One requirement, and a list of settings that each turn on one part.

The dashboard deploys, loads and is useful with only the first. Everything else turns on one part of the product, and that part says so until it is on.

The one requirement

An AWS Organization with all features enabled, and access to its management account. Every figure is read across the whole organization, and the read-only role lives in the management account. Without both there is nothing to read.

The settings, and what each one turns on

Each is a one-off change in the management account, made by you. The read-only role cannot make any of them.

Turn onWhat it turns onUntil then, the dashboard
Cost ExplorerCosts, accounts, Regions and commitments, and the untagged spend on Cost AttributionEvery cost figure is unavailable. The first activation takes up to 24 hours to fill, so turn this on first
A cost allocation tag for your attribution tagThe spend no owner can be charged for, on Cost AttributionThe page says the tag is not activated, rather than showing a figure
An organization-wide Resource Explorer view, or an AWS Config aggregatorResources, and the tagging compliance scoreIt says no resource has been indexed, and shows no totals rather than zeros
Security Hub, enabled and delegated across the accountsSecurityNothing on the page is an all-clear until it is. The identity controls are not checked at all
GuardDuty, with a detector in the dashboard's RegionThe threat findings on SecurityThose findings are not counted. The rest of the page still answers
Cost Optimization HubSavings, on CostsIt says nothing has looked across your accounts for spend to reclaim
Compute OptimizerRightsizing, where Cost Optimization Hub finds nothingThere is no rightsizing recommendation to fall back on
A Control Tower landing zoneThe controls half of GovernanceGovernance answers on service control policies alone, and names the controls half unavailable
AWS Health's organizational view, and a support plan with API accessAWS Health, on the DashboardThe panel names which of the two is missing

Nothing is left as an empty panel that could be mistaken for good news. If you will never have the support plan, or never enrol in Cost Optimization Hub, you can hide AWS Health and Savings in Settings, which also stops the reads.

Three that need more than a line

Cost Explorer is the long pole

Its first activation fills in over up to 24 hours. Turn it on at the first conversation, not on the day you deploy.

The resource inventory is a rollout, not a switch

Resource Explorer costs nothing to run, but it needs an index in every member account and a view scoped to the whole organization. Setting it up can ask for CloudFormation StackSets trusted access, the broadest permission in the whole setup, which lets CloudFormation create a role in every account, now and later. We raise it with you during onboarding rather than leave it in a checklist. An AWS Config aggregator is the other choice, and suits an organization already running a landing zone.

Security Hub and GuardDuty are regional

The dashboard reads the Region it is deployed to. Findings from your other Regions reach it only through cross-Region aggregation, and the Security page says which Regions it covered.

What is not required

Optional: make the Anthropic keys tamper-proof

Keys you add for AI Spend are protected by a policy that anyone with the right IAM permissions in the workload account could change, and every change is logged. To make that impossible rather than visible, apply two things in your management account:

The dashboard behaves the same with or without them, so this belongs in a security review.

Leaving

Removing the read-only role ends our access completely and at once. The services you turned on stay on, because turning them off would need the write access the role refuses to hold. Turn them off yourself if you want to.

Also in Assurance

Point it at your organization and see the first answer the same afternoon.

30 minutes of one engineer · your AWS data stays in your account

Book a walkthrough