Skip to main content

Cloud connections overview

AvailableReviewed 21 August 2026

A connector is a read-only path from a cloud billing export into your FinomateAI tenant. FinomateAI does not create, start, stop or delete cloud resources through a connector.

Connected accounts with AWS, Azure and Google Cloud status
Sample organisation. Add one provider first; the others can follow.

What you grant

ProviderIdentityData
AWSCross-account IAM role with an external IDCost and Usage Report (or FOCUS) in S3
AzureService principalBilling export in a storage account
Google CloudService accountBigQuery billing export

Keep the identity read-only. If a security review asks whether FinomateAI can change infrastructure, the answer is no.

Prepare before you open onboarding

Agree four things with your cloud and finance teams:

  1. Scope — which payer, subscriptions or projects belong in the first connection.
  2. Export — the bucket, container or dataset that already receives a current report.
  3. Owner — who will operate the connector after go-live.
  4. Comparison bill — the completed period you will reconcile first.

Provider guides