How it works

From a connected cloud account to an approved savings action.

SpendSage moves through eight stages, from securely connecting your account to automating optimizations you've approved. Here's what happens at each one.

01
Connect your account

Grant access without handing over a password.

Connection happens through an IAM cross-account role and STS AssumeRole. SpendSage never asks for or stores permanent credentials.

  • IAM cross-account role, scoped to what's needed
  • Temporary credentials via STS AssumeRole
  • No passwords, no long-lived keys
Account status

production-account

Connected
IAM role STS AssumeRole SpendSage
02
Collect billing data

Pull in the data that actually explains your bill.

SpendSage ingests your Cost & Usage Reports along with infrastructure metadata, giving it a complete picture rather than just a total.

  • Cost & Usage Reports (CUR)
  • Resource and configuration metadata
  • Scheduled, incremental collection
Data sources
Cost & Usage Reports
EC2 / EBS / RDS metadata
Tags & account structure
03
Process and analyze

Raw billing rows become a queryable cost model.

Data is cleaned, normalized, and organized by service, account, and time so it can be broken down, compared, and forecast.

  • Normalized by service, account, and region
  • Trend and forecast calculations
  • Ready for dashboards and AI analysis
Monthly spend

$42,800

04
Detect waste

Find the resources quietly costing you money.

SpendSage continuously scans for idle, unattached, or oversized resources across compute, storage, and networking.

  • Idle EC2, unused EBS, stale snapshots
  • Unattached Elastic IPs
  • Oversized RDS and Lambda resources
Detected this week
Idle EC2 · m5.xlarge Low risk
Unattached EBS · 200GB Low risk
05
Explain costs

Understand spikes without digging through raw bills.

When spend moves outside its normal range, SpendSage explains what changed and why, in plain language you can ask follow-up questions about.

  • Automatic spike and anomaly detection
  • Root-cause explanations, not just alerts
  • Natural language follow-up questions
Ask SpendSage
Why did spend jump on Tuesday?
A 3x increase in EC2 usage in us-east-1, driven by an autoscaling event on the checkout service.
06
Recommend savings

Every recommendation comes with a number and a risk level.

Recommendations are ranked by estimated monthly savings, so your team always knows what to act on first.

  • Estimated monthly savings per action
  • Risk level for every recommendation
  • Ranked so the biggest wins surface first
Top recommendation

Rightsize 4 EC2 instances

Estimated monthly savings: $1,240

Low risk
07
Approval

Nothing changes in your account without a review.

Your team reviews each recommendation and decides what to approve. SpendSage never modifies infrastructure on its own.

  • Explicit approval required per action
  • Full context shown before you approve
  • Analysis and recommendations, always separate from execution
Pending approval
Rightsize 4 EC2 instances Awaiting review
08
Automation

Approved actions become infrastructure changes.

Once approved, optimizations can be applied through generated Terraform and GitHub pull requests, with rollback if something doesn't look right. This stage is on our roadmap.

  • Terraform generation for approved changes
  • GitHub pull requests instead of direct changes
  • Rollback support if something looks wrong
Automation
Approved action Terraform GitHub PR
On the roadmap
Built for engineering teams Secure cross-account connection No passwords required Analysis before automation

Connect an account and see it work end to end.

Get your first waste detection and savings recommendations.

Get started