Two accounts
| Account | What lives there |
|---|---|
| Workload account | One account in your organization. It holds the whole dashboard: the site on CloudFront and S3, the API on API Gateway and Lambda, the cache in DynamoDB, sign-in on Amazon Cognito, and any Anthropic keys you add, in Secrets Manager. |
| Management account | The read-only role, and nothing else. Every read of Organizations, Cost Explorer, Security Hub, GuardDuty, Config and IAM goes through it. |
Keep them apart. The dashboard can be deployed into the management account, and nothing stops it, but then a compromise of the dashboard would be a compromise of the management account.
How a figure reaches the screen
- You sign in with an account an administrator created for you. Nobody can sign themselves up, and multi-factor authentication is available.
- The browser asks the API on the same address the page came from, so nothing is called cross-origin.
- The API assumes the read-only role for a short-lived session and asks AWS for the figures. It holds no long-lived key to your management account.
- The answer is cached in your account for 4 hours, so one read serves everyone who opens the page in that window, and Cost Explorer, which bills per request, is not asked again on every page view.
- The page shows the figures with the verdict computed beside them. Amounts are stored in US dollars, as AWS bills them, and converted to your currency in the browser.
Who runs it
Our cloud team deploys and updates the dashboard in your workload account. The management account is only ever read, through the role you applied.
Anthropic keys, if you add them
AI Spend can read Claude bought direct from Anthropic, using keys you set in Settings. They are stored in Secrets Manager in your workload account, encrypted under a KMS key whose policy lets only the dashboard's API decrypt them, and the secret's own policy denies the read to every other principal, our deploy role included. A key is never shown back once it is set.
That protection is tamper-evident rather than tamper-proof: someone with the right IAM permissions in the account could change the policy, and every such change is a CloudTrail event. If you want it tamper-proof,two settings in your management account make it so.
What crosses the boundary
No AWS data of yours is sent to an account we operate. Two things do cross, and both are deliberate:
- A message you send us. The message box on the Support page sends the text your staff typed, and the sender's email address, to our cloud team's chat channel and notification topic. Nothing else on the page is sent.
- The "What's new" list. The dashboard reads it from a file we publish, so our logs show when a dashboard was opened. Nothing of yours goes with the request.
The dashboard also reads, without sending anything of yours:
- The ECB daily reference rates, for currency conversion.
- AWS's own What's New feed, narrowed to the services you pay for.
- Anthropic's reporting API, with the keys you set, if you set them.
- The web addresses you ask it to watch for uptime.