Before you connect

Who needs which access

Each cloud asks one person with the right role to approve FinOpsAI once. This page lists every step, the minimum role for it, and the simpler role most companies already have. Forward it to your cloud administrators before the setup call. Every grant is read-only.

01One line per cloud

CloudWho to ask for
FinOpsAI workspaceWorkspace Owner or Admin
Google CloudBilling Account Administrator + Owner of the export project
AWSAdministrator in the management (payer) account
Microsoft AzureGlobal Administrator (Entra) + Owner of the subscription
Unused paid seats (optional)Entra Global Administrator · Google Workspace Super Admin

02FinOpsAI workspace

Ask for: Workspace Owner or Admin

StepMinimum roleWhereOr simply
☐Sign up and create the workspaceNone — the first person becomes OwnerFinOpsAI—
☐Add a cloud, Connect everything, Check again, RefreshOwner or Admin (Members can only view)FinOpsAI—
☐Invite people, approve domain-join requestsOwner or AdminFinOpsAI—

03Google Cloud

Ask for: Billing Account Administrator + Owner of the export project

StepMinimum roleWhereOr simply
☐Switch on the billing export (Standard + Detailed)Billing Account Administrator + BigQuery UserBilling account; export projectBilling Account Administrator + project Owner
☐Connect with Google — create and share the export datasetBigQuery Admin (or Data Owner on the dataset)Export projectProject Owner
☐Connect with Google — add the read-only rolesProject IAM AdminEach project FinOpsAI readsProject Owner
☐Connect with Google — switch on the BigQuery and Recommender APIsService Usage AdminExport projectProject Owner
☐One grant for the whole organization (optional)Organization AdministratorOrganization—

04AWS

Ask for: Administrator in the management (payer) account

StepMinimum roleWhereOr simply
☐Create the FinOpsAI-Connect stack (FOCUS export, bucket, read role)CloudFormation + IAM (create role) + S3 (create bucket) + Data Exports (create export) + Billing readManagement (payer) accountAdministratorAccess
☐Billing access for IAM users (once, if never done)Root user switches on "IAM user and role access to Billing information"Management account—
☐Switch on StackSets trusted access (whole organization) (optional)organizations:EnableAWSServiceAccess + IAM service-linked roleManagement account only — not a delegated adminAdministratorAccess
☐Create the FinOpsAI-Organization stack (read role in every member account) (optional)CloudFormation StackSets (service-managed) + IAM + LambdaManagement accountAdministratorAccess
☐Create the FinOpsAI-Hygiene stack (live reads: snapshots, images, bucket lifecycle, backup plans) (optional)CloudFormation + IAM (add a policy to the FinOpsAI role)Each connected accountAdministratorAccess

05Microsoft Azure

Ask for: Global Administrator (Entra) + Owner of the subscription

StepMinimum roleWhereOr simply
☐Admin consent for the FinOpsAI appPrivileged Role Administrator or Cloud Application AdministratorEntra ID (directory)Global Administrator
☐Deploy to Azure — Reader + Cost Management ReaderUser Access Administrator (or Role Based Access Control Administrator) + deploy rightsThe subscriptionSubscription Owner
☐Set it up for me — storage, FOCUS export, data readerNothing extra — FinOpsAI uses the roles the template granted——
☐Export at billing scope (EA / MCA contracts) (optional)Billing account contributor or Enterprise AdministratorBilling account—
☐Every subscription — grant at the tenant root (optional)Global Administrator with "Access management for Azure resources" switched on (becomes User Access Administrator at the root)Tenant root management group—

06Unused paid seats (optional)

Ask for: Entra Global Administrator · Google Workspace Super Admin

StepMinimum roleWhereOr simply
☐Microsoft 365Privileged Role Administrator or Global Administrator (approves the Graph read permissions)Entra ID—
☐AWS seatsNothing extra — the FinOpsAI stack already granted it——
☐Google WorkspaceSuper Admin (domain-wide delegation)Google Admin console—

07Notes