One guide per cloud, written for the administrator who will do the work — forward the link and they need nothing else. Every connection is read-only and keyless: FinOpsAI never receives keys, secrets or passwords, and you can revoke access from your own console at any time.
Enable the export, grant BigQuery Data Viewer on the dataset to your workspace identity — the wizard opens the page and watches for the grant. About 10 min.
AWSS3 bucket in ap-south-1, a Data Export, then one CloudFormation template generated for your workspace creates the read-only role. About 15 min.
AzureOne admin consent and one Deploy to Azure click; FinOpsAI creates the FOCUS export for you inside rg-finopsai. About 10 min.
| Google Cloud | AWS | Azure | |
|---|---|---|---|
| What you create | Billing export to BigQuery | FOCUS 1.2 Data Export to S3 | FOCUS export to Blob Storage |
| How access is granted | IAM grant on the dataset | IAM role trusting one Google identity (CloudFormation) | Admin consent + one ARM template (Deploy to Azure) |
| Identity you grant | Your workspace identity fa-<company>@… (shown in the wizard) | Your workspace identity's unique ID (in the generated template) | App finopsai-ingestor-fed |
| Secrets exchanged | None | None | None |
| Where the data is read | In place, in your dataset | Loaded into FinOpsAI's store in asia-south1 | Loaded into FinOpsAI's store in asia-south1 |
| Residency choice | Dataset in asia-south1 | Bucket in ap-south-1 | Storage account in Central India |
| Who in your organisation | Billing Account Admin + project Owner | Management-account admin | Entra admin (consent) + subscription Owner (template) |
| Time to first data | ≤ 24 h | ≤ 24 h | Minutes — FinOpsAI runs the export |
| Revoke | Remove the principal | Delete the stack | Delete rg-finopsai / the enterprise app |