Ask your cost data questions in plain English
Copilot turns a question into a read-only SQL query on your cost data, runs it, and shows the query next to the answer and the chart so anyone can check the number.
- 1Ask about the Aug 20 EKS jump
The question goes in as plain English: why did Amazon EKS spend jump on Aug 20.
- 2Read the query it ran
Copilot shows read-only SQL on cost_daily: EKS cost by day and team, Aug 13 to Aug 27. An analyst can rerun it.
- 3Get the answer and a chart
EKS hit $1,002, 48.1% above its 7-day average, and Checkout accounts for 78% of the increase. Suggested follow-ups sit underneath.
Every cost question waits for one analyst
Engineers and managers ask plain questions. Copilot answers from the same data as Cost Explorer and shows the query it ran.
Simple cost questions wait a week
What usually happens: “Why did Bedrock go up?” becomes a ticket for the one analyst who knows the CUR schema, and it waits a week.
How CloudLens resolves it: Copilot answers it in plain English, with a chart and the SQL query behind the number.
ResolvedSecurity won’t approve cost data in AI
What usually happens: Security blocks the tool, because nobody can say which fields leave the tenant.
How CloudLens resolves it: Copilot is off until an admin consents. Only allow-listed columns are sent, ids become tokens, and every call is logged.
ResolvedAI answers nobody can check
What usually happens: A chatbot gives a confident figure that nobody can reproduce, and it ends up in a board deck.
How CloudLens resolves it: Every answer shows its SQL, so an analyst can read it and rerun it before the number goes anywhere.
ResolvedHow Sofia prepared for her quarterly review
Twenty minutes of questions she would otherwise have sent to the FinOps team.
Lumora Retail is a fictional company. The people, names and numbers are sample data.
Asks why EKS cost jumped on Aug 20
Reads the SQL
Asks a follow-up about Bedrock
Uses ⌘K from the budgets page
Security checks the processing log
See Copilot’s guardrails on your data
Every answer comes with its query
An analyst can check the number before it goes into a deck.
Identifiers stay inside your tenant
- Explicit opt-in consent
- Allow-listed columns only
- Ids tokenized, calls logged
- 1An admin turns consent on
“Allow Copilot on cost data” is off by default and only admins can change it.
- 2Check the allow-listed columns
Day, service, team, account, resource and cost columns can be sent. Tag values and user emails are never sent.
- 3Watch identifiers become tokens
Before the request leaves, prod-core becomes ACCT_1 and checkout-api becomes RES_4. Service and cost go through unchanged.
- 4Review the processing log
Each model call by Ana, Ravi and Mei is listed with its time, table, row count and a tokenized tag.
Ask about spikes, teams and trends
- Read-only SQL, shown inline
- Charts in the answer
- Conversation history kept
- 1Ask which team's Bedrock grew fastest
The question is about Amazon Bedrock spend this month, typed the way a manager would say it.
- 2Read the SQL
The query reads cost_monthly for Amazon Bedrock, August and September 2026, grouped by team and month.
- 3Get the answer and next questions
Search & Discovery grew 31%, from $3,410 to $4,470, and Checkout is flat at $2,120. Chips offer a model-family breakdown or a budget.
Ask from any page with ⌘K
- Global keyboard shortcut
- Answers inline
- Jump to any page
- 1Press ⌘K on Overview
The palette opens over the page, with suggestions like unallocated spend by account and Go to Recommendations.
- 2Type the question
“Top 5 services by amortized cost last month,” then Enter.
- 3Read the ranked answer
Amortized cost for August 2026 lists EC2, RDS, EKS, S3 and Data Transfer as bars, with the Overview still behind it.
A cost assistant security can approve
Answers from your data
Every answer comes from a query on your cost tables, not from what a model happens to know.
Governed by default
Consent, column allow-lists, tokenization and a processing log are part of the product.
Where you already are
A keyboard shortcut on every page, with the conversation saved for later.
Copilot questions
No. It stays off until an administrator explicitly consents for the organization.
Only columns on the allow-list. Account and resource identifiers are replaced with tokens such as ACCT_1 before anything is sent.
Yes. Each answer shows the query it ran, and every model call is recorded in a processing log that admins can review.
No. Copilot runs read-only queries against cost data. Changes to resources go through Savings Proposals, with approvals.
Ready to see CloudLens in action?
Connect a read-only AWS role or Azure service principal. We'll walk you through your bill, your security graph and the first things worth fixing.
