Connection guides

Connect your cloud to FinOpsAI

One guide per cloud, written for the administrator who will do the work — forward the link and they need nothing else. Every connection is read-only and keyless: FinOpsAI never receives keys, secrets or passwords, and you can revoke access from your own console at any time.

Access: read-only, revocable
Credentials stored: none
Region: asia-south1 (Mumbai)
Google Cloud

BigQuery billing export

Enable the export, grant BigQuery Data Viewer on the dataset to your workspace identity — the wizard opens the page and watches for the grant. About 10 min.

AWS

FOCUS 1.2 Data Export + IAM role

S3 bucket in ap-south-1, a Data Export, then one CloudFormation template generated for your workspace creates the read-only role. About 15 min.

Azure

Cost Management FOCUS export

One admin consent and one Deploy to Azure click; FinOpsAI creates the FOCUS export for you inside rg-finopsai. About 10 min.


01What every connection has in common

Google CloudAWSAzure
What you createBilling export to BigQueryFOCUS 1.2 Data Export to S3FOCUS export to Blob Storage
How access is grantedIAM grant on the datasetIAM role trusting one Google identity (CloudFormation)Admin consent + one ARM template (Deploy to Azure)
Identity you grantYour workspace identity fa-<company>@… (shown in the wizard)Your workspace identity's unique ID (in the generated template)App finopsai-ingestor-fed
Secrets exchangedNoneNoneNone
Where the data is readIn place, in your datasetLoaded into FinOpsAI's store in asia-south1Loaded into FinOpsAI's store in asia-south1
Residency choiceDataset in asia-south1Bucket in ap-south-1Storage account in Central India
Who in your organisationBilling Account Admin + project OwnerManagement-account adminEntra admin (consent) + subscription Owner (template)
Time to first data≤ 24 h≤ 24 hMinutes — FinOpsAI runs the export
RevokeRemove the principalDelete the stackDelete rg-finopsai / the enterprise app

02Before you send this to your cloud team