Documentation

Everything CostLens can access, and exactly how it works

The complete client walkthrough, the exact IAM permissions granted, and answers to the questions a security review usually asks.

Getting started

Start to finish, this is every step a new customer goes through.

  1. 1

    Sign up

    Create a CostLens account. No AWS access yet — this step doesn't touch your cloud at all.

  2. 2

    Click “Connect AWS account”

    Opens AWS CloudFormation directly in your own console, every parameter already filled in. Nothing to configure.

  3. 3

    Review before you approve

    The read-only policy is right there in the CloudFormation review screen. Nothing is created in your account until you click Create.

  4. 4

    Create the stack

    About 30 seconds. One IAM role appears in your account. No access keys, ever.

  5. 5

    Paste your account ID back into CostLens

    Twelve digits, nothing else. We reconstruct the role ARN from it — no ARN to copy-paste, no room to fat-finger it.

  6. 6

    Your first scan runs automatically

    Findings with dollar figures and remediation commands show up within minutes.

  7. 7

    (Recommended) Enable AWS Compute Optimizer

    Free and AWS-native. Unlocks rightsizing and idle-resource detection on top of everything CostLens already checks.

Permissions you need to run the stack yourself

This is about your own IAM user or role in the AWS console - separate from what CostLens's role ends up granting us (see Security & permissions below). To create the stack, whoever clicks "Create stack" needs:

cloudformation:CreateStack
cloudformation:DescribeStacks
cloudformation:DescribeStackEvents
iam:CreateRole
iam:PutRolePolicy
iam:GetRole

Plus ticking "I acknowledge that AWS CloudFormation might create IAM resources" in the console - required because the stack creates a named role (CAPABILITY_NAMED_IAM). Most admin-level users already have all of this; a locked-down IAM user built for least-privilege console access may need it added explicitly.

Security & permissions

We never hold an AWS credential. Access is role-to-role, gated by a per-tenant secret, and read-only by policy — here's exactly what that means.

  • Cost & billing data

    Spend history, forecasts, and Savings Plans recommendations, via AWS Cost Explorer.

  • AWS's own rightsizing data

    Compute Optimizer recommendations — free, AWS-native, we just read what AWS already computed.

  • Resource inventory

    EC2, load balancers, RDS, Lambda, ECS, EKS, EFS, OpenSearch, ElastiCache, DynamoDB, ECR, CloudWatch Logs, Auto Scaling, Savings Plans — list and describe metadata only, never what's running inside them.

  • S3 bucket configuration only

    Lifecycle rules, versioning status, tags, region. Never object contents.

  • CloudWatch utilization metrics

    Read-only usage data — what powers every idle-resource check.

  • AWS's public pricing catalog

    For accurate dollar estimates on every finding.

  • Explicitly denied, not just left out

    s3:GetObject, DynamoDB item reads, Secrets Manager, and SSM Parameter Store are hard-Denyd in the policy — not merely absent from the allow list. Even a future mistake on our end can't grant access to them.

View the exact IAM actions ▾
# BillingAndCostAnalysis
ce:GetCostAndUsage, ce:GetCostForecast, ce:GetDimensionValues, ce:GetTags,
ce:GetRightsizingRecommendation, ce:GetSavingsPlansPurchaseRecommendation,
ce:GetReservationPurchaseRecommendation, ce:GetReservationUtilization,
ce:GetReservationCoverage, ce:GetSavingsPlansUtilization,
ce:GetSavingsPlansCoverage, ce:GetAnomalies, ce:DescribeCostCategoryDefinition

# ComputeOptimizerRecommendations
compute-optimizer:Get*, compute-optimizer:Describe*, compute-optimizer:Export*

# ResourceInventory
ec2:DescribeRegions, ec2:DescribeInstances, ec2:DescribeInstanceTypes,
ec2:DescribeVolumes, ec2:DescribeVolumesModifications, ec2:DescribeSnapshots,
ec2:DescribeImages, ec2:DescribeAddresses, ec2:DescribeNatGateways,
ec2:DescribeVpcs, ec2:DescribeSubnets, ec2:DescribeRouteTables,
ec2:DescribeVpcEndpoints, ec2:DescribeReservedInstances, ec2:DescribeTags,
ec2:DescribeSecurityGroups, ec2:DescribeNetworkInterfaces,
elasticloadbalancing:DescribeLoadBalancers,
elasticloadbalancing:DescribeTargetGroups,
elasticloadbalancing:DescribeTargetHealth,
elasticloadbalancing:DescribeListeners, rds:DescribeDBInstances,
rds:DescribeDBClusters, rds:DescribeDBSnapshots,
rds:DescribeReservedDBInstances, rds:DescribeDBClusterSnapshots,
rds:ListTagsForResource, lambda:ListFunctions,
lambda:GetFunctionConfiguration, lambda:ListProvisionedConcurrencyConfigs,
ecs:ListClusters, ecs:ListServices, ecs:DescribeServices,
ecs:DescribeClusters, eks:ListClusters, eks:DescribeCluster,
eks:ListNodegroups, eks:DescribeNodegroup, eks:ListFargateProfiles,
eks:DescribeFargateProfile, elasticfilesystem:DescribeFileSystems,
elasticfilesystem:DescribeLifecycleConfiguration, es:ListDomainNames,
es:DescribeDomain, es:DescribeDomains, elasticache:DescribeCacheClusters,
elasticache:DescribeReservedCacheNodes, dynamodb:ListTables,
dynamodb:DescribeTable, savingsplans:DescribeSavingsPlans,
savingsplans:DescribeSavingsPlansOfferings,
autoscaling:DescribeAutoScalingGroups, ecr:DescribeRepositories,
ecr:DescribeImages, ecr:GetLifecyclePolicy, logs:DescribeLogGroups

# S3Metadata
s3:ListAllMyBuckets, s3:GetBucketLocation, s3:GetLifecycleConfiguration,
s3:GetBucketTagging, s3:GetIntelligentTieringConfiguration,
s3:ListBucketMultipartUploads, s3:ListMultipartUploadParts,
s3:GetBucketVersioning

# UtilizationMetrics
cloudwatch:GetMetricData, cloudwatch:GetMetricStatistics, cloudwatch:ListMetrics

# PricingLookup
pricing:GetProducts, pricing:DescribeServices, pricing:GetAttributeValues

# NeverReadObjectData (explicit Deny, not an absence of Allow)
s3:GetObject, s3:GetObjectVersion, dynamodb:GetItem, dynamodb:Query,
dynamodb:Scan, secretsmanager:GetSecretValue, ssm:GetParameter,
ssm:GetParameters

This is the real policy — the same one CloudFormation shows you before you click Create.

FAQ

Does CostLens ever get write access to my AWS account?▾

No. The IAM policy grants only Describe/Get/List actions. Object data and secrets (S3 object contents, DynamoDB items, Secrets Manager, SSM Parameter Store) carry an explicit Deny, not just an absence of Allow — see Security & permissions below.

What happens if I revoke access?▾

Delete the CloudFormation stack (or run terraform destroy). The IAM role disappears immediately. There are no access keys to rotate and nothing left behind to leak.

Which AWS regions do you scan?▾

Free plan: 4 regions, on demand. Pro: 25 regions, swept nightly. You can also point CostLens at specific regions instead of the default auto-discovery.

Is the free tier really $0.00 in AWS costs?▾

Not exactly — CloudWatch's GetMetricData API bills a few cents per scan. It's pennies, not dollars, and it's billed to your AWS account directly, never to CostLens.

What if a finding doesn't apply to me?▾

Dismiss it — it stays dismissed across future scans. Confidence levels are also honest: low for estimates that could shift with incremental billing, high only for findings we're certain about.

Do you support Google Cloud or Azure yet?▾

Not yet. AWS is live today; the same read-only, dollar-quantified approach is coming to Google Cloud and Azure next.