User Guide
Cloud accounts
Connect Azure, AWS, and GCP with read-only credentials — CCO auto-discovers all subscriptions.
How it works#
Each cloud account represents a connection to one cloud organization (Azure tenant, AWS organization, or GCP organization). When you connect an account, CCO:
- Validates your credentials against the cloud API
- Auto-discovers all accessible subscriptions/accounts
- Enables cost tracking for all discovered subscriptions
- Begins fetching cost data on the next 4-hour cycle
Azure setup#
Create a Service Principal with Cost Management Reader access:
az ad sp create-for-rbac --name "CostOptimizer" \
--role "Cost Management Reader" \
--scopes /Then enter in CCO:
- ✓Tenant ID (Azure AD directory ID)
- ✓Client ID (Service Principal app ID)
- ✓Client Secret (Service Principal password)
Tip
Assigning the role at the root management group level grants access to all subscriptions. CCO auto-discovers them — no need to add subscriptions individually.
AWS setup#
Create an IAM user or role with read-only cost access:
- ✓AWS Organization ID
- ✓Access Key ID
- ✓Secret Access Key
- ✓Required policies: Cost Explorer read, Resource Groups Tagging API read
GCP setup#
Create a Service Account with billing read access:
- ✓GCP Organization ID
- ✓Service Account JSON key file (pasted as text)
- ✓Required roles: BigQuery Billing read, Resource Manager read
Managing subscriptions#
After connecting, each discovered subscription appears as a toggle row under the account card. You can:
- ✓Enable/disable cost tracking per subscription
- ✓Verify credentials (re-checks API access and re-syncs subscriptions)
- ✓Disconnect the account (soft-delete — can reconnect later)
Note
Disconnecting an account soft-deletes it. The row stays in the database so historical cost data is preserved. Reconnecting with the same tenant ID reactivates the existing account instead of creating a duplicate.
Multi-tenant (MSP)#
MSP licenses support unlimited tenants. Connect one account per client organization, then create data scope groups to isolate visibility:
- ✓Each client gets their own cloud account(s)
- ✓Create groups scoped to each client's subscriptions
- ✓Assign client analysts to their group for data isolation
- ✓Generate aggregate or per-client reports
Tenant limits
Business licenses allow 1 tenant per provider. MSP licenses allow unlimited. The limit is enforced when connecting a new account.