# Home

<figure><img src="/files/iG0AuzUewVRqSo8jui9I" alt=""><figcaption></figcaption></figure>

FinOps for Cloud is SoftwareOne's cloud financial management platform designed to help organizations gain visibility into and optimize their spending across platforms like Amazon Web Services, Microsoft Azure, and Google Cloud.

With FinOps for Cloud, you can explore and analyze your cloud expenses, monitor resource usage, and implement policies to ensure efficient and cost-effective cloud management. The platform's user-friendly interface and robust features empower organizations to achieve greater visibility and control over cloud infrastructure, enabling smarter decision-making and improved financial planning.

## Get started <a href="#featured-resources" id="featured-resources"></a>

<table data-card-size="large" data-view="cards"><thead><tr><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><strong>Overview</strong></td><td>Discover key features of FinOps for Cloud.</td><td><a href="/pages/xkcISUCQaUNF0CyOToGV">/pages/xkcISUCQaUNF0CyOToGV</a></td></tr><tr><td><strong>Access Your Organization</strong></td><td>Get started by signing in to your organization.</td><td><a href="/pages/nUyuUbsJB1vVqu8EHyad">/pages/nUyuUbsJB1vVqu8EHyad</a></td></tr><tr><td><strong>Navigate the User Interface</strong></td><td>Become familiar with the user interface.</td><td><a href="/pages/e90l13kJej3GWnLmHPmK">/pages/e90l13kJej3GWnLmHPmK</a></td></tr><tr><td><strong>Add Data Sources</strong></td><td>Add your AWS, Azure, or Google data sources.</td><td><a href="/pages/5rE6SLlLwQOM1zLDuDTe">/pages/5rE6SLlLwQOM1zLDuDTe</a></td></tr></tbody></table>

## Visualize costs and usage

<table data-card-size="large" data-view="cards"><thead><tr><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><strong>Cost Explorer</strong></td><td>Analyze costs and understand the cost structure for your organization. </td><td><a href="/pages/UinfEGPN5YuJQJxLrCno">/pages/UinfEGPN5YuJQJxLrCno</a></td></tr><tr><td><strong>Cost Map</strong></td><td>View a breakdown of expenses and network transfer costs by location.</td><td><a href="/pages/gY5bLMlT9Mv5Y9iLmDom">/pages/gY5bLMlT9Mv5Y9iLmDom</a></td></tr></tbody></table>

## Optimize and control costs <a href="#optimize_and_control_costs" id="optimize_and_control_costs"></a>

<table data-view="cards"><thead><tr><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><strong>Recommendations</strong></td><td>View savings and security recommendations to reduce costs.</td><td><a href="/pages/xhEE8TN88X1QLPbwXE73">/pages/xhEE8TN88X1QLPbwXE73</a></td></tr><tr><td><strong>Resources</strong></td><td>Monitor and manage your cloud resources effectively.</td><td><a href="/pages/7ap56WSLUwyzpXEakSoz">/pages/7ap56WSLUwyzpXEakSoz</a></td></tr><tr><td><strong>Pools</strong></td><td>Group your cloud resources to maximize efficiency.</td><td><a href="/pages/jagQG83AtKPSfTzX4UsP">/pages/jagQG83AtKPSfTzX4UsP</a></td></tr><tr><td><strong>Anomaly Detection</strong></td><td>Review anomalies and create detection policies.</td><td><a href="/pages/GsBPJOOr3vZx7oTO2vYP">/pages/GsBPJOOr3vZx7oTO2vYP</a></td></tr><tr><td><strong>Quotas and Budgets</strong></td><td>Create quotas and budgets and set up alerts.</td><td><a href="/pages/EPbw3HZ2f6nfIvyu6kbr">/pages/EPbw3HZ2f6nfIvyu6kbr</a></td></tr><tr><td><strong>Tagging Policies</strong></td><td>Create and manage tagging policies.</td><td><a href="/pages/0ZsJlwzpNv2Mv6jHco64">/pages/0ZsJlwzpNv2Mv6jHco64</a></td></tr></tbody></table>

## Manage your organization

<table data-card-size="large" data-view="cards"><thead><tr><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><strong>User Management</strong></td><td>Add or remove members from your organization.</td><td><a href="/pages/GtKoLony7cdefWqsdv63">/pages/GtKoLony7cdefWqsdv63</a></td></tr><tr><td><strong>Settings</strong></td><td>Manage your invitations and notification settings.</td><td><a href="/pages/flDkNaRn9JQ2isSH99KY">/pages/flDkNaRn9JQ2isSH99KY</a></td></tr></tbody></table>


# Overview

SoftwareOne's FinOps for Cloud helps businesses optimize cloud spending by providing real-time insights, budget tracking, and cost management. This solution enables teams to allocate resources efficiently, control expenses, and drive financial accountability across cloud environments.

FinOps integrates with public cloud providers, including Amazon Web Services, Microsoft Azure, and Google Cloud.

Built on the [open-source OptScale platform from Hystax](/help-and-support/open-source), the FinOps platform contains several features that enhance your cloud usage experience by providing detailed insights and management capabilities without actively interfering with your environment.

Here are some of the key features:

* **Cost explorer** - Analyze your cloud spending with clarity. This feature includes tools that help you break down your cost structure, uncover trends, and identify opportunities to optimize spending across your organization.
* **Recommendations** - Use recommendations to discover hidden inefficiencies in your cloud infrastructure. Our recommendations highlight overlooked configuration issues and security risks to help you optimize performance, reduce costs, and strengthen your cloud posture.
* **Budgeting tools** - Set, track, and adjust cloud budgets with built-in forecasting tools. Stay ahead of unexpected costs and ensure every team stays aligned with financial goals throughout the cloud lifecycle.
* **Ownership and accountability** - Empower teams to take ownership of their cloud spending. With clear cost allocation, usage breakdowns, and automated alerts, you can easily promote responsible consumption.
* **Analytics and Insights** - Gain insights into your cloud usage and spending across different platforms. With up-to-date dashboards and analytics, you can quickly identify inefficiencies and take action before costs spiral out of control.

To learn more, see [our demo video on YouTube](https://youtu.be/O49trgK7Oeg?si=TJSyz_LHNkK0O5th).


# How FinOps for Cloud Works

FinOps for Cloud supports three major cloud service providers, including Amazon Web Services (AWS), Google Cloud Platform (GCP), and Microsoft Azure.

To use FinOps, you only need to provide **read-only** access to your connected cloud account. This allows FinOps to view and retrieve data without making any changes. It also that FinOps does not interfere with any processes in your environment.

When the read-only access has been granted, the following data is used:&#x20;

* Billing information, including all details related to your cloud expenses.
* For actively discoverable types, the current state of resources is collected. This is essential for implementing constraints like Time to Live (TTL), expense limits, and recommendations.
* Monitoring data from the cloud is used to identify underutilized instances.

The following sections explain how FinOps for Cloud obtains these details for each of the supported cloud platforms.

## Amazon Web Services

For AWS accounts:

* The billing information is retrieved from the Data Exports located in a designated S3 bucket in the cloud. For details, see [GetObject](https://docs.aws.amazon.com/AmazonS3/latest/API/API_GetObject.html) in the AWS S3 API Reference Guide.
* [Amazon CloudWatch](https://docs.aws.amazon.com/cloudwatch/) is the source of monitoring data.&#x20;
* Resource discovery is done using the Discovery API. For reference, see the following pages in the Amazon EC2 API Reference:
  * [DescribeInstances](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeInstances.html) - Describes the specified instances or all instances.
  * [DescribeVolumes](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVolumes.html) - Describes the specified EBS volumes or all of your EBS volumes.
  * [DescribeSnapshots](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeSnapshots.html) - Describes the specified EBS snapshots available to you or all of the EBS snapshots available to you.
  * [ListBuckets](https://docs.aws.amazon.com/AmazonS3/latest/API/API_ListBuckets.html) - Returns a list of all buckets owned by the authenticated sender of the request.

## Microsoft Azure

For Azure cloud accounts:

* The billing information is retrieved from the Billing API. For details, see [Usage Details - List](https://learn.microsoft.com/en-us/rest/api/consumption/usage-details/list?view=rest-consumption-2024-08-01\&tabs=HTTP) in the Microsoft documentation.
* Cloud's monitoring service is used as the source of all monitoring data.
* Resource discovery is done using the Discovery API. For reference, see the following pages in Microsoft documentation:
  * [Virtual Machines - List All](https://docs.microsoft.com/en-us/rest/api/compute/virtual-machines/list-all) - Lists all of the virtual machines in the specified subscription.
  * [Disks - List](https://docs.microsoft.com/en-us/rest/api/compute/disks/list) - Lists all the disks under a subscription.
  * [Snapshots - List](https://docs.microsoft.com/en-us/rest/api/compute/snapshots/list) - Lists snapshots under a subscription.
  * [Storage Accounts - List](https://docs.microsoft.com/en-us/rest/api/storagerp/storage-accounts/list) - Lists all the storage accounts available under the subscription.

## Google Cloud Platform

For Google Cloud accounts:

* The billing information is retrieved from the BigQuery Service.
* Cloud's monitoring service is used as the source of all monitoring data.
* Resource discovery is done using the Discovery API. For reference, see the following pages in Google Cloud documentation:
  * [Method: instances.list](https://cloud.google.com/compute/docs/reference/rest/v1/instances/list) - Retrieves the list of instances contained within the specified zone.
  * [Method: disks.list](https://cloud.google.com/compute/docs/reference/rest/v1/disks/list) - Retrieves a list of persistent disks contained within the specified zone.
  * [Method: snapshots.list](https://cloud.google.com/compute/docs/reference/rest/v1/snapshots/list) - Retrieves the list of Snapshot resources contained within the specified project.
  * [Buckets: list](https://cloud.google.com/storage/docs/json_api/v1/buckets/list) - Retrieves a list of buckets for a given project, ordered in the list lexicographically by name.
  * [Method: addresses.list](https://cloud.google.com/compute/docs/reference/rest/v1/addresses/list) - Retrieves a list of addresses contained within the specified region.


# Comparing FinOps for Cloud and Spend Management

FinOps for Cloud is SoftwareOne's cloud management tool offering comprehensive insights into your cloud infrastructure.&#x20;

If you have previously used SoftwareOne's Cloud Spend Management for managing your cloud expenses, this topic will help you understand the key differences between FinOps for Cloud and Cloud Spend Management.&#x20;

### Integration with cloud vendors

<table><thead><tr><th width="202">Feature</th><th width="242">FinOps for Cloud</th><th>Cloud Spend Management</th></tr></thead><tbody><tr><td>Name</td><td><a href="/pages/5rE6SLlLwQOM1zLDuDTe">Data Sources</a></td><td><a href="https://docs.platform.softwareone.com/extensions/cloud-tools/cloud-tenant-setup">Cloud Tenant Setup</a></td></tr><tr><td>Amazon Web Services</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture> Supported</td><td><picture><source srcset="/files/r8Gs89EGqlIYEKGD1plT" media="(prefers-color-scheme: dark)"><img src="/files/xLTgS5ob5aJJK71T0TIF" alt="" data-size="line"></picture> Supported (currently unavailable)</td></tr><tr><td>Google Cloud Platform</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture> Supported</td><td><picture><source srcset="/files/rHS02aG4ePMdkVvolma4" media="(prefers-color-scheme: dark)"><img src="/files/dneqkfT8HcwR67EMm5d3" alt="" data-size="line"></picture> Not supported</td></tr><tr><td>Microsoft 365</td><td><picture><source srcset="/files/rHS02aG4ePMdkVvolma4" media="(prefers-color-scheme: dark)"><img src="/files/dneqkfT8HcwR67EMm5d3" alt="" data-size="line"></picture> Not supported</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture> Supported</td></tr><tr><td>Microsoft Azure</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture> Supported</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture> Supported</td></tr></tbody></table>

### Cost allocation

<table><thead><tr><th width="204">Feature</th><th width="247">FinOps for Cloud</th><th>Cloud Spend Management</th></tr></thead><tbody><tr><td>Name</td><td><a href="/pages/jagQG83AtKPSfTzX4UsP">Pools</a></td><td><a href="https://docs.platform.softwareone.com/extensions/cloud-tools/custom-groups">Custom Groups</a></td></tr><tr><td>Resource allocation</td><td>Allocate resources by name, ID, tags, data source, resource type, and region.</td><td>Allocate resources by tags or virtual tags.</td></tr></tbody></table>

### Cost visualization

<table><thead><tr><th width="204">Feature</th><th width="259">FinOps for Cloud</th><th>Cloud Spend Management</th></tr></thead><tbody><tr><td>Name</td><td><a href="/pages/jagQG83AtKPSfTzX4UsP">Pools </a>+ <a href="/pages/7ap56WSLUwyzpXEakSoz">Resources</a></td><td><a href="https://docs.platform.softwareone.com/modules-and-features/other-tools/dashboards">Dashboard </a>+ <a href="https://docs.platform.softwareone.com/modules-and-features/other-tools/reports">Reports</a></td></tr><tr><td>Customizable dashboards</td><td><picture><source srcset="/files/rHS02aG4ePMdkVvolma4" media="(prefers-color-scheme: dark)"><img src="/files/dneqkfT8HcwR67EMm5d3" alt="" data-size="line"></picture> Not supported</td><td>Configuration of tiles to represent data.</td></tr><tr><td>Cost drill-down</td><td>Ability to filter data using  categories (such as service, region, resource type, data source, owner, pool, and more) and periods (daily, weekly, or monthly). See <a href="/pages/7ap56WSLUwyzpXEakSoz">Resources</a>.</td><td>Ability to filter data using categories (such as platform type, provider, tenant, subscription, custom group, provider, resource name, tag, and more) and periods (half-year, monthly). See <a href="https://docs.platform.softwareone.com/modules-and-features/other-tools/reports">Reports</a>.</td></tr><tr><td>Detailed reports</td><td><picture><source srcset="/files/rHS02aG4ePMdkVvolma4" media="(prefers-color-scheme: dark)"><img src="/files/dneqkfT8HcwR67EMm5d3" alt="" data-size="line"></picture> Not supported</td><td>Reports can be customized to focus on specific metrics or time periods. They can also be downloaded, emailed, or published to SFTP.</td></tr><tr><td>Consolidated consumption</td><td>Costs are displayed on a chart (bar or linear) with details placed in a table. See <a href="/pages/7ap56WSLUwyzpXEakSoz">Resources</a>.</td><td>Different chart types (such as bar, linear, area, horizontal bar, and pie) and tables (table, summary table) are used to display costs. See <a href="https://docs.platform.softwareone.com/modules-and-features/other-tools/reports">Reports</a>.</td></tr></tbody></table>

### Cost optimization

<table><thead><tr><th width="200">Feature</th><th width="268">FinOps for Cloud</th><th>Cloud Spend Management</th></tr></thead><tbody><tr><td>Name</td><td><a href="/pages/xhEE8TN88X1QLPbwXE73">Recommendations</a></td><td><a href="https://docs.platform.softwareone.com/extensions/cloud-tools/recommendations">Recommendations</a> + <a href="https://docs.platform.softwareone.com/extensions/cloud-tools/cloud-cost-optimization">Cloud Cost Optimization</a></td></tr><tr><td>High level overview</td><td>Main data overview contains information like total possible monthly savings, check time log, savings with commitments and savings on storage.</td><td>Overview of savings breakdown by Strategy, Total Predicted Cost, and Total Predicted Savings for 1 or 3 years.</td></tr><tr><td>Recommendations filtering</td><td>Based on categories (such as Savings, Security, or Critical) and applicable cloud provider services.</td><td>Based on categories (such as Cost Optimization, Operational Excellence, or Security) and applicable cloud provider services.</td></tr><tr><td>Recommendation options</td><td>Information with short description, assigned category, affected cloud providers, affected resources, potential savings (in total and per each resource), actions (download report, settings, exclude pools, pin) and settings (each recommendation has its own conditions that can be updated during every auto check).</td><td>Shows Cost Optimization Strategy with predicted savings in the chosen currency or as percentage. Also includes a description of the purpose of chosen change.</td></tr><tr><td>Legacy data</td><td>Access to Archived recommendations.</td><td>Access to Realised and Unrealised recommendations.</td></tr></tbody></table>

### Tagging

<table><thead><tr><th width="196">Feature</th><th width="272">FinOps for Cloud</th><th>Cloud Spend Management</th></tr></thead><tbody><tr><td>Name</td><td><a href="/pages/0ZsJlwzpNv2Mv6jHco64">Tagging Policies</a></td><td><a href="https://docs.platform.softwareone.com/extensions/cloud-tools/tags-and-resources">Tags</a></td></tr><tr><td>New tags setup</td><td><p>Tagging policy must specify if tag is required, prohibited, or if there's a correlation. </p><p></p><p>Resources affected by the policy are chosen based on filters, such as suggested filters, data source, pool, region, service, resource type, resource state, with recommendations, with violated constraints, paid network traffic from/to.</p></td><td><p>Allows you to manage and create tags. You can also specify the rule,  name, add a new tag, or group as a new tag. </p><p></p><p>You can also select an existing tag or create a new tag if it doesn't exist.  Additionally, you can filter resources based on criteria, such as resource type, region, service, and more. </p><p></p><p>Additional options include 'With recommendations', 'With violated constraints', and 'Paid network traffic from/to'. Resources are displayed in a table containing columns, such as Resource Name, Data Source, Pool, Region, Service Name, Resource Type, Resource State, and Software Asset.</p></td></tr><tr><td>Virtual tags</td><td><picture><source srcset="/files/rHS02aG4ePMdkVvolma4" media="(prefers-color-scheme: dark)"><img src="/files/dneqkfT8HcwR67EMm5d3" alt="" data-size="line"></picture> Not supported</td><td> <picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture> Supported</td></tr><tr><td>Uploading tags to cloud provider</td><td><picture><source srcset="/files/rHS02aG4ePMdkVvolma4" media="(prefers-color-scheme: dark)"><img src="/files/dneqkfT8HcwR67EMm5d3" alt="" data-size="line"></picture> Not supported</td><td>Manage tags in manual or automated Resource rules based on resource properties, option to write tags back to vendor.</td></tr></tbody></table>

### Budgeting and forecasting

<table><thead><tr><th width="189">Feature</th><th width="279">FinOps for Cloud</th><th>Cloud Spend Management</th></tr></thead><tbody><tr><td>Name</td><td><a href="/pages/EPbw3HZ2f6nfIvyu6kbr">Quotas and Budgets</a></td><td><a href="https://docs.platform.softwareone.com/extensions/cloud-tools/budgets">Budgets</a></td></tr><tr><td>Cloud budget manager</td><td>Tabular view when creating a new quota or budget policy is possible. Each policy allows you to review resources grouped by configured filters.</td><td>Configurable views to display Consumption and Utilization grouped by Custom Groups or Provider.</td></tr><tr><td>New budget setup</td><td><p>Budget policy must contain the type, such as resource quota, recurring budget, or expiring budget. </p><p></p><p>Resources affected by the policy are chosen based on filters, such as suggested filters, data source, pool, region, service, resource type, resource state, with recommendations, with violated constraints, tags, and paid network traffic from/to.</p></td><td><p>Allows you to set up a budget by specifying the parent group name, name, total amount in USD, start date, end date, and owner email address. </p><p>Resources affected by the budget are chosen based on filters such as suggested filters, data source, pool, region, service, resource type, resource state, with recommendations, with violated constraints, tags, paid network traffic from/to.</p></td></tr></tbody></table>

### Chargeback

<table><thead><tr><th width="179">Feature</th><th width="287">FinOps for Cloud</th><th>Cloud Spend Management</th></tr></thead><tbody><tr><td>Name</td><td>Chargebacks</td><td><a href="https://docs.platform.softwareone.com/extensions/cloud-tools/chargebacks">Chargebacks</a></td></tr><tr><td>Chargebacks</td><td><picture><source srcset="/files/rHS02aG4ePMdkVvolma4" media="(prefers-color-scheme: dark)"><img src="/files/dneqkfT8HcwR67EMm5d3" alt="" data-size="line"></picture> Not supported</td><td><p>Allows you to distribute cloud spend to the relevant business units and cost centers across your organization. </p><p></p><p>You can select the account for which you want to add chargebacks by specifying details such as date, amount, and reason, and add multiple chargebacks. The form includes a table listing of your existing chargebacks.</p></td></tr></tbody></table>

### Anomaly detection and spike alerting

<table><thead><tr><th width="171">Feature</th><th width="266">FinOps for Cloud</th><th>Cloud Spend Management</th></tr></thead><tbody><tr><td>Name</td><td><a href="/pages/GsBPJOOr3vZx7oTO2vYP">Anomaly Detection</a></td><td><a href="https://docs.platform.softwareone.com/modules-and-features/other-tools/reports/consumption-alerts">Alerts</a></td></tr><tr><td>New anomaly detection setup</td><td><p>The anomaly detection policy must specify the type, such as Resource Count or Expenses. </p><p></p><p>Resources affected by the policy are chosen based on filters such as suggested filters, data source, pool, region, service, resource type, resource state, with recommendations, with violated constraints, tags, paid network traffic from/to.</p></td><td><p>Three types of cloud consumption alerts are supported, including Spike Alerts, Overage Alerts, or Reserved Instance Utilization. </p><p></p><p>Spike alerting identifies usage anomalies in Azure or AWS environments. Overage alerting notifies you if consumption exceeds defined values. Reserved Instance alerting monitors the utilization of reservation purchases.</p></td></tr><tr><td>Manage anomaly detection</td><td>List of all implemented policies with their names, visualization of the status, short description and applied filters.</td><td>List of implemented alerts with their names, type, visibility, last run, along with the most important columns to quickly grasp the context of the definition.</td></tr><tr><td>Anomaly detection details</td><td>Detailed information about the policy together with detailed history showing all historical violations.</td><td>The preview section is a graphical representation of the alert, highlighting the time at which it occurs. You can interact with this chart, which includes 'hover-over text' when viewing a vertical bar in the chart.</td></tr></tbody></table>

### Governance and compliance

<table><thead><tr><th width="172">Feature</th><th width="271">FinOps for Cloud</th><th>Cloud Spend Management</th></tr></thead><tbody><tr><td>Name</td><td><a href="/pages/iwnjyIgaRGenuqOseBx6">Events</a></td><td> N/A</td></tr><tr><td>List of historical events</td><td><p>General list of events with simple filtering by All, Info, Warning, Error. </p><p></p><p>You can also check event details, such as exact date, object name, object type, and short description.</p></td><td><picture><source srcset="/files/rHS02aG4ePMdkVvolma4" media="(prefers-color-scheme: dark)"><img src="/files/dneqkfT8HcwR67EMm5d3" alt="" data-size="line"></picture> Not supported (Audit trail redirects to Marketplace)</td></tr></tbody></table>

### Collaboration

<table><thead><tr><th width="174">Feature</th><th width="274">FinOps for Cloud</th><th>Cloud Spend Management</th></tr></thead><tbody><tr><td>Name</td><td><a href="/pages/GtKoLony7cdefWqsdv63">User Management</a></td><td> N/A</td></tr><tr><td>Roles and permissions</td><td>Supports four types of permissions, including Organization Manager, Manager, Engineer, and Member.</td><td>User management (Moved to Marketplace in v2)</td></tr><tr><td>Name</td><td><a href="/pages/e90l13kJej3GWnLmHPmK#organization-selector">Organization</a></td><td><a href="https://docs.platform.softwareone.com/modules-and-features/other-tools/collaboration-site">Collaboration Site</a></td></tr><tr><td>Multi-organization approach</td><td>A user can be a part of different organizations and can switch between them using the Organization menu.</td><td>A user can be a part of different organizations with different role and can switch between them.</td></tr><tr><td>Document collaboration</td><td><picture><source srcset="/files/rHS02aG4ePMdkVvolma4" media="(prefers-color-scheme: dark)"><img src="/files/dneqkfT8HcwR67EMm5d3" alt="" data-size="line"></picture> Not supported</td><td>Store and share large files conveniently.</td></tr></tbody></table>

### Notifications

<table><thead><tr><th width="201">Feature</th><th width="279">FinOps for Cloud</th><th>Cloud Spend Management</th></tr></thead><tbody><tr><td>Name</td><td><a href="/pages/flDkNaRn9JQ2isSH99KY">Settings</a></td><td>Alerting</td></tr><tr><td>Reporting</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture> Supported </td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture> Supported </td></tr><tr><td>Alerts</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture> Supported </td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture> Supported </td></tr><tr><td>Notification settings</td><td><p>The Organization Manager can change notification settings. </p><p></p><p>Notifications can be enabled or disabled from these modules: FinOps, Policy Alerts, Recommendations, System notifications, and Account management.</p></td><td>Supports individual notifications with an option to share the notifications with other users.</td></tr><tr><td>Notification service</td><td>Email</td><td>Portal only, email and/or SMS</td></tr></tbody></table>


# Getting Started

FinOps for Cloud is a SaaS product that is built on top of Optscale [open source](/help-and-support/open-source).&#x20;

It enables you to optimize cloud spending by providing real-time insights, budget tracking, and cost management. You can also allocate resources, control expenses, and drive financial accountability across cloud environments.&#x20;

See the following links to get started:

{% content-ref url="/spaces/6rFi99rib6iBPaHxldNx/pages/nUyuUbsJB1vVqu8EHyad" %}
[Access Your Organization](/finops-for-cloud/getting-started/access-your-organization)
{% endcontent-ref %}

{% content-ref url="/spaces/6rFi99rib6iBPaHxldNx/pages/e90l13kJej3GWnLmHPmK" %}
[Navigate the User Interface](/finops-for-cloud/getting-started/overview)
{% endcontent-ref %}

{% content-ref url="/spaces/6rFi99rib6iBPaHxldNx/pages/5rE6SLlLwQOM1zLDuDTe" %}
[Add Data Sources](/finops-for-cloud/getting-started/data-sources)
{% endcontent-ref %}

{% content-ref url="/spaces/6rFi99rib6iBPaHxldNx/pages/p0WoDxTXP9QrrhKjVIFy" %}
[Invite Users to Your Organization](/finops-for-cloud/getting-started/invite-users-to-your-organization)
{% endcontent-ref %}

{% content-ref url="/spaces/6rFi99rib6iBPaHxldNx/pages/UinfEGPN5YuJQJxLrCno" %}
[Cost Explorer](/analysis/cost-explorer)
{% endcontent-ref %}

## Additional resources

Once your organization is set up within FinOps for Cloud and a data source is connected, you can perform several tasks to optimize your cloud spending and manage overall costs.&#x20;

Use the following reference to access the relevant documentation:

<table><thead><tr><th width="396">What do you want to do?</th><th>See this page for details</th></tr></thead><tbody><tr><td>Set quotas and budgets to manage your cloud spending effectively.</td><td><a href="/pages/EPbw3HZ2f6nfIvyu6kbr">Quotas and Budgets</a></td></tr><tr><td>Allocate resources by name, ID, tags, data source, resource type, and region.</td><td><a href="/pages/jagQG83AtKPSfTzX4UsP">Pools</a></td></tr><tr><td>Create tagging polices to categorize your resources.</td><td><a href="/pages/0ZsJlwzpNv2Mv6jHco64">Tagging Policies</a></td></tr><tr><td>Identify anomalies in your spending.</td><td><a href="/pages/GsBPJOOr3vZx7oTO2vYP">Anomaly Detection</a></td></tr><tr><td>View savings and security recommendations.</td><td><a href="/pages/xhEE8TN88X1QLPbwXE73">Recommendations</a></td></tr></tbody></table>


# Access Your Organization

To use [FinOps for Cloud](https://portal.finops.softwareone.com/), you need an account. This account is different from your Marketplace Platform account.&#x20;

When you order a [FinOps for Cloud subscription from the SoftwareOne Marketplace](https://docs.platform.softwareone.com/extensions/finops-for-cloud/order-finops-for-cloud-from-marketplace), we will process your order and create an organization for you. This organization represents your account.

FinOps for Cloud provides different experiences for first-time access, depending on whether you are an organization administrator or user.

### FinOps for Cloud Administrators

Once we process your order, the organization administrator will receive a password recovery email containing a verification code. This email will be sent to the address specified during the ordering process.

To set up a new password and sign in, the organization administrator must follow these steps:

1. Open the password recovery email from SoftwareOne FinOps for Cloud.
2. Select **Recover password**.&#x20;

<figure><img src="/files/vuPVgdkwNbRrQbfjXQxF" alt="" width="563"><figcaption><p>The password recovery email.</p></figcaption></figure>

3. Enter the verification code from the email and select **Confirm**.

<figure><img src="/files/ju7fYPrPBvgFIzTqBBni" alt="" width="484"><figcaption><p>The email verification code.</p></figcaption></figure>

4. Enter your new password and confirm it matches the one you just entered. Then, select **Reset password**.
5. Select **Proceed to FinOps for Cloud** to sign in to your organization.

After signing in, you must connect your data source to FinOps. For more information, see [Add Data Sources](/finops-for-cloud/getting-started/data-sources).

### FinOps for Cloud Users

If you've been added to an organization, you'll receive an invitation email from SoftwareOne FinOps for Cloud.

To join your organization:

1. Select the invite link in your email. The registration page opens.

<figure><img src="/files/EXF0Z9i2HrEyUgnooJ2z" alt="" width="473"><figcaption><p>The registration page for FinOps for Cloud.</p></figcaption></figure>

2. Enter your full name and password.&#x20;
3. Confirm that your new password matches the one you entered in the **Password** field, then select **Register**. You'll receive a verification code by email.
4. Enter the verification code to verify your email and select **Confirm**. You'll be directed to FinOps for Cloud.&#x20;
5. Select **Accept** to join your organization and start using FinOps for Cloud.

<figure><img src="/files/K5VJjwOOp9dJY5c017NC" alt=""><figcaption><p>Accept your pending invitation.</p></figcaption></figure>


# Invite Users to Your Organization

When setting up your FinOps organization, it's important to consider the different roles you need for your account members.&#x20;

The roles available within FinOps for Cloud include Organization Manager, Manager, Engineer, and Member. For a description of these roles, see [User Management](/system/user-management). Once you have determined the appropriate roles for each individual you want to add to your account, open **User management** to start adding new users.&#x20;

## Inviting users to your organization

{% hint style="info" %}
In FinOps for Cloud, you cannot send an invitation to yourself. If you attempt to invite yourself, the platform displays a message.
{% endhint %}

To invite new members to your organization:

1. Navigate to the **User management** page.
2. Select **Invite**.
3. On the **Invite users** page, complete the following steps:
   1. **Email** - Enter the email addresses of the members you want to invite. You can enter multiple addresses.&#x20;
   2. **Add role** - Select **Add role** to choose a role. You must also select a pool for each member. All pools and sub-pools existing within your environment are displayed. Note that a member with **Manager** and **Engineer** roles can belong to several different pools.
4. Select **Invite**.

A confirmation message is displayed stating that the user has been invited, and an invitation email is sent to the individual.&#x20;


# Navigate the User Interface

After signing in to FinOps for Cloud, the first thing you’ll see is the **Home** page.

<figure><img src="/files/YCrsvqks5fcbCb3R1uSb" alt=""><figcaption><p>The Home page in SoftwareOne FinOps for Cloud.</p></figcaption></figure>

## Home page

The **Home** page is a dashboard that displays your organization’s current spending and projected expenses for the upcoming month.&#x20;

The following sections are available on the dashboard. Note that selecting the forward arrow<img src="/files/vIwsaImuRLfcXK4JGpP1" alt="<svg xmlns=&#x22;http://www.w3.org/2000/svg&#x22; height=&#x22;24px&#x22; viewBox=&#x22;0 -960 960 960&#x22; width=&#x22;24px&#x22; fill=&#x22;#472AFF&#x22;><path d=&#x22;m321-80-71-71 329-329-329-329 71-71 400 400L321-80Z&#x22;/></svg>" data-size="line">opens up the details page for that section:

* **Organization expenses** - Displays the total expenses of the previous month, the expenses of the current month, and this month's forecast. The red line on the chart shows the expense limit.
* **Top resource expenses for the last 30 days** - Displays the resources with the highest expenses. Select the resource to open its details page.
* **Recommendations** - Displays the possible monthly savings. The expenses are separated into categories, such as **Cost**, **Security**, and **Critical**. Select the category to navigate to the Recommendations page.
* **Policy violations** - Displays all policy violations along with the policy name and type. Select the policy name to open its details page. Pay special attention to the **Status** field. If it's red, it means the policy has been violated.
* **Pools requiring attention** - Displays the **Exceeded limit** or **Forecast overspend** pools. Use the buttons in the **Actions** column to see the resources list and cost explorer.

## Sidebar

The sidebar on the left is the main navigation menu containing these options:

* [Recommendations](/insights/recommendations) - Displays all recommendations so you can get the most out of your connected data sources.&#x20;
* [Resources ](/insights/resources)- Allows you to view and allocate your expenses for the cloud resources, monitor their performance, and set constraints. See Resources to learn about organizing and categorizing resources based on your specific requirements.
* [Pools ](/insights/pools)- Displays pools with limits or projected expenses. You can categorize resources into a hierarchy of pools manually or using assignment rules.&#x20;
* [Cost explorer](/analysis/cost-explorer) - Allows you to visualize your expenses.
* [Cost map](/analysis/cost-map) - Displays a breakdown of expenses and network traffic using an interactive map. You can view expenses by geographic location and service to identify areas of high spending.&#x20;
* [Anomaly detection](/policies/anomaly-detection) - Enables you to identify and respond to unusual patterns or deviations, control costs, and manage resources efficiently.&#x20;
* [Quotas and budgets](/policies/quotas-and-budgets) - Allows you to create quotas and budgets.
* [Tagging policies](/policies/tagging) - Allows you to add new tagging policies and manage the existing ones.
* [User management](/system/user-management) - Allows you to invite new members to your organization and manage existing members.
* [Data sources](/system/data-sources) - Enables you to add your billing data sources to FinOps for Cloud.
* [Events ](/system/events)- Lets you see all events that have occurred within your organization. The events include informational messages, warnings, and error messages.
* [Settings ](/system/settings)- Allows you to view organization details, view pending invitations, and manage email notifications.&#x20;

## Organization selector <a href="#organization-selector" id="organization-selector"></a>

The **Organization** selector is available in the header.&#x20;

It displays your current organization and enables you to switch between organizations if you belong to several organizations in FinOps.

You can also select **Organization overview** for an overview of all organizations and key information for each organization. Organizations that require attention and optimization are marked in red.

## Documentation and profile buttons

The header also includes these additional options:

<img src="/files/NBcc77wBvm9QLUOud9wK" alt="" data-size="line"> - Select to access the product documentation.

<img src="/files/oHmFA6EwVchqmLqwuW3B" alt="" data-size="line"> - Select to sign out of your account.


# Add Data Sources

To start monitoring your cloud resources, you must connect your billing source to FinOps for Cloud. The supported data sources include Amazon Web Services, Google Cloud Platform, and Microsoft Azure.&#x20;

The onboarding process in FinOps requires you to meet certain prerequisites based on the data source you want to add. These prerequisites can differ depending on the source.

Additionally, you might need to complete certain tasks on the cloud provider's side and some in FinOps for Cloud. For instance, if you are connecting an AWS source, you must create Cost and Usage Reports, configure policies in the AWS console, and then add your AWS account to FinOps.&#x20;

## Adding a data source

{% hint style="info" %}
Before adding a data source, make sure to go through the following links to understand the prerequisites and onboarding steps for supported data sources:&#x20;

* [Amazon Web Services](/system/data-sources/amazon-web-services)
* [Microsoft Azure](/system/data-sources/microsoft-azure)
* [Google Cloud Platform](/system/data-sources/google-cloud-platform)

Then, follow the steps in this section to add your data source to FinOps for Cloud.
{% endhint %}

To add a new data source:

1. From the left sidebar, select **Data sources**.
2. On the **Data sources** page, select **Add**.

<figure><img src="/files/qUUOpuD49OpffiJUavNY" alt=""><figcaption><p>The Data Sources page  in FinOps for Cloud.</p></figcaption></figure>

3. On the **Connect data source** page, do the following:
   1. Select the data source you want to add, for example, **AWS**, **Azure**, or **GCP**.&#x20;
   2. Select the connection type:
      1. **AWS** - Choose if you want to connect a root account or a linked account.
      2. **Azure** - Choose if you want to connect a tenant or a subscription.&#x20;
      3. **GCP** - Choose if you want to connect a tenant or a project. &#x20;
4. Enter the account credentials. The fields and options vary depending on the source you are connecting.
5. Select **Connect**.

When the data source is connected, the details and cloud expenses of the connected cloud account are displayed on the page.&#x20;

To view the resource details, select the resource name. You can then see all the properties and manage the data source, including renaming, updating credentials, and disconnecting.


# Cost Explorer

The **Cost explorer** feature contains tools and options to help you analyze costs and understand the cost structure for your organization.&#x20;

Using this feature, you can view your total expenses for the selected period and compare them with the total expenses from the previous period. You can also view a chart of your expense data to understand your overall spending and identify any trends or changes in your spending patterns.

<figure><img src="/files/1cswOf6yIkTfR6I5yAxl" alt=""><figcaption><p>The Cost Explorer in FinOps for Cloud.</p></figcaption></figure>

The Cost Explorer contains the following options to display a breakdown of your expenses:

* **Time interval** - Use this to change the time interval on the graph. You can change the time interval to **Daily**, **Weekly**, or **Monthly**. This allows for a more detailed or broader view of cost trends over different periods.
* **Date range** - Use this to adjust the date range. The date range selector offers flexibility in analyzing costs over different time frames.
* **See expenses breakdown by** - Allows you to explore and analyze the expense breakdown by **Source**, **Pool**, or **Owner**. When you select any of these options, a detailed pie chart and data summary are displayed.

You can also download your Cost Explorer views as a PDF file using the **Download** option on the page.


# Cost Map

Cost map is an easy-to-use visualization tool that provides an overview of your organization’s cloud expenses. It enables you to view a breakdown of expenses by location/region and service to identify areas of high spending and understand usage patterns.&#x20;

Cost map supports all Microsoft Azure, AWS cloud, and GCP regions. You can use the cost map to visualize regional cloud spend and network traffic at a glance.&#x20;

* The **Region** cost map allows you to view your total expenses for both the current and previous periods. You can also visualize your spending geographically across cloud providers and regions.&#x20;
* The **Network traffic** cost map allows you to visualize data transfer and connectivity costs. You can view accumulated expenses for paid network traffic between regions or services.&#x20;

Both cost maps contain a date range filter, allowing you to select a custom date range or choose from predefined time range options to view the expenses you are interested in.

### Region cost map

The **Region** cost map contains various visual elements to help you differentiate cloud providers and expenses.&#x20;

<div data-with-frame="true"><figure><img src="/files/SlLsSOcyHjGaw1xNzftr" alt=""><figcaption><p>The Region cost map in FinOps for Cloud.</p></figcaption></figure></div>

* The map uses color coding to differentiate between cloud providers. Refer to the legend above the map to interpret colors.&#x20;
* Each circle on the map represents the total cost for a specific region. If no spending is detected during the selected period, the circle shows a value of zero.
* The size of the circle indicates the level of expense; for example, larger circles indicate higher costs.&#x20;
* Round circles represent the combined costs across multiple cloud providers. For example, the circle over Ireland in the above image represents the total spending for both Azure and AWS (for example, `$260.2`).&#x20;
* Pointed circles represent only one provider (for example, the pointed circle over Poland in the above image shows Azure-only spend of `$79.44`).
* Hovering over a circle displays detailed information, including the geographical location and expenses. You can also drill down to the list of resources by selecting **Show resources**. &#x20;

The **Summary by region** table on the page lists expenses for each region along with the percentage of total expenses. You can sort the data by selecting the corresponding column header, and view the resources associated with a specific region by selecting the show resources icon in the **Actions** column.

### Network traffic cost map

The **Network traffic** cost map is a visual representation of the expenses associated with data transfer between regions. You can use this map to identify geographic locations where transfer costs are high and take steps to minimize those costs.&#x20;

<div data-with-frame="true"><figure><img src="/files/Lq0NFdIGIxizvBgkeHER" alt=""><figcaption><p>The Network traffic cost map in FinOps for Cloud.</p></figcaption></figure></div>

The cost map contains tabs, each representing a different cloud provider. You can switch between these tabs to view the corresponding network traffic details.&#x20;

The network traffic is displayed on the map and in the **Network traffic expenses** table. When you select a link on the map, the table is filtered to display only the relevant data. Similarly, if you select the text in the **From / To** column, the map updates to show the network traffic expenses originating from that specific source only.


# View Cost Map

The cost map enables you to visualize your cloud expenses by region/location and service, so you can detect areas with high spending across cloud providers.&#x20;

A cost map can also be used to view data transfer and connectivity costs.

### Viewing the cost map

To view the cost map:&#x20;

1. From the left sidebar, navigate to the **Cost map** page.
2. (Optional) Adjust the date range filter to view the data for a specific time period.&#x20;
3. Use the [Region cost map](/analysis/cost-map#region-cost-map) as follows to visualize your spending geographically across cloud deployments:
   * Hover over a circle to see detailed expense information. Use the **Show resources** link to open the **Resources** page, which displays all corresponding resources.
   * Toggle between the full-screen and regular window mode.
   * Use the **Summary by region** table to view details, such as expenses for your specified time period, the percentage of total expenses, and related cloud resources.&#x20;
4. Select the [Network traffic cost map](/analysis/cost-map#network-traffic-cost-map) to analyze costs associated with data transfer and connectivity.


# Recommendations

The **Recommendations** page is designed to make you aware of the less apparent deficiencies of the infrastructure, like configuration flaws and security risks.&#x20;

To receive recommendations, it's essential to [add a data source](/finops-for-cloud/getting-started/data-sources) to FinOps for Cloud. When a data source is added, FinOps for Cloud analyzes it to provide recommendations to help you optimize costs and improve resource security, performance, and availability.&#x20;

Currently, FinOps for Cloud performs a check every 3 hours.

<figure><img src="/files/vJ81uauyT2l0iOv5xZZE" alt=""><figcaption><p>Recommendations in FinOps for Cloud.</p></figcaption></figure>

The **Recommendations** page displays a summary of each recommendation [across different categories](https://docs.finops.softwareone.com/insights/recommendations/recommendation-categories) and suggests actions to help you make informed decisions. The summary varies, depending on the condition. For instance, it might show AWS S3 duplicates found during the last check, checks that did not start or finish successfully, and so on.

Recommendations also contain one of the following symbols:

* A red symbol <img src="/files/hqqODcrHukZLmhHu3rji" alt="" data-size="line"> indicates a critical situation, indicating that you must focus on the card and its information.
* A green symbol <img src="/files/eaIfrGlUB1rLRXrLZzA9" alt="" data-size="line"> indicates that there are no recommendations or your potential savings are zero.
* An orange symbol <img src="/files/v9gGUKorRspkWBOZLzzh" alt="" data-size="line"> appears when certain items require attention, for instance, if there are inactive IAM users in your organization.

## Additional actions

On the **Recommendations** page, you can do the following:

* See your **possible monthly savings** that can be achieved if the recommended suggestions are implemented.
* See the **last check time**. This is the time when FinOps for Cloud last checked for an update.
* See the **next check time**. This is the time when the next recommendation check is due.
* Filter recommendations based on data source, category (**Savings**, **Security**, **Critical**, and **Non-empty**), and applicable services.&#x20;
* Customize the parameters for a recommendation, exclude pools, and pin or unpin recommendations. For more information, see [Customize Recommendations](/insights/recommendations/customize-recommendations).
* Use the **Force check** option to run the data sources' evaluation sequence and initialize a force check. Only [Organization Managers](/system/user-management) can initialize a force check.


# Recommendation categories

The following are the available recommendation categories in FinOps for Cloud and their descriptions:

* **Savings** - These recommendations help you save money and reduce costs.&#x20;
* **Security** - These recommendations help to improve the security of your connected data source.&#x20;
* **Critical** - These recommendations must be prioritized and addressed immediately to prevent potential disruptions or vulnerabilities.
* **Non-empty** - These recommendations help ensure that all active resources are being utilized efficiently and are not incurring unnecessary costs.

See the following links for a list of savings and security recommendations:

{% content-ref url="/spaces/6rFi99rib6iBPaHxldNx/pages/ZaPaAj07zp2V3K3EY9MT" %}
[Savings Optimization Recommendations](/insights/recommendations/recommendation-categories/savings-optimization-recommendations)
{% endcontent-ref %}

{% content-ref url="/spaces/6rFi99rib6iBPaHxldNx/pages/D1Ppun5YV6a8FidB01oE" %}
[Security Recommendations](/insights/recommendations/recommendation-categories/security-recommendations)
{% endcontent-ref %}


# Savings Optimization Recommendations

{% hint style="info" %}
All parameters in **bold** are custom parameters. You can change the parameters by selecting<img src="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAGAAAABgCAYAAADimHc4AAAAAXNSR0IArs4c6QAAAw9JREFUeF7tnMuNE0EQhqs6Bx4ZIMGBAOAA0zbIhABEAAJiYREbwUIIrMDugQMEwAEkMuCRwxQarediCTHdas3fZf0+rrq6Zr6va3ddU7YKX1ACCs3O5EIB4ENAARQAJgBOzwqgADABcHpWAAWACYDTswIoAEwAnJ4VQAFgAuD0rAAKABMAp2cFUEAega7rNiKyCSFcM7ObY7Sqfh2G4YeInPd9f563I3a1qwqIMZ6JyKP/IHuTUnqMxTo/uxsBMUabf1siKSUX9+biImOMz0XkZY4AEXmRUjrJjFl8efMC1uv1rWEYPpeQCSHc3m63X0pil4ppXkCM8bWIPCkEcppSeloYu0iYBwEfReROIY1PKaW7hbGLhDUvoOu636p6qYSGmf3p+/5ySexSMc0LiDH+FJErhUB+pZSuFsYuEta8gNVq9d7M7pXQUNUPu93ufknsUjHNC+i67kRVn5UAMbNXfd+P/8I2+/IgYKOq70oImtmD1lsTzQsYwc9sQRw6ctGScCFgL4GtiJJfAzVjZrYkXLQgJi5uKmC64H1r4qGIXDezG+PPVfWbiHwPIbxtvfVweCDdCahZUS3sRQFgCxRAAWAC4PSsAAoAEwCnZwVQAJgAOL27CuBcEPDEzGzKuWjCuWtFcC4Ie/I5F4Tiz7kgFPl9Xs4F4QVwLgjpgHNBSPoXz4M5F4R0wLkgJH0R4VwQXgDngsAOOBeEFjDmZyuiAQucC2pAAueCGpBwTJfg7oHMMcEf74UCwEYpgALABMDpWQEUACYATs8KoIA8ApwLyuNVdTXngqrizNuMzbg8XlVXz2zCHeZ08WG95v8Icy6o6lnO34xzQfnMqkbEGDkXVJVo5macC8oEVns554JqE83cj3NBmcBqL+dcUG2imfuNrQd+X1AmtNrLZ7YgDtO6+KhS82/EJqpsRdQ+1gX7zWxJuGhBTLfvpgKmC+ZcUMHJZci/CbirgGOTSQFgoxRAAWAC4PSsAAoAEwCnZwVQAJgAOD0rgALABMDpWQEUACYATs8KoAAwAXB6VgBYwF/mZEdwBsiwPwAAAABJRU5ErkJggg==" alt="<svg xmlns=&#x22;http://www.w3.org/2000/svg&#x22; height=&#x22;24px&#x22; viewBox=&#x22;0 -960 960 960&#x22; width=&#x22;24px&#x22; fill=&#x22;#434343&#x22;><path d=&#x22;M480-160q-33 0-56.5-23.5T400-240q0-33 23.5-56.5T480-320q33 0 56.5 23.5T560-240q0 33-23.5 56.5T480-160Zm0-240q-33 0-56.5-23.5T400-480q0-33 23.5-56.5T480-560q33 0 56.5 23.5T560-480q0 33-23.5 56.5T480-400Zm0-240q-33 0-56.5-23.5T400-720q0-33 23.5-56.5T480-800q33 0 56.5 23.5T560-720q0 33-23.5 56.5T480-640Z&#x22;/></svg>" data-size="line">on the card and selecting **Settings**.
{% endhint %}

### Abandoned instances <a href="#abandoned-instances" id="abandoned-instances"></a>

Instances that have an average CPU consumption of less than **5%** and network traffic below **1000 bytes/s** for the last **7 days**. We recommend terminating these instances to reduce expenses.

### Obsolete images <a href="#obsolete-images" id="obsolete-images"></a>

Images that haven't been used for a while might be subject to deletion, which would unlock the underlying snapshots. Image selection criteria:

* The image creation date was more than 1 week ago.
* No instances have been created from/related to this image in the past **7 days**.

You can download the list of obsolete images as JSON for subsequent automated processing with the help of [Cleanup Scripts](/insights/recommendations/clean-up-scripts-based-on-recommendations).

### Obsolete snapshots <a href="#obsolete-snapshots" id="obsolete-snapshots"></a>

Redundant and old snapshots save up on storage expenses if deleted. You can download the list of snapshots as JSON for use in further implementations like clean-up scripts and maintenance procedures. Selection criteria:

* The source EBS volume doesn't exist anymore.
* No AMIs are created from this EBS snapshot.
* It hasn't been used for volume creation for the last **4 days**.

The list of obsolete snapshots can be downloaded as JSON for subsequent automated processing with the help of [Cleanup Scripts](/insights/recommendations/clean-up-scripts-based-on-recommendations).

### Obsolete IPs <a href="#obsolete-ips" id="obsolete-ips"></a>

Obsolete IPs can be tracked for Azure and AWS clouds to reduce expenses. The following is the selection criteria for the obsolete IPs:

* The IP was created more than **7 days** ago.
* The IP hasn't been used in the last **7 days**.
* It costs money to be kept.

### Not attached volumes <a href="#not-attached-volumes" id="not-attached-volumes"></a>

Notification about volumes that haven't been attached for more than one day. These are considered to be forgotten or no longer relevant. We recommend that you delete such resources.

You can download the list of unattached volumes as JSON for subsequent automated processing with the help of [Cleanup Scripts](/insights/recommendations/clean-up-scripts-based-on-recommendations).

### Underutilized instances <a href="#underutilized-instances" id="underutilized-instances"></a>

This recommendation is aimed at the detection of underutilized instances in AWS and Azure and suggests more suitable flavors for these machines. An instance is considered to be underutilized if:

* It is active.
* It has existed for more than **3 days**.
* Its CPU metric average for the past **3 days** is less than 80%.

### Reserved instances opportunities <a href="#reserved-instances-opportunities" id="reserved-instances-opportunities"></a>

This card contains instances that are active and have sustainable compute consumers for more than **90 days**. Instances that haven't been covered with Reserved Instances or Saving Plans are also included.

For all such instances, consider purchasing Reserved Instances to save on compute usage. Check **RI/SP Coverage** to see the detailed breakdown of current reservations.

### Abandoned kinesis streams <a href="#abandoned-kinesis-streams" id="abandoned-kinesis-streams"></a>

This card shows Kinesis Streams with provisioned Shard capacity that haven't performed operations in the last **7 days**. Consider removing them to reduce expenses.

### Instances with migration opportunities <a href="#instances-with-migration-opportunities" id="instances-with-migration-opportunities"></a>

This card shows opportunities to migrate instances if the tool detects that the same instance type is cheaper in a geographically close region (within the same continent).

Some of your active instances might cost less in another nearby region with the same specifications. Consider migrating them to the recommended region to reduce expenses.

### Instances for shutdown <a href="#instances-for-shutdown" id="instances-for-shutdown"></a>

This recommendation means that some of your instances have an inactivity pattern that allows you to set up an on/off power schedule (average CPU consumption is less than **5%** and network traffic below **1000 bytes/s** for the last **14 days**). Consider creating a power schedule to reduce expenses.

### Instances with spot (pre-emptible) opportunities <a href="#instances-with-spot-preemptible-opportunities" id="instances-with-spot-preemptible-opportunities"></a>

This list contains instances that:

* Are running for the last **3 days**.
* Have existed for less than **6 hours**.
* Were not created as Spot (or Preemptible) Instances. Consider using Spot (Preemptible) Instances.

### Underutilized RDS instances <a href="#underutilized-rds-instances" id="underutilized-rds-instances"></a>

An underutilized instance is one average CPU consumption of less than **80%** for the last **3 days**. FinOps for Cloud detects such active RDS instances and lists them on the card. Consider switching to the recommended size from the same family to reduce expenses.

### Obsolete snapshot chains <a href="#obsolete-snapshot-chains" id="obsolete-snapshot-chains"></a>

Some snapshot chains don't have source volumes or images created from their snapshots and have not been used for volume creation for the last **3 days**. Consider their deletion to save on snapshot storage expenses.

### Instances with subscription opportunities <a href="#instances-with-subscription-opportunities" id="instances-with-subscription-opportunities"></a>

The instances in the list are active and have been identified as sustained compute consumers (for more than **90 days**) but are not covered by subscription or Savings Plans. Consider purchasing subscriptions to reduce computing costs.

### Not deallocated instances <a href="#not-deallocated-instances" id="not-deallocated-instances"></a>

Detection of inactive, non-deallocated machines that have not been running for more than **1 day** and are still billed by the cloud.

You can download the list of non-deallocated VMs as JSON for subsequent automated processing with the help of [Cleanup Scripts](/insights/recommendations/clean-up-scripts-based-on-recommendations).

### Instances eligible for generation upgrade <a href="#instances-eligible-for-generation-upgrade" id="instances-eligible-for-generation-upgrade"></a>

Upgrade older generation instances to the latest generation within the same family.

### Abandoned Amazon S3 buckets <a href="#abandoned-amazon-s3-buckets" id="abandoned-amazon-s3-buckets"></a>

A bucket is abandoned if the average data size is less than **1024 megabytes**, the Tier1 request quantity is less than **100**, and the `GET` request quantity is less than **2000** for the last **7 days**.

We recommend that you delete it to reduce expenses. Change the check period and other parameters in the card's **Settings**.


# Security Recommendations

### Inactive IAM users <a href="#inactive-iam-users" id="inactive-iam-users"></a>

Users who have been inactive for more than **90 days** are considered obsolete and subject to deletion. This is due to the security risks they pose for the organization, as they can be compromised and become access points for malicious users.

The number of days is a custom parameter. Use **Settings** to change it. You can also download a list of inactive users as JSON or XLSX by selecting the download icon <img src="/files/3pbgrANBARAHZObDgxLk" alt="" data-size="line">.

<figure><img src="/files/3FWkgRZY1wZabEZjfgOE" alt=""><figcaption><p>Inactive IAM users</p></figcaption></figure>

### Instances with insecure Security Groups settings <a href="#instances-with-insecure-security-groups-settings" id="instances-with-insecure-security-groups-settings"></a>

Security check that browses through the resources to find network vulnerabilities and provides a list of instances liable to RDP/SSH hacking. The following are the insecure ports and permissions:

* port tcp/22
* port tcp/3389
* all inbound traffic

with one of:

* CidrIp: 0.0.0.0/0
* CidrIpv6: ::/0

**AWS**

* Describe regions: *ec2.describe\_regions()*
* Describe instances: *ec2.describe\_instances()*
* Describe security groups: *ec2.describe\_security\_groups()*

**Azure**

* Describe instances: *compute.virtual\_machines.list\_all()*
* Describe security groups: *network.network\_security\_groups.list\_all()*

{% hint style="info" %}
Network interfaces without associated security groups are skipped.
{% endhint %}

You can download the list of insecure Security Groups as JSON for subsequent automated processing.

### IAM users with unused console access <a href="#iam-users-with-unused-console-access" id="iam-users-with-unused-console-access"></a>

The active IAM users that have console access turned on, but have not used it for more than **90 days** are in the list. Consider revoking console access to increase security.

Note that the number of days is a custom parameter. Use **Settings** to change it.

### Public S3 buckets <a href="#public-s3-buckets" id="public-s3-buckets"></a>

The S3 buckets in the list are public. Ensure that the buckets use the correct policies and are not publicly accessible unless explicitly required.


# View Recommendations

## Viewing recommendations <a href="#ariaid-title7" id="ariaid-title7"></a>

To view recommendations:

1. Navigate to the **Recommendations** page from the sidebar.
2. (Optional) Choose the billing data source for which you want to view recommendations. You can select multiple sources at once. For information on the supported sources and how to add them, see [Add Data Sources](/finops-for-cloud/getting-started/data-sources).
3. (Optional) Choose a category. The default setting is **All**, meaning all recommendations are displayed, but you can filter by **Savings**, **Security**, **Critical**, and **Non-empty** to display the recommendations you want to see.
4. (Optional) Select the applicable service from the list. You can select multiple services at once.
5. (Optional) Choose if you want to view your recommendations in the form of cards or tables.
6. Review the suggested optimizations and their projected savings.
7. Select a recommendation to open a summary page.&#x20;

## Viewing archived recommendations

Recommendations are archived when they are no longer active, either because they have been applied, the associated resource has been removed, or they have become irrelevant due to changes in resource properties.

To view your archived recommendations:

1. On the **Recommendations** page, select **Archive**.

<figure><img src="/files/ULJMyMCwGRGjsgsZHgIF" alt=""><figcaption><p>The Archive option on the Recommendations page.</p></figcaption></figure>

2. On the **Archived recommendations** page:
   1. (Optional) Use the date selector to use a custom date range, or select any of these options:&#x20;
      * **This month** - Displays archived recommendations from the current month.
      * **Last month** - Displays archived recommendations from the last month.
      * **Last 7 days** - Displays archived recommendations from seven days ago until now.
      * **Last 30 days** - Displays archived recommendations from 30 days ago until now.
   2. Select the recommendation to view details, such as the data and time when the recommendation was detected, the resource to which the recommendation applies, and more.


# Customize Recommendations

The more option<img src="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAGAAAABgCAYAAADimHc4AAAAAXNSR0IArs4c6QAAAw9JREFUeF7tnMuNE0EQhqs6Bx4ZIMGBAOAA0zbIhABEAAJiYREbwUIIrMDugQMEwAEkMuCRwxQarediCTHdas3fZf0+rrq6Zr6va3ddU7YKX1ACCs3O5EIB4ENAARQAJgBOzwqgADABcHpWAAWACYDTswIoAEwAnJ4VQAFgAuD0rAAKABMAp2cFUEAega7rNiKyCSFcM7ObY7Sqfh2G4YeInPd9f563I3a1qwqIMZ6JyKP/IHuTUnqMxTo/uxsBMUabf1siKSUX9+biImOMz0XkZY4AEXmRUjrJjFl8efMC1uv1rWEYPpeQCSHc3m63X0pil4ppXkCM8bWIPCkEcppSeloYu0iYBwEfReROIY1PKaW7hbGLhDUvoOu636p6qYSGmf3p+/5ySexSMc0LiDH+FJErhUB+pZSuFsYuEta8gNVq9d7M7pXQUNUPu93ufknsUjHNC+i67kRVn5UAMbNXfd+P/8I2+/IgYKOq70oImtmD1lsTzQsYwc9sQRw6ctGScCFgL4GtiJJfAzVjZrYkXLQgJi5uKmC64H1r4qGIXDezG+PPVfWbiHwPIbxtvfVweCDdCahZUS3sRQFgCxRAAWAC4PSsAAoAEwCnZwVQAJgAOL27CuBcEPDEzGzKuWjCuWtFcC4Ie/I5F4Tiz7kgFPl9Xs4F4QVwLgjpgHNBSPoXz4M5F4R0wLkgJH0R4VwQXgDngsAOOBeEFjDmZyuiAQucC2pAAueCGpBwTJfg7oHMMcEf74UCwEYpgALABMDpWQEUACYATs8KoIA8ApwLyuNVdTXngqrizNuMzbg8XlVXz2zCHeZ08WG95v8Icy6o6lnO34xzQfnMqkbEGDkXVJVo5macC8oEVns554JqE83cj3NBmcBqL+dcUG2imfuNrQd+X1AmtNrLZ7YgDtO6+KhS82/EJqpsRdQ+1gX7zWxJuGhBTLfvpgKmC+ZcUMHJZci/CbirgGOTSQFgoxRAAWAC4PSsAAoAEwCnZwVQAJgAOD0rgALABMDpWQEUACYATs8KoAAwAXB6VgBYwF/mZEdwBsiwPwAAAABJRU5ErkJggg==" alt="<svg xmlns=&#x22;http://www.w3.org/2000/svg&#x22; height=&#x22;24px&#x22; viewBox=&#x22;0 -960 960 960&#x22; width=&#x22;24px&#x22; fill=&#x22;#434343&#x22;><path d=&#x22;M480-160q-33 0-56.5-23.5T400-240q0-33 23.5-56.5T480-320q33 0 56.5 23.5T560-240q0 33-23.5 56.5T480-160Zm0-240q-33 0-56.5-23.5T400-480q0-33 23.5-56.5T480-560q33 0 56.5 23.5T560-480q0 33-23.5 56.5T480-400Zm0-240q-33 0-56.5-23.5T400-720q0-33 23.5-56.5T480-800q33 0 56.5 23.5T560-720q0 33-23.5 56.5T480-640Z&#x22;/></svg>" data-size="line">in a recommendation card contains features that you can use to adjust parameters and exclude pools.

These features allow you to fine-tune and optimize results to better meet specific goals or conditions. The available parameters and pools you can exclude from a recommendation vary based on the recommendation you are accessing.

## Customizing a recommendation

To customize a recommendation:

1. Navigate to the **Recommendations** page.
2. Find the required recommendation, then select the more icon<img src="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAGAAAABgCAYAAADimHc4AAAAAXNSR0IArs4c6QAAAw9JREFUeF7tnMuNE0EQhqs6Bx4ZIMGBAOAA0zbIhABEAAJiYREbwUIIrMDugQMEwAEkMuCRwxQarediCTHdas3fZf0+rrq6Zr6va3ddU7YKX1ACCs3O5EIB4ENAARQAJgBOzwqgADABcHpWAAWACYDTswIoAEwAnJ4VQAFgAuD0rAAKABMAp2cFUEAega7rNiKyCSFcM7ObY7Sqfh2G4YeInPd9f563I3a1qwqIMZ6JyKP/IHuTUnqMxTo/uxsBMUabf1siKSUX9+biImOMz0XkZY4AEXmRUjrJjFl8efMC1uv1rWEYPpeQCSHc3m63X0pil4ppXkCM8bWIPCkEcppSeloYu0iYBwEfReROIY1PKaW7hbGLhDUvoOu636p6qYSGmf3p+/5ySexSMc0LiDH+FJErhUB+pZSuFsYuEta8gNVq9d7M7pXQUNUPu93ufknsUjHNC+i67kRVn5UAMbNXfd+P/8I2+/IgYKOq70oImtmD1lsTzQsYwc9sQRw6ctGScCFgL4GtiJJfAzVjZrYkXLQgJi5uKmC64H1r4qGIXDezG+PPVfWbiHwPIbxtvfVweCDdCahZUS3sRQFgCxRAAWAC4PSsAAoAEwCnZwVQAJgAOL27CuBcEPDEzGzKuWjCuWtFcC4Ie/I5F4Tiz7kgFPl9Xs4F4QVwLgjpgHNBSPoXz4M5F4R0wLkgJH0R4VwQXgDngsAOOBeEFjDmZyuiAQucC2pAAueCGpBwTJfg7oHMMcEf74UCwEYpgALABMDpWQEUACYATs8KoIA8ApwLyuNVdTXngqrizNuMzbg8XlVXz2zCHeZ08WG95v8Icy6o6lnO34xzQfnMqkbEGDkXVJVo5macC8oEVns554JqE83cj3NBmcBqL+dcUG2imfuNrQd+X1AmtNrLZ7YgDtO6+KhS82/EJqpsRdQ+1gX7zWxJuGhBTLfvpgKmC+ZcUMHJZci/CbirgGOTSQFgoxRAAWAC4PSsAAoAEwCnZwVQAJgAOD0rgALABMDpWQEUACYATs8KoAAwAXB6VgBYwF/mZEdwBsiwPwAAAABJRU5ErkJggg==" alt="<svg xmlns=&#x22;http://www.w3.org/2000/svg&#x22; height=&#x22;24px&#x22; viewBox=&#x22;0 -960 960 960&#x22; width=&#x22;24px&#x22; fill=&#x22;#434343&#x22;><path d=&#x22;M480-160q-33 0-56.5-23.5T400-240q0-33 23.5-56.5T480-320q33 0 56.5 23.5T560-240q0 33-23.5 56.5T480-160Zm0-240q-33 0-56.5-23.5T400-480q0-33 23.5-56.5T480-560q33 0 56.5 23.5T560-480q0 33-23.5 56.5T480-400Zm0-240q-33 0-56.5-23.5T400-720q0-33 23.5-56.5T480-800q33 0 56.5 23.5T560-720q0 33-23.5 56.5T480-640Z&#x22;/></svg>" data-size="line">.
3. To update the recommendation parameters, select **Settings** and make the required changes. When saved, new settings are applied during the next recommendations check.
4. To exclude a pool from a specific recommendation, select **Exclude pools**. When excluded, the excluded objects are displayed on the **Excluded** tab within the **Recommendations** page.
5. To pin or unpin a recommendation, select **Pin** or **unpin**, depending on the available option. Pinned recommendations always appear as the first one in your list of recommendations until they are unpinned.&#x20;

{% hint style="info" %}
The option to pin a recommendation is only available in the card view.
{% endhint %}


# Clean-up Scripts Based on Recommendations

{% hint style="danger" %}
The script deletes all recommended resources (based on the downloadable JSON file) and ignores errors. After completion, a summary lists deleted resources, non-existent or already deleted resources, and resources that couldn't be deleted due to other reasons.
{% endhint %}

## Amazon Web Services (AWS) <a href="#aws-source" id="aws-source"></a>

### Prerequisites

* [AWS Command Line Interface (AWS CLI)](https://docs.aws.amazon.com/cli/latest/userguide/getting-started-install.html)
* jq - The package allows executing JSON scripts with bash. See [Download jq](https://stedolan.github.io/jq/download/).

### Implementation

1. Install the requirements on a machine running Linux OS.
2. Configure the AWS Command Line Interface. (Run the **aws configure** command. For information, see the [AWS User Guide](https://docs.aws.amazon.com/cli/latest/userguide/cli-configure-quickstart.html)).
3. Download the script from the corresponding subsection on the **Recommendations** page.
4. From the same page, download the JSON file containing a list of all resources recommended for deletion.
5. Run the script as follows: `bash <script_name> <path to json file>.`

## Microsoft Azure <a href="#azure-source" id="azure-source"></a>

### Prerequisites

* [Azure CLI](https://learn.microsoft.com/en-us/cli/azure/install-azure-cli-linux?pivots=apt)
* jq - The package allows executing JSON scripts with bash. See [Download jq](https://stedolan.github.io/jq/download/).

### Implementation

#### Azure Azure CLI

1. Install the requirements on a machine running Linux OS.
2. Sign in with the Azure CLI.
3. Download the script from the corresponding subsection of the Recommendations page.
4. From the same page, download the JSON file containing a list of all resources that are recommended for deletion.
5. Run the script as follows: `bash <script_name> <path to json file>`.

#### Azure Shell

1. Open [Azure Cloud Shell](https://portal.azure.com/#cloudshell/).
2. Download the script and the JSON file from the corresponding subsection of the Recommendations page.
3. Copy these files using the **Upload/Download files** button. The files will be placed in `/usr/csuser/clouddrive`.
4. Run the script as follows: `bash <script_name> <path to json file>` using absolute paths or navigate to the necessary folder before executing.

## Google Cloud Platform

### Prerequisites&#x20;

* [Google Cloud CL](https://cloud.google.com/sdk/gcloud)
* jq - The package allows executing JSON scripts with bash. See [Download jq](https://stedolan.github.io/jq/download/).

### Implementation

1. Install on a machine running Linux OS.
2. Configure gcloud: run gcloud init. See [Initializing the gcloud CLI](https://cloud.google.com/sdk/docs/initializing) for more information.
3. Run script bash `<script_name> <path to recommendation json file>`.


# Resources

The **Resources** page provides a detailed overview of all available cloud resources, detailing their usage and associated costs. You can use this page to efficiently monitor and manage your cloud resources.

The page displays data in graphical format and in a table. The graphic visualization includes various types of charts, such as bar charts and line graphs, helping you understand trends, patterns, and anomalies in your cloud resource usage and expenses. The tabular data includes specific data points and metrics, including columns for different parameters, such as resource type, cost, usage, tags, owner, and more.

<figure><img src="/files/GrKQVhPgNzpMKm9nrLRq" alt=""><figcaption><p>The Resources page in FinOps for Cloud.</p></figcaption></figure>

### Using resource filters

By default, the **Resources** page displays details about all cloud resources, including total expenses and the resource count. You can narrow down the data using customization features such as date range and filters.

* The **Date range** filter allows you to select a custom date range for your data. This provides flexibility in analyzing cloud resource usage and expenses over different periods.
* The **Filters** section contains various options to include or exclude specific data. This includes filtering by resource type, owner, expense type, tags, and more. Each filter has its own suboptions you can select and apply. Additionally, you can combine multiple filters to further refine your analysis.

When you apply the filter options, the corresponding data updates automatically based on your selections. You can view the data as a chart or within the resources table.&#x20;

To download the chart as a PNG image file, select **Export data**.

### Additional actions <a href="#additional-actions" id="additional-actions"></a>

On the **Resources** page, you can do the following:

* Save, apply, and manage your existing perspectives. A perspective is a customized view containing filters and settings you have specified. For more details, see [Manage Perspectives](/insights/resources/manage-perspectives).
* Download a list of resources in the Excel or JSON format. For more details, see [Download Resources](/insights/resources/download-resources).
* View the full details of a resource and apply constraints to a specific resource using the resource details page. For more details, see [View Resource Details](/insights/resources/view-resource-details) and [Apply Constraints](/insights/resources/resources-constraint-policies).


# Manage Perspectives

The **Perspective** feature on the **Resources** page allows you to create new perspectives.

A perspective is a customized view that you can create using only the filters you need. For example, you can save a view that shows only certain data sources, regions, or resource types. This ensures you can quickly return to your preferred view without reconfiguring the filters each time.&#x20;

You can create multiple perspectives and save them for future use. When saving perspectives, make sure to use different names, as you cannot have two perspectives with the same name. If you use the same name for a new perspective, the platform overwrites the existing one.

You can also share the perspective URL with others in your organization, and delete a perspective if it's no longer needed.

### Saving a perspective

To save a custom perspective:

1. From the sidebar, navigate to the **Resources** page.
2. Select **Save perspective**.
3. Under **Save as**, enter a name for your custom perspective, then select **Save**. The configuration is saved as a perspective.

### Applying a saved perspective

Saved perspectives are displayed when you select **Perspective** on the **Resources** page. The option is enabled only if you have previously saved at least one perspective.

To apply a saved perspective:

1. On the **Resources** page, select **Perspectives**.
2. Choose the perspective you want to view and select **Apply**.

When the perspective is applied, the **Resources** page updates its title to include the name of the perspective. Additionally, a link to copy the URL appears beside the name, allowing you to share the perspective with others.

### Deleting a perspective

You can delete perspectives that are no longer needed.

To delete a perspective:

1. On the **Resources** page, select **Perspectives**.
2. Select the **See all Perspectives** link.&#x20;
3. From the available perspectives, find the one you want to delete. Then, under **Actions**, select the delete icon.

<figure><img src="/files/yjeIAABHlmsXB9sDxKam" alt=""><figcaption><p>The Actions column containing an option to delete a perspective.</p></figcaption></figure>

4. In the **Delete perspective** panel, select **Delete** again to confirm the action.


# Download Resources

You can download a complete list of discovered cloud resources for analysis, reports, or integration with external tools.

The downloaded file includes metadata such as resource type, cost, usage, tags, ownership, and more.

### Downloading resources

To download a list of resources:

1. From the sidebar, navigate to the **Resources** page.
2. (Optional) Select the data range and apply filters as needed.
3. Select **Download**. The **Download** option appears above the table that lists all cloud resources. You might need to scroll down to see it.
4. Choose either **XLSX spreadsheet** or **JSON file** to start the download.

If the data is too large, the FinOps platform shows a message. To continue, modify the filters to reduce the amount of data, and then try downloading again.


# View Resource Details

Use the resource details page to view detailed information about each resource.&#x20;

You can check resource properties, review associated expenses, and see any pool constraints applied through resource policies. From the same page, you can also add an assignment rule if needed.

### Viewing resource details

To view resource details and add an assignment rule:

1. From the sidebar, navigate to the **Resources** page.
2. (Optional) [Use resource filters](/insights/resources#using-resource-filters) to display specific resources, or use **search** to find the required resource.
3. In the **Resource** column, select the link for the resource to view.
4. On the resource details page, use the **Details**, **Constraints**, and **Expenses** tabs to view the data.
5. To create a new assignment rule, select **Add Assignment Rule**. For more details, see [Configure Assignment Rules](/insights/pools/add-assignment-rules).


# Apply Constraints

To address the ever-dynamic cloud infrastructure where resources are being created and deleted continuously, FinOps for Cloud contains a set of tools to help limit the related expenses and the lifetime of individual assets.

This is implemented in the form of constraints that you can set for a specific resource or generally for a pool. You can set two types of constraints:

* **TTL** - Represents time to live. A resource must not live for more than the specified period.
  * For a resource, specify a date and time.
  * For a pool, input an integer between 1 and 720 hours.
* **Daily expenses limit** - The resource spending must not exceed the specified amount in dollars. Input as an integer, min $ 1, 0 - unlimited.

When FinOps discovers active resources in the connected source, it checks that they don't violate any existing pool constraints that were applied as policies before.

When a resource hits a constraint, both the Manager and Owner of the resource are alerted through email. If a resource is unassigned, alerts are sent to the organization managers. An exclamation mark also appears next to the pool name on the **Pools** page.

{% hint style="info" %}
FinOps for Cloud sends notifications about violated constraints and doesn't interact with the connected source itself to perform any constraint-related adjustments.
{% endhint %}

### Applying constraints to a resource <a href="#resources-constraints" id="resources-constraints"></a>

To apply constraints to a resource:

1. On the **Resources** page, select the required resource.
2. On the resource details page, select the **Constraints** tab.

<figure><img src="/files/gO56bSTztvKG8kTFhx88" alt=""><figcaption><p>The Constraints tab on the resource details page.</p></figcaption></figure>

3. Use the slider to enable the required setting. Then, select edit to enter the value. When done, select <img src="/files/rCLMDoTPyjmNC43pHWEt" alt="pencil" data-size="line"> to save your changes.

<figure><img src="/files/RKEtrOcOARKJ4Qjrs9RX" alt=""><figcaption><p>Available constraint type</p></figcaption></figure>

{% hint style="info" %}
If a resource doesn't have a specific constraint set, it inherits the policies from its Pool. However, the resource owner or manager can override an existing Pool constraint policy for an individual resource by issuing a custom constraint for any given asset.
{% endhint %}


# Pools

The **Pools** page in FinOps for Cloud allows you to view and manage your organization’s resource pools, including their limits, expenses, and forecasts. You can also monitor resource usage, identify potential overspending, and optimize costs by visualizing current expenses and forecast.

All pools and sub-pools are organized in a hierarchical structure to help you navigate and manage them easily. The **Expenses** and **Forecast** columns provide insights into your current expenses and projected costs for each pool and sub-pool.&#x20;

You can also see the pool owner and perform actions, like adding new subpools, viewing the resource list, opening the pool in the cost explorer, and deleting the pool and its subpools.

## About Assignment Rules

Newly created resources are automatically distributed into pools based on assignment rules. If the resources have certain tags, they are immediately assigned to the appropriate pool upon first discovery. Resources that don't belong to any pool are assigned to the data source pool, which is created automatically when the data source is connected.

Assignment rules are evaluated according to priority. You can manually reapply these rules across the entire organization or within a specific pool. Additionally, you can manage assignment rules by editing them or adjusting their priority.&#x20;

To learn more, see the following links:

{% content-ref url="/spaces/6rFi99rib6iBPaHxldNx/pages/uXVfDg3at8iDIxE0YHll" %}
[Configure Assignment Rules](/insights/pools/add-assignment-rules)
{% endcontent-ref %}

{% content-ref url="/spaces/6rFi99rib6iBPaHxldNx/pages/7JYIcMlMPON1k7Ff39Rc" %}
[View and Manage Assignment Rules](/insights/pools/view-and-manage-assignment-rules)
{% endcontent-ref %}

{% content-ref url="/spaces/6rFi99rib6iBPaHxldNx/pages/dXj0jyfEh4EhpQ0hKQgg" %}
[Reapply Ruleset](/insights/pools/re-apply-ruleset)
{% endcontent-ref %}

{% content-ref url="/spaces/6rFi99rib6iBPaHxldNx/pages/Ypza9SBrquicACLsU2zY" %}
[Create Pool Constraint Policies](/insights/pools/pool-constraint-policies)
{% endcontent-ref %}

{% content-ref url="/spaces/6rFi99rib6iBPaHxldNx/pages/nvqeaDWqL0qTKxjZhipf" %}
[View Pool Assignment Rules](/insights/pools/view-pool-assignment-rules)
{% endcontent-ref %}

{% content-ref url="/spaces/6rFi99rib6iBPaHxldNx/pages/U2JDBttmBNkNGJQCXM3u" %}
[Delete Pools](/insights/pools/delete-a-pool)
{% endcontent-ref %}


# Configure Assignment Rules

There are two ways to configure assignment rules in FinOps for Cloud. You can add them from the **Pools** or **Resources** pages.

When a new rule is added, it's always prioritized across the organization. It means that any discovered resources are first checked against the conditions of this new rule. If the resource doesn't meet the new rule's conditions, it's checked against the remaining rules in descending order until a matching rule is found.

## Configuring a new assignment rule

To configure a new assignment rule:

1. Navigate to the **Add automatic Resource Assignment Rule** page using one of the following steps:
   * Open the **Pools** page and select **Configure assignment rules**. Next, on the **Assignment rules** page, select **Add**.
   * Open the **Resources** page and select a resource. On the resource's details page, select **Add assignment rule**.
2. Under **Name**, enter a name for the rule.
3. Under **Conditions**, select all conditions that must be fulfilled for the rule to become applicable. The following conditions are available:

<table><thead><tr><th width="204">Type</th><th width="185">Key/Value</th><th>Description</th></tr></thead><tbody><tr><td>Name/ID starts with</td><td>string value</td><td>Matches resources where the name or ID begins with the specified value.</td></tr><tr><td>Name/ID ends with</td><td>string value</td><td>Matches resources where the name or ID ends with the specified value.</td></tr><tr><td>Name/ID is</td><td>string value</td><td>Matches resources with an exact name or ID match.</td></tr><tr><td>Name/ID contains</td><td>string value</td><td>Matches resources where the name or ID contains the specified substring.</td></tr><tr><td>Tag is</td><td>key-value pair</td><td>Matches resources with a tag that matches both the specified key and value.</td></tr><tr><td>Tag exists</td><td>key-value pair</td><td>Matches resources that have a tag with the specified key.</td></tr><tr><td>Tag value starts with</td><td>key-value pair</td><td>Matches resources with a tag value starting with the specified value for the given key.</td></tr><tr><td>Source is</td><td>selected row</td><td>Matches resources from a selected data source. Options are presented in a dropdown for selecting the source.</td></tr><tr><td>Resource type is</td><td>string value</td><td>Matches resources where the resource type contains the specified value.</td></tr><tr><td>Region is</td><td>string value</td><td>Matches resources where the region contains the specified value.</td></tr></tbody></table>

4. Add additional conditions as required.
5. Under **Assign to**, review the **Target pool** and **Owner**. By default, the matching resource is included in the selected target pool and assigned to an owner. You can change the values as relevant.
6. Select **Create** to finalize the rule.


# View and Manage Assignment Rules

The **Assignment rules** page in FinOps for Cloud allows you to add a new automatic resource assignment rule.&#x20;

From this page, you can also reapply the entire ruleset to all resources within a selected pool, even if the ruleset was previously assigned manually.

You can manage existing rules and search for specific rules using filters such as **Name**, **Assigned To**, **Conditions**, and **Priority**.

## Viewing assignment rules

1. Navigate to the **Pools** page.&#x20;
2. Select **Configure assignment rules**. The list of rules is displayed.&#x20;

<figure><img src="/files/dFnhc6X2gVuOLuWxYf2b" alt=""><figcaption><p>The Assignment rules page displaying all rules.</p></figcaption></figure>

For each rule, you can view the following details:

* **Name** - The name of the rule. Active rules are marked with green dots next to their names, and inactive ones are marked with grey dots.
* **Assign to** - The pool and the owner to whom the resource is assigned.
* **Conditions** - Shows a summary of the conditions that trigger the rule.
* **Priority** - Displays the priority used to apply assignment rules to resources.

## Managing assignment rules

The **Actions** column on the **Assignment Rules** page contains options you can use to manage your existing rules.

* To modify a rule, select the edit icon <img src="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAGAAAABgCAYAAADimHc4AAAD/klEQVR4AeycvY7TQBDHbUQNPdLFqUGioqFLR4EoobkH4CWQckg8AhW68qq7DtHR8QYUUFCQD5GnSBFm7uzLlx3P2LPetfd/8njt9dhj/35xnFziPEjw55UABHjFnyQQAAGeCXgujzMAAjwT8FweZwAEeCbguTzOAAjwTMBz+TjPAM/Qd8tDwC4ND9MQkEOfTCYPR6PRNMuyK4qfFBsKbq+o/yJPM28ggJAS6Nez2exHmqYM+py6nlPwwO059U/H4/FXEvGUOy0jegEElaF/I6gvKSqHzWbzhkR8p/y3lUkNFkQtgGBeENSpgtsTyr+m9cwkRCuAIGrh33uylBClgDbwCwtWEqITYAHfUkJUAizhW0mIRoAL+DsSLs/Ozl4U85q2QwGa3bLNdQk/39NHdE34lE+rmsEL6AD+LXAS8Ipr3c4oRoMWwEAIjOZ1vgLdcSrVUr9THqyAruHnOiCAQXiCz6Wf8UgTgzsDPMJn7r94pIlBCfAMn7n/5pEmBiMgAPgJXYT/auBz7iAEhACfYP5Zr9efqVUNvRcQCPyEPi/4sFqt/qnoU3KvBSjh39DxclBjOxD8j8vlsnTbdZV6K0ALf7FYvOMgII1A0XqlQw6fP1UrXV7X2UsBTeAXIFgCXSy/FPNt2rbwuXbvBLSBzwfMMZ/P3zM8nm4avD497TR+5Bd1eyXAAn5x4AyPIRbzmpbX4/U161Tl9kaAJfwCRg7xspiXtJbwuV4vBLiAzwefx+O8rW2s4XPB4AW4hJ9l2TVBEH3FxAV8qh32TXpDhx+0gBjgBysgFvhBCjCBz0dWEiE85x/uVlAX4djgs4xgBMQIPxgBscIPQkDM8L0LiB2+VwGAz/gTP++EAf8OPo87fxUE+Ix9G50KAPwt+GKqMwGAXyDfbw0F7G94dw7wd2nsTzsXAPj7wA/nnAoA/EPcx/POBAD+MeyyHicCAL8MdXmfuQDALwdd1WsqAPCrMFf3mwkA/GrIp5aYCAD8U4hPL2stAPBPA65b2koA4CdJHeC65Y0FAH4dWtnyRgIAXwZXkqUWAPgSrPIctYA0TaW/vXDDd6NIdyXEL01J971NnlqAsBjgC0G5EAD4QvicZi4ATzuMVR7mAqSlY33OP+TjRQDgbzV0LgDwt/B5qlMBZvB5zwcSnQkA/PJHjLkAAs2/u38UVN7r3YhUP8jBXECbo3R1K2ibfXK9bjACYoTPcoMQECv8IATEDN+7gNjhexUA+Izf0x0ygH8Hn8fqizD9tzNtG/nv9HD96EMhIHpWTgBAgBOs8o1CgJyVk0wIcIJVvlEIkLNykgkBTrDKNwoBclZOMiHACVb5RiFAzspJJgQ4wSrfKATUsHK9+D8AAAD//0AN7NMAAAAGSURBVAMAB9Dp3z/s4QcAAAAASUVORK5CYII=" alt="<svg xmlns=&#x22;http://www.w3.org/2000/svg&#x22; height=&#x22;24px&#x22; viewBox=&#x22;0 -960 960 960&#x22; width=&#x22;24px&#x22; fill=&#x22;#1f1f1f&#x22;><path d=&#x22;M200-200h57l391-391-57-57-391 391v57Zm-80 80v-170l528-527q12-11 26.5-17t30.5-6q16 0 31 6t26 18l55 56q12 11 17.5 26t5.5 30q0 16-5.5 30.5T817-647L290-120H120Zm640-584-56-56 56 56Zm-141 85-28-29 57 57-29-28Z&#x22;/></svg>" data-size="line">. You can edit the name of the rule, conditions, and assignment details. You can also enable or disable the rule.
* To set the rule priority to the highest, select <img src="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAGAAAABgCAYAAADimHc4AAAE/ElEQVR4AeyajWrVQBCFb32QvpYIIoKIICKCFEGkP5QilFKQUgpSClIKxadq+yLXc9pd2MSbZCfZzGzoSLbZn9mZne/cXFM6L1b+z5SAC2CKf7VyAVwAYwLG4f0JcAGMCRiH9yfABTAmYBzenwAXwJiAcfjn+QQYQ0/DuwApDYO+C2AAPQ3pAqQ0DPougAH0NKQLkNIw6LsABtDTkC5ASsOg7wIYQE9DugApDYP+ogXY3t7eZzPgViykogDFzvzoiOC3trb22Nh/nFzgj0UKQOAEH3mzz7k4XtJ9cQIQNIG3IXOOa+352seLEoCACboLKtdo07Ve4/xiBCBYAh6CSBvaDtnVsr4IAQiUYHOh0ZZ7cu0t7aoXgCAJVAqJe7hXuk/bvmoBCJAgx0LhXvoYu19jX7UCEBwBToVAH/Q11c9c+6sUgMAIrlTS9EWfpfyV9FOdAARFYDlJwu4vW6btHn3n2Ja0GfJVlQAEBKB7Q4cO67d3d3cv2TC+RRu86JsxBg0VDaoRgGAIKDP3m/v7+1fRNvRv4rjvzhiM1WejuVaFAARCMJmJXwP467ZtmLtuz28aMxZjblrTnjMXgCAIJCfx9Xr9B6DfdNlyjTZd6+k8YzJ2OmfRNxWAAAgiM/Grh4eHt0O2weZqyI7rjM0zsG/VzARg4gSQmfglPt3vMm1XwfYyx55n4FlybOewMRGACTPxnIRg9xtA3+fYpjbcw73pXFcfdmavqOoCSOAD2AVeMz/gPuoKey9yNluJoCqAEP45PsUfc+D12QQf5302cc1CBDUBhPDPAO5TBDP1Hnyd5fjRFkFFAAl8vEb+ArDPObA6bTYs0Cd9b1j6b0pThNkFkMAHiVO8Rn7BfZYr+D7Nca4lwuwC5CQbbE7wKf0a+lk3isuWZRyMQoyTMDS/zS4APnX7ePQP+jLFp+0YYHb6bNprBI99o+qCGAt7j9s+0zHPzLOnc3P0ZxeAh2YiTIj9dsP8T7wufmvP940j/GgDmOL3eMZk7OgjvWP+gGdO5+bqqwjAwzMhJsZ+0o4w/z0ZD3bb8OOGMSKE2EfRB+88I+b32ddoagIwGSbGBNlHO8RXwQ/cs68u+NHBGBHCGQ7pg2fjGdnXaqoCMCkmyESR+C7HuW0IfvQzUoRdnolni3607uoCMDFpornw6ZttjAjSMzFOiWYigOTgUvjR9xgR4l7Ne9UCjIUfAS5BhIICxLTL3KfCj6eoXYQqBSgFfwkiVCeABD4+3V4XFD9lJe4S+IjndUGAUOwSwve6oGLk4UgI3+uCwKzYJYGP31a9LqgYeTiSwIe51wUBQrFLCN/rgoqRhyMJfLxqel0QmBW7JPARtPq6IJxx0qX6i5gQvtcFTZK2tVkI3+uCWvwmDSXw8arpdUGTaLc2S+Bjq9cFAYLVJa4LGnNQ/CmUtUdeF5TCw6umuC4o3S/tQ4Qdxuzbh69CldIUlbcg/r2VCW1KGPPiuqBNfqRzXhf0RExcF/S0rcxPfDBYk+R1QWVwjvOCryPWJnld0Dh8ZXZBBK8LEqGcwRhfR2rliOnxVf4TTgN6v0nABWjyUB+5AOrImwFdgCYP9ZELoI68GdAFaPJQH7kA6sibAV2AJg/1kQugjrwZ0AVo8lAfCQRQP9uzCOgCGMvsArgAxgSMw/sT4AIYEzAO70+AC2BMwDi8PwEugDEB4/D+BAwIMPfyPwAAAP//5W9Y9wAAAAZJREFUAwCLZTzfp7nlJQAAAABJRU5ErkJggg==" alt="<svg xmlns=&#x22;http://www.w3.org/2000/svg&#x22; height=&#x22;24px&#x22; viewBox=&#x22;0 -960 960 960&#x22; width=&#x22;24px&#x22; fill=&#x22;#1f1f1f&#x22;><path d=&#x22;m296-224-56-56 240-240 240 240-56 56-184-183-184 183Zm0-240-56-56 240-240 240 240-56 56-184-183-184 183Z&#x22;/></svg>" data-size="line">. The priority of the other rules is then decreased by one.
* To decrease rule priority by 1, select <img src="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAGAAAABgCAYAAADimHc4AAAC3ElEQVR4Aeyb0W0bMRBEpRSiAuJ+UmT6cQpQIwoHOAKMEeV82iPfbjyGDkdboGf2PVMfsv3t4g+UgAWg+C8XC7AAmAAc7xNgATABON4nwAJgAnC8T4AFwATg+K95AmDoY7wFjDSAtQUA0MdICxhpAGsLAKCPkRYw0gDWFgBAHyMtYKQBrC0AgD5GWsBIA1hbAAB9jFwoYIz1uhOwgE4CulsABL7HWkAnAd0tAALfYy2gk4DuFgCB77EW0ElAdwuAwPdYC+gkoDsi4Ha7fYfmfRo7q9PTwO2J5QI06PV6/an71gG/qQvVaamAPmgj/kYN3LL/eNCdlgkYB90I4BIydFoi4C+Dbg4umIQsnaYL+MegmIRMnaYK+MSgyyVk6zRVwP1+//V4PH40yu/t2ntMfzk6AF9d39VdM+iTWddUASqtATRIW6MSMsJvTNb8lyQtISv8ZQIUREnIDF9cpr8EKaRfyyRsgdnhq+ZSAQpcJaECfPFYLkChsyVUgS8WiAAFz5JQCb44YAIUfraEavDFABWgAmdJqAhf8+MCVCIqoSp8zZ5CgIq8KqEyfM2dRoDKvCJBv9hpe9/atfdY8t7OXomPz6cSoHJHJbQ9ZeG37mveC1LQkeughL1vnfInv5c+8QT0b3nO/SQJqeGLVFoBKheUkB6+ZkwtQAVflFACvuZLL0AlD0ooA1+zlRCgop+UUAq+5iojQGV3JJSDr5lKCVDhJxJKwtc85QSo9AcJZeFrlpICVLxL0F9caK2vVbzKChBsgdelddWrtIAM0KMdLCBKMLjfAoIAo9stIEowuN8CggCj2y0gSjC43wKCAKPbLSBKMLjfAoIAo9stIEowuN8CggCj22sKiE6daL8FwDIswAJgAnC8T4AFwATgeJ8AC4AJwPE+ARYAE4DjfQLqCICb/qfxPgGwWAuwAJgAHO8TYAEwATjeJ8ACYAJwvE+ABcAE4HifgB0Bs5/+DQAA//8EDZsBAAAABklEQVQDABIWttBglfBSAAAAAElFTkSuQmCC" alt="<svg xmlns=&#x22;http://www.w3.org/2000/svg&#x22; height=&#x22;24px&#x22; viewBox=&#x22;0 -960 960 960&#x22; width=&#x22;24px&#x22; fill=&#x22;#1f1f1f&#x22;><path d=&#x22;M480-344 240-584l56-56 184 184 184-184 56 56-240 240Z&#x22;/></svg>" data-size="line">. The rule is then swapped with the rule behind it.
* To increase the rule priority by 1, select<img src="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAGAAAABgCAYAAADimHc4AAAEF0lEQVR4AeyWgWYdQRSGkz5IXqtKVakqVVWqSlWTiCgVoSJCRagI0adK8iLp+dhlrHt3Z+/cnX+3/eOOmZ05Z/45378T+2THf1ICNkCKf2fHBtgAMQGxvG+ADRATEMv7BtgAMQGxvG+ADRATEMv/nzdADD2VtwEpDcHYBgigp5I2IKUhGNsAAfRU0gakNARjGyCAnkragJSGYGwDBNBTSRuQ0hCMbYAAeipZ0YBU1uOWgA1oSYh6GyAC38ragJaEqLcBIvCtrA1oSYh6GyAC38ragJaEqLcBIvCtrA1oSYh6GzAx+KHtF23A3t7eAW2oyDmvL9YAwO/u7u7TGM8Zct/ZFmkAwAHfFsaYufZ5Sf3iDAA0wLuQmWOtOz/350UZAGBAr4PKGjHr1uc4vxgDAAvgIYjEEDsUN5f1RRgAUMDmQiOWnNx4ZdzsDQAkQMdCIofcsXm142dtAAABuSkUctlj0/waebM1AHAALIXAHuxVus9U+bM0AGCA27joTiJ7sWdnehaPszMAUADLoRNxf2iZsfvsnRNbM2ZWBgAogO5nAri9u7t7Sov422iDP/ZGYzCwYsBsDAAMgDJrv7m/v3/Wxjbjm/a5r0cDrb6YmmuzMAAggMks/DqAP+/GNnPX3flVz2ihuWqt9pzcAEAAJKfwx8fH3wH6xbpY1ohZt57Oo4l2OqcYSw0AACAyC796eHh4ORTbxFwNxbGONmdgrGoyAygcAJmFX8bb/SozdqeJvcyJ5wycJSd2ihiJARRM4TkFRdyvAPo6JzaNIYfcdG7dOOJkn6jVDRgDP4BdxGfmm+g3+jW5FznJKhOqGjAS/nm8xW9z4PXFNHuc98W0awoTtmhAW8bqfiT8swD3bvVO42ebvc5yMmubUMWAMfDjM/JnAHufA2tMDHuyd05OTRMmN2AM/IBzGp+RH6Kf5NfsfZqzeS0TJjcgp9gm5iTe0o/NeLKu0TiZTGDkxpMbEG/dQVz9w75zxdv2I8B86ovZ5hpaaPbtyZk5e1/MNtYmN4BDUggFMe62mP8en4ufu/NTP6OJ9iqdmD/kzKvWtj1XxQAOTUEUxjhpxzH/JXmuOmy0j1NRzhjzB+nclONqBlAEhVEg42hH8a/ga/TSX3OGIw7B2Tgj41qtqgEURYEUGoV/43kOjbNwJs5W+zzVDaBARaHo9jXVmSQG9IFY2lrpeW1AKcHCfBtQCLA03QaUEizMtwGFAEvTbUApwcJ8G1AIsDTdBpQSLMy3AYUAS9NtQCnBwnwbUAiwNH2ZBpRWPaN8GyA2wwbYADEBsbxvgA0QExDL+wbYADEBsbxvgA0QExDL+wYsxwDxSf9Red8AsbE2wAaICYjlfQNsgJiAWN43wAaICYjlfQNsgJiAWN43YMCAqZf/AgAA///IiQNLAAAABklEQVQDAGmvHtBw+iSxAAAAAElFTkSuQmCC" alt="<svg xmlns=&#x22;http://www.w3.org/2000/svg&#x22; height=&#x22;24px&#x22; viewBox=&#x22;0 -960 960 960&#x22; width=&#x22;24px&#x22; fill=&#x22;#1f1f1f&#x22;><path d=&#x22;M480-528 296-344l-56-56 240-240 240 240-56 56-184-184Z&#x22;/></svg>" data-size="line"> . The rule is swapped with the previous rule.
* To assign the rule with the lowest priority across the given organization, select <img src="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAGAAAABgCAYAAADimHc4AAAFA0lEQVR4Aeycj2oUMRDGrz5I26eSQilCKUIpRSilUErpH0SQIoiIICKICOJr3YvU+ZUshHVvk+xmM4kduXizyezON9/v9nqnoS9W9kfVAQOgav9qZQAMgLIDyuXtDjAAyg4ol7c7wAAoO6Bc3u4AA6DsgHL553kHKJvulzcAvhsKsQFQMN0vaQB8NxRiA6Bgul/SAPhuKMQGQMF0v6QB8N1QiA2Agul+SQPgu6EQGwAF0/2SBQH4ZS3uHFABsL29fdsJqOVZS1NxADS6tbV1s7Ozc1+L+WhBE9pKayoKgAZp1DV5LY2/dbHak9NwjQC0oZG41CgGgMZosNfYlcy/680VO3S1r/yCaJT5Ym+RRQDQEI35jXaxzF/u7u6+745LPVOT2kP1ZP4GzUNruecWB0AjNDQm/PHx8ULeCh7GcnKuUYuaY9dEM9rHcnKsLQ4gQeS5GPMhIX9SqqtxPunkBU5aHMB6vb6VV9tdpPYzedV9jMxNTnPXPos5Ec1oj8mdk7M4AMTRCA0Rh4bc+m/kVfoplJe6zjW5dsx5aEVzTO7cnCIAEElDNEYcMU7FsM8ReVEp7lqnMcloRGtMbkxOKKcYAITQGA0SR4wTMe5LRN5oirvGyWiSW0QbGt1hkaeiAOiIBmmUOGIcy8fFrxF5gynu3OPBxd4kmtDWm178sDgAOqJRGiYODcl7La/ib6G8/jrncG5/fuhY8u7QNLS29JwKAJqiYRonjhhHYuj3iLynFJd79HQQ+AsNaAmkLbasBoCOaBwDiCPGoXyM/BHKczmHoTzWqY0GYq2hCoCmMQAjiENDPka+klf3z015rJGzad2fpya1/TmNWB0ATWMEhhBHjAMx+lc/z80d9OeHjqlFzaG10nNVAKBpDMEY4oixL4b/7vJcvN8djz1Tg1pjOSXXqgFA0xiDQcQRY08+Zv5hSO6ejOCDa1MjmFgwoSoA9I1BGEUcGpL3khHKY13y1D5qUn/TqA4AQlMgkP/P6E3Uaj4yqwSAsFwQajafPqsFgLi5EGo3nx6rBoDAqRBaMJ/+VADIt9Wk//ROhTDF/FRNmJdjFAdAo/JtNXlfUCyEKebL94h7NKEth6kp1ygKgAZp1AlM3hcUgjDRfPYm2b4gByX4tAnCFPPlBcGeJNsXJN9mk/YF9SFMMZ+acjdeDhGXedsXNGSMP9dBmGK+vOc/yHkX/vX6cSkIRX8G9JvsHSfvCwICo3ed0UMxn71H/+O+oOG+MUhebbYvaNieMr8zLgWC3Pq2L2gDrFnTKRCkkO0LEhOyPxIh2L6g7ATkgokQjuXjou0LEt+yPlIgyA9w2xeU1X13sRQIcortCxITsj8SIdi+oOwE5IIpEOQjqu0LEs+yP1IgSHHbFyQmZH8kQqhmX9BcI2r6t6BVIgTbFzSX/tD5KRDkI6rtCxoyce5cCoSYWgKqyk1ZaK/qLQhB3cgFoWbz6bVaAIibC6F28+mxagAInAqhBfPpr3oAiEyF0Ir59NYEAITGQmjJfPpqBgBiQxBaM5+emgKA4E0QWjSffpoDgOh17xeAtGo+vTQJAOHdndCy+fTRLADEA4FB3OpoGkCrpvu6DYDvhkJsABRM90saAN8NhdgAKJjulzQAvhsKsQFQMN0vaQB8NxTiBAAK6p5BSQOgDNkAGABlB5TL2x1gAJQdUC5vd4ABUHZAubzdAQZA2QHl8nYHBAAsvfwXAAD//zD/lKIAAAAGSURBVAMADzwU7qpsf+YAAAAASUVORK5CYII=" alt="<svg xmlns=&#x22;http://www.w3.org/2000/svg&#x22; height=&#x22;24px&#x22; viewBox=&#x22;0 -960 960 960&#x22; width=&#x22;24px&#x22; fill=&#x22;#1f1f1f&#x22;><path d=&#x22;M480-200 240-440l56-56 184 183 184-183 56 56-240 240Zm0-240L240-680l56-56 184 183 184-183 56 56-240 240Z&#x22;/></svg>" data-size="line">. All other affected rules are then updated.
* To delete a rule, select <img src="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAGAAAABgCAYAAADimHc4AAAChklEQVR4AeycvVHDQBCFLYogVSMk9EEHDuiFwB24BlISCiAklDOGIsTuDIFItCPu1u9O/hjtIM/69ud9fg4c6O7An1QBAEjlPxwAAACxAuL2OAAAYgXE7XEAAMQKiNvjAACIFRC3v00HiEVftgfAUg3BfXMAxnGcx8QQaLzasjkAq9PuMAkAMVQA9A6g9vd1th6tzYsDsokH9QEQCJSdBkC2wkF9AAQCZaevCCB7lT7rA0DMDQC9A5imaZgWEe2zfG+L91vnj94f5XFApFByHgDJAkflARAplJwHQLLAUXkARAol5wGQLHBUHgCRQoX56HhzAKLf66OFSs9H9WvnmwNQe8HW6wFATAgAABArIG6PAwAgVkDcHgcAQKyAuD0OAECCAh2VxAFiWAAAgFgBcXscAACxAuL2OAAAYgXE7XEAAMQKiNvjgP0AEG/SaXscIAYHAACIFRC3xwEAECsgbo8DACBWQNweBwBArIC4PQ4oBFB6HAClChaeB0ChgKXHAVCqYOF5ABQKWHq8OQDR8yOihUvPR/Vr55sDUHvB1usBQEwIAAAQKyBujwMA8A8FdnQEB4hhZgD4WtspepaDOr82u+VWd7P85qs6gGEYPjZP0cmBIWG36gDmef7sRM/NY2bsVh2AbfVqsder+m7VAdhvMT7keYcEzr+7VV2tOgCfzgZ98v97iqydUgC48DbwYN+Zz37fc/gOvkvWDmkAfODL5fJiCzzY/cnizeLbovXLZ/RZTz6775A5cCoAH9wWeLdP0NHi0eLe4s+zpht87TP6rEef3XfIjA0AMse43doAELMHAADECojb4wAAiBUQt8cBABArIG6PAwAgVkDcHgcEALLTPwAAAP//joBvcQAAAAZJREFUAwDvUAbfFPR8cwAAAABJRU5ErkJggg==" alt="<svg xmlns=&#x22;http://www.w3.org/2000/svg&#x22; height=&#x22;24px&#x22; viewBox=&#x22;0 -960 960 960&#x22; width=&#x22;24px&#x22; fill=&#x22;#1f1f1f&#x22;><path d=&#x22;M280-120q-33 0-56.5-23.5T200-200v-520h-40v-80h200v-40h240v40h200v80h-40v520q0 33-23.5 56.5T680-120H280Zm400-600H280v520h400v-520ZM360-280h80v-360h-80v360Zm160 0h80v-360h-80v360ZM280-720v520-520Z&#x22;/></svg>" data-size="line">. To learn more, see [Delete Pools](/insights/pools/delete-a-pool).


# Reapply Ruleset

The **Re-apply ruleset** option initiates a new check of the already assigned resources against the current ruleset.

When selected, this option reorganizes the resources, even if they were previously assigned otherwise. This feature helps you manage assignments, especially when the rules are edited, new ones are added, or the priority of existing rules is changed.

{% hint style="info" %}
The option to reapply a ruleset is only available to individuals with Organization Manager or Root Pool Manager permissions.
{% endhint %}

## Reapplying a ruleset <a href="#re-apply-ruleset" id="re-apply-ruleset"></a>

To reapply a ruleset:

1. Navigate to the **Pools** page.&#x20;
2. Select **Configure assignment rules**, then select **Re-apply ruleset**.
3. Choose whether to reapply the ruleset to the resources in the **entire organization** or a **specific pool**.&#x20;
4. If you selected **Specific pool**, choose the pool from the list. Optionally, select **With sub-pools** to include sub-pools.
5. Select **Run** to start the process.


# Create Pool Constraint Policies

If you want to implement policies for an entire pool, instead of a single resource, you can do so from the **Constraints** option within the pool's details page.

Only individuals with a **Manager** role can enforce shared constraints across the pool. While shared constraints apply pool-wide, custom resource-specific constraints can still be configured and will override the general policy.

## Creating a pool constraint policy

To configure pool constraint policies:

1. Navigate to the **Pools** page.&#x20;
2. Select the desired pool group or subpool.
3. Go to the **Constrains** tab and select the edit icon.
4. Enter values in the **TTL** (Time-to-live) or **Daily expense limit** fields.&#x20;
5. Select <img src="/files/rCLMDoTPyjmNC43pHWEt" alt="pencil" data-size="line"> to save your changes. The constraint will apply to the resources within the selected pool or subpool.&#x20;

<figure><img src="/files/pAnxJGi0fwLF1ebeDBoC" alt=""><figcaption><p>Pool constraint policies.</p></figcaption></figure>

{% hint style="info" %}
A constraint will not be visible if the related resource has already been deleted from FinOps or if a resource has been tracked only by imported billing data.
{% endhint %}


# View Pool Assignment Rules

You can view the assignment rules associated with a selected pool from the **Assignment rules** tab on the pool's details page.&#x20;

This view provides insight into how resources are assigned and managed within the pool, ensuring transparency and making it easier to verify or update rules by centralizing them in one place.

Each rule displays key information, including its **Name**, **Owner**, and **Conditions**. The **Conditions** column offers a detailed summary of the criteria defined for each rule, such as **Name/ID contains**, **Tag is**, or **Source is**.

## Viewing pool assignment rules

To view the assignment rules for a pool:

1. Navigate to the **Pools** page.&#x20;
2. Select the desired pool group or subpool.
3. Select the **Assignment rules** tab. All assignment rules that have the given pool as a target are displayed.
4. (Optional) Select **See all assignment rules** to navigate to the main assignment rules listing page, where you can manage all rules across different pools.

<figure><img src="/files/8abfiHSp5FaJXUPyVUMb" alt=""><figcaption><p>Assignment rules for a pool.</p></figcaption></figure>


# Delete Pools

If you no longer need a pool, you can delete it. However, a pool can only be deleted if it doesn't contain any sub-pools. If the pool you want to delete contains subpools, you must first delete all subpools.

Note that to delete a pool, you must have the **Manager** role in the parent of the pool you want to delete.

## Deleting a pool <a href="#pool-deletion" id="pool-deletion"></a>

{% hint style="warning" %}
Once a pool is deleted, it cannot be recovered
{% endhint %}

To delete a pool:

1. Navigate to the **Pools** page.
2. In the **Actions** column, select the delete icon <img src="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAGAAAABgCAYAAADimHc4AAAChklEQVR4AeycvVHDQBCFLYogVSMk9EEHDuiFwB24BlISCiAklDOGIsTuDIFItCPu1u9O/hjtIM/69ud9fg4c6O7An1QBAEjlPxwAAACxAuL2OAAAYgXE7XEAAMQKiNvjAACIFRC3v00HiEVftgfAUg3BfXMAxnGcx8QQaLzasjkAq9PuMAkAMVQA9A6g9vd1th6tzYsDsokH9QEQCJSdBkC2wkF9AAQCZaevCCB7lT7rA0DMDQC9A5imaZgWEe2zfG+L91vnj94f5XFApFByHgDJAkflARAplJwHQLLAUXkARAol5wGQLHBUHgCRQoX56HhzAKLf66OFSs9H9WvnmwNQe8HW6wFATAgAABArIG6PAwAgVkDcHgcAQKyAuD0OAECCAh2VxAFiWAAAgFgBcXscAACxAuL2OAAAYgXE7XEAAMQKiNvjgP0AEG/SaXscIAYHAACIFRC3xwEAECsgbo8DACBWQNweBwBArIC4PQ4oBFB6HAClChaeB0ChgKXHAVCqYOF5ABQKWHq8OQDR8yOihUvPR/Vr55sDUHvB1usBQEwIAAAQKyBujwMA8A8FdnQEB4hhZgD4WtspepaDOr82u+VWd7P85qs6gGEYPjZP0cmBIWG36gDmef7sRM/NY2bsVh2AbfVqsder+m7VAdhvMT7keYcEzr+7VV2tOgCfzgZ98v97iqydUgC48DbwYN+Zz37fc/gOvkvWDmkAfODL5fJiCzzY/cnizeLbovXLZ/RZTz6775A5cCoAH9wWeLdP0NHi0eLe4s+zpht87TP6rEef3XfIjA0AMse43doAELMHAADECojb4wAAiBUQt8cBABArIG6PAwAgVkDcHgcEALLTPwAAAP//joBvcQAAAAZJREFUAwDvUAbfFPR8cwAAAABJRU5ErkJggg==" alt="<svg xmlns=&#x22;http://www.w3.org/2000/svg&#x22; height=&#x22;24px&#x22; viewBox=&#x22;0 -960 960 960&#x22; width=&#x22;24px&#x22; fill=&#x22;#1f1f1f&#x22;><path d=&#x22;M280-120q-33 0-56.5-23.5T200-200v-520h-40v-80h200v-40h240v40h200v80h-40v520q0 33-23.5 56.5T680-120H280Zm400-600H280v520h400v-520ZM360-280h80v-360h-80v360Zm160 0h80v-360h-80v360ZM280-720v520-520Z&#x22;/></svg>" data-size="line">.&#x20;
3. In the confirmation dialog, select **I understand and want to delete this pool**.
4. Select **Delete** to confirm.

When the pool is deleted, all resources from that pool are reassigned to its parent pool. Any rules that previously referenced the deleted pool are automatically redirected to the root pool.


# Anomaly Detection

Anomaly detection is an integral part of a cloud security and management strategy.&#x20;

It helps maintain the integrity and performance of cloud services while identifying and addressing potential issues before they cause significant damage or disruption. An anomaly is defined as a deviation from the normal pattern of cost or usage for a specific resource or group of resources.&#x20;

### Anomaly detection in FinOps for Cloud

Anomaly detection in FinOps for Cloud helps you identify unusual behavior that may indicate a security breach, system malfunction, or other operational challenges.&#x20;

You can create new anomaly detection policies and manage them from the **Anomaly detection** page.

FinOps for Cloud supports two types of anomaly detection policies, including resource count and cost:

* **Resource count** - These anomalies refer to inconsistencies or unexpected variances in the number of resources being utilized or allocated compared to what is expected or provisioned. Resource count anomalies can occur in various cloud resources, such as virtual machines, storage, network bandwidth, or cloud services, like databases and application servers.&#x20;
* **Expense** - These anomalies refer to instances where the actual financial expenditure on cloud resources deviates significantly from expected or budgeted costs. Expense anomalies can represent underlying issues, such as inefficient resource utilization, misconfigurations, unauthorized access, or even billing errors from cloud service providers.&#x20;

When creating policies, you can also define the evaluation period, thresholds, and filters.

<div data-with-frame="true"><figure><img src="/files/flY2to7phnoZrgD9Jhjr" alt=""><figcaption><p>Anomaly detection in FinOps for Cloud.</p></figcaption></figure></div>

### Additional actions <a href="#additional-actions" id="additional-actions"></a>

From the **Anomaly detection** page, you can create new policies and view existing policies. You can also do the following:

* Select a policy to view detailed policy information, including violations if applicable.
* Search for a specific policy by its name or description.&#x20;
* Track the dynamics in the **Status** column and hover over it to see both the average and current values.
* Check the instances where the policy is applicable. An en dash (–) in the **Filters** column means the policy applies to all cases.
* View the resources connected to policy by selecting the **Show resources** icon in the **Actions** column.&#x20;


# Create Anomaly Detection Policies

Organization Managers can create new anomaly detection policies by defining the policy name and description, and the parameters under which anomalies will be identified.&#x20;

FinOps for Cloud supports two types of anomaly detection policies, including **Resource count** and **Expense**. To learn about these policy types, see [Anomaly Detection](/policies/anomaly-detection).

### Creating a new anomaly detection policy

To create a new anomaly detection policy:

1. Navigate to the **Anomaly detection** page, then select **Add**. The **Create anomaly detection policy** page opens.

<div data-with-frame="true"><figure><img src="/files/YvwEyK5Kpv2yGvrPeF0R" alt=""><figcaption><p>The Create anomaly detection policy page in FinOps for Cloud.</p></figcaption></figure></div>

2. Enter a descriptive name for the policy and select the policy type:
   * Select **Resource count** if you want the daily resource count to not exceed the average amount over the last evaluation period, according to the threshold percentage.
   * Select **Expense** if you want FinOps for Cloud to detect when everyday expenses exceed the average sum for the last evaluation period above the threshold percentage.
3. Enter the evaluation period in days and define the threshold percentage.
4. (Optional) Select any filters to be used to trigger policy alerts. You can apply multiple filters. If applicable, select **Show more** to view all filter options.
5. Select **Save** to finish creating the new policy.

Once the policy has been created, FinOps for Cloud sends an email notification to the Organization Manager every time an anomaly is detected.


# Manage Anomaly Detection Policies

The **Anomaly detection** page displays all resource count and expense anomaly policies you have created. You can get detailed information for a policy by selecting the policy name. This includes general information, the date of violation, status, average, and actual counts.&#x20;

From the policy details page, you can edit the policy name. You can also delete the policy, [download the chart as a PNG file](/policies/anomaly-detection/export-chart), and view the violation history.

<div data-with-frame="true"><figure><img src="/files/UDhaHV2rSGH94ipLKJDM" alt=""><figcaption><p>The details page of an anomaly detection policy.</p></figcaption></figure></div>

### Renaming a policy

To rename an existing anomaly detection policy:

1. Navigate to the **Anomaly detection** page.
2. In the list of policies, select the policy you want to rename.
3. On the policy details page, select the edit icon <img src="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAGAAAABgCAYAAADimHc4AAAD/klEQVR4AeycvY7TQBDHbUQNPdLFqUGioqFLR4EoobkH4CWQckg8AhW68qq7DtHR8QYUUFCQD5GnSBFm7uzLlx3P2LPetfd/8njt9dhj/35xnFziPEjw55UABHjFnyQQAAGeCXgujzMAAjwT8FweZwAEeCbguTzOAAjwTMBz+TjPAM/Qd8tDwC4ND9MQkEOfTCYPR6PRNMuyK4qfFBsKbq+o/yJPM28ggJAS6Nez2exHmqYM+py6nlPwwO059U/H4/FXEvGUOy0jegEElaF/I6gvKSqHzWbzhkR8p/y3lUkNFkQtgGBeENSpgtsTyr+m9cwkRCuAIGrh33uylBClgDbwCwtWEqITYAHfUkJUAizhW0mIRoAL+DsSLs/Ozl4U85q2QwGa3bLNdQk/39NHdE34lE+rmsEL6AD+LXAS8Ipr3c4oRoMWwEAIjOZ1vgLdcSrVUr9THqyAruHnOiCAQXiCz6Wf8UgTgzsDPMJn7r94pIlBCfAMn7n/5pEmBiMgAPgJXYT/auBz7iAEhACfYP5Zr9efqVUNvRcQCPyEPi/4sFqt/qnoU3KvBSjh39DxclBjOxD8j8vlsnTbdZV6K0ALf7FYvOMgII1A0XqlQw6fP1UrXV7X2UsBTeAXIFgCXSy/FPNt2rbwuXbvBLSBzwfMMZ/P3zM8nm4avD497TR+5Bd1eyXAAn5x4AyPIRbzmpbX4/U161Tl9kaAJfwCRg7xspiXtJbwuV4vBLiAzwefx+O8rW2s4XPB4AW4hJ9l2TVBEH3FxAV8qh32TXpDhx+0gBjgBysgFvhBCjCBz0dWEiE85x/uVlAX4djgs4xgBMQIPxgBscIPQkDM8L0LiB2+VwGAz/gTP++EAf8OPo87fxUE+Ix9G50KAPwt+GKqMwGAXyDfbw0F7G94dw7wd2nsTzsXAPj7wA/nnAoA/EPcx/POBAD+MeyyHicCAL8MdXmfuQDALwdd1WsqAPCrMFf3mwkA/GrIp5aYCAD8U4hPL2stAPBPA65b2koA4CdJHeC65Y0FAH4dWtnyRgIAXwZXkqUWAPgSrPIctYA0TaW/vXDDd6NIdyXEL01J971NnlqAsBjgC0G5EAD4QvicZi4ATzuMVR7mAqSlY33OP+TjRQDgbzV0LgDwt/B5qlMBZvB5zwcSnQkA/PJHjLkAAs2/u38UVN7r3YhUP8jBXECbo3R1K2ibfXK9bjACYoTPcoMQECv8IATEDN+7gNjhexUA+Izf0x0ygH8Hn8fqizD9tzNtG/nv9HD96EMhIHpWTgBAgBOs8o1CgJyVk0wIcIJVvlEIkLNykgkBTrDKNwoBclZOMiHACVb5RiFAzspJJgQ4wSrfKATUsHK9+D8AAAD//0AN7NMAAAAGSURBVAMAB9Dp3z/s4QcAAAAASUVORK5CYII=" alt="<svg xmlns=&#x22;http://www.w3.org/2000/svg&#x22; height=&#x22;24px&#x22; viewBox=&#x22;0 -960 960 960&#x22; width=&#x22;24px&#x22; fill=&#x22;#1f1f1f&#x22;><path d=&#x22;M200-200h57l391-391-57-57-391 391v57Zm-80 80v-170l528-527q12-11 26.5-17t30.5-6q16 0 31 6t26 18l55 56q12 11 17.5 26t5.5 30q0 16-5.5 30.5T817-647L290-120H120Zm640-584-56-56 56 56Zm-141 85-28-29 57 57-29-28Z&#x22;/></svg>" data-size="line">.
4. Under **Name**, enter the new name, then save your changes.&#x20;

### Deleting a policy

{% hint style="warning" %}
Deleted policies cannot be restored.
{% endhint %}

To delete an existing anomaly detection policy:

1. Navigate to the **Anomaly detection** page.
2. In the list of policies, select the policy you want to delete.
3. On the policy details page, select **Delete**.
4. In the confirmation panel, select **Delete** to confirm the action.


# Export Chart

The **Export chart** option on the policy details page allows you to download the chart as a PNG file.&#x20;

By default, the chart displays data categorized by service along with daily expenses. You can modify these settings using the **Categorize by** and **Expenses** options. Additionally, you can hover over the chart to view detailed information.

<div data-with-frame="true"><figure><img src="/files/UDhaHV2rSGH94ipLKJDM" alt=""><figcaption><p>The Export chart option to download the chart as a PNG file.</p></figcaption></figure></div>

### Exporting a chart

To export the chart as a PNG file:

1. Navigate to the **Anomaly detection** page.
2. Select the desired policy.
3. On the policy details page, do the following:
   1. Select the required category. By default, the **Service** category is selected.
   2. Choose whether you want the chart to display daily, weekly, or monthly expenses. By default, the **Daily** option is selected.
   3. Use the slider to show or hide legends on the chart.
4. Select **Export chart** to download the chart to your system.


# Quotas and Budgets

Quotas and budgets are two crucial concepts to consider when managing cloud storage. These tools help organizations control costs and manage resources efficiently.&#x20;

Budgets refer to the financial limits an organization sets to manage the costs associated with cloud storage usage, and quotas limit the storage resources a user, application, or department can consume.

### Quotas and budgets in FinOps for Cloud

In FinOps for Cloud, quotas and budgets are used to create policies that ensure cost optimization and compliance with your budget constraints.&#x20;

FinOps for Cloud supports three types of policies, including resource quota, recurring budget, and expiring budget. You can define the policy type along with thresholds and filters during policy creation.&#x20;

Once the policy is created, you can view it on the **Quotas and budgets** page.

<div data-with-frame="true"><figure><img src="/files/PEt2Pg6Pzitz6XMd7CDg" alt=""><figcaption><p>Quotas and budgets in FinOps for Cloud.</p></figcaption></figure></div>

### Additional actions <a href="#additional-actions" id="additional-actions"></a>

From the **Quotas and budgets** page, you can create a new policy and view your existing quotas or budgets. You can also do the following:

* Select a policy to view detailed policy information, including violations if applicable.
* View the timestamp of the last check.&#x20;
* See the current resource count or expense value in the **Status** column. Use the progress bar to understand how close the current value is to the set threshold. The color of the progress bar reflects the ratio of the current value to the quota or budget.
  * **Red** - Indicates that the resource count or expenses exceed the quota or budget.
  * **Yellow** - Indicates that the resource count or expenses are approaching the threshold, specifically in the range of 90% and 100%.
  * **Green** - Indicates that the values are within the limit and don't exceed the quota or budget.
* View all filters that display the criteria used to select resources for the quota or budget.
* View resources connected to a quota or budget by selecting the **Show resources** icon in the **Actions** column.


# Create Quota or Budget Policies

Organization Managers can create a new quota or budget policy using the **Add** option on the **Quota and budgets** page.

### Creating a new quota or budget

To create a new policy:

1. Navigate to the **Quota and Budgets** page, then select **Add**.&#x20;
2. On the **Create quota or budget policy** page, provide a descriptive name for the new policy and select the policy type. The following options are available:
   * **Resource quota** - Triggers once per day if the current number of resources exceeds the limit.&#x20;
   * **Recurring budget** - Triggers once per month if the expenses for the current month exceed the limit.
   * **Expiring budget** - Triggers when the total expenses from the start date exceed the limit.

<div data-with-frame="true"><figure><img src="/files/mNMZfqcTTgMsNeOf77Hq" alt=""><figcaption><p>Create quota or budget policy in FinOps for Cloud. </p></figcaption></figure></div>

3. Enter the values in the additional fields according to your selected policy type.&#x20;
   * For a resource quota policy, enter the maximum number of resources.
   * For a recurring budget policy, enter the monthly budget value.
   * For an expiring budget policy, enter the total budget and the start date.
4. &#x20;(Optional) Apply additional filters as needed.
5. Select **Save** to finish creating the new policy.&#x20;

When the policy has been created, use the **Status** column on the **Quota and Budgets** page to view the current resource count or expense value. If the value exceeds the quota or budget, the progress bar turns red. Otherwise, it remains green. The progress bar also indicates how close the current value is to the set threshold values.


# Manage Quota or Budget

When a quota or budget policy has been created, Organization Managers can edit the policy name or delete the policy.&#x20;

When editing a policy, you cannot change the policy type or update properties, including filters associated with the quota or budget.

### Renaming a quota or budget <a href="#ariaid-title1" id="ariaid-title1"></a>

To rename an existing quota or budget policy:

1. Navigate to the **Quotas and budgets** page.
2. In the list of policies, find the policy you want to manage, then select the policy name.
3. On the policy details page, select the edit icon <img src="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAGAAAABgCAYAAADimHc4AAAD/klEQVR4AeycvY7TQBDHbUQNPdLFqUGioqFLR4EoobkH4CWQckg8AhW68qq7DtHR8QYUUFCQD5GnSBFm7uzLlx3P2LPetfd/8njt9dhj/35xnFziPEjw55UABHjFnyQQAAGeCXgujzMAAjwT8FweZwAEeCbguTzOAAjwTMBz+TjPAM/Qd8tDwC4ND9MQkEOfTCYPR6PRNMuyK4qfFBsKbq+o/yJPM28ggJAS6Nez2exHmqYM+py6nlPwwO059U/H4/FXEvGUOy0jegEElaF/I6gvKSqHzWbzhkR8p/y3lUkNFkQtgGBeENSpgtsTyr+m9cwkRCuAIGrh33uylBClgDbwCwtWEqITYAHfUkJUAizhW0mIRoAL+DsSLs/Ozl4U85q2QwGa3bLNdQk/39NHdE34lE+rmsEL6AD+LXAS8Ipr3c4oRoMWwEAIjOZ1vgLdcSrVUr9THqyAruHnOiCAQXiCz6Wf8UgTgzsDPMJn7r94pIlBCfAMn7n/5pEmBiMgAPgJXYT/auBz7iAEhACfYP5Zr9efqVUNvRcQCPyEPi/4sFqt/qnoU3KvBSjh39DxclBjOxD8j8vlsnTbdZV6K0ALf7FYvOMgII1A0XqlQw6fP1UrXV7X2UsBTeAXIFgCXSy/FPNt2rbwuXbvBLSBzwfMMZ/P3zM8nm4avD497TR+5Bd1eyXAAn5x4AyPIRbzmpbX4/U161Tl9kaAJfwCRg7xspiXtJbwuV4vBLiAzwefx+O8rW2s4XPB4AW4hJ9l2TVBEH3FxAV8qh32TXpDhx+0gBjgBysgFvhBCjCBz0dWEiE85x/uVlAX4djgs4xgBMQIPxgBscIPQkDM8L0LiB2+VwGAz/gTP++EAf8OPo87fxUE+Ix9G50KAPwt+GKqMwGAXyDfbw0F7G94dw7wd2nsTzsXAPj7wA/nnAoA/EPcx/POBAD+MeyyHicCAL8MdXmfuQDALwdd1WsqAPCrMFf3mwkA/GrIp5aYCAD8U4hPL2stAPBPA65b2koA4CdJHeC65Y0FAH4dWtnyRgIAXwZXkqUWAPgSrPIctYA0TaW/vXDDd6NIdyXEL01J971NnlqAsBjgC0G5EAD4QvicZi4ATzuMVR7mAqSlY33OP+TjRQDgbzV0LgDwt/B5qlMBZvB5zwcSnQkA/PJHjLkAAs2/u38UVN7r3YhUP8jBXECbo3R1K2ibfXK9bjACYoTPcoMQECv8IATEDN+7gNjhexUA+Izf0x0ygH8Hn8fqizD9tzNtG/nv9HD96EMhIHpWTgBAgBOs8o1CgJyVk0wIcIJVvlEIkLNykgkBTrDKNwoBclZOMiHACVb5RiFAzspJJgQ4wSrfKATUsHK9+D8AAAD//0AN7NMAAAAGSURBVAMAB9Dp3z/s4QcAAAAASUVORK5CYII=" alt="<svg xmlns=&#x22;http://www.w3.org/2000/svg&#x22; height=&#x22;24px&#x22; viewBox=&#x22;0 -960 960 960&#x22; width=&#x22;24px&#x22; fill=&#x22;#1f1f1f&#x22;><path d=&#x22;M200-200h57l391-391-57-57-391 391v57Zm-80 80v-170l528-527q12-11 26.5-17t30.5-6q16 0 31 6t26 18l55 56q12 11 17.5 26t5.5 30q0 16-5.5 30.5T817-647L290-120H120Zm640-584-56-56 56 56Zm-141 85-28-29 57 57-29-28Z&#x22;/></svg>" data-size="line">.
4. Under **Name**, enter the new name, then save your changes.

### Deleting a quota or budget <a href="#ariaid-title1" id="ariaid-title1"></a>

{% hint style="warning" %}
Deleted policies cannot be restored.
{% endhint %}

To delete an existing quota or budget policy:

1. Navigate to the **Quotas and budgets** page.
2. In the list of policies, find the policy you want to manage, then select the policy name.
3. On the policy details page, select **Delete**.
4. In the confirmation panel, select **Delete** to confirm the action.


# View Policy Violation History

A violation history is available for those policies where the resource count or the expenses have exceeded the quota or budget.&#x20;

Violated policies are displayed in red on the **Quotas and budgets** page.

### Viewing the policy violation history

To view the policy violation history:

1. Navigate to the **Quotas and budgets** page.
2. In the list of policies, find the policy for which you want to view the violation history.
3. Select the policy name.
4. On the policy details page, use the **Policy Violations History** section to view details including:
   1. The date and time when the policy violation occurred.
   2. The budgeted expense value vs the actual expense.
   3. The resources linked to the quota or budget.


# Tagging Policies

Tagging Policies are a type of policy that can help ensure that your resources are properly categorized and monitored.&#x20;

Tagging policies use custom tags, which are descriptive labels assigned to resources. These tags help identify resources among others, making it easier for you to locate and manage them.&#x20;

### Tagging policies in FinOps for Cloud

In FinOps for Cloud, Organization Managers can create new tagging policies using the **Add** option on the **Tagging policies** page.&#x20;

When creating a new policy, you can specify the tagging rules applicable to resources when they are tagged. If the policy is violated, FinOps for Cloud sends an email notification to the Organization Manager.&#x20;

<div data-with-frame="true"><figure><img src="/files/XDb3qaV6bBK8BZvXOMZY" alt=""><figcaption><p>Tagging policies in FinOps for Cloud.</p></figcaption></figure></div>

### Additional actions <a href="#additional-actions" id="additional-actions"></a>

From the **Tagging Policies** page, you can create new policies and monitor your existing tagging policies. You can also do the following:

* View the timestamp of the last policy check.&#x20;
* Review the status of the policy, including any violations, to determine resources that are not complying with the tagging policy.
  * A red icon indicates that resources violating the tagging rules have been identified.
  * A green icon shows that all resources covered by the policy currently meet its tagging rules.
  * No status information yet means that the policy is newly created and hasn't run an evaluation cycle, or the filters may exclude all current resources, resulting in no data to check.
* Read a brief description of what the policy monitors, including the scope, type, and enforcement timeline.
* Access all resources associated with the tagging policy by selecting the **Show resources** icon in the **Actions** column.&#x20;


# Create Tagging Policies

Organization Managers create new tagging policies by using the **Add** option on the **Tagging policies** page. Multiple policies can be created; for instance, you can create one policy that applies to all resources and another policy that applies to specific resource types.

After entering the policy details and filters, you can save the policy to begin monitoring. This ensures that the policy is applied to relevant resources and helps ensure compliance with the organization's tagging standards.

### Creating a tagging policy

To create a new tagging policy:

1. Navigate to the **Tagging policies** page, then select **Add**.&#x20;
2. On the **Create tagging policy** page, enter a name for the policy and select the date and time when the policy must start.

<div data-with-frame="true"><figure><img src="/files/GkN9zcvVwkGtR4ZN5fuU" alt=""><figcaption><p>Create a new tagging policy.</p></figcaption></figure></div>

3. Choose whether the policy requires certain tags, prohibits certain tags, or defines a correlation between tags.
4. Enter the values in the additional fields according to your selected tagging rule.
   * If you selected the **Required tag** option, specify tags that must be present.
   * If you selected the **Prohibited tag** option, specify tags that must not be present.
   * If you selected the **Tags correlation** option, specify the primary and correlated tags.
5. (Optional) Use filters to apply additional tagging rules.
6. Select **Save** to finish creating the policy.&#x20;

Once the policy has been created, FinOps for Cloud sends an email notification to the Organization Manager when the policy is violated.&#x20;


# Edit or Delete Tagging Policies

You can delete a tagging policy or edit the policy name at any time. You can't edit tags that are used in policies.

{% hint style="warning" %}
Deleted policies cannot be restored.
{% endhint %}

### Editing or deleting tagging policies

To edit or delete a tagging policy:

1. Navigate to the **Tagging policies** page.
2. Select the policy you want to manage. The details page of the policy opens:

<div data-with-frame="true"><figure><img src="/files/VRtuis5cQyFN2AVG4lcJ" alt=""><figcaption><p>The details page of a tagging policy.</p></figcaption></figure></div>

3. Complete the following steps as necessary:&#x20;
   * To edit the policy name, select the edit icon <img src="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAGAAAABgCAYAAADimHc4AAAD/klEQVR4AeycvY7TQBDHbUQNPdLFqUGioqFLR4EoobkH4CWQckg8AhW68qq7DtHR8QYUUFCQD5GnSBFm7uzLlx3P2LPetfd/8njt9dhj/35xnFziPEjw55UABHjFnyQQAAGeCXgujzMAAjwT8FweZwAEeCbguTzOAAjwTMBz+TjPAM/Qd8tDwC4ND9MQkEOfTCYPR6PRNMuyK4qfFBsKbq+o/yJPM28ggJAS6Nez2exHmqYM+py6nlPwwO059U/H4/FXEvGUOy0jegEElaF/I6gvKSqHzWbzhkR8p/y3lUkNFkQtgGBeENSpgtsTyr+m9cwkRCuAIGrh33uylBClgDbwCwtWEqITYAHfUkJUAizhW0mIRoAL+DsSLs/Ozl4U85q2QwGa3bLNdQk/39NHdE34lE+rmsEL6AD+LXAS8Ipr3c4oRoMWwEAIjOZ1vgLdcSrVUr9THqyAruHnOiCAQXiCz6Wf8UgTgzsDPMJn7r94pIlBCfAMn7n/5pEmBiMgAPgJXYT/auBz7iAEhACfYP5Zr9efqVUNvRcQCPyEPi/4sFqt/qnoU3KvBSjh39DxclBjOxD8j8vlsnTbdZV6K0ALf7FYvOMgII1A0XqlQw6fP1UrXV7X2UsBTeAXIFgCXSy/FPNt2rbwuXbvBLSBzwfMMZ/P3zM8nm4avD497TR+5Bd1eyXAAn5x4AyPIRbzmpbX4/U161Tl9kaAJfwCRg7xspiXtJbwuV4vBLiAzwefx+O8rW2s4XPB4AW4hJ9l2TVBEH3FxAV8qh32TXpDhx+0gBjgBysgFvhBCjCBz0dWEiE85x/uVlAX4djgs4xgBMQIPxgBscIPQkDM8L0LiB2+VwGAz/gTP++EAf8OPo87fxUE+Ix9G50KAPwt+GKqMwGAXyDfbw0F7G94dw7wd2nsTzsXAPj7wA/nnAoA/EPcx/POBAD+MeyyHicCAL8MdXmfuQDALwdd1WsqAPCrMFf3mwkA/GrIp5aYCAD8U4hPL2stAPBPA65b2koA4CdJHeC65Y0FAH4dWtnyRgIAXwZXkqUWAPgSrPIctYA0TaW/vXDDd6NIdyXEL01J971NnlqAsBjgC0G5EAD4QvicZi4ATzuMVR7mAqSlY33OP+TjRQDgbzV0LgDwt/B5qlMBZvB5zwcSnQkA/PJHjLkAAs2/u38UVN7r3YhUP8jBXECbo3R1K2ibfXK9bjACYoTPcoMQECv8IATEDN+7gNjhexUA+Izf0x0ygH8Hn8fqizD9tzNtG/nv9HD96EMhIHpWTgBAgBOs8o1CgJyVk0wIcIJVvlEIkLNykgkBTrDKNwoBclZOMiHACVb5RiFAzspJJgQ4wSrfKATUsHK9+D8AAAD//0AN7NMAAAAGSURBVAMAB9Dp3z/s4QcAAAAASUVORK5CYII=" alt="<svg xmlns=&#x22;http://www.w3.org/2000/svg&#x22; height=&#x22;24px&#x22; viewBox=&#x22;0 -960 960 960&#x22; width=&#x22;24px&#x22; fill=&#x22;#1f1f1f&#x22;><path d=&#x22;M200-200h57l391-391-57-57-391 391v57Zm-80 80v-170l528-527q12-11 26.5-17t30.5-6q16 0 31 6t26 18l55 56q12 11 17.5 26t5.5 30q0 16-5.5 30.5T817-647L290-120H120Zm640-584-56-56 56 56Zm-141 85-28-29 57 57-29-28Z&#x22;/></svg>" data-size="line">. Then, provide the new name and save your changes.&#x20;
   * To delete the policy, select **Delete** and then select **Delete** again in the confirmation panel to confirm the action.


# User Management

The **User management** page in FinOps for Cloud displays a list of existing members within your organization. For each member, you can view details, such as their name, unique ID, last login time, email address, and assigned roles.

From this page, Organization Managers can also invite new members or remove existing members from the organization.

## Role overview

In FinOps for Cloud, roles can be assigned when [inviting a user to the organization](/finops-for-cloud/getting-started/invite-users-to-your-organization).

By default, the Member role is assigned to allow the individual to have read-only access. You can select other roles and assign them at the pool level. When assigning roles, we recommend assigning the Organization Manager role only to those individuals who need the highest level of access and permission to perform actions without any restrictions.

The following table lists the roles in FinOps for Cloud. These roles cannot be edited, and you cannot create new ones.

<table><thead><tr><th width="196">Role</th><th>Description</th></tr></thead><tbody><tr><td><strong>Member</strong></td><td>The <strong>Member</strong> role is assigned by default to all users. <strong>Members</strong> have read-only access across the platform and can view dashboards, resources, pools, policies, recommendations, and analysis features. They can also download reports and exports where supported. <strong>Members</strong> cannot make any modifications to the platform.</td></tr><tr><td><strong>Engineer</strong></td><td>The <strong>Engineer</strong> role is assigned at the resource level. <strong>Engineers</strong> can view the entire platform. This includes pool structures, recommendations, and analysis views, but their editing capabilities are limited to the specific resources they are responsible for. All other areas are available in read-only mode.</td></tr><tr><td><strong>Manager</strong></td><td>The <strong>Manager</strong> role is assigned at the pool level. <strong>Managers</strong> can administer the pools they have been assigned to, including creating and deleting sub-pools, configuring assignment rules, and re-applying resource assignment rules. This permission cascades downward: a <strong>Manager</strong> assigned to a pool automatically has the same management permissions over all child pools beneath it, at every level of nesting. Areas of the platform outside their assigned pools are available in read-only mode.</td></tr><tr><td><strong>Organization Manager</strong></td><td>The <strong>Organization Manager</strong> has full administrative control over the entire FinOps for Cloud environment. This role can invite and remove users, manage all pools and sub-pools across the organization, configure all policy types (anomaly detection, quotas and budgets, and tagging policies), and fully manage data sources. <strong>Organization Managers</strong> also have unrestricted access to all analysis, reporting, and configuration features. This role should be assigned only to individuals who require the highest level of access.</td></tr></tbody></table>

## Which role should I assign?

The right role depends on what a person needs to do in the platform. The table below maps each role to the kinds of team members most likely to need it, using the [FinOps Foundation's standard personas](https://www.finops.org/framework/personas/) as a reference point. In practice, one person may fulfil multiple personas, and not every organization will have all of these roles.

<table><thead><tr><th width="155">Platform role</th><th width="185.333251953125">Likely personas</th><th>Assign this role to people who...</th></tr></thead><tbody><tr><td><strong>Member</strong></td><td>Finance, Product, Procurement, Leadership, ITAM, Sustainability</td><td>Need visibility into cloud spend and usage to inform decisions, reporting, or governance, but have no need to make changes in the platform. A good default for anyone who needs to stay informed without being given edit access.</td></tr><tr><td><strong>Engineer</strong></td><td>Engineering</td><td>Build and operate the cloud infrastructure that generates the costs. They need visibility into recommendations and resource data to act on optimization opportunities, but their changes are scoped to the resources they own.</td></tr><tr><td><strong>Manager</strong></td><td>FinOps Practitioner, Finance, ITFM</td><td>Own cost accountability for a specific business unit, team, or project. They manage a defined pool of cloud spend and need to act on it, creating sub-pools, assigning resources, and responding to budget alerts, but don't need organization-wide control.</td></tr><tr><td><strong>Organization Manager</strong></td><td>FinOps Practitioner, Leadership</td><td>Lead the FinOps practice, own the platform configuration, and need unrestricted access to manage users, data sources, policies, and all pools across the organization. Typically, one or two people.</td></tr></tbody></table>

A few practical guidelines for Organization Managers assigning roles:

* **Default to Member** for anyone whose primary need is visibility or reporting. It is easy to upgrade later.
* **Assign Manager at the right pool level.** A Manager assigned to a top-level pool inherits access to all child pools beneath it, so take care when assigning to high-level pools.
* **Limit Organization Manager access.** This role has no restrictions. It can delete objects, disconnect data sources, and modify all policies. Assign it only to those who genuinely need full administrative control.

## Permissions reference

**Legend**

<picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture> Allowed

— Not allowed

### Home

<table><thead><tr><th width="271.9630126953125">Feature / Permission</th><th width="107.25927734375">Member</th><th width="107.25927734375">Engineer</th><th width="109.25927734375">Manager</th><th>Organization Manager</th></tr></thead><tbody><tr><td>View organization overview</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr></tbody></table>

### Recommendations

<table><thead><tr><th width="269">Feature / Permission</th><th width="108">Member</th><th width="108.74072265625">Engineer</th><th width="113.962890625">Manager</th><th>Organization Manager</th></tr></thead><tbody><tr><td><em>Overview</em></td><td></td><td></td><td></td><td></td></tr><tr><td>View recommendations</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td>Filter recommendations</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td>Change view (cards / table)</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td>Search recommendations</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td>View recommendations archive</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td>Run recommendations check</td><td>—</td><td>—</td><td>—</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td>Download script</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td>Download xlsx/json</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td><em>Recommendation</em></td><td></td><td></td><td></td><td></td></tr><tr><td>View recommendation settings</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td>Edit recommendation settings</td><td>—</td><td>—</td><td>—</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td>View excluded pools</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td>Edit excluded pools</td><td>—</td><td>—</td><td>—</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td>Pin recommendations</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td>Dismiss recommendation</td><td>—</td><td>—</td><td>—</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr></tbody></table>

### Resources

<table><thead><tr><th width="273.4444580078125">Feature / Permission</th><th width="107.25927734375">Member</th><th width="108">Engineer</th><th width="109.74072265625">Manager</th><th>Organization Manager</th></tr></thead><tbody><tr><td><em>Overview</em></td><td></td><td></td><td></td><td></td></tr><tr><td>View resources</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td>Filter resources</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td>View saved perspective (view)</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td>Create saved perspective (view)</td><td>—</td><td>—</td><td>—</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td>Export expenses chart</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td>Download xlsx/json</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td><em>Resource</em></td><td></td><td></td><td></td><td></td></tr><tr><td>View resource details</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td>Add assignment rule</td><td>—</td><td>—</td><td><p><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></p><p> <sup>1</sup></p></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr></tbody></table>

### Pools

<table><thead><tr><th width="273.4444580078125">Feature / Permission</th><th width="105.0369873046875">Member</th><th width="110.9630126953125">Engineer</th><th width="109.7408447265625">Manager</th><th>Organization Manager</th></tr></thead><tbody><tr><td><em>Overview</em></td><td></td><td></td><td></td><td></td></tr><tr><td>View pools</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td>Add / edit / delete pool</td><td>—</td><td>—</td><td><p><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></p><p> <sup>1</sup></p></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td><em>Assignment rules</em></td><td></td><td></td><td></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td>View assignment rules</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td>Search assignment rules</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td>Add / edit / delete assignment rule</td><td>—</td><td>—</td><td><p><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></p><p> <sup>1</sup></p></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td>Reorder assignment rules</td><td>—</td><td>—</td><td>—</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td>Re-apply assignment rules</td><td>—</td><td>—</td><td><p><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></p><p> <sup>1</sup></p></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr></tbody></table>

### FinOps

<table><thead><tr><th width="276.4073486328125">Feature / Permission</th><th width="102.8148193359375">Member</th><th width="110.9630126953125">Engineer</th><th width="108">Manager</th><th>Organization Manager</th></tr></thead><tbody><tr><td><em>Cost Explorer</em></td><td></td><td></td><td></td><td></td></tr><tr><td>View cost explorer</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td>Filter cost explorer</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td>Download PDF</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td>View expense breakdowns</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td><em>Cost Map</em></td><td></td><td></td><td></td><td></td></tr><tr><td>View map</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td>Filter map</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr></tbody></table>

### Policies

<table><thead><tr><th width="277.1480712890625">Feature / Permission</th><th width="102.0740966796875">Member</th><th width="110.9630126953125">Engineer</th><th width="110.2222900390625">Manager</th><th>Organization Manager</th></tr></thead><tbody><tr><td><em>Anomaly detection</em></td><td></td><td></td><td></td><td></td></tr><tr><td>View anomaly detections</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td>Add / edit / delete anomaly detection</td><td>—</td><td>—</td><td>—</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td>View anomaly detection details</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td>View anomaly detection resources</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td>Export anomaly detection chart</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td><em>Quotas and Budgets</em></td><td></td><td></td><td></td><td></td></tr><tr><td>View quota or budget</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td>Add / edit / delete quota or budget</td><td>—</td><td>—</td><td>—</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td>View quota or budget resources</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td><em>Tagging policies</em></td><td></td><td></td><td></td><td></td></tr><tr><td>View tagging policy</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td>Add / edit / delete tagging policy</td><td>—</td><td>—</td><td>—</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td>View tagging policy resources</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr></tbody></table>

### System

<table><thead><tr><th width="277.888916015625">Feature / Permission</th><th width="104.29638671875">Member</th><th width="111.7037353515625">Engineer</th><th width="111.7037353515625">Manager</th><th>Organization Manager</th></tr></thead><tbody><tr><td><em>User management</em></td><td></td><td></td><td></td><td></td></tr><tr><td>Invite users</td><td>—</td><td>—</td><td>—</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td>Download xlsx/json</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td>View last login date and time</td><td>—</td><td>—</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td>Delete users</td><td>—</td><td>—</td><td>—</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td><em>Data sources</em></td><td></td><td></td><td></td><td></td></tr><tr><td>View data sources</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td>Add data source</td><td>—</td><td>—</td><td>—</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td>Rename data source</td><td>—</td><td>—</td><td>—</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td>Update data source credentials</td><td>—</td><td>—</td><td>—</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td>Perform billing re-import <sup>2</sup></td><td>—</td><td>—</td><td>—</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td>Disconnect data source</td><td>—</td><td>—</td><td>—</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td><em>Events</em></td><td></td><td></td><td></td><td></td></tr><tr><td>View events</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td>Filter and search events</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td><em>Settings</em></td><td></td><td></td><td></td><td></td></tr><tr><td>View organization details</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td>View and accept invitations</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td>Manage email notifications <sup>3</sup></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr></tbody></table>

<sup>1</sup> Managers are limited to pools and sub-pools they have been assigned to. This applies to all child pools beneath an assigned pool, at every level of nesting.

<sup>2</sup> Supported for all AWS accounts and GCP projects. For Azure, billing re-import is supported at the subscription level only. It cannot be performed on an Azure tenant, even if that tenant's subscriptions were automatically discovered.

<sup>3</sup> Members and Engineers have access to a reduced subset of notifications. See the [Notifications Reference](#notifications-reference) table below.

## Notifications reference

<table><thead><tr><th width="279.3702392578125">Notification</th><th width="102.073974609375">Member</th><th width="110.9630126953125">Engineer</th><th width="114.6666259765625">Manager</th><th>Organization Manager</th></tr></thead><tbody><tr><td><em>FinOps</em></td><td></td><td></td><td></td><td></td></tr><tr><td>Weekly expense report</td><td>—</td><td>—</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td>Pool limit exceed alert</td><td>—</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td>Pool limit alert</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td>Saving spike</td><td>—</td><td>—</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td><em>Policy alerts</em></td><td></td><td></td><td></td><td></td></tr><tr><td>Resource constraints report</td><td>—</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td>Resource constraint violation alert</td><td>—</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td>Anomaly detection</td><td>—</td><td>—</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td>Expiring budget policy violation</td><td>—</td><td>—</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td>Quota policy violation</td><td>—</td><td>—</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td>Recurring budget policy violation</td><td>—</td><td>—</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td>Tagging policy violation</td><td>—</td><td>—</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td><em>Recommendations</em></td><td></td><td></td><td></td><td></td></tr><tr><td>New security recommendation detection</td><td>—</td><td>—</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td><em>System notifications</em></td><td></td><td></td><td></td><td></td></tr><tr><td>Environment changed</td><td>—</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td>Expenses initial processing completed</td><td>—</td><td>—</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td>Report import failed</td><td>—</td><td>—</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr><tr><td><em>Account management</em></td><td></td><td></td><td></td><td></td></tr><tr><td>Invitation notification</td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td><td><picture><source srcset="/files/N643hzuF5qdVdGg3H3BQ" media="(prefers-color-scheme: dark)"><img src="/files/DwH2ZdOPYhEr6h2PpkFO" alt="" data-size="line"></picture></td></tr></tbody></table>


# View and Manage Users

In FinOps for Cloud, the **User management** page shows a list of existing users in your organization and what role they have been assigned. Each page shows up to 50 users.&#x20;

For each user, you can also view the following information:

* The user's name and the unique ID assigned to them by FinOps for Cloud.
* The last time the user accessed the organization.
* The user's email address.

From this page, you can find a specific user using the **Search** option, invite new users, and remove users who no longer need access to your organization.&#x20;

### Inviting users to your organization

Organization Managers can invite a new user to the FinOps organization by selecting **Invite** on the **Users** **management** page. To learn more, see [Invite Users to Your Organization](/finops-for-cloud/getting-started/invite-users-to-your-organization).

### Removing a user from your organization

Organization Managers can remove an individual from an organization. To remove an individual:

1. Navigate to the **User management** page.
2. From the list of users, find the individual you want to remove.&#x20;
3. In the **Actions** column, select the delete icon.
4. In the **Delete user** panel, select the organization manager who will take over all the assets of the individual you want to remove. This step is mandatory.
5. Select **Delete** to confirm the action.


# Download Users

You can download a complete list of users in your organization as an Excel or a JSON file for offline analysis, reporting, or integration with external tools.

The downloaded file includes details for each user, such as user ID, first and last name, organization ID, last login, and more.

### Downloading users

To download a list of users:

1. Navigate to the **User management** page.
2. Select **Download**.
3. Choose your desired format, XLSX or JSON, to start the download.


# Data Sources

The **Add** option on the **Data sources** page allows you to connect your data source to FinOps for Cloud. The supported data sources include Amazon Web Services, Google Cloud Platform, and Microsoft Azure.&#x20;

Before adding a data source, you must complete certain prerequisites, depending on the type of data source you are adding. In addition, you might also need to complete certain tasks on the cloud provider's side and some in FinOps for Cloud.&#x20;

To learn about all the prerequisites and onboarding steps for each of the supported data sources, see the following links:

* [Amazon Web Services](/system/data-sources/amazon-web-services)
* [Microsoft Azure](/system/data-sources/microsoft-azure)
* [Google Cloud Platform](/system/data-sources/google-cloud-platform)

To manage the settings of your connected data sources, see [Manage Data Sources](/system/data-sources/manage-data-sources).


# Amazon Web Services

Learn how you can add your AWS data sources to the FinOps platform. FinOps for Cloud supports both AWS organizations and individual AWS standalone accounts.

## Know your account types

FinOps for Cloud supports three account types as described in the following table:

{% hint style="warning" %}
If you want to add a member account in an AWS Organization to FinOps for Cloud, but you do not have access to the management account, follow the instructions for a [standalone account](#aws-standalone-accounts).
{% endhint %}

<table><thead><tr><th width="179" valign="top">Term</th><th valign="top">Definition and use</th></tr></thead><tbody><tr><td valign="top">Management account</td><td valign="top"><p>A management account is an AWS account you use to create your AWS Organization. The owner of the management account is responsible for paying for all usage, data, and resources used by the accounts in the organization.</p><p>A management account is also called a root account, master account, billing account, or payer account.</p><p>In FinOps for Cloud, use this account type when adding an AWS Organization <a href="#with-access-to-the-management-account">management account</a>.</p></td></tr><tr><td valign="top">Member account</td><td valign="top"><p>A member account is an AWS account, other than the management account, that is part of an AWS Organization. The management account is responsible for paying for all member accounts in the organization.</p><p>A member account is also referred to as a linked account, child account, usage account, or sub-account.</p><p>In FinOps for Cloud, use this account type when adding an AWS Organization member account, <a href="#with-access-to-the-management-account">and the management account has already been added to FinOps for Cloud</a>.</p></td></tr><tr><td valign="top">Standalone account</td><td valign="top"><p>A standalone account refers to an account that is not part of an AWS Organization. It stands on its own, without being linked to any other accounts for consolidated billing, management, or policy control.</p><p>A standalone account is also referred to as an individual account, non-organizational account, or unlinked account.</p><p>In FinOps for Cloud, use this account type when:</p><ul><li>Adding <a href="#aws-standalone-accounts">standalone AWS account</a> that is not part of an AWS Organization</li><li>Adding an AWS member account that is part of an AWS Organization, <a href="#without-access-to-the-management-account">but access to the management account is not available</a>.</li></ul></td></tr></tbody></table>

## Assumed roles vs IAM user access keys

FinOps for Cloud supports adding data sources using two authentication methods:

* **Assumed role** - This is the recommended approach to adding AWS accounts to FinOps for Cloud. An IAM role is an identity that does not have its own permanent credentials (password or access keys). Instead, it defines permissions that a trusted entity (such as an AWS service, another AWS account, or an application running on an EC2 instance) can *assume* to obtain temporary security credentials.
* **IAM user with access key** - Access keys are a set of permanent credentials consisting of an Access Key ID and a Secret Access Key. They are associated with a specific IAM User (or the root user, which is strongly discouraged) and are used for making programmatic API requests to AWS, typically from the AWS CLI, SDKs, or third-party applications. Read more about the security risks associated with this approach in the [AWS documentation](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_access-keys.html).

{% hint style="info" %}
SoftwareOne strongly recommends using assumed roles to configure your data sources.
{% endhint %}

## Configuring your AWS accounts

### AWS Organizations

Depending on the access to your management account and other member accounts, there are different ways to add AWS data sources to FinOps for Cloud.

{% hint style="info" %}
If you add only a management account without connecting its member accounts, any expenses from those unconnected member accounts are ignored, even if they appear in the data export file.

To ensure expenses are captured for both management and member accounts, you must add all AWS accounts individually. FinOps for Cloud doesn't process data from unconnected member accounts.
{% endhint %}

#### With access to the management account

If you have access to create a Cost and Usage Report (CUR) and Identity and Access Management (IAM) roles or users in your management account, follow these steps:

{% stepper %}
{% step %}
**Add your management account**

To add your management account:

1. [Create a Cost and Usage Report in AWS](/system/data-sources/amazon-web-services/create-cost-and-usage-reports).
2. [Create the `FinOpsForCloudBillingImport` ](/system/data-sources/amazon-web-services/configure-aws-access#create-a-policy-for-billing-imports)[IAM role policy](https://docs.finops.softwareone.com/system/data-sources/amazon-web-services/configure-aws-access#create-a-policy-for-billing-imports).
3. [Create the `FinOpsForCloudResourceDiscovery` IAM role policy](https://docs.finops.softwareone.com/system/data-sources/amazon-web-services/configure-aws-access#create-a-policy-for-resource-discovery).
4. If you are using an assumed role (recommended):
   1. [Create the `FinOpsForCloudAccessRole` IAM role](https://docs.finops.softwareone.com/system/data-sources/amazon-web-services/configure-aws-access#creating-a-new-iam-role).
5. If you are using an IAM user with an access key:
   1. [Create the `FinOpsForCloudUser` IAM user](https://docs.finops.softwareone.com/system/data-sources/amazon-web-services/configure-aws-access#creating-a-new-iam-user).
   2. [Create an access key for the `FinOpsForCloudUser` IAM user](https://docs.finops.softwareone.com/system/data-sources/amazon-web-services/configure-aws-access#creating-an-access-key-for-finops-for-cloud).
6. [Add the management account data source to FinOps for Cloud.](https://docs.finops.softwareone.com/system/data-sources/amazon-web-services/add-your-aws-account-to-finops-for-cloud#adding-a-management-or-standalone-aws-account)
   {% endstep %}

{% step %}
**Add your member accounts to FinOps for Cloud**

{% hint style="info" %}
When adding a member account, and you have already added the management account, there is no need to create a cost and usage report or create the `FinOpsForCloudBillingImport` policy.
{% endhint %}

To add your member accounts:

1. [Create the `FinOpsForCloudResourceDiscovery` IAM policy](https://docs.finops.softwareone.com/system/data-sources/amazon-web-services/configure-aws-access#create-a-policy-for-resource-discovery).
2. If you are using an assumed role (recommended):
   1. [Create the `FinOpsForCloudAccessRole` IAM role](https://docs.finops.softwareone.com/system/data-sources/amazon-web-services/configure-aws-access#creating-a-new-iam-role).
3. If you are using an IAM user with an access key:
   1. [Create the `FinOpsForCloudUser` IAM user](https://docs.finops.softwareone.com/system/data-sources/amazon-web-services/configure-aws-access#creating-a-new-iam-user).
   2. [Create an access key for the `FinOpsForCloudUser` IAM user](https://docs.finops.softwareone.com/system/data-sources/amazon-web-services/configure-aws-access#creating-an-access-key-for-finops-for-cloud).
4. [Add the member account data source to FinOps for Cloud.](https://docs.finops.softwareone.com/system/data-sources/amazon-web-services/add-your-aws-account-to-finops-for-cloud#adding-a-member-aws-account)
5. Repeat steps 1 - 4 for each member account you want to add.
   {% endstep %}
   {% endstepper %}

{% hint style="success" %}
When the member accounts are added, FinOps for Cloud automatically identifies the management account and uses the imported cost and usage data from that account.
{% endhint %}

#### Without access to the management account

If you don't have access to your management account, you can create individual CURs in each member account and add them to FinOps for Cloud as if they were standalone accounts.

To add your member account to FinOps for Cloud, follow the steps below for [AWS standalone accounts](#aws-standalone-accounts).

### AWS standalone accounts

To add a standalone AWS account:

1. [Create a Cost and Usage report in AWS.](/system/data-sources/amazon-web-services/create-cost-and-usage-reports)
2. [Create the `FinOpsForCloudBillingImport` IAM policy](https://docs.finops.softwareone.com/system/data-sources/amazon-web-services/configure-aws-access#create-a-policy-for-billing-imports).
3. [Create the `FinOpsForCloudResourceDiscovery` IAM policy](https://docs.finops.softwareone.com/system/data-sources/amazon-web-services/configure-aws-access#create-a-policy-for-resource-discovery).
4. If you are using an assumed role (recommended):
   1. [Create the `FinOpsForCloudAccessRole` IAM role](https://docs.finops.softwareone.com/system/data-sources/amazon-web-services/configure-aws-access#creating-a-new-iam-role).
5. If you are using an IAM user with an access key:
   1. [Create the `FinOpsForCloudUser` IAM user](https://docs.finops.softwareone.com/system/data-sources/amazon-web-services/configure-aws-access#creating-a-new-iam-user).
   2. [Create an access key for the `FinOpsForCloudUser` IAM user](https://docs.finops.softwareone.com/system/data-sources/amazon-web-services/configure-aws-access#creating-an-access-key-for-finops-for-cloud).
6. [Add the standalone account data source to FinOps for Cloud.](https://docs.finops.softwareone.com/system/data-sources/amazon-web-services/add-your-aws-account-to-finops-for-cloud#adding-a-management-or-standalone-aws-account)


# Create Cost and Usage Reports

You can create a new Cost and Usage Report (CUR) from the AWS console. For details, see [Creating reports](https://docs.aws.amazon.com/cur/latest/userguide/cur-create.html) in the AWS Data Exports User Guide.

When creating the report, use the following settings:

1. Under **Export details**, choose **Standard data export**.
2. For **Export name**, enter *billing-{your AWS account number}*. Replace *{your AWS account number}* with a valid AWS account ID.
3. Under **Data table content settings**, select **CUR 2.0**.
4. For **Additional export content**, select **Include resource IDs**. Leave the **Split cost allocation data** checkbox clear.
5. For **Time granularity**, choose **Hourly**.
6. Under **Data export delivery options**, do the following:
   1. For **Compression type and file format**, select **Parquet - Parquet**.
   2. For **File versioning**, select **Overwrite existing data export file**.
7. Under **Data export storage settings**, enter the **S3 bucket name** as *billing-export-{your AWS account number}*. Replace *{your AWS account number}* with a valid AWS account ID.
8. For the **S3 path prefix**, enter *reports* as your prefix.

The following image displays the recommended CUR settings:

<div data-with-frame="true"><figure><img src="/files/w0siHQ5NO1zWUKs5ZtsN" alt=""><figcaption><p>The recommended Cost and Usage Report settings.</p></figcaption></figure></div>


# Configure AWS Access

Configuring access to your AWS account for FinOps for Cloud requires the creation of two policies for billing imports and resource discovery, and a trusted role (recommended) or IAM user.

## AWS IAM Policies

FinOps for Cloud requires two policies, depending on the type of account being onboarded:

* **Billing import access policy** - This policy allows FinOps for Cloud to read cost and usage data from the configured S3 bucket. This policy is only required when you are onboarding an account that contains a cost and usage report.
* **Resource discovery access policy** - This policy allows FinOps for Cloud to discover new and changed resources in your AWS account more often than AWS updates the cost and usage reports. This allows FinOps for Cloud to show information about your spend that is more up-to-date than what is contained in the cost and usage report.

{% hint style="warning" %}
Note that any service control policies configured in your organization may prevent FinOps for Cloud from importing your data. For more information, read about [Service Control Policies](#service-control-policies) below.
{% endhint %}

### Create a policy for billing imports

The billing import access policy is only required for accounts with cost and usage reports configured for FinOps for Cloud.

A suggested name for the policy is `FinOpsForCloudBillingImport`.

{% hint style="warning" %}
In the following policy, be sure to replace `<bucket_name>` with a valid name of your S3 bucket.
{% endhint %}

{% code lineNumbers="true" %}

```json
{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Sid": "FinOpsForCloudGetBillingFiles",
            "Effect": "Allow",
            "Action": [
                "s3:GetObject"
            ],
            "Resource": "arn:aws:s3:::<bucket_name>/*"
        },
        {
            "Sid": "FinOpsForCloudManageBillingBucket",
            "Effect": "Allow",
            "Action": [
                "s3:GetBucketLocation",
                "s3:ListBucket",
                "s3:PutBucketPolicy",
                "s3:PutObject"

            ],
            "Resource": "arn:aws:s3:::<bucket_name>"
        }
    ]
}
```

{% endcode %}

### Create a policy for resource discovery

The resource discovery access policy is required for all accounts.

A suggested name for the policy is `FinOpsForCloudResourceDiscovery`.

{% code lineNumbers="true" %}

```json
{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Sid": "FinOpsforCloudGetResources",
            "Effect": "Allow",
            "Action": [
                "bcm-data-exports:GetExport",
                "bcm-data-exports:ListExports",
                "cloudwatch:GetMetricStatistics",
                "cur:DescribeReportDefinitions",
                "ec2:Describe*",
                "elasticloadbalancing:Describe*",
                "iam:GetAccessKeyLastUsed",
                "iam:GetLoginProfile",
                "iam:ListAccessKeys",
                "iam:ListUsers",
                "s3:GetAnalyticsConfiguration",
                "s3:GetBucketAcl",
                "s3:GetBucketLocation",
                "s3:GetBucketPolicy",
                "s3:GetBucketPolicyStatus",
                "s3:GetBucketPublicAccessBlock",
                "s3:GetBucketTagging",
                "s3:GetIntelligentTieringConfiguration",
                "s3:GetLifecycleConfiguration",
                "s3:GetMetricsConfiguration",
                "s3:GetObject",
                "s3:ListAllMyBuckets",
                "s3:ListBucket"
            ],
            "Resource": "*"
        }
    ]
}
```

{% endcode %}

## AWS IAM assumed role

### Creating a new IAM role

To create a new IAM role for FinOps for Cloud, see [Create a role using custom trust policies](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_create_for-custom.html) in the AWS IAM user guide.

When creating the role, use the following settings:

1. For **Trusted entity type**, choose **Custom trust policy**.
2. Under **Custom trust policy**, copy and paste the following trust policy:

{% code lineNumbers="true" %}

```json
{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Principal": {
                "AWS": "arn:aws:iam::654035049067:user/ffc-service-user"
            },
            "Action": "sts:AssumeRole"
        }
    ]
}
```

{% endcode %}

3. Select **Next**.
4. Under **Permissions policies**, select the following policies:
   1. `FinOpsForCloudResourceDiscovery` (always required)
   2. `FinOpsForCloudBillingImport` (required only for management or standalone accounts with cost and usage reports buckets)
5. Under **Set permissions boundary,** select **Create role without a permissions boundary**. Then, select **Next**.
6. Under **Role name**, enter `FinOpsForCloudAccessRole`. Then, enter your own optional description and add any tags you require.
7. Select **Create role**.

## AWS IAM user and access key

### Creating a new IAM user

To create a new IAM user for FinOps for Cloud, see [Create an IAM user in your AWS account](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_users_create.html) in the AWS IAM User Guide.

When creating the user, use the following settings:

1. For **User name**, enter `FinOpsForCloudUser`.
2. In **Provide user access to the AWS Management Console**, select **No**.
3. Under **Set permissions**, select **Attach policies directly**.
   1. `FinOpsForCloudResourceDiscovery` (always required)
   2. `FinOpsForCloudBillingImport` (required only for accounts with cost and usage reports buckets)

### Creating an access key for FinOps for Cloud

To create an access key for FinOps for Cloud, see [Create an access key for an IAM user](https://docs.aws.amazon.com/IAM/latest/UserGuide/access-keys-admin-managed.html#admin-create-access-key) in the AWS IAM User Guide.

When creating the access key, choose **Third-party service** as your use case.

{% hint style="warning" %}
Be sure to store your access key and secret access key securely. This is your only chance to view or download the newly created access key, as it cannot be recovered later.
{% endhint %}

## Service Control Policies

When onboarding an AWS datasource, **FinOps for Cloud** requires access to cost, usage, and resource data. This access is granted by attaching an IAM policy with the required permissions (Actions) to the IAM identity used by the assumed role.

In environments governed by AWS Service Control Policies (SCPs), it is important to understand how permission evaluation works:

* **SCPs apply at the organisation level** and define the maximum allowed permissions.
* **Explicit Deny statements in an SCP always override IAM permissions**, regardless of what is granted in the attached IAM policy.
* SCPs may restrict access based on conditions such as **AWS Region** or **calling identity**.

If an SCP denies any of the actions required for resource discovery, **FinOps for Cloud** will be unable to retrieve cost, usage, or resource information. This will result in incomplete or failed data ingestion.

### What you need to verify

To ensure successful onboarding and ongoing data collection:

* Confirm that the IAM identity used for the assumed role is **not restricted by SCP Deny rules** for any required actions.
* Review SCP conditions (e.g. region restrictions or principal constraints) that may unintentionally block access.
* Ensure that all required actions defined in the Resource Discovery IAM policy are **effectively allowed** after SCP evaluation.

If any required action is denied by an SCP, resource discovery will fail and **FinOps for Cloud** will not function as expected.


# Add your AWS account to FinOps for Cloud

The final step in configuring your AWS account for FinOps for Cloud is to add the AWS data source.

## Adding a management or standalone AWS account

The steps to add a management account or standalone account are similar.

* If you are adding a management account, choose the **Management** account type
* If you are adding a standalone account, or a member account without a management account, choose the **Standalone** account type.

When you add a management or standalone account, you must enter the details of the role to assume (or IAM user and access key) as well as the details of the billing export.

<figure><img src="/files/Ya6cKhpncpd3aa47Fb3M" alt=""><figcaption><p>Adding a management account to FinOps for Cloud using an assumed role</p></figcaption></figure>

## Adding a member AWS account

The steps to add a member account that already has its management account added to FinOps for Cloud are simpler.

<figure><img src="/files/buWF5a8XOr6RwNP6nsfi" alt=""><figcaption><p>Adding a member account to FinOps for Cloud using an assumed role</p></figcaption></figure>


# Switch from Access Key to Assumed Role

Using an assumed role to connect your AWS account to FinOps for Cloud is the recommended approach. Follow this guide to switch your existing AWS accounts using an access key to use an assumed role.

For more information on access keys vs assumed roles read our documentation here: [Amazon Web Services](/system/data-sources/amazon-web-services).

{% hint style="warning" %}
Switching from an access key to an assumed role is permanent. After you make this change, you can’t switch back to using an access key for this data source.

If you later want to use an access key again, you’ll need to delete the data source and recreate it with access key credentials. This will delete all existing data for this data source and require a full reimport of the resource and billing data.

If you are changing an AWS organizations management account, this will also affect the billing data of any member account data sources linked to that management account.
{% endhint %}

## How to switch from using an access key to an assumed role

{% stepper %}
{% step %}

### Create a new IAM role

If you're currently using access keys, you may not have configured an IAM role with a trust policy. To do this, follow the instructions under **Creating a new IAM role** on this page: [Configure AWS Access](/system/data-sources/amazon-web-services/configure-aws-access#aws-iam-assumed-role)
{% endstep %}

{% step %}

### Update your AWS data source in FinOps for Cloud

1. Navigate to **Data sources** in FinOps for Cloud
2. Click on the AWS data source you wish to change to an assumed role.
3. Click on **Update credentials** at the top right of the data source details screen.
4. Under the **Authentication** heading, toggle the authentication type to **Assumed role**.
5. Enter the name of your assumed role in the **Assumed Role Name** field.
6. Click **Save**.
   {% endstep %}
   {% endstepper %}

## What to expect after the change

Once you have switched from using an access key to an assumed role, the billing import and resource discovery for the account in question will continue uninterrupted.


# Migrate from Legacy CUR to CUR 2.0

If you connected an AWS data source using the Legacy CUR export schema and want to migrate to CUR 2.0, you will need to create a new CUR 2.0 report and then update the AWS data source within FinOps for Cloud.&#x20;

{% hint style="info" %}
You can create a new S3 bucket for the CUR 2.0 report or use your existing legacy CUR S3 bucket.

If you use your existing S3 bucket, you must specify a report prefix that is different from the one used for the legacy CUR report.
{% endhint %}

## Migrating from Legacy CUR to CUR 2.0

{% stepper %}
{% step %}
**Create a new CUR 2.0 report**

In the AWS Console, create an export of CUR 2.0 with its new schema.

See [Creating reports](https://docs.aws.amazon.com/cur/latest/userguide/cur-create.html) in the AWS Data Exports User Guide for the necessary steps.&#x20;

When creating the report, use the recommended settings in [Create Cost and Usage Reports](/system/data-sources/amazon-web-services/create-cost-and-usage-reports).&#x20;
{% endstep %}

{% step %}
**Update your existing data source in FinOps for Cloud**

When the report is ready, use the following steps to update your existing AWS data source in FinOps for Cloud:

1. Select the existing AWS data source on the **Data sources** page in FinOps for Cloud. The page with detailed information opens.
2. Select **Update credentials** to update the data source's credentials.
3. In **Update AWS cloud credentials**, do the following:
   1. Enable **Update data export parameters** to update the billing bucket information.
   2. Select **Standard data export (CUR 2.0)**
      1. If you used the same S3 bucket as your legacy CUR reports, update the **Export name** and **Export path prefix**.
      2. If you created a new S3 bucket for your CUR 2.0 reports, update the **Export name**, **S3 bucket name**, and **Export path prefix**.
   3. Select **Save** and wait for a new export to import.

<div data-with-frame="true"><figure><img src="/files/9oqpCDOILZD3PcTDRDhl" alt=""><figcaption><p>Migrate to CUR 2.0 and update the credentials.</p></figcaption></figure></div>
{% endstep %}
{% endstepper %}


# Request Historical Data

When you create a Cost and Usage Report in an AWS-linked account, the S3 bucket is automatically populated with data from the beginning of the current month.&#x20;

However, if the AWS account has existed for longer than this period, you can request a backfill of historical cost and usage data.

## Requesting a backfill of your cost data

To request a backfill of your historical data, create a support case with AWS.&#x20;

For information on how to open a support case and the information to include in your request, see the following link in the AWS Data Exports User Guide:

<https://docs.aws.amazon.com/cur/latest/userguide/troubleshooting.html#backfill-data>

## Performing a billing reimport in FinOps <a href="#perform-a-billing-reimport" id="perform-a-billing-reimport"></a>

To perform a billing reimport in FinOps for Cloud:

1. Navigate to the **Data sources** page.
2. Select the AWS data source containing the updated S3 bucket, then select **Billing reimport**.
3. In **Import from**, choose the start date of your historical billing data.
4. Select **Schedule import**.&#x20;

<div data-with-frame="true"><figure><img src="/files/wKjBDBGiVWkBzq0luG28" alt=""><figcaption><p>The option to reimport billing data.</p></figcaption></figure></div>

Once the import process has been initiated, it might take several hours for the process to complete, depending on the amount of historical data.&#x20;


# Microsoft Azure

Learn how you can add your Azure data sources to the FinOps for Cloud platform. FinOps for Cloud supports both Azure tenants and individual Azure subscriptions.

## Configuring your Azure data sources

### Add an Azure tenant

Adding an Azure tenant requires the creation of an app registration and the assignment of the Reader role to each Azure subscription.

To do this, follow these steps:

{% stepper %}
{% step %}
**Configure Azure Access**

1. [Create the app registration](https://docs.finops.softwareone.com/system/data-sources/microsoft-azure/configure-azure-access#create-the-app-registration)
2. [Create a client secret](https://docs.finops.softwareone.com/system/data-sources/microsoft-azure/configure-azure-access#create-a-client-secret)
3. [Assign the Reader role](https://docs.finops.softwareone.com/system/data-sources/microsoft-azure/configure-azure-access#assign-the-reader-role)
   {% endstep %}

{% step %}
**Add your tenant to FinOps for Cloud**

1. [Add your Azure tenant to FinOps for Cloud](https://docs.finops.softwareone.com/system/data-sources/microsoft-azure/add-your-azure-subscriptions-to-finops-for-cloud#adding-an-azure-tenant-to-finops-for-cloud)
2. [\[Optional\] Reimport historical billing data](https://docs.finops.softwareone.com/system/data-sources/microsoft-azure/import-historical-data#performing-a-billing-reimport-in-finops)
   {% endstep %}
   {% endstepper %}

### Add individual Azure subscriptions

Adding individual Azure subscriptions requires the creation of an app registration and the assignment of the Reader role to each Azure subscription.

To do this, follow these steps:

{% stepper %}
{% step %}
**Configure Azure Access**

1. [Create the app registration](https://docs.finops.softwareone.com/system/data-sources/microsoft-azure/configure-azure-access#create-the-app-registration)
2. [Create a client secret](https://docs.finops.softwareone.com/system/data-sources/microsoft-azure/configure-azure-access#create-a-client-secret)
3. [Find your Azure subscription IDs](https://docs.finops.softwareone.com/system/data-sources/microsoft-azure/configure-azure-access#create-a-client-secret)
4. [Assign the Reader role](https://docs.finops.softwareone.com/system/data-sources/microsoft-azure/configure-azure-access#assign-the-reader-role)
   {% endstep %}

{% step %}
**Add your tenant to FinOps for Cloud**

1. [Add your Azure subscriptions to FinOps for Cloud](https://docs.finops.softwareone.com/system/data-sources/microsoft-azure/add-your-azure-subscriptions-to-finops-for-cloud#adding-an-individual-azure-subscription-to-finops-for-cloud)
2. [\[Optional\] Reimport historical billing data](https://docs.finops.softwareone.com/system/data-sources/microsoft-azure/import-historical-data#performing-a-billing-reimport-in-finops)
   {% endstep %}
   {% endstepper %}

## Important

{% hint style="warning" %}
Adding the same Azure subscription by adding it under a tenant and also adding it individually will cause problems when importing billing data.
{% endhint %}


# Configure Azure Access

Configuring access to your Azure subscriptions for FinOps for Cloud requires the creation of an App Registration and assigning the Reader role in each subscription.

## Configure Azure for FinOps for Cloud

FinOps for Cloud requires an app registration to connect to your Azure subscriptions.

As you create your app registration, make a note of the following:

* Application (client) ID
* Directory (tenant) ID
* Client secret

Additionally, if you plan to add individual Azure subscriptions rather than the tenant itself, make a note of each Subscription ID to be added.

### Create the app registration

More information about creating app registrations can be found here: <https://learn.microsoft.com/en-us/entra/identity-platform/quickstart-register-app>

To create the app registration, follow these steps:

1. Sign in to the Azure Portal with a user that has enough permissions to create an app registration.
2. Browse to **Entra ID** > **App registrations** and select **New registration**.
3. Provide a name for the application. We recommend `FinOpsForCloud` .
4. Under **Supported account types**, select **Accounts in this organizational directory only**.
5. Select **Register** to complete the app registration.

On the app registration **Overview** page, make a note of:

1. The **Application (client) ID**.
2. The **Directory (tenant) ID**.

### Create a client secret

More information about creating a client secret can be found here: <https://learn.microsoft.com/en-us/entra/identity-platform/how-to-add-credentials?tabs=client-secret>

1. On the `FinOpsForCloud` app registration **Overview** page, expand the **Manage** menu on the left and click **Certificates & secrets**.
2. Select **New client secret** and add a description for your secret.
3. Select an expiration for the secret. SoftwareOne recommends setting an expiration value of less than 12 months.
4. Select **Add**.

Make a note of the client secret **Value** for use in FinOps for Cloud. This secret value is *never displayed again* after you leave this page.

### Find your subscription IDs

If you intend to add individual Azure subscriptions to FinOps for Cloud rather than a tenant, follow these steps to make a note of your subscription IDs.

1. In the top search field of the Azure Portal, search for **Subscriptions**.
2. For each subscription you wish to add to FinOps for Cloud, make a note of the ID in the **Subscription ID** column.

### Assign the Reader Role

When adding either individual Azure subscriptions or an Azure tenant to FinOps for Cloud, the Reader role in each subscription must be assigned to the app registration.

{% hint style="warning" %}
You must have **Owner** or **User Access Administrator** permissions on the subscription to assign roles.
{% endhint %}

1. In the top search field of the Azure Portal, search for **Subscriptions**.
2. For each subscription you wish to add to FinOps for Cloud, add the **Reader** role as follows:
   1. Select the specific subscription, then click on **Access control (IAM)** in the left menu.
   2. Click **+ Add** and select **Add role assignment**.
   3. On the **Role** tab, search for and select the **Reader** role.
   4. On the **Members** tab, set "Assign access to" to **User, group, or service principal**.
   5. Click **+ Select members**, search for `FinOpsForCloud`, and select it.
   6. Click **Review + assign** to finalize.

### Next steps

When you have completed these steps, you are ready to [Add your Azure subscriptions to FinOps for Cloud](/system/data-sources/microsoft-azure/add-your-azure-subscriptions-to-finops-for-cloud).


# Add your Azure subscriptions to FinOps for Cloud

The final step in configuring your Azure subscriptions for FinOps for Cloud is to add the Azure data source(s).

## Adding an individual Azure subscription to FinOps for Cloud

To add individual Azure subscriptions to FinOps for Cloud, follow these steps:

1. In FinOps for Cloud, navigate to **System** > **Data sources**.
2. Click **+ Add** and select **Azure**.
3. Under **Connection type**, select **Subscription**.
4. Enter the details record in the [Configure Azure Access](/system/data-sources/microsoft-azure/configure-azure-access) steps.
5. Repeat this process for each Azure subscription to be added.

## Adding an Azure tenant to FinOps for Cloud

To add an Azure tenant to FinOps for Cloud, follow these steps:

1. In FinOps for Cloud, navigate to **System** > **Data sources**.
2. Click **+ Add** and select **Azure**.
3. Under **Connection type**, select **Tenant**.
4. Enter the details record in the [Configure Azure Access](/system/data-sources/microsoft-azure/configure-azure-access) steps.
5. This step only needs to be performed once. FinOps for Cloud will automatically discover all configured Azure subscriptions in the tenant.

## Next steps

FinOps for Cloud will import billing data for the current and previous month. Microsoft stores up to 13 months of billing data. If you wish to import more historical data, follow the steps under [Import Historical Data](/system/data-sources/microsoft-azure/import-historical-data).


# Import Historical Data

Microsoft stores up to 13 months of billing data. Follow these steps to import it.

## Performing a billing reimport in FinOps

To perform a billing reimport in FinOps for Cloud:

1. Navigate to the **Data sources** page.
2. Select the Azure data source, then select **Billing reimport**.
3. In **Import from**, choose the start date of your historical billing data.
4. Select **Schedule import**.

Once the import process has been initiated, it might take several hours for the process to complete, depending on the amount of historical data.

{% hint style="info" %}
A billing reimport can only be started on individual Azure subscriptions. This functionality is not available to the parent tenant.
{% endhint %}


# Google Cloud Platform

This topic describes how to connect your Google Cloud Platform (GCP) account to SoftwareOne's FinOps for Cloud. When connecting your account, you will need to provide the billing data details, such as the dataset name and table name.

<figure><img src="/files/2eUp9eH99YjsIJG6sxpL" alt=""><figcaption><p>Google Cloud data source</p></figcaption></figure>

## Enabling billing export <a href="#enable-billing-export" id="enable-billing-export"></a>

To enable billing data export, see [Set up Cloud Billing data export to BigQuery](https://cloud.google.com/billing/docs/how-to/export-data-bigquery-setup) in the Google documentation.

After you have enabled billing data export, a new table is displayed in your BigQuery project.

Note the names of the dataset and the table. You'll need these details when connecting your cloud account to FinOps for Cloud.

<figure><img src="/files/7VVQQwxkbb41QVxiA55S" alt=""><figcaption><p>Billing export</p></figcaption></figure>

## Creating a role for FinOps for Cloud <a href="#prepare-a-role-for-optscale" id="prepare-a-role-for-optscale"></a>

You can create a role using Google Cloud CLI or Google Cloud Console:

{% tabs %}
{% tab title="Google Cloud CLI" %}
To assign the role via [gcloud CLI](https://cloud.google.com/sdk/gcloud), run the following command:

```
gcloud iam roles create optscale_connection_role --project=hystaxcom --permissions=bigquery.jobs.create,bigquery.tables.getData,compute.addresses.list,\compute.addresses.setLabels,compute.disks.list,compute.disks.setLabels,compute.firewalls.list,compute.globalAddresses.list,compute.instances.list,compute.instances.setLabels,compute.images.list,compute.images.setLabels,compute.machineTypes.get,compute.machineTypes.list,compute.networks.list,compute.regions.list,compute.snapshots.list,compute.snapshots.setLabels,compute.zones.list,iam.serviceAccounts.list,monitoring.timeSeries.list,storage.buckets.get,storage.buckets.getIamPolicy,storage.buckets.list,storage.buckets.update
```

{% endtab %}

{% tab title="Google Cloud Console" %}

1. Sign in to the [Google Cloud console](https://console.cloud.google.com/welcome).
2. In the Search bar, enter **Roles**, and then on the [Roles page](https://console.cloud.google.com/iam-admin/roles), click **Create Role**.
3. Provide the role title and description.
4. Click **Add permissions** and add the following permissions to the created role:
   * bigquery.jobs.create
   * bigquery.tables.getData
   * compute.addresses.list
   * compute.addresses.setLabels
   * compute.disks.list
   * compute.disks.setLabels
   * compute.firewalls.list
   * compute.globalAddresses.list
   * compute.instances.list
   * compute.instances.setLabels
   * compute.images.list
   * compute.images.setLabels
   * compute.machineTypes.get
   * compute.machineTypes.list
   * compute.networks.list
   * compute.regions.list
   * compute.snapshots.list
   * compute.snapshots.setLabels
   * compute.zones.list
   * iam.serviceAccounts.list
   * monitoring.timeSeries.list
   * storage.buckets.get
   * storage.buckets.getIamPolicy
   * storage.buckets.list
   * storage.buckets.update
5. Click **Add**.
6. Click **Create**.
   {% endtab %}
   {% endtabs %}

## Creating a service account <a href="#create-service-account" id="create-service-account"></a>

Learn about service accounts in the Google documentation - [Service accounts | IAM Documentation | Google Cloud](https://cloud.google.com/iam/docs/service-accounts).

To create a service account:

1. From your GCP console, select [Service Accounts ](https://console.cloud.google.com/iam-admin/serviceaccounts)in the left-hand menu and click **Create Service Account**.
2. Enter a service account name and optionally, enter a description of the service account.
3. Select **Create and continue**.
4. Select the [role you created](#prepare-a-role-for-optscale) and click **Continue**.
5. Select **Done**.

## Generating an API key for your service account <a href="#generate-api-key-for-your-service-account" id="generate-api-key-for-your-service-account"></a>

To generate an API key for your service account:

1. Find your service account in the service accounts list and click its name to go to the service account details page.
2. Go to the **Keys** tab.
3. Select **Add key** > **Create new key**.

The service account API key will be downloaded as a JSON file. Use this file when connecting your cloud account to FinOps.

## Connecting the data source in FinOps for Cloud <a href="#connect-data-source-in-optscale" id="connect-data-source-in-optscale"></a>

Use the newly downloaded service account credentials JSON file with the billing dataset details to connect your GCP cloud account. Next, click **Connect** to complete the setup.

<figure><img src="/files/mt9UI4e70TdhOVILE0Mr" alt=""><figcaption><p>Google Cloud data source</p></figcaption></figure>


# Manage Data Sources


# Reimport Billing

The **Billing Reimport** option is available on the details page of a data source in FinOps for Cloud.&#x20;

This feature allows you to manually reimport your billing data starting from a specific date into FinOps for Cloud. You can manually reimport data if:

* Your billing data has not been imported as expected.
* You have made configuration or permission-related changes that require reimporting data to reflect those updates.
* You need historical billing data from months that were not previously imported.&#x20;

## Performing a billing reimport

{% hint style="warning" %}
Before performing a billing reimport, note the following points:

* Importing billing data from the specified date overwrites the existing billing records. This can cause discrepancies or interruptions in current billing data.
* The reimport process is irreversible. Once the process has been initiated, it cannot be stopped. Additionally, the process could take some time to complete, depending on the amount of data.
* The new billing data will be imported during the next billing import report processing.
  {% endhint %}

To manually trigger a billing data reimport:

1. In FinOps for Cloud, navigate to the **Data sources** page.&#x20;
2. Select the desired data source.&#x20;
3. On the details page of the selected data source, select **Billing reimport**.
4. Choose the start date from which you want historical data imported, then select **Set**.
5. Select **Schedule import** to start the reimport process.

<figure><img src="/files/wKjBDBGiVWkBzq0luG28" alt=""><figcaption><p>Schedule import option.</p></figcaption></figure>


# Rename Data Source

The **Rename** option on the details page of a data source allows you to update the name displayed for that source.

## Renaming a data source

To rename a data source:

1. In FinOps for Cloud, navigate to the **Data sources** page.&#x20;
2. Select the data source you want to rename.
3. On the details page of the selected data source, select **Rename**.
4. Enter the new name, then select **Save**.&#x20;

The updated name is now displayed in FinOps for Cloud. Note that the previous data source name might still appear in historical data.


# Disconnect Data Source

The **Disconnect** option on the details page of a data source lets you disconnect and remove a data source from FinOps for Cloud.&#x20;

When a data source has been disconnected, you’ll only be charged for the days the data source was connected. Once it’s disconnected, billing will stop, and you won’t receive any further invoices.&#x20;

## Disconnecting a data source

{% hint style="warning" %}
Disconnecting a data source removes all historical data associated with that source.
{% endhint %}

To disconnect a data source from FinOps for Cloud:

1. In FinOps for Cloud, navigate to the **Data sources** page.&#x20;
2. Select the data source you want to disconnect.
3. On the details page of the selected data source, select **Disconnect**.
4. Select **Disconnect** again to confirm the action.


# Events

The **Events** page is a read-only page that allows you to view all events that have occurred within your organization.&#x20;

The data on this page is continuously updated, so you can monitor and track events in real time. You can view both system-generated and user-generated events. The following are examples of events:

* Discovery of new resources for cloud accounts.
* Automatic assignment of resources to a pool.
* Invitations sent to new account members.
* Resource discovery failures.

<figure><img src="/files/HXtZ9N2s9X5xaPLoG7VF" alt=""><figcaption><p>Events page in FinOps for Cloud.</p></figcaption></figure>

In addition to viewing a list of events, you can also search for a specific event, filter the events based on severity, and select an event to view detailed event information.

### Filtering events

By default, all events are displayed on the page.&#x20;

To filter the list of events, choose from one of these options: **Info**, **Warning**, or **Error**.&#x20;

Additionally, you can also use the date selector <img src="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAGAAAABgCAYAAADimHc4AAAD5UlEQVR4AeydsW4TQRRFPfwDBFHYruETQEg0SGmgS0H4gyjwLbjIF5CGVDRBdDR0NJSUawkpiG9Ay33yriJH3lnPvLFvsnvRPO96Z+689+7xoCiJlHsT/aM6IABU+ycTARAAsgPk9DoBAkB2gJxeJ0AAyA6Q0+/8BMxms3oWCXL/k1htNrfr+nYOYNcN3PX9xwngFlETADIMARAAsgPk9DoBAkB2gJzefQLwtfIhYjGfz7/ieoVY+7q/r7+b6/f9PqO+q6bXBWo97NP3zbsAoICPSHCJOK3r+iWuB4ihj4Om11M0etl4gNu8kQ0AiWukPEaMfRw3XmT5kAVgOp2+y8o2YFGuJ8kAkOhpCOHDgL3Mai3AE/MmVZwMAInepCZZrR/+a443yQBg42OExmYHkr3JAfBkc249hQPJ3uQAuI9EnaOqqlANODobX01EvVktWX/NAbC+g965HBAAl31+sQD4PXTtIAAu+/xiAfB76NpBAFz2+cUC4PcwukPfZHEA9p3BIUefoanzxQGkFjD29QJA/gQIgACQHSCn1wkQALID5PQ6AUMDMOSfBVhvpXnpBJR2NHG/YQJINIG5XACY7iO3AMAE5hAApvvILQAwgTkEgOk+ctMATKfTz/i5wW8Lu0ctScM0prWw+yQxFpvGtBZ2j0eUQQGApusQwit0/MjC7u0Z7rcattY0WEzRI2+xsXcAMO9TV/WxuVYTWxObK6Vv9yl13TsAFP4c0TVic60mtiY2V0rf7lPkygDwL1J5bK6VxdbE5krp232KXAsC2K6euq5/dK2MzbWa2JrYXCl9u0+p694BLJfL113Fx+ZaTWxNbK6Uvt2n1HXvAKzw5tu6F7j/08RF8wxv+0ezlqbvr3D7FRQAVh5MPEI8bOLInqUEdFR9Sq2xtTQAsaLGNCcAZNoCIABkB8jpdQIEgOwAOb1OgBOAVy4AXgedegFwGuiVC4DXQadeAJwGeuUC4HXQqRcAp4FeuQB4HXTqBcBpoFcuAF4HnXoBcBrold9NAN6ub5FeAMgwBEAAyA6Q0+sECADZAXL6nBNgv0zVWfYs8jfDhjDX2fhqIurNasn6azKAEMLP9S30rnUgZHiTDKCu619tQl3XHcjxJhkAUn5BaGx2INmbZABVVVmS8835R/30vPEmyYQEANf7ItHb63e6MwdyPckC0CQM+D/vvd2POcwDmB9yPcgGYAmXy+UCBTzD/RniG+IvYujDerRez6x388DTsAuAJUYB3/EJOEG8QDxADPrvB6A/69F6PbHezQNPuAF4kks7mQgA+VMgAAJAdoCcXidAAMgOkNPrBPQA2PX0fwAAAP//sASD/wAAAAZJREFUAwCxqpbup+p4xAAAAABJRU5ErkJggg==" alt="<svg xmlns=&#x22;http://www.w3.org/2000/svg&#x22; height=&#x22;24px&#x22; viewBox=&#x22;0 -960 960 960&#x22; width=&#x22;24px&#x22; fill=&#x22;#1f1f1f&#x22;><path d=&#x22;M320-400q-17 0-28.5-11.5T280-440q0-17 11.5-28.5T320-480q17 0 28.5 11.5T360-440q0 17-11.5 28.5T320-400Zm160 0q-17 0-28.5-11.5T440-440q0-17 11.5-28.5T480-480q17 0 28.5 11.5T520-440q0 17-11.5 28.5T480-400Zm160 0q-17 0-28.5-11.5T600-440q0-17 11.5-28.5T640-480q17 0 28.5 11.5T680-440q0 17-11.5 28.5T640-400ZM200-80q-33 0-56.5-23.5T120-160v-560q0-33 23.5-56.5T200-800h40v-80h80v80h320v-80h80v80h40q33 0 56.5 23.5T840-720v560q0 33-23.5 56.5T760-80H200Zm0-80h560v-400H200v400Zm0-480h560v-80H200v80Zm0 0v-80 80Z&#x22;/></svg>" data-size="line"> to choose a custom date range for the events you want to view.&#x20;

### Searching for an event

To search for a specific event, enter a keyword in the **Search** field and press **Enter**.

### Viewing event details

To view detailed information for an event, select the event.&#x20;

You can then view the date and time the event occurred, a description of the event, and details of the object involved in the event.


# Settings

The **Settings** page in FinOps for Cloud lets you view and manage your organization settings, account invitations, and email notifications.&#x20;

<figure><img src="/files/J5egr1iNKrqDiBxjkbyZ" alt=""><figcaption><p>Settings page within FinOps for Cloud</p></figcaption></figure>

* **Organization** - From this tab, you can retrieve and copy your organization ID and edit your organization name. You can also view the organization's currency. Note that you can connect only those data sources that match the organization's currency. This setting cannot be changed if at least one data source is already connected.
* **Invitations** - If you have any pending invitations to join an organization on the FinOps platform, those invitations are displayed on this tab. Use this tab to manage those pending invitations.
* **Email notifications** - Use this tab to configure email alerts. For details, see [Manage Email Notifications](/system/settings/manage-email-notifications).


# Manage Email Notifications

In FinOps for Cloud, you can customize your email notification settings to determine which notifications you want to receive to stay informed about important updates.&#x20;

The notifications are organized into various categories, including:

* **FinOps** - This includes weekly expense reports, pool limit alerts, and notifications for new saving opportunities.
* **Policy alerts** - This includes all policy-related alerts.
* **Recommendations** - This includes all savings and security recommendations.
* **System notifications** - This includes system status or operational messages.
* **Account management** - This includes notifications related to account invitations.

### Managing email notifications

To manage your email notifications:

1. Navigate to the **Settings** page, then select the **Email notifications** tab.
2. Select the arrow next to each category to expand it and view the individual notification types. A list of alerts appears, along with toggle switches to enable or disable them.
3. Use the toggle button to manage your preferences:
   * Purple (On) - You will receive email notifications.
   * Gray (Off) - You won't receive email notifications.

At the top of each category, a label shows how many alerts are active out of the total available (for example, **Active: 4/4**).&#x20;


# Contact Support

If you experience an issue with FinOps for Cloud, you can contact Marketplace Platform Support.

Our support team is here to assist you with any technical issues and troubleshoot errors you may encounter while using FinOps for Cloud.

### Describing your issue <a href="#describing-your-issue" id="describing-your-issue"></a>

When contacting us, we recommend that you provide as much detail as possible, including:

* The date and time when the issue started.
* The number of people affected by the issue.
* Your expected outcome.
* Your organization ID (available on the [Settings](/system/settings) page).
* If applicable, a screenshot or screen recording of the error message.

### Contacting Marketplace Platform Support <a href="#contacting-marketplace-platform-support" id="contacting-marketplace-platform-support"></a>

Marketplace Platform Support is available Monday to Friday, from 05:30 to 19:30 UTC.&#x20;

To create a support case:

1. [Sign in to your Marketplace account](https://portal.platform.softwareone.com/).
2. Select the help icon <i class="fa-circle-question">:circle-question:</i> in the header, then choose **Need help**.
3. In the guided **Add case** flow:
   1. If you are prompted to select an issue, select **Platform Support**, then select **Next**. If the flow opens at **Help resources**, continue to the next step.
   2. Review the suggested resources, including documentation. If you still need assistance, select **Next**.
   3. Enter a description of your issue, then select **Add**.

Your case is submitted to Marketplace Platform Support. You can view and track your case on the [Cases](https://docs.platform.softwareone.com/modules-and-features/helpdesk/cases) page in the Marketplace.

Alternatively, you can contact Marketplace Platform Support by email at <marketplace-support@softwareone.com>

We aim to acknowledge all support cases on the same day as they are submitted, within our core business hours. However, the response time may vary during busy periods.


# FAQs

This section contains answers to the most commonly asked questions about FinOps for Cloud.&#x20;

It covers key areas such as general product information, billing processes, invoicing, and data sources.&#x20;

<table data-card-size="large" data-view="cards"><thead><tr><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><strong>General FAQs</strong></td><td>Find answers to the common questions about, FinOps for Cloud, including setup, access, and more.</td><td><a href="/pages/n9cz6Kijpp4WKPHizRSY">/pages/n9cz6Kijpp4WKPHizRSY</a></td></tr><tr><td><strong>Billing and Invoicing FAQs</strong></td><td>Find answers to questions about pricing, invoices, billing cycles, and more.</td><td><a href="/pages/UBCOussZkMOyN1b6seEH">/pages/UBCOussZkMOyN1b6seEH</a></td></tr><tr><td><strong>Data Sources FAQs</strong></td><td>Find answers to questions about adding and managing data sources.</td><td><a href="/pages/FjYntsj3tfWkUTeHm5jT">/pages/FjYntsj3tfWkUTeHm5jT</a></td></tr></tbody></table>


# General

<details>

<summary>What is FinOps for Cloud?</summary>

SoftwareOne’s FinOps for Cloud helps businesses in optimizing their cloud spending by offering real-time insights, budget tracking, and cost management.  This solution allows you to allocate resources effectively, control expenses, and promote financial accountability across cloud environments.

FinOps for Cloud is built on the open-source project Optscale, developed by Hystax. For information on key features, see [Overview](/finops-for-cloud/overview).

</details>

<details>

<summary>How does FinOps for Cloud differ from Spend Management?</summary>

FinOps for Cloud is SoftwareOne's tool for managing cloud infrastructure, providing detailed insights into your cloud environment.&#x20;

If you have previously used SoftwareOne's Cloud Spend Management to oversee your cloud expenses, see [Comparing FinOps for Cloud and Spend Management](/finops-for-cloud/overview/comparing-finops-for-cloud-and-spend-management) to understand the key differences between the two services.

</details>

<details>

<summary>How do I order a FinOps for Cloud subscription?</summary>

You can order a FinOps for Cloud subscription from the SoftwareOne Marketplace Platform.

For details on how to place an order, see [Order FinOps for Cloud from Marketplace](https://docs.platform.softwareone.com/extensions/finops-for-cloud/order-finops-for-cloud-from-marketplace).&#x20;

</details>

<details>

<summary>How do I access the FinOps for Cloud platform?</summary>

You can access the platform using the **Sign In** option at the upper right on this help page, or using this link: <https://portal.finops.softwareone.com/>.

</details>

<details>

<summary>Do you offer a trial period for FinOps for Cloud?</summary>

When you place an order for a FinOps for Cloud subscription, you’ll automatically receive a 30-day trial at no cost.&#x20;

You’ll be notified via email 7 days before your trial ends, so you have time to decide whether to continue.&#x20;

If you want to extend your trial period, contact [Marketplace Platform Support](/help-and-support/contact-support).

</details>

<details>

<summary>How do I get started with FinOps for Cloud?</summary>

Use the following links to get started:&#x20;

1. [Order FinOps for Cloud from Marketplace](https://docs.platform.softwareone.com/extensions/finops-for-cloud/order-finops-for-cloud-from-marketplace)
2. [Access your organization](/finops-for-cloud/getting-started/access-your-organization)
3. [Get familiar with the user interface](/finops-for-cloud/getting-started/overview)
4. [Invite users to your organization](/finops-for-cloud/getting-started/invite-users-to-your-organization)
5. [Add a data source](/finops-for-cloud/getting-started/data-sources)

</details>

<details>

<summary>Which cloud providers can be monitored through FinOps for Cloud?</summary>

Currently, we support Amazon Web Services, Google Cloud Platform, and Microsoft Azure data sources.&#x20;

</details>

<details>

<summary>Who receives notifications for quotas, budgets, and other functionalities?</summary>

Notification emails are sent to individuals who have opted to receive alerts.&#x20;

These notifications can be managed from the **Settings** page. For more information, see [Manage Email Notifications](/system/settings/manage-email-notifications).

</details>

<details>

<summary>Can I download data from FinOps for Cloud?</summary>

You can download your resources, charts, and lists of users.

* To download your charts, use the **Export chart** option on the **Resources** page. The charts will be downloaded as PNG files. To learn more, see [Export chart](/policies/anomaly-detection/export-chart).
* To download your list of users, use the **Download** option on the **User Management** page. You can download the list as a spreadsheet or a JSON file. To learn more, see [Download Users](/system/user-management/download-users).
* To download the Cost Explorer data as a PDF, select the **Download** option on the **Cost Explorer** page. To learn more, see [Cost Explorer](/analysis/cost-explorer).

</details>

<details>

<summary>Can I rename my FinOps for Cloud organization?</summary>

Organization Managers can rename the organization from the **Settings** page in FinOps for Cloud.&#x20;

</details>


# Billing and Invoicing

<details>

<summary>How is FinOps for Cloud billed?</summary>

FinOps for cloud is billed monthly at a rate of 4% based on your selected billing currency. The billing cycle follows the calendar month.

Note that the 4% fee might be waived depending on your agreement with SoftwareOne.

</details>

<details>

<summary>Will I still be charged for FinOps for Cloud if I have an Essentials agreement with SoftwareOne?</summary>

If you have an Essentials agreement with SoftwareOne, your fee is waived in accordance with your agreement.&#x20;

This means that if your subscription falls under the Essentials agreement, you won't incur any additional charges. You will still receive an invoice, but the applicable fees will appear as credited, resulting in a total balance of $0.&#x20;

However, if you have connected data sources that are not included in your Essentials agreement, you will incur charges.

</details>

<details>

<summary>Will I be charged if I disconnect a data source from FinOps for Cloud?</summary>

You’ll only be billed for the days your data source is connected. Once you disconnect the data source, billing will stop, and you will no longer receive invoices.

{% hint style="warning" %}
Disconnecting a data source results in the loss of any historical data associated with it.
{% endhint %}

</details>

<details>

<summary>Where can I view my invoices?</summary>

You can view your invoices on the **Invoices** page in the Marketplace Platform. The page is located under **Billing** in the main navigation menu. To learn more, see [Invoices](https://docs.platform.softwareone.com/modules-and-features/billing/invoices).

FinOps for Cloud is billed monthly, typically on the 1st of each month or the next business day.

</details>

<details>

<summary>My Azure CSP subscriptions have been transferred from another partner to SoftwareOne. Will I incur any charges for these subscriptions?</summary>

Once your subscriptions are transferred, they must be synced to an active Microsoft Azure agreement in the Marketplace.&#x20;

During this process, your entitlements are created automatically, and the associated fee is waived. Note that the subscriptions that are transferred must be part of an Essentials agreement for the fee to be waived.

</details>

<details>

<summary>My SoftwareOne Cloud Spend agreement is valid until December 2025. Can I still move to FinOps for Cloud?</summary>

Yes, you can switch to FinOps for Cloud even if your Cloud Spend agreement is valid until December 2025. However, your data won't be migrated from Cloud Spend to FinOps for Cloud.

If you want to switch, you must place an order for a FinOps for Cloud subscription from the Marketplace Platform. For details on how to place an order, see [Order FinOps for Cloud from Marketplace](https://docs.platform.softwareone.com/extensions/finops-for-cloud/order-finops-for-cloud-from-marketplace).&#x20;

Once your order has been processed, you'll receive FinOps for Cloud at no additional charge until December 2025.

</details>

<details>

<summary>Why does the pricing in FinOps not match the SoftwareOne invoice?</summary>

SoftwareOne's FinOps for Cloud is designed to show your estimated costs for the current period, whereas billing management is only available when your SoftwareOne invoice has been issued.

There are a few reasons why the amounts in FinOps and your invoice will differ:

* All amounts displayed in FinOps for Cloud are estimates for the current period, so they won’t exactly match your invoice. These estimated amounts are provided so you can make informed decisions about budgeting and resource optimization proactively.
* Billing management presents data directly from your billing documents, such as invoices and statements. You can access this data only after these documents have been issued, and the amount will match exactly what is listed on your invoice.
* Your invoice is generated at the end of your monthly billing period, whereas FinOps data is updated daily, so you can proactively monitor expenses.
* Your FinOps account may show cost information from various cloud service providers, like Microsoft and AWS, whereas your invoice only contains subscriptions and items ordered through SoftwareOne Marketplace.

The following table summarizes these differences:

<table><thead><tr><th width="164">Component</th><th width="242">FinOps for Cloud</th><th width="249">SoftwareOne invoice</th></tr></thead><tbody><tr><td>Amount</td><td>Always shows the estimated amount for the current period.</td><td>Always shows the exact amount.</td></tr><tr><td>Subscriptions</td><td>Contains subscriptions from all connected cloud service providers.</td><td>Contains SoftwareOne subscriptions only.</td></tr><tr><td>Data availability</td><td>Available daily, even before the invoice has been issued.</td><td>Available monthly, only after the invoice is generated.</td></tr><tr><td>Other features</td><td>Offers enhanced features, like tagging policies and budgets.</td><td>Doesn't offer advanced analytics and monitoring.</td></tr></tbody></table>

To learn more about SoftwareOne invoices and billing documents, see [Understand Your Billing Documents](https://docs.platform.softwareone.com/modules-and-features/marketplace/billing/understand-your-billing-documents).

</details>


# Data Sources

<details>

<summary>How do I add a data source?</summary>

Data sources can be added using the **Add** option on the Data Sources page. For more details, see [Add Data Sources](/finops-for-cloud/getting-started/data-sources).

</details>

<details>

<summary>Are there any prerequisites to adding a data source?</summary>

Yes, adding a data source involves certain prerequisites depending on the type of source you want to add (Azure, AWS, or GCP). For specific details, see the following links:

* [Amazon Web Services](/system/data-sources/amazon-web-services)
* [Microsoft Azure](/system/data-sources/microsoft-azure)
* [Google Cloud Platform](/system/data-sources/google-cloud-platform)

</details>

<details>

<summary>I have connected my data source, but I can't view any cost or usage data.</summary>

This can occur due to a mismatch between the currency you selected when ordering the FinOps for Cloud subscription from the Marketplace and the currency used by your cloud provider for billing.

To avoid discrepancies, your organization currency must match the currency of the data source. Selecting a different currency may prevent the data source from being added or could result in no cost and usage data being displayed.

To resolve this issue, you must cancel your current agreement and create a new one with the correct currency. For more details, see the following links in the SoftwareOne Marketplace Platform documentation:

* [Order FinOps for Cloud from Marketplace](https://docs.platform.softwareone.com/extensions/finops-for-cloud/order-finops-for-cloud-from-marketplace)
* [Cancel Your FinOps for Cloud Order](https://docs.platform.softwareone.com/extensions/finops-for-cloud/cancel-your-finops-order)

</details>

<details>

<summary>What's the difference between terminating a FinOps for Cloud subscription vs disconnecting a data source?</summary>

If you choose to cancel your FinOps for Cloud subscription, you will no longer be able to sign in to FinOps for Cloud, and all of your data will be permanently deleted. For more details, see [Cancel Your FinOps Order](https://docs.platform.softwareone.com/extensions/finops-for-cloud/cancel-your-finops-order).&#x20;

Alternatively, if you remove a data source, only that specific data source will be affected. You’ll still have access to FinOps for Cloud and your other data sources. For removed data sources, you will be charged until the date of removal.

{% hint style="warning" %}
Removing a data source permanently deletes all historical data associated with it.
{% endhint %}

</details>

<details>

<summary>I have an Essentials agreement for Azure. Can I still add an AWS or GCP data source to FinOps for Cloud?</summary>

Yes, if you have an Essentials agreement for Azure, you can add your additional data sources, including AWS and GCP, to FinOps for Cloud.&#x20;

If your AWS account is covered under an AWS Essentials agreement, FinOps for Cloud is already included, so there’s no additional cost.&#x20;

For any other accounts not covered by an Essentials agreement, a standard 4% consumption fee might apply.

</details>

<details>

<summary>How do I onboard multiple subscriptions at once into FinOps for Cloud?</summary>

You can proceed with the tenant-level integration via data sources. However, you will still need to perform role assignment and grant the **Reader** role to each subscription.

To learn more, see [Microsoft Azure](/system/data-sources/microsoft-azure).

</details>

<details>

<summary>How does the Billing Reimport option work? </summary>

The **Billing Reimport** option is available on the details page of a data source.

Using this option, you can manually reimport your billing data starting from a specific date. Data can be reimported only if:

* Your billing data has not been imported previously as expected.
* You have made configuration or permission-related changes that require reimporting data to reflect those updates.
* You need historical billing data from months not previously imported.

For details on how to perform a billing reimport, see [Reimport Billing](/system/data-sources/manage-data-sources/reimport-billing).

</details>

<details>

<summary>How do I disconnect a data source?</summary>

To remove a data source, use the **Disconnect** option on the details page of a data source you want to remove. To learn more, see [Disconnect Data Source](/system/data-sources/manage-data-sources/disconnect-data-source).

</details>


# Release Notes

This page includes the latest enhancements, fixes, and new features in SoftwareOne’s FinOps for Cloud.

## Release Date: 3 February 2026

### Switch AWS data source from access key to assumed role

FinOps for Cloud now supports seamlessly updating an AWS data source from using an access key to an assumed role.

SoftwareOne and AWS strongly recommend using an assumed role.

{% hint style="warning" %}
Note: Switching from an access key to an assumed role is permanent. After you make this change, you can’t switch back to using an access key for this data source. For more information, see our [documentation](/system/data-sources/amazon-web-services/switch-from-access-key-to-assumed-role).
{% endhint %}

### Automatic configuration of AWS data sources discontinued

To strengthen our alignment with a read‑only operating model and least‑privilege security practices, FinOps for Cloud will **no longer offer the ability to&#x20;*****automatically*****&#x20;create AWS Cost and Usage Reports (CUR) or provision their associated S3 buckets**.

Administrative users must now **create and configure CUR exports and S3 buckets directly in AWS** before connecting them to FinOps for Cloud.

FinOps for Cloud continues to support **connecting to existing customer‑managed CUR exports** without requiring elevated permissions.&#x20;

***

## Release Date: 12 December 2025 <a href="#release-date-20-february-2025" id="release-date-20-february-2025"></a>

### Download Recommendations

You can now download insights directly from recommendation tiles, making it easier to export and share optimization suggestions.

### Fixes

* Removed all usages of the deprecated ADAL authentication library and upgraded all Microsoft authentication to MSAL. This is Microsoft's recommended library for all new development. Read about this more at [Microsoft Learn](https://learn.microsoft.com/en-us/entra/identity-platform/msal-migration).
* Minor improvements to **AWS Assumed Role** data source for better reliability.
* Various stability, reliability, and performance improvements.

***

## Release Date: 15 September 2025 <a href="#release-date-20-february-2025" id="release-date-20-february-2025"></a>

### Cost Map for Cloud Spend Analysis

Cost map is a new feature that offers a visual and interactive representation of your cloud spend across regions and cloud providers. The **Cost map** page includes two tabs:

* **Region** - This tab allows you to visualize your spending geographically across cloud deployments.
* **Network traffic** - This tab allows you to analyze costs associated with data transfer and connectivity.

Additionally, the Cost Explorer view now includes a new breakdown option called **Geography**, allowing you to analyze expenses by region.

### New Download Functionality

A new download option has been introduced to facilitate offline analysis, reporting, and integration with external tools. You can now download data from the following modules in FinOps for Cloud:

* **Resources** - Download your resource data as an Excel spreadsheet or JSON file. You can also download Charts as PNG files.
* **Cost explorer** - Download the data as a PDF.&#x20;
* **User management** - Export your list of users as an Excel spreadsheet or JSON file.&#x20;

### New Filters in Resource View

New filtering options are added to the [Resources](/insights/resources) page to help you narrow down and analyze cloud assets more effectively. You can now filter resources by:

* **Multi-select fields** - This allows you to select multiple values across key dimensions for more flexible filtering.
* **First seen date** - This allows you to identify newly discovered resources.
* **Last seen date** - This allows you to track resources that might have been removed or are inactive.

### Improved Email Formatting

We have enhanced the formatting of monetary values in all email communications.&#x20;

Currency values are now presented consistently for better readability and a reduced risk of misinterpretation, especially in automated alerts and summaries.

***

## Release Date: 15 May 2025 <a href="#release-date-20-february-2025" id="release-date-20-february-2025"></a>

### Global Availability

SoftwareOne's  [FinOps for Cloud](https://portal.finops.softwareone.com/) is a new solution designed to help you optimize costs and manage your resources effectively.&#x20;

With FinOps for Cloud, you can explore and analyze your cloud expenses, monitor resource usage, and implement policies to ensure efficient and cost-effective cloud management. With a user-friendly interface and robust features, the solution provides greater visibility and control over cloud infrastructure. Use the left sidebar to learn more about these features in detail.


# Terms of Use

Please read these terms of use carefully.

Welcome to SoftwareOne’s FinOps for Cloud! Please read this agreement (**“Agreement”**) carefully before using the FinOps for Cloud Services or website. The FinOps for Cloud Software as a Service (**“SaaS”**) license granted by this Agreement is conditioned upon the organization identified within the Interface (**“Company”**) having executed a software purchase or other service agreement (**“Contract”**) with SoftwareOne AG or one of its affiliates (**“SoftwareOne”**) and allows Company to use the Services, associated software, and Interface for the purposes stated in this Agreement and the Contracts.

If your Company does not have a Contract with SoftwareOne, then your Company does not have a license to the Services. If you or your Company has been provided access to the Services without a Contract with SoftwareOne, then do not use the Services and contact SoftwareOne immediately using the information found at <https://www.softwareone.com/en/contact-us>.

**Last updated: 7 May 2025**

By clicking “I Accept” in an electronic version of this Agreement, or making any use of the Services or Interface you are accepting the terms and conditions of this Agreement on behalf of your Company and you are representing that you have full legal authority to accept this Agreement on behalf of your Company. If you do not agree to the terms of this Agreement, or do not have the necessary authority to bind your Company, do not use the Services or Interface and contact SoftwareOne regarding the Contracts.

This Agreement is entered into on the date that it is accepted and is between Company and SoftwareOne. This Agreement contains the terms and conditions that govern Company’s access to and use of the Services and Interface for the purpose submitting and managing Content. **“Content”** means all information, data, files, software, code, text, images, photographs, graphics, e-mail addresses, web pages, reviews, discussion board postings and other materials uploaded or transmitted to SoftwareOne. **“Interface”** means SoftwareOne’s online application that allows Users to interact with the Services for the sole purposes of managing your Content, and utilizing SoftwareOne’s services described in the Interface or the Contracts. **“Services”** means: (i) SoftwareOne’s FinOps for Cloud SaaS, together with its Interface and Software, and any modifications, improvements, or updates to any of the forgoing; (ii) any additional services selected by Company within the Interface.

## **1. Using the FinOps for Cloud Services**

The Services are made available to achieve and manage the purposes described in the Contracts and to create, manage and submit Content. The Organization Manager must be at least eighteen (18) years of age to enter into this Agreement and open a FinOps for Cloud account with SoftwareOne. Once an authorized representative of Company creates the FinOps for Cloud account and identifies an initial Organization Manager, SoftwareOne will generate the Organization Manager’s login credentials and Company will be responsible for all activities occurring under its FinOps for Cloud account. The Organization Manager, and each User are responsible for keeping their respective account user names and passwords safe and secure. Users shall not share their login credentials with anyone. SoftwareOne may refuse any request to open an account for any reason. Certain Services may require the acceptance of additional terms or license agreements (**“Additional Terms”**), which will be presented to the Organization Manager within the Interface or another form, as SoftwareOne deems appropriate prior to the purchase of such Services. Upon acceptance, the Additional Terms will become part of this Agreement as if set forth in full herein. SoftwareOne may send Users announcements, administrative messages, and other information. Each individual User may opt out of some of those communications if they are not essential to the delivery of the Services. The type of Services available will be set by SoftwareOne and a Organization Manager and each User’s access to the Services is dependent upon the permissions role as set by the Organization Manager. **“Organization Manager”** means an employee of Company that has the authority and permission to edit user access, rights, and capabilities. **“User”** means an employee of Company that is authorized to use the Services by the Organization Manager. References to a User and Users herein include the Organization Manager.

The Organization Manager shall notify SoftwareOne if

* any User of the Services leaves the employment of Company
* Company wishes to remove any of Company’s designated Users from the Services. A Organization Manager may block, but not remove a Company user from accessing the Services.

## **2. Prohibited Activities**

Company shall ensure that each User of the Services and Interface use them only for lawful purposes and consistent with the terms of this Agreement; by way of example, the following are prohibited:

* Uploading or transmitting Content that violates or promotes the violation of, any applicable law, rule or regulation;
* Uploading or transmitting Content that promotes violence or contains violent materials;
* Uploading or transmitting Content that infringes the intellectual property or proprietary rights of others, including patent, copyright, trademark and trade secret rights;
* Uploading or transmitting Content that is unlawful, libelous, defamatory, obscene, pornographic, indecent, lewd, harassing, threatening, harmful, invasive of privacy or publicity rights, abusive, inflammatory, or otherwise objectionable;
* Uploading or transmitting harmful Content, including viruses, trojan horses, worms, time bombs, cancelbots, or any other computer programming routines that may damage, interfere with, surreptitiously intercept, or expropriate any system, program, data, or personal information;
* Uploading or transmitting Content that promotes discrimination or employs discriminatory practices based on race, sex, religion, nationality, sexual orientation, or age;
* Uploading or transmitting Content offering or disseminating fraudulent goods, services, schemes, or promotions (for example, make-money-fast schemes, chain letters, pyramid schemes);
* The use of the Services for commercial purposes, other than Company’s internal purposes or to receive the benefits under the Contracts; and
* Using the Services to impersonate any person or entity, including the forging of an electronic mail message.

Company is responsible for use of the Services and Interface by its employees, independent contractors, and other representatives. SoftwareOne may suspend or cease providing access to the Services if Users do not comply with SoftwareOne’s requirements or if SoftwareOne is investigating suspected misconduct.

## **3. Content in Our Services**

**Third Party Content.** The Services display some material that is not the property of SoftwareOne (e.g. maps). This material is the sole responsibility of its owner. SoftwareOne may review third party material to determine whether it is illegal or violates our policies, and may remove or refuse to display what it reasonably believe violates our policies or the law.

**Company Content.** The Services allow Users to submit and manage Content for use as provided in the Interface and Contracts. Company retains all right, title and interest in all Content that Users upload into the Services. When a User uploads or otherwise submits Content to the Services, Company hereby grant SoftwareOne a perpetual, worldwide, royalty free, fully paid up license to use, host, store, reproduce, modify, create derivative works from, communicate, sub-license, update, display and distribute (to Company and its authorized users of the Services) such Content to: (i) perform any requirement stated in the Interface and the Contracts; (ii) allow SoftwareOne to perform and improve the Services; (iii) to develop new services. If the Content contains any confidential information it will be maintained pursuant to the confidentiality provisions of the Contract. By submitting Content to SoftwareOne, Company represents and warrants that it has all necessary rights and authorizations to do so. SoftwareOne may reject Content if it determines that it is unsuitable for any reason. SoftwareOne may use, reproduce, sell, publicize, or otherwise exploit Aggregate Data in any way. **“Aggregate Data”** means Content that has been anonymized to remove personally identifiable information, Company identifying information, including the names and addresses of Company and any of its Users or customers.

**Risk of Exposure.** Company recognizes and agrees that storing Content online involves risks of unauthorized disclosure or exposure and that, in accessing and using the Services, Company assumes such risks. SoftwareOne offers no representation, warranty, or guarantee that Content will not be exposed or disclosed through errors or the actions of third parties.

**Accuracy of Content.** SoftwareOne will not be responsible and liable for the accuracy of Content uploaded to the Services.

**Deletion of Content.** SoftwareOne may permanently erase Content if: (i) Company’s account is delinquent, suspended, or terminated for 30 days or more; or (ii) Company breaches this Agreement or any Contract.

## **4. Limited License, Ownership, Obligations and Proprietary Rights**

**Limited License.** The use of the Services may require the use of downloadable and non-downloadable software (**“Software”**) that is the property of SoftwareOne or its licensors. During the term of this Agreement, SoftwareOne hereby grants Company a limited, non-assignable, non-sublicenseable, non-exclusive, license to use the Software through the Interface for the sole purpose of using the Services and submitting Content. This license will immediately and automatically terminate: (i) if Company fails to comply with its obligations under this Agreement or a licensor’s licensing terms at any time; or (ii) upon the termination of this Agreement.

**Obligations & Restrictions.** Company is solely responsible for its use of the Services and Interface, including any Content submitted thereto. Company shall only use the Services, for Company’s internal business purposes and in compliance with this Agreement, any access instructions contained on within the Interface, and all applicable local, state, national and international laws, rules, and regulations. Company shall not: (i) improperly access or tamper with the Services; (ii) attempt to interfere with or disrupt the Services, or Interface for any other user; (iii) license, sublicense, sell, resell, transfer, assign, distribute, or otherwise commercially exploit the Services or make them available to any third party in any way or use the Services for service bureau or time-sharing purposes or in any other way allow third parties to exploit the Services; (iv) modify or make derivative works based upon the Services; (v) create internet “links” or “frame” or “mirror” any Content of the Services, on any other server or wireless or internet-based device; (vi) translate, reverse engineer, disassemble, decompile, recompile, update, or modify all or any part of the Services; (vii) allow any other party to use or access the Services without the express written consent of SoftwareOne; (viii) attempt to gain unauthorized access to the Services; (ix) make any other use of the Services that is contrary to the terms of this Agreement or any Contract; or (x) access the Services in order to build a competitive product or service, to build a product using similar ideas, features, functions or graphics of the Services, or to copy any ideas, features, functions or graphics of the Services.

**Reservation of Rights.** Except for the limited licenses granted in section 4(a), SoftwareOne hereby reserves all right, title and interest (including all intellectual property and proprietary rights) in and to the Services. If Company communicates any ideas or suggestions (**“Feedback”**) to SoftwareOne, SoftwareOne will own all right, title and interest in and to such Feedback and will be entitled to use it without restriction. Company hereby irrevocably assign all right, title and interest in and to such Feedback to SoftwareOne and shall provide SoftwareOne with such assistance as SoftwareOne may reasonably require to document, perfect or maintain its rights in and to such Feedback.

## **5. Fees & Taxes**

Any fees for the Services are stated either within the Interface or the applicable purchase order and invoice between SoftwareOne and Company. Modification to the Services beyond the scope of the applicable purchase order and invoice may result in an additional charge to Company. The fees exclude all applicable sales, use, and other taxes (other than taxes on SoftwareOne’s income), duties, charges, and related fees and penalties in each case arising from any payments to be made to SoftwareOne under this Agreement (collectively, **“Taxes”**), and Company will be responsible for payment of all Taxes. Company shall make all payments of fees to SoftwareOne free and clear of, and without reduction for, any withholding taxes; any such taxes are the sole responsibility of Company, and Company shall provide SoftwareOne with official receipts issued by the appropriate taxing authority, or such other evidence as SoftwareOne may reasonably request, to establish that such taxes have been paid. Fees are non-refundable upon the termination of this Agreement by Company. If SoftwareOne terminates this Agreement for any reason other than a breach of the Agreement by Company, then SoftwareOne will refund any prepaid fees for the remaining term of the Services. Any such refund will be paid within forty-five (45) days of SoftwareOne’s notice of termination.

## **6. Confidentiality**

**Confidential Information.** **“Confidential Information”** means non-public information of a competitive or commercially sensitive, proprietary, financial, or trade secret nature, or information that involves or implicates privacy interests. Confidential Information includes any information labeled “Confidential” or “Proprietary”, business plans, strategies, forecasts, analyses, financial information, employee information, technology information, trade secrets, products, technical data, specifications, documentation, rules and procedures, methods, contracts, presentations, know-how, product plans, business methods, product functionality, data, customers, markets, competitive analysis, databases, formats, methodologies, applications, developments, inventions, processes, payment, delivery and inspection procedures, designs, drawings, algorithms, formulas or information relating to engineering, marketing, or finance and any other information that the Recipient should reasonably believe to be confidential given the circumstances.

**Exclusions from Confidentiality.** Confidential Information excludes information that: (i) is known by the Recipient prior to its receipt; (ii) is now or becomes publicly known by acts not attributable to the Recipient; (iii) is disclosed to Recipient by a third party who has the legal right to make such a disclosure; (iv) is disclosed by the Recipient with Discloser’s prior written consent; (v) is subsequently developed by the Recipient independently of any disclosures made hereunder and without use or access to any of the Discloser’s Confidential Information; or (vi) is required to be disclosed pursuant to governmental regulation or court order.

**Confidentiality Obligations.** Each party acknowledges that certain information it will receive from the other party may be Confidential Information of the other party. Any party receiving Confidential Information (**“Recipient”**) shall exercise the same degree of care and protection with respect to the Confidential Information of the party disclosing Confidential Information (**“Discloser”**) that it exercises with respect to its own Confidential Information, but in no event less than a reasonable standard of care. Recipient and its Personnel may only use Discloser’s Confidential Information to the extent necessary to fulfill its obligations under this Agreement during the term hereof. The Recipient shall not, directly or indirectly, disclose, copy, distribute, republish or allow any third party to have access to any Confidential Information of the Discloser.

**Injunctive Relief.** Each party acknowledges that any violation of its obligations relating to Confidential Information, and Services would result in damages to the other party that are largely intangible but nonetheless real, and that cannot be remedied by an award of damages. Accordingly, any such violation will give the other party the immediate right to a court-ordered injunction or other appropriate order to enforce those obligations. A party’s right to injunctive relief is in addition to any other rights and remedies available to such party at law and in equity. The prevailing party obtaining injunction will be entitled to recover all reasonable expenses, including attorney fees, incurred in obtaining such enforcement.

## **7. Copyrights, Privacy and Data Protection**

**Copyrights.** SoftwareOne respects the intellectual property rights of others and expects Users to do the same. SoftwareOne will respond to notices of alleged copyright infringement and terminate accounts of repeat infringers according to the process set out in the US Digital Millennium Copyright Act. Copyright concerns should be delivered to <legal@softwareone.com>.

**Privacy.** SoftwareOne is committed to protecting the privacy of our customers. Information SoftwareOne collects from Users is used solely for purposes of managing our relationship with Company or as otherwise provided in SoftwareOne’s Privacy and Security Policy, a copy of which can be viewed here <https://www.softwareone.com/en/privacy-statement>. By using the Services, Company represents and warrants that it has obtained all necessary permissions for SoftwareOne to use personal data of Users in accordance with our Privacy and Security Policy.

**Data Protection.** SoftwareOne acknowledges and agrees that it has appropriate experience and capabilities, and will implement appropriate technical and organizational measures, to ensure that the processing of personal data by Company in the course of providing the Services will meet such requirements of the applicable data protection laws and regulations as apply to SoftwareOne in its capacity as a data processor, provided always that Company acknowledges and agrees that SoftwareOne shall not be in breach of this clause where any failure to comply with data protection laws and regulations is caused by or results from the acts or omissions of Company, its officers, employees or agents.

**How SoftwareOne Uses "Cookies."** SoftwareOne uses a feature on an internet browser called a "cookie." Cookies are small files that a web browser places on a computer's hard drive. SoftwareOne uses cookies to let it know that a User has an account with SoftwareOne, and is authorized to use Services. SoftwareOne may also use cookies to retrieve certain information Users have previously provided so that they do not need to re-enter this information every time. Cookies are not used to access information entered on the secure server. This information can only be accessed when a User enters their username and password.

**Security.** A User’s personal information, such as name, address, phone, email, or credit card number, is never stored in a cookie. It is stored on SoftwareOne’s secure server, and is not available to any other site.

## **8. Term and Termination**

The term of this Agreement will begin upon acceptance of this Agreement and will end when terminated by either Company or SoftwareOne. Company may terminate this Agreement at any time and for any reason by providing SoftwareOne with written notice. SoftwareOne may terminate this Agreement and all User accounts for any reason or no reason, without notice. This Agreement will automatically terminate, without notice, upon termination of the Contracts between SoftwareOne and Company. Upon any termination of this Agreement, Company shall immediately cease all use of all the Services and Interface. Any provisions that would, by their nature, survive the termination or expiration of this Agreement will so survive, including Sections 3, 4(e), 6, 7, 10, 11, 12, 14, 15 and 16.

## **9. Modification**

SoftwareOne may change or improve the Services, including adding or removing functionalities and features, or suspend or stop the Services completely. Company may stop using the Services at any time. SoftwareOne may stop providing the Services or add or create new limits to the Services at any time. If SoftwareOne suspends Services that contain Content, it will provide Company with reasonable advance notice to allow it to remove that Content from that particular Service. Due to things like changes in the law or technology, SoftwareOne may modify the terms and conditions contained in this Agreement at any time by posting a change notice within the Interface. SoftwareOne may also require Company to accept an updated version of this Agreement reflecting such modified terms and conditions. If any modification is unacceptable Company’s only recourse is to terminate this Agreement. Company’s continued use of the Services following any posting of a change notice or revised Agreement will constitute binding acceptance of the revisions.

## **10. Representations and Warranties**

Each party represents that it has all necessary right, power and authority to enter into this Agreement and that upon Company’s acceptance it will create a binding contract between the parties. Company represents and warrants that: (i) it is the owner or authorized licensee of all Content uploaded or transmitted to the Services; (ii) Company has all necessary rights to grant the Content license to SoftwareOne; (iii) the submission of Content does not violate the intellectual property rights of any third party; (iv) that each User is at least eighteen (18) years of age; (v) all Content uploaded or transmit using the Services is complete, accurate and correct; and (vi) Company and its Users will comply with all applicable laws, rules, and regulations in the use of the Services.

## **11. Indemnification**

Company shall indemnify SoftwareOne, including its employees, officers, directors and agents for all losses and liabilities, including reasonable attorneys’ fees and costs, arising from any of the following: (i) Company’s breach of any of its representations, warranties or obligations under this Agreement; (ii) Company’s use of the Services, including the use of Services by Company’s authorized users in violation of this Agreement; and (iii) any claim that the Content infringes any patent, copyright, trademark, trade secret, or other proprietary right. SoftwareOne shall indemnify Company, including its employees, officers, directors and for all losses and liabilities, including reasonable attorneys’ fees and costs, arising from any claim alleging that the Services infringe any patent, copyright, trademark, trade secret or other proprietary right. The forgoing indemnification is conditioned upon the indemnified party: (a) providing the indemnifying party with timely written notice of the applicable claim; (b) tendering the exclusive control over the defense and settlement of the claim to the indemnifying party; and (c) cooperating with the indemnifying party in the defense and settlement of the claim at the indemnifying party’s expense.

## **12. Disclaimers and Limitation of Liability**

SoftwareOne cannot and does not warrant, verify, or guarantee the quality, accuracy, or integrity of Content uploaded or transmitted to the Services. Company is solely liable for all Content. SoftwareOne makes no representation or warranty that it will review any of the Content for accuracy. Company’s access to and use of the Services is at its own risk. The Services are licensed as a service on an “AS IS” and “AS AVAILABLE” basis. SOFTWAREONE HEREBY DISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, OF TITLE, MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, OR NON-INFRINGEMENT. WITHOUT LIMITING THE GENERALITY OF THE FORGOING, SOFTWAREONE MAKES NO WARRANTY THAT: (I) THE SERVICES WILL MEET COMPANY’S REQUIREMENTS; OR (II) THE SERVICES BE AVAILABLE ON AN UNINTERRUPTED, SECURE OR ERROR-FREE BASIS.

TO THE MAXIMUM EXTENT PERMITTED BY LAW, SOFTWAREONE WILL NOT BE LIABLE FOR ANY SPECIAL, EXEMPLARY, PUNITIVE, CONSEQUENTIAL, INCIDENTAL OR INDIRECT DAMAGES, OF ANY KIND, INCLUDING LOST PROFITS, BUSINESS INTERRUPTION, LOSS OF BUSINESS OPPORTUNITY, OR GOODWILL, OCCASIONED BY THE BREACH OF ANY OBLIGATION UNDER THIS AGREEMENT FOR ANY CAUSE WHATSOEVER, WHETHER FORESEEABLE OR NOT, ON ANY THEORY OF LIABILITY EVEN IF SOFTWAREONE HAS BEEN NOTIFIED OF THE POSSIBILITY OF SUCH DAMAGE, AND NOTWITHSTANDING THE FAILURE OF THE ESSENTIAL PURPOSE OF ANY REMEDY SPECIFIED IN THIS AGREEMENT. SOFTWAREONE’S MAXIMUM TOTAL LIABILITY TO COMPANY FOR USE OF THE SERVICES WILL BE EQUAL TO THE TOTAL AMOUNT PAID BY COMPANY DURING TWELVE MONTHS LEADING UP TO ANY CLAIM.

Some jurisdictions do not allow for certain limitations on liability, so the above may not apply to Company.

## **13. Relationship of the Parties**

The parties are independent contractors. Nothing in this Agreement creates any partnership, joint venture, agency, franchise, or employment relationship between Company, and SoftwareOne. Company has no authority to make or accept any offers or representations on SoftwareOne’s behalf.

## **14. Disputes**

In case of any controversy or dispute, SoftwareOne and Company shall discuss the matter in controversy or dispute and make a diligent effort to find an amicable solution. If an amicable solution is not reached, all disputes arising out of or in connection with this Agreement or its validity will be finally resolved by the courts of the state/country in which the offices of the SoftwareOne affiliate entering into the Contract are located. The United Nations Convention on the International Sales of Goods will not apply to these Terms or any Contract. SoftwareOne may obtain injunctive or other relief in any state, federal or national court of competent jurisdiction for any actual or alleged infringement of its intellectual property or proprietary rights. The Services are of a special, unique and extraordinary character which gives them a particular value to SoftwareOne that cannot be readily estimated and may not be adequately compensated for in monetary damages alone. Accordingly, in additional to all other remedies available at law or in equity, SoftwareOne will be entitled injunctive or equitable relief if Company breaches this Agreement.

## **15. Export Restrictions**

The Services may be subject to the export control regulations of the U.S., Switzerland and the European Union. Company shall not use the Services or otherwise transfer, export or them or access thereto to countries against which the United States, Switzerland, or the European Union maintains an embargo (collectively, **“Embargoed Countries”**), or to or by a national or resident thereof, or any person or entity on a list of specially designated nationals (collectively, **“Designated Nationals”**). The lists of Embargoed Countries and Designated Nationals are subject to change without notice. Company hereby represents and warrants that it is not located in, under the control of, or are a national or resident of an Embargoed Country; that its Users are not Designated Nationals; and that it shall comply strictly with all U.S., Swiss, and European Union export laws, and assume sole responsibility for obtaining licenses to export or re-export as may be required.

## **16. Miscellaneous**

There are no third party beneficiaries to this Agreement. Company shall not assign this Agreement without SoftwareOne’s prior written consent. This Agreement, together with the Contract and any other agreements for additional services accepted within the Interface, represent the entire agreement of the parties regarding the subject matter hereof. SoftwareOne’s failure to enforce any provision of this Agreement will not act as a waiver to enforce the same or any other provision in the future. SoftwareOne may provide Company with notices under this Agreement by delivering them to the electronic mail address listed within the interface.


# Open Source

At SoftwareOne, we believe in the power of open source. Open source communities drive innovation, foster transparency, and accelerate progress through shared knowledge and collaborative development. This belief has shaped the foundation of our latest FinOps tool, [FinOps for Cloud](https://portal.finops.softwareone.com/), which is built on top of the open-source project [OptScale](https://github.com/hystax/optscale) developed by [Hystax](https://hystax.com/).

### Built on OptScale, Powered by Partnership

FinOps for Cloud represents a key step in SoftwareOne’s commitment to delivering powerful, user-centric tools for cloud financial operations. By leveraging OptScale, an advanced open source platform for cloud cost management and optimization, we are able to accelerate value delivery to our customers while aligning with a growing and active open source ecosystem.

Our collaboration with Hystax has been instrumental in bringing this vision to life. We are deeply grateful for the open and cooperative relationship we enjoy with their team, and we recognize the high-quality foundation their work on OptScale provides. As part of this collaboration, SoftwareOne is proud to contribute back to the OptScale project and support its continued evolution.

### Our Approach to "FinOps for Cloud"

The initial release of FinOps for Cloud focuses on delivering core capabilities that empower organizations to gain visibility into cloud usage and manage costs effectively. While this version does not yet include the full suite of features available in OptScale, it has been designed with scalability and extensibility in mind.

As we continue to evolve our FinOps strategy and product roadmap, we are actively evaluating additional OptScale capabilities and assessing how best to bring them to our users. Our intent is to provide a balanced experience that meets enterprise needs while remaining tightly aligned with the open source project's development.

### Looking Ahead

SoftwareOne remains committed to fostering open source collaboration. Our work with [Hystax](https://hystax.com/) and the [OptScale](https://github.com/hystax/optscale) community is just the beginning. By contributing code, sharing feedback, and engaging with the broader community, we aim to support and extend the ecosystem that enables cost-efficient, cloud-native operations for organizations around the world.

We look forward to continuing this journey and invite our partners, customers, and the open source community to join us as we build the future of FinOps together.


