Skip to content

Cloud setup overview ​

CLARITY connects to your cloud accounts using read-only credentials to pull cost data, resource inventories, performance metrics, and optimization recommendations. No write access is required, and no changes are made to your infrastructure.

What you need ​

ProviderCredential TypeMinimum PermissionsSetup Time
AWSAccess Key ID + Secret Access KeyReadOnlyAccess + Billing Read~5 min
AzureService Principal (App Registration)Reader + Cost Management Reader~10 min
GCPService Account Key (JSON)Viewer + BigQuery Data Viewer + Billing Viewer~10 min

Security ​

All credentials are encrypted at rest using AES-256-GCM with per-credential random salts derived from the instance's session secret. Credentials are:

  • Never transmitted to third parties or external services
  • Never logged in plaintext — audit logs record credential operations without exposing secrets
  • Decrypted only in memory at the moment they are needed to query your cloud provider
  • Organization-scoped, not user-scoped — see the note below

Cloud accounts are shared across the whole deployment

Connected cloud accounts belong to the CLARITY instance, not to the user who added them. Every authenticated user of your instance can see every connected cloud account and its costs and resources. What a user's role changes is what they can do: only admins can delete a cloud account, and only admins and editors can add one or trigger a sync. Viewers can read everything.

If you need cost data for different teams kept apart from each other, use separate CLARITY deployments — roles are not a data-partitioning mechanism.

Data Security

Your cloud credentials are encrypted at rest and decrypted only in memory when needed. Cost data and resource inventories are stored securely and never shared with third parties.

Provider guides ​

Follow the detailed setup guide for each provider you want to connect:

What happens after setup ​

Once you add credentials, CLARITY immediately begins an initial sync:

  1. Resource Discovery — Inventories all supported resources (EC2, VMs, GCE instances, databases, containers, storage, etc.)
  2. Cost Data Pull — Retrieves service-level and resource-level billing data. The first sync for a new account pulls up to 12 months of history so trends and comparisons work immediately; later syncs fetch a rolling recent window and periodically re-check the last three months. On AWS this first pull is the single largest Cost Explorer charge you will see, at $0.01 per request.
  3. Metrics Collection — Gathers CPU, memory, network, and storage utilization from CloudWatch, Azure Monitor, or Cloud Monitoring
  4. Optimization Analysis — Generates insights for idle, underutilized, and over-provisioned resources
  5. Commitment Scan — Checks for Reserved Instance, Savings Plan, and Committed Use Discount opportunities

The initial sync typically completes within 2-5 minutes. Subsequent syncs run automatically on a per-provider schedule set for the deployment: AWS every 24 hours, Azure and GCP every 6 hours. AWS is deliberately slower because Cost Explorer bills $0.01 per request against your own account. The cadence is the same on every tier.

Multi-Cloud FinOps Platform