Free cost scan
Ten minutes to a one-page answer.
Connect a read-only role, press start. We read Cost Explorer, Cost Anomaly Detection and Cost Optimization Hub and write back: what AWS already explains, the largest movers it does not, and a go or no-go.
- 1Your account2 min
- 2Connect AWS5 min
- 3Start the scan3 min
Tell us what we are looking at
Nothing here is required to be exact. It helps us read the report with the right expectations.
Create a read-only role in your payer account
Three clicks in the AWS console. The stack creates one IAM role that trusts the Cloudblame account with the external ID below. It can read billing and metadata; it cannot create, change or delete anything.
-
Your external ID
…Generated in your browser for this scan. Already filled into the template; keep it for your records.
-
Open CloudFormation
Open CloudFormation quick create
Opens the AWS console in a new tab in the region you choose. Sign in to the management (payer) account.
Connected this account before? CloudFormation stops with “CloudCostControlReadOnly already exists”. Delete the old cloudblame-readonly stack in that account (CloudFormation → Stacks), then open quick create again; the new stack carries the external ID above.
What you will see- Stack name: cloudblame-readonly, parameters prefilled
- Tick “I acknowledge that AWS CloudFormation might create IAM resources with custom names”
- Create stack. About a minute. Then open the Outputs tab and copy RoleArn.
-
Paste the Role ARN
Automated scans are not switched on yet. Leave your details and we run the scan by hand within two business days.
Review and start
The scan takes two to five minutes. You can leave this page; the report link is also emailed.
- Account
- —
- Role
- —
- Spend
- —
- Stack
- —
- Report to
- —
- Queued
- Assuming the read-only role
- Reading 90 days of Cost Explorer data
- Reading Cost Anomaly Detection
- Reading Cost Optimization Hub
- Reading Savings Plans coverage
- Writing the report
- Done
0:00 elapsed
Open the reportTrack it in the console
What happens next
- Read the report; every number cites its source.
- If it says go, open the console and start an investigation on an unexplained mover.
- Delete the stack any time to revoke access.
The scan failed. Most often the role was deleted or the external ID differs. Fix and start again, or email [email protected].
Prefer to talk first?
Leave your email. We run the same scan by hand.
No stack and no role yet. We reply within two business days, agree a time, and run the one-page scan with you on a call. Same report, same read-only limits. Your answers from step 1 come along.