New Savings Proposals: approve, test and roll back cost changesLearn more Sign in|Talk to a cloud engineer

What your cloud costs and what it exposes

CloudLens reads your bill and your estate once and links them resource by resource. Finance sees where the money goes, security sees what can reach sensitive data, and both are talking about the same checkout-api.

What you're watching
  1. 1
    Bill and estate flow in

    AWS CUR 2.0 and Azure cost exports bring the bill. Read-only AWS APIs, Azure Resource Graph and EKS bring the resources behind it.

  2. 2
    One graph joins them

    CloudLens counts 12,480 resources against $184,312 of spend this month, so each resource carries its own cost.

  3. 3
    Three results come out

    $23,480 a month in priced recommendations, 17 ranked attack paths, and changes moving from Pending Approval to Applied.

Who does thisHead of platform, FinOps lead and security engineer working from the same screenWhat you getCost, risk and change status for Lumora Retail come from one connected graph instead of three separate exports.
$184,312monthly spend you can explore
$23,480/moin priced recommendations
94.2%of spend allocated to teams
17attack paths ranked by reach

Figures are from Lumora Retail, a fictional sample company.

Two tools, two different stories about the same resource

Cost and security teams look at the same cluster and reach different conclusions. These are the gaps that follow.

Shared context

The same resource has two names

What usually happens: Finance talks about a cost center, security talks about an instance, and nobody realises they mean the same machine.

How CloudLens resolves it: Both views use the same resource, the same name and the same owning team, so one conversation covers both.

Resolved
Access

Every tool needs its own access

What usually happens: A cost report, a posture scanner and a compliance export each need their own connection to the cloud and their own vendor review.

How CloudLens resolves it: One read-only connection feeds cost, security and compliance.

Resolved
Priorities

Work lands in the wrong order

What usually happens: A team rightsizes a cheap test instance while an exposed database holding customer data waits in another tool's queue.

How CloudLens resolves it: Recommendations carry dollars and findings carry reach, so priorities are set with both in view.

Resolved

From read-only access to an applied fix

Connect read-only

An IAM role or StackSet for AWS, a reader service principal for Azure, an access entry for EKS.

Ingest and scan

AWS CUR 2.0 and Azure cost exports for the bill. Read-only APIs for resources, identity and network.

Build one graph

Each dollar is joined to the resource it belongs to, and each resource to what it can reach.

Price, rank and act

Recommendations priced per resource and risks ranked by reach, then Proposals, Scheduler, Jira, Slack and Teams.

A weekly review that covers both lists

Lumora Retail's platform, FinOps and security leads meet every Monday. Since connecting CloudLens, they work from one screen instead of three exports.

MCMaya ChenHead of Platform, Lumora Retail

Lumora Retail is a fictional company. The people, names and numbers are sample data.

    1
    Mon 09:00

    The review starts in one place

    Maya opens CloudLens with the FinOps lead and the security engineer. Spend is down 8.7% on the month and 38 findings are critical.
    2
    Mon 09:15Cost + risk

    One resource shows up in both lists

    The analytics-sandbox instances are flagged as idle, worth $1,910 a month, and Atlas shows they are reachable from the internet through an open security group.
    3
    Mon 09:30

    Both go to the owning team

    Dimension Studio already maps the instances to Data Platform. Maya creates FINOPS-219 from the recommendation and SEC-77 from the finding, both in that team's Jira project.
    4
    Wed 15:00Approved

    The stop is approved

    Data Platform adds the stop to a Savings Proposal. The approver reads the dry run and approves it for the weekend window.
    5
    Sat 02:10

    Applied in the change window

    The proposal stops the instances. The team removes the open rule the same night, and the Atlas finding resolves on the next scan.
    6
    Mon 09:00

    Next week's review

    The saving appears in the realized-savings ledger and SEC-77 shows Done in Jira. The meeting moves on to the next item.

The idle instance is often the exposed one

See attack paths
Because cost and security read the same resources, CloudLens can show that an idle instance costing $1,910 a month also sits behind an open port with an admin role. One change removes both the cost and the risk.
  • Shared resource names
  • Cost and risk on one row
  • Owners from Dimension Studio
What you're watching
  1. 1
    Five sources connect

    Two feeds carry the bill and three carry the estate: AWS APIs, Azure Resource Graph and EKS. All of them use read-only access.

  2. 2
    Resources and spend meet

    The hub counts resources and this month's spend together, so cost and configuration describe the same objects.

  3. 3
    Savings and risks side by side

    Priced recommendations and 17 attack paths come off the same graph, with Critical and High counts next to the dollars.

Who does thisFinOps lead and security engineer reviewing the same resourcesWhat you getA resource that appears in both lists is easy to spot, because both lists come from one graph.

Tickets, alerts and changes in tools you use

All integrations
Create Jira issues from any recommendation or finding, post recommendations to Slack or Teams, and apply changes through Savings Proposals with approval, a dry run and rollback.
  • Jira status sync
  • Slack and Teams
  • Savings Proposals
  • Scheduler
What you're watching
  1. 1
    Create an issue from the row

    On the checkout-api rightsizing row, Create issue opens a Jira form already filled with project FINOPS, summary, savings and owner.

  2. 2
    FINOPS-218 links back

    The key appears in the Jira column and the recommendation moves to In Progress, so the list shows work that has started.

  3. 3
    Done in Jira gets reconciled

    Priya moves FINOPS-218 to Done. CloudLens flags the difference, and Reconcile marks the recommendation Addressed.

Who does thisFinOps lead creating the ticket, with the Checkout engineer who does the workWhat you getThe saving is tracked in the Checkout team's Jira workflow, and the recommendation status matches it.
Want to see cost and risk on one resource?

Scan one account with read-only access

Read-only to see, approved to change

SAML 2.0 SSO, each organization's data kept separate, and Copilot only after an admin turns it on.

Ready to see CloudLens in action?

Connect a read-only AWS role or Azure service principal. We'll walk you through your bill, your security graph and the first things worth fixing.