The one requirement
An AWS Organization with all features enabled, and access to its management account. Every figure is read across the whole organization, and the read-only role lives in the management account. Without both there is nothing to read.
The settings, and what each one turns on
Each is a one-off change in the management account, made by you. The read-only role cannot make any of them.
| Turn on | What it turns on | Until then, the dashboard |
|---|---|---|
| Cost Explorer | Costs, accounts, Regions and commitments, and the untagged spend on Cost Attribution | Every cost figure is unavailable. The first activation takes up to 24 hours to fill, so turn this on first |
| A cost allocation tag for your attribution tag | The spend no owner can be charged for, on Cost Attribution | The page says the tag is not activated, rather than showing a figure |
| An organization-wide Resource Explorer view, or an AWS Config aggregator | Resources, and the tagging compliance score | It says no resource has been indexed, and shows no totals rather than zeros |
| Security Hub, enabled and delegated across the accounts | Security | Nothing on the page is an all-clear until it is. The identity controls are not checked at all |
| GuardDuty, with a detector in the dashboard's Region | The threat findings on Security | Those findings are not counted. The rest of the page still answers |
| Cost Optimization Hub | Savings, on Costs | It says nothing has looked across your accounts for spend to reclaim |
| Compute Optimizer | Rightsizing, where Cost Optimization Hub finds nothing | There is no rightsizing recommendation to fall back on |
| A Control Tower landing zone | The controls half of Governance | Governance answers on service control policies alone, and names the controls half unavailable |
| AWS Health's organizational view, and a support plan with API access | AWS Health, on the Dashboard | The panel names which of the two is missing |
Nothing is left as an empty panel that could be mistaken for good news. If you will never have the support plan, or never enrol in Cost Optimization Hub, you can hide AWS Health and Savings in Settings, which also stops the reads.
Three that need more than a line
Cost Explorer is the long pole
Its first activation fills in over up to 24 hours. Turn it on at the first conversation, not on the day you deploy.
The resource inventory is a rollout, not a switch
Resource Explorer costs nothing to run, but it needs an index in every member account and a view scoped to the whole organization. Setting it up can ask for CloudFormation StackSets trusted access, the broadest permission in the whole setup, which lets CloudFormation create a role in every account, now and later. We raise it with you during onboarding rather than leave it in a checklist. An AWS Config aggregator is the other choice, and suits an organization already running a landing zone.
Security Hub and GuardDuty are regional
The dashboard reads the Region it is deployed to. Findings from your other Regions reach it only through cross-Region aggregation, and the Security page says which Regions it covered.
What is not required
- A CloudTrail trail. The activity feed reads the event history every account already has.
- Control Tower, except for the controls half of Governance. An organization governed by service control policies alone is governed, and the page says so.
- A separate workload account, strictly. The dashboard can run in the management account, but we advise against it: a compromise of the dashboard would then be a compromise of the management account.
Optional: make the Anthropic keys tamper-proof
Keys you add for AI Spend are protected by a policy that anyone with the right IAM permissions in the workload account could change, and every change is logged. To make that impossible rather than visible, apply two things in your management account:
- A service control policy or resource control policy that denies changing or removing the secrets' resource policy, except to a named break-glass role.
- An alarm, from CloudTrail or EventBridge, on any attempt to change the policy or delete the secrets.
The dashboard behaves the same with or without them, so this belongs in a security review.
Leaving
Removing the read-only role ends our access completely and at once. The services you turned on stay on, because turning them off would need the write access the role refuses to hold. Turn them off yourself if you want to.