User Guide

Cloud accounts

Connect Azure, AWS, and GCP with read-only credentials — CCO auto-discovers all subscriptions.

How it works#

Each cloud account represents a connection to one cloud organization (Azure tenant, AWS organization, or GCP organization). When you connect an account, CCO:

  1. Validates your credentials against the cloud API
  2. Auto-discovers all accessible subscriptions/accounts
  3. Enables cost tracking for all discovered subscriptions
  4. Begins fetching cost data on the next 4-hour cycle

Azure setup#

Create a Service Principal with Cost Management Reader access:

az ad sp create-for-rbac --name "CostOptimizer" \ --role "Cost Management Reader" \ --scopes /

Then enter in CCO:

  • ✓Tenant ID (Azure AD directory ID)
  • ✓Client ID (Service Principal app ID)
  • ✓Client Secret (Service Principal password)
Tip
Assigning the role at the root management group level grants access to all subscriptions. CCO auto-discovers them — no need to add subscriptions individually.

AWS setup#

Create an IAM user or role with read-only cost access:

  • ✓AWS Organization ID
  • ✓Access Key ID
  • ✓Secret Access Key
  • ✓Required policies: Cost Explorer read, Resource Groups Tagging API read

GCP setup#

Create a Service Account with billing read access:

  • ✓GCP Organization ID
  • ✓Service Account JSON key file (pasted as text)
  • ✓Required roles: BigQuery Billing read, Resource Manager read

Managing subscriptions#

After connecting, each discovered subscription appears as a toggle row under the account card. You can:

  • ✓Enable/disable cost tracking per subscription
  • ✓Verify credentials (re-checks API access and re-syncs subscriptions)
  • ✓Disconnect the account (soft-delete — can reconnect later)
Note
Disconnecting an account soft-deletes it. The row stays in the database so historical cost data is preserved. Reconnecting with the same tenant ID reactivates the existing account instead of creating a duplicate.

Multi-tenant (MSP)#

MSP licenses support unlimited tenants. Connect one account per client organization, then create data scope groups to isolate visibility:

  • ✓Each client gets their own cloud account(s)
  • ✓Create groups scoped to each client's subscriptions
  • ✓Assign client analysts to their group for data isolation
  • ✓Generate aggregate or per-client reports
Tenant limits
Business licenses allow 1 tenant per provider. MSP licenses allow unlimited. The limit is enforced when connecting a new account.