Allowed
Read billing, inventory, and optimization metadata.
Security model
FinOps Pack cannot modify, stop, start, delete, deploy, or reconfigure AWS resources. It only reads billing, inventory, and optimization metadata required to generate the review.
Read billing, inventory, and optimization metadata.
Modify, delete, deploy, stop, start, or access application data.
What FinOps Pack can read
What FinOps Pack cannot do
External ID
External ID is AWS's confused-deputy safeguard for cross-account roles. FinOps Pack generates one value per review. The value in your trust policy and the value submitted in the review form must match exactly.
Remove access
If you used CloudFormation, delete the finops-pack-readonly
stack. If you created the role manually, delete the IAM role and attached policy.
aws cloudformation delete-stack --stack-name finops-pack-readonly
aws cloudformation wait stack-delete-complete --stack-name finops-pack-readonly
Default permissions
{}
Data handling
Unsupported regions
The public review flow covers commercial AWS regions. GovCloud and China need a separate deployment and trust model.
Next step