Act where your team already works
CloudLens reads AWS, Azure and Kubernetes with read-only access, then sends the work to Jira, Slack, Microsoft Teams and email. People sign in through your SAML identity provider.
- 1Work goes out to Jira and Slack
FINOPS-218 is created in Jira and a cost anomaly alert is sent to Slack, both from the same CloudLens organization.
- 2Sign-in and cloud access check in
An employee signs in through Okta SSO, and AWS reports the read-only role as validated.
- 3Teams and Macie follow
A recommendation is posted to Microsoft Teams, and Amazon Macie results classify a data store as holding PII.
Built into CloudLens, with nothing extra to buy
Every integration, in one place
Filter by what you want to connect. Each one is configured by an admin in Settings, with a test before it goes live.
Jira
TicketingCreate issues and epic bundles from recommendations, EOL and Atlas findings. Status synced both ways.
Learn moreSlack
ChatCost anomaly alerts for medium and high severity, and recommendations posted to a channel.
Learn moreMicrosoft Teams
ChatPost recommendations to any channel through an incoming webhook.
Learn moreOkta
IdentitySAML 2.0 single sign-on with email-domain discovery and admin group mapping.
Learn moreMicrosoft Entra ID
IdentitySAML 2.0 SSO from a metadata URL, pasted XML or manual fields.
Learn moreGoogle Workspace
IdentitySAML 2.0 SSO with a Test SSO Login before you save.
Learn moreAWS
CloudRead-only IAM role via CloudFormation, or a StackSet across your whole Organization.
Learn moreMicrosoft Azure
CloudAdmin consent, service principal, reader roles and Cost Management exports.
Learn moreKubernetes
CloudEKS clusters through an access entry — pods, workloads and CIS Kubernetes checks.
Learn moreAmazon Macie
DataSensitive-data findings joined to the security graph for PII, PCI and PHI.
Learn moreAnomaly, budget, proposal and schedule alerts, plus the weekly cost report.
Learn moreApprovals in Slack & Teams
ChatApprove savings proposals and schedules without leaving chat.
Learn moreTell us what your team works in
Configured once, tested before use
Set up by an admin
Webhooks, the Jira service account and SSO are configured in Settings by an admin, so nobody connects a personal token.
Tested before saving
Test connection for Jira, a test message for Slack and Teams, and Test SSO Login for SAML. You see each one work first.
Credentials handled carefully
Jira API tokens are stored encrypted. Cloud access uses a read-only role or a reader service principal, never keys pasted into a form.
Integration FAQ
Not yet. Approvals happen in CloudLens and the approver is notified by email. Approving from chat is in early access through Atlas Labs.
No. CloudLens reads Jira's live status and shows it next to its own. If they disagree, the row is flagged so someone can reconcile it.
Cost anomaly alerts for medium and high severity, plus any recommendation someone chooses to post to a channel.
No. AWS uses a read-only IAM role (CloudFormation or StackSet), Azure uses a service principal with reader roles, and EKS uses an access entry.
Ready to see CloudLens in action?
Connect a read-only AWS role or Azure service principal. We'll walk you through your bill, your security graph and the first things worth fixing.
