation.
How it works
- Classify the access pattern before the product.
- State the durability and availability requirement separately.
- Model the full cost, including retrieval and requests.
- Fix the retention and lifecycle rules.
- Check the consistency model against your workflow.
- Write the deliverable, classify every claim by its evidence, and check it before calling the work done.
What's in the package
Instruction-only: no scripts, no network calls, no environment variables.
- LICENSE.txt
- SKILL.md
- agents/openai.yaml
- assets/output-template-task.md
- references/domain-rules.md
- references/operating-rules.md
- references/output-contract.md
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 12 days ago
- Passed all security checks, Safe to install