The AWS bill and the risk, answered before anyone asks.
What changed, what is exposed and whether the guardrails held, each opening with a verdict and the accounts, services and resources behind it.
What it answers
The questions that come to you, and where each answer lives.
- What changed, and which account changed it?
The services, accounts and cost centres that moved most over the window you pick, against the window of the same length before it.
Costs
- What is exposed right now?
Open Security Hub and GuardDuty findings by severity, the accounts not reporting at all, and the identity controls behind them.
Security
- Did the guardrails hold?
Service control policies and Control Tower controls on a timeline that says which day it was and what it was.
Governance
- What are we running, and where?
Everything in the organization by type, account and Region, down to the row and the tag it is missing.
Resources
- What is AI costing us?
Bedrock on the AWS bill and Claude bought direct from Anthropic, summed across all four token types, with the direct spend set against a monthly budget you choose.
AI Spend
Where it starts
The pages you will open first.
Security
Open findings by severity, the accounts not reporting at all, and the identity hygiene behind them.
61open, 9 older than 30 days
Security Hub · IAM
Governance
Whether the guardrails held, on a timeline that says which day it was and what it was.
25/26days the guardrails held
AWS Health · Config
Resources
Everything you are running, by type, account and Region, down to the row and the tag it is missing.
18Regions with something running
AWS Config
Deployed into your AWS account, and read-only.
- Read-only
- Your AWS account, your Region
- Encrypted at rest in your account
- Revocable in one action
To put the guardrails in place rather than only watch them, see Landing Zone.
Also in Solutions
Point it at your organization and see the first answer the same afternoon.
30 minutes of one engineer · your AWS data stays in your account