How it works

Connect once, read-only

You create the access yourself with a template or script you can read first. We never install anything or change anything in your cloud.

  1. 1

    Create your account

    Sign up with your work email. You get 50K free tokens — no credit card.

  2. 2

    Connect a cloud

    AWS: launch our CloudFormation template (one click) and paste back the role it creates. Azure: sign in with Microsoft and have an admin approve read-only access. Google Cloud: run one command in Cloud Shell.

  3. 3

    See cost and security

    Security data appears within minutes. Cost data appears once your billing export has delivered — usually within 24 hours of creating a new export.

  4. 4

    Ask the copilot

    Ask questions in plain English. Each answer is charged in tokens at what it actually cost to produce; dashboards are free.

Security

Exactly what we can read

Taken from our CloudFormation templates, the Azure consent screen and our Google Cloud setup script.

AWS

You launch our CloudFormation template in your own account. It creates an IAM role named anycloud2bi-reader that only our service’s role can assume, and only with an External ID unique to your workspace. You can read the template before launching it; its SHA-256 is shown in the app.

Read-only access

  • List and read objects in the Cost and Usage Report (CUR 2.0) bucket and prefix — nothing else in S3
  • Read-only cost APIs: Cost Explorer, Compute Optimizer, Cost Optimization Hub, Budgets, Pricing, Free Tier, Invoicing (list and download invoices), Billing recommended actions, Data Exports and CUR definitions
  • Read tags, resource groups and CloudWatch metrics
  • Describe EC2 instances, RDS DB instances and SageMaker notebooks and endpoints
  • Read AWS Health events and Trusted Advisor checks
  • Management account only: list and describe AWS Organizations accounts

Optional: If you choose “Cost + Security” when connecting, the role also gets the AWS managed SecurityAudit and ViewOnlyAccess policies (read-only access to Security Hub, GuardDuty, Inspector, Macie, IAM, Access Analyzer, Config, CloudTrail and similar).

What it creates: Optionally, the template also creates a private, encrypted S3 bucket (anycloud2bi-cur-<your account id>) and a daily CUR 2.0 Data Export into it. Both are kept if you delete the stack, so you never lose billing history.

Microsoft Azure

Your Entra ID admin consents to the AnyCloud2BI app. You then assign read-only Azure roles to it at the subscription or management-group scope you choose.

Read-only access

  • Microsoft Graph application permissions shown on the consent screen: User.Read.All, Directory.Read.All, AuditLog.Read.All (users, MFA status, sign-in and audit logs)
  • Reader — resource inventory, Advisor recommendations, activity log
  • Cost Management Reader — cost and usage, budgets, forecasts
  • Security Reader — Defender for Cloud secure score and findings

Optional: Optional roles for specific pages: Billing Reader (invoices), Reservations Reader (commitments) and Storage Blob Data Reader on a storage account you choose (faster cost data from a Cost Management export).

What it creates: Nothing is created in your tenant except the app’s service principal from the consent, and — only if you use our ARM template — a storage account and daily cost export in a resource group you name.

Google Cloud

You run our setup script in Cloud Shell (you can read it first). It creates a service account named anycloud2bi-sa and grants it read-only roles. With Workload Identity Federation no key is ever created, and only AnyCloud2BI’s own service role can use the account; with the key option you paste a service-account key into AnyCloud2BI, which stores it in AWS Secrets Manager.

Read-only access

  • BigQuery Data Viewer and BigQuery Job User — query your billing export dataset
  • Compute Viewer, Cloud Asset Viewer, Recommender Viewer — inventory and recommendations
  • Security Reviewer and Logs Viewer — IAM review and audit logs

Optional: For organization-wide views, the same viewer roles plus Organization Viewer at the organization level.

What it creates: A service account (and, for Workload Identity Federation, an identity pool and provider) in the project you choose.

  • We never change, start, stop or delete anything in your cloud. Every permission above is read-only.
  • We don’t keep copies of your billing files. They are queried where they live (Azure export files are read into temporary Lambda storage and discarded); only aggregated results, such as monthly totals by service, are stored in your workspace to keep pages fast.
  • With the Google service-account key option, the key is stored in AWS Secrets Manager under your workspace and read only by our service. Workload Identity Federation avoids storing any key.
  • Cloud credentials, raw cost rows and the text of your questions are never written to our logs.

Copilot

Questions you can ask

  • What were my top 5 AWS services by cost last month?
  • Why did Azure spend go up compared with the previous month?
  • How much could I save with Savings Plans on EC2?
  • Which accounts have critical security findings?
  • Show untagged spend by account.
  • Who deleted an S3 bucket in the last two days?

See your AWS, Azure and Google Cloud spend in one place.

Read-only. No agents. 50K free tokens, no credit card.