Cloud setup overview
CLARITY connects to your cloud accounts using read-only credentials to pull cost data, resource inventories, performance metrics, and optimization recommendations. No write access is required, and no changes are made to your infrastructure.
What you need
| Provider | Credential Type | Minimum Permissions | Setup Time |
|---|---|---|---|
| AWS | Access Key ID + Secret Access Key | ReadOnlyAccess + Billing Read | ~5 min |
| Azure | Service Principal (App Registration) | Reader + Cost Management Reader | ~10 min |
| GCP | Service Account Key (JSON) | Viewer + BigQuery Data Viewer + Billing Viewer | ~10 min |
Security
All credentials are encrypted at rest using AES-256-GCM with per-credential random salts derived from the instance's session secret. Credentials are:
- Never transmitted to third parties or external services
- Never logged in plaintext — audit logs record credential operations without exposing secrets
- Decrypted only in memory at the moment they are needed to query your cloud provider
- Organization-scoped, not user-scoped — see the note below
Cloud accounts are shared across the whole deployment
Connected cloud accounts belong to the CLARITY instance, not to the user who added them. Every authenticated user of your instance can see every connected cloud account and its costs and resources. What a user's role changes is what they can do: only admins can delete a cloud account, and only admins and editors can add one or trigger a sync. Viewers can read everything.
If you need cost data for different teams kept apart from each other, use separate CLARITY deployments — roles are not a data-partitioning mechanism.
Data Security
Your cloud credentials are encrypted at rest and decrypted only in memory when needed. Cost data and resource inventories are stored securely and never shared with third parties.
Provider guides
Follow the detailed setup guide for each provider you want to connect:
- AWS Setup Guide — IAM user with read-only policies, CLI or CloudFormation
- Azure Setup Guide — Service Principal with Reader and Cost Management Reader roles
- Google Cloud Setup Guide — Service Account with Viewer, BigQuery, and Billing roles
What happens after setup
Once you add credentials, CLARITY immediately begins an initial sync:
- Resource Discovery — Inventories all supported resources (EC2, VMs, GCE instances, databases, containers, storage, etc.)
- Cost Data Pull — Retrieves service-level and resource-level billing data. The first sync for a new account pulls up to 12 months of history so trends and comparisons work immediately; later syncs fetch a rolling recent window and periodically re-check the last three months. On AWS this first pull is the single largest Cost Explorer charge you will see, at $0.01 per request.
- Metrics Collection — Gathers CPU, memory, network, and storage utilization from CloudWatch, Azure Monitor, or Cloud Monitoring
- Optimization Analysis — Generates insights for idle, underutilized, and over-provisioned resources
- Commitment Scan — Checks for Reserved Instance, Savings Plan, and Committed Use Discount opportunities
The initial sync typically completes within 2-5 minutes. Subsequent syncs run automatically on a per-provider schedule set for the deployment: AWS every 24 hours, Azure and GCP every 6 hours. AWS is deliberately slower because Cost Explorer bills $0.01 per request against your own account. The cadence is the same on every tier.