New Savings Proposals: approve, test and roll back cost changesLearn more Sign in|Talk to a cloud engineer

Ask your cost data questions in plain English

Copilot turns a question into a read-only SQL query on your cost data, runs it, and shows the query next to the answer and the chart so anyone can check the number.

What you're watching
  1. 1
    Ask about the Aug 20 EKS jump

    The question goes in as plain English: why did Amazon EKS spend jump on Aug 20.

  2. 2
    Read the query it ran

    Copilot shows read-only SQL on cost_daily: EKS cost by day and team, Aug 13 to Aug 27. An analyst can rerun it.

  3. 3
    Get the answer and a chart

    EKS hit $1,002, 48.1% above its 7-day average, and Checkout accounts for 78% of the increase. Suggested follow-ups sit underneath.

Who does thisEngineering manager, with an analyst checking the SQLWhat you getA cost answer with its query attached, so the number can be checked before anyone quotes it.
Offuntil an admin opts the organization in
Allow-listonly approved columns are sent to the model
ACCT_1account and resource ids are tokenized first
Everymodel call is recorded in a processing log

Every cost question waits for one analyst

Engineers and managers ask plain questions. Copilot answers from the same data as Cost Explorer and shows the query it ran.

Speed

Simple cost questions wait a week

What usually happens: “Why did Bedrock go up?” becomes a ticket for the one analyst who knows the CUR schema, and it waits a week.

How CloudLens resolves it: Copilot answers it in plain English, with a chart and the SQL query behind the number.

Resolved
Security

Security won’t approve cost data in AI

What usually happens: Security blocks the tool, because nobody can say which fields leave the tenant.

How CloudLens resolves it: Copilot is off until an admin consents. Only allow-listed columns are sent, ids become tokens, and every call is logged.

Resolved
Trust

AI answers nobody can check

What usually happens: A chatbot gives a confident figure that nobody can reproduce, and it ends up in a board deck.

How CloudLens resolves it: Every answer shows its SQL, so an analyst can read it and rerun it before the number goes anywhere.

Resolved

How Sofia prepared for her quarterly review

Twenty minutes of questions she would otherwise have sent to the FinOps team.

SLSofia LindEngineering manager, Lumora Retail

Lumora Retail is a fictional company. The people, names and numbers are sample data.

    1
    Wed 14:00

    Asks why EKS cost jumped on Aug 20

    Copilot groups the daily cost by team and replies that Checkout accounts for most of the increase, with a daily chart.
    2
    Wed 14:03

    Reads the SQL

    The query is shown inline: amortized cost for Amazon EKS by day and team, Aug 13 to Aug 27. It is the question she meant to ask.
    3
    Wed 14:10

    Asks a follow-up about Bedrock

    “Which teams use Amazon Bedrock and how fast is it growing?” The answer lists Search & Discovery and Growth with month-over-month change.
    4
    Wed 14:20⌘K

    Uses ⌘K from the budgets page

    Without leaving the page, she asks for last quarter’s spend by team and copies the table into her review doc.
    5
    Thu 09:00Logged

    Security checks the processing log

    The log lists each model call from Sofia’s questions, with account ids sent as tokens like ACCT_1.
Want AI answers security will sign off on?

See Copilot’s guardrails on your data

Every answer comes with its query

An analyst can check the number before it goes into a deck.

Identifiers stay inside your tenant

Copilot is off until an admin turns it on. Only allow-listed columns can be sent. Account and resource identifiers are replaced with tokens before any request, and every call is written to a processing log.
  • Explicit opt-in consent
  • Allow-listed columns only
  • Ids tokenized, calls logged
What you're watching
  1. 1
    An admin turns consent on

    “Allow Copilot on cost data” is off by default and only admins can change it.

  2. 2
    Check the allow-listed columns

    Day, service, team, account, resource and cost columns can be sent. Tag values and user emails are never sent.

  3. 3
    Watch identifiers become tokens

    Before the request leaves, prod-core becomes ACCT_1 and checkout-api becomes RES_4. Service and cost go through unchanged.

  4. 4
    Review the processing log

    Each model call by Ana, Ravi and Mei is listed with its time, table, row count and a tokenized tag.

Who does thisHead of security, with the admin who owns Copilot settingsWhat you getA clear record of which columns reach the model, in what form, and who asked.

Ask about spikes, teams and trends

Ask about a spike, a team, a service or a month. Copilot writes read-only SQL against your cost tables, returns the answer with a chart and keeps the conversation for later.
  • Read-only SQL, shown inline
  • Charts in the answer
  • Conversation history kept
What you're watching
  1. 1
    Ask which team's Bedrock grew fastest

    The question is about Amazon Bedrock spend this month, typed the way a manager would say it.

  2. 2
    Read the SQL

    The query reads cost_monthly for Amazon Bedrock, August and September 2026, grouped by team and month.

  3. 3
    Get the answer and next questions

    Search & Discovery grew 31%, from $3,410 to $4,470, and Checkout is flat at $2,120. Chips offer a model-family breakdown or a budget.

Who does thisEngineering manager or FinOps analystWhat you getThe team behind Bedrock growth, named with figures anyone can trace to the query.

Ask from any page with ⌘K

Press ⌘K on any page to ask a question or jump to a view, without leaving what you were looking at. The palette also suggests questions and pages, such as unallocated spend by account or Go to Recommendations. The answer opens in the same panel.
  • Global keyboard shortcut
  • Answers inline
  • Jump to any page
What you're watching
  1. 1
    Press ⌘K on Overview

    The palette opens over the page, with suggestions like unallocated spend by account and Go to Recommendations.

  2. 2
    Type the question

    “Top 5 services by amortized cost last month,” then Enter.

  3. 3
    Read the ranked answer

    Amortized cost for August 2026 lists EC2, RDS, EKS, S3 and Data Transfer as bars, with the Overview still behind it.

Who does thisEngineering manager or FinOps analystWhat you getA quick answer without losing your place on the page you were working on.

A cost assistant security can approve

Answers from your data

Every answer comes from a query on your cost tables, not from what a model happens to know.

Governed by default

Consent, column allow-lists, tokenization and a processing log are part of the product.

Where you already are

A keyboard shortcut on every page, with the conversation saved for later.

Copilot questions

No. It stays off until an administrator explicitly consents for the organization.

Only columns on the allow-list. Account and resource identifiers are replaced with tokens such as ACCT_1 before anything is sent.

Yes. Each answer shows the query it ran, and every model call is recorded in a processing log that admins can review.

No. Copilot runs read-only queries against cost data. Changes to resources go through Savings Proposals, with approvals.

Ready to see CloudLens in action?

Connect a read-only AWS role or Azure service principal. We'll walk you through your bill, your security graph and the first things worth fixing.