Each cloud asks one person with the right role to approve FinOpsAI once. This page lists every step, the minimum role for it, and the simpler role most companies already have. Forward it to your cloud administrators before the setup call. Every grant is read-only.
| Cloud | Who to ask for |
|---|---|
| FinOpsAI workspace | Workspace Owner or Admin |
| Google Cloud | Billing Account Administrator + Owner of the export project |
| AWS | Administrator in the management (payer) account |
| Microsoft Azure | Global Administrator (Entra) + Owner of the subscription |
| Unused paid seats (optional) | Entra Global Administrator · Google Workspace Super Admin |
Ask for: Workspace Owner or Admin
| Step | Minimum role | Where | Or simply | |
|---|---|---|---|---|
| ☐ | Sign up and create the workspace | None — the first person becomes Owner | FinOpsAI | — |
| ☐ | Add a cloud, Connect everything, Check again, Refresh | Owner or Admin (Members can only view) | FinOpsAI | — |
| ☐ | Invite people, approve domain-join requests | Owner or Admin | FinOpsAI | — |
Ask for: Billing Account Administrator + Owner of the export project
| Step | Minimum role | Where | Or simply | |
|---|---|---|---|---|
| ☐ | Switch on the billing export (Standard + Detailed) | Billing Account Administrator + BigQuery User | Billing account; export project | Billing Account Administrator + project Owner |
| ☐ | Connect with Google — create and share the export dataset | BigQuery Admin (or Data Owner on the dataset) | Export project | Project Owner |
| ☐ | Connect with Google — add the read-only roles | Project IAM Admin | Each project FinOpsAI reads | Project Owner |
| ☐ | Connect with Google — switch on the BigQuery and Recommender APIs | Service Usage Admin | Export project | Project Owner |
| ☐ | One grant for the whole organization (optional) | Organization Administrator | Organization | — |
Ask for: Administrator in the management (payer) account
| Step | Minimum role | Where | Or simply | |
|---|---|---|---|---|
| ☐ | Create the FinOpsAI-Connect stack (FOCUS export, bucket, read role) | CloudFormation + IAM (create role) + S3 (create bucket) + Data Exports (create export) + Billing read | Management (payer) account | AdministratorAccess |
| ☐ | Billing access for IAM users (once, if never done) | Root user switches on "IAM user and role access to Billing information" | Management account | — |
| ☐ | Switch on StackSets trusted access (whole organization) (optional) | organizations:EnableAWSServiceAccess + IAM service-linked role | Management account only — not a delegated admin | AdministratorAccess |
| ☐ | Create the FinOpsAI-Organization stack (read role in every member account) (optional) | CloudFormation StackSets (service-managed) + IAM + Lambda | Management account | AdministratorAccess |
| ☐ | Create the FinOpsAI-Hygiene stack (live reads: snapshots, images, bucket lifecycle, backup plans) (optional) | CloudFormation + IAM (add a policy to the FinOpsAI role) | Each connected account | AdministratorAccess |
Ask for: Global Administrator (Entra) + Owner of the subscription
| Step | Minimum role | Where | Or simply | |
|---|---|---|---|---|
| ☐ | Admin consent for the FinOpsAI app | Privileged Role Administrator or Cloud Application Administrator | Entra ID (directory) | Global Administrator |
| ☐ | Deploy to Azure — Reader + Cost Management Reader | User Access Administrator (or Role Based Access Control Administrator) + deploy rights | The subscription | Subscription Owner |
| ☐ | Set it up for me — storage, FOCUS export, data reader | Nothing extra — FinOpsAI uses the roles the template granted | — | — |
| ☐ | Export at billing scope (EA / MCA contracts) (optional) | Billing account contributor or Enterprise Administrator | Billing account | — |
| ☐ | Every subscription — grant at the tenant root (optional) | Global Administrator with "Access management for Azure resources" switched on (becomes User Access Administrator at the root) | Tenant root management group | — |
Ask for: Entra Global Administrator · Google Workspace Super Admin
| Step | Minimum role | Where | Or simply | |
|---|---|---|---|---|
| ☐ | Microsoft 365 | Privileged Role Administrator or Global Administrator (approves the Graph read permissions) | Entra ID | — |
| ☐ | AWS seats | Nothing extra — the FinOpsAI stack already granted it | — | — |
| ☐ | Google Workspace | Super Admin (domain-wide delegation) | Google Admin console | — |