Cloud connections overview
A connector is a read-only path from a cloud billing export into your FinomateAI tenant. FinomateAI does not create, start, stop or delete cloud resources through a connector.

What you grant
| Provider | Identity | Data |
|---|---|---|
| AWS | Cross-account IAM role with an external ID | Cost and Usage Report (or FOCUS) in S3 |
| Azure | Service principal | Billing export in a storage account |
| Google Cloud | Service account | BigQuery billing export |
Keep the identity read-only. If a security review asks whether FinomateAI can change infrastructure, the answer is no.
Prepare before you open onboarding
Agree four things with your cloud and finance teams:
- Scope — which payer, subscriptions or projects belong in the first connection.
- Export — the bucket, container or dataset that already receives a current report.
- Owner — who will operate the connector after go-live.
- Comparison bill — the completed period you will reconcile first.