Portfolio view

Every cloud account in one workspace

Connect AWS accounts and GCP projects to one workspace. Each scan collects from every account, and findings, cost and fixes stay tied to the account they belong to.

It doesn’t discover member accounts in AWS Organizations; you connect each account.

The problem

When a cloud account is treated as the whole workspace, adding a second one breaks things. You can’t compare accounts, tell which account a finding belongs to, or be sure a fix runs in the right place.

How it works

  1. Add accounts

    Run the onboarding wizard for each AWS account (cross-account role or in-account collector) or GCP project (service account key). Adding an account leaves your primary account unchanged.

  2. Collect and attribute

    Each scan collects from every account, records what each one returned, and ties findings and cost to their account.

  3. Compare and act

    View all accounts or pick one in the header. Approved AWS fixes run through the cross-account role of the account the finding came from.

  • 1 account

    on the free plan; paid plans and the trial allow more

  • Per account

    whether collection completed, how many records, which collectors failed

  • Refused

    a fix whose account can’t be resolved, rather than run in the primary account

  • AWS only

    for changes; GCP projects are collected and analysed

Capabilities

Many AWS accounts and GCP projects in one workspace, with every finding tied to its account.

  1. One workspace, many accounts

    Add AWS accounts and GCP projects to one workspace, rename them and choose a primary. Removing an account needs the owner role and disconnects only that account. The free plan allows one account; paid plans and the trial allow more.

  2. Collected and attributed per account

    Each scan collects from every account with that account’s own access and records the result per account. Findings take their account from the resource they name; findings about spend as a whole fall back to your primary account.

  3. Reports and briefs per account

    With two or more accounts, each scan writes a workspace report plus a report for each account that has findings. Paid and trial workspaces also get a daily brief per account. Pick an account to read its own.

  4. Fixes and safety rules per account

    Approved AWS fixes run through the cross-account role of the account the finding came from, and are refused if that account can’t be resolved. Automation safety rules and Slack channels can be set per account, so production and staging can differ. An account’s environment label, set in Settings → Accounts, says whether it is production, and an account with no label counts as production.

In depth

Adding and managing accounts

Settings → Accounts lists every connected account. Admins add accounts through the onboarding wizard, rename them, and choose which one is primary. Adding another account doesn’t change which one is primary. Only the owner can remove an account, and removing one disconnects that account alone.

The primary account matters in two places. Findings that don’t point at a single resource are attributed to it, and the cost report shows it when no account is selected.

The free plan is limited to one account. Pro and the free trial include 10 cloud accounts; if you need more than 10, talk to us.

How collection works per account

Each scan goes through every connected account and collects with that account’s own access:

  • AWS accounts on the cross-account role: GetFinOps assumes that account’s role with an External ID.
  • AWS accounts using the in-account collector: it reads the latest snapshots from that account’s bucket.
  • GCP projects: it uses that project’s service account key and billing export dataset.

Evidence that each account was scanned

An AWS account without an assumable role is skipped and marked failed, rather than read with some other credentials. Each run then records a result for every account: its collection status, how many records it returned, the collectors that failed and the fetches that failed inside them.

The account cards on the home page show each account’s collection status and record count from the latest scan, so an account whose collection failed or was partial doesn’t show as complete.

What the account selector scopes

The header selector appears once a workspace has two or more accounts. If a selected account has since been removed, pages return an error instead of an empty result, so a stale selection can’t pass for a clean account.

Picking an account scopes these pages to it:

  • Findings and the remediation plan.
  • The cost report and cost allocation.
  • Budgets: that account’s budgets plus workspace-wide ones.
  • Reports and daily briefs.
  • Executions, tag governance, Kubernetes clusters and sustainability.

Reports and daily briefs per account

A scan merges every account into one run and always writes a workspace report. With two or more accounts it also writes a report for each account that has findings, built from that account’s findings and plan. Accounts with no findings get no report of their own.

Paid and trial workspaces also get a daily brief for each account with findings, next to the workspace brief. Free workspaces get the workspace brief only.

Fixes and safety rules per account

An approval carries the account of its finding. When it runs, GetFinOps assumes that account’s cross-account role. If the account can’t be found, the fix is refused rather than run against the primary account.

Automation Safety has a workspace default and a row per account. Each account row can block or allow fixes in production, turn on a notice when a fix is blocked, and choose the Slack channel that hears about it. The workspace default sets which environment names count as production. An account’s environment comes from its label, which you choose when you add the account and can change in Settings → Accounts or Automation Safety; an account with no label counts as production. Slack approval cards name the account and go to its channel when one is set.

What it does not do

  • It doesn’t discover member accounts in AWS Organizations; you connect each account.
  • A self-hosted Marketplace install reads AWS data with its own credentials, so it sees the account it runs in, not other AWS accounts you add.
  • It doesn’t make changes in GCP projects.
  • It doesn’t apply fixes in AWS accounts connected through the in-account collector.
  • The tag compliance trend and the commitments view cover the whole workspace, not a single account.
  • The cost report shows one account at a time; the by-account charts show the workspace total.

FAQ

Questions

Is there a limit on accounts?

The free plan allows one cloud account. Pro and the free trial include 10 cloud accounts; if you need more than 10, talk to us.

Does it find the accounts in my AWS Organization automatically?

No. You connect each account yourself. Discovering member accounts through AWS Organizations isn’t built yet.

Can I see just one account?

Yes. Once a workspace has two or more accounts, a selector in the header scopes findings, cost, budgets, reports and other pages to one account. Choose “All accounts” to see the whole workspace.

Can production and staging have different rules?

Yes. Automation Safety has a workspace default and a row for each account, so you can block automated fixes in a production account and allow them in staging. Each account’s environment label says whether it is production: you choose it when you add the account and can change it in Settings → Accounts, and an account with no label counts as production. Rows you leave blank inherit the workspace default.

How are GCP projects handled?

Each GCP project is its own account, with its own service account key and billing export dataset. GetFinOps collects and analyses GCP projects, but it only makes changes in AWS.

Try free — no credit card

Create a workspace and connect an AWS or GCP account, or book a demo first.