📨 For teams that look after several AWS accounts

AWS notification emails,
sorted by customer.

Forward the AWS notifications you receive to one address. Sabaki checks they really came from AWS, works out which customer and which account each one is about, says what is happening, what it affects and what to do by when — and delivers it to Slack and a per-customer inbox.

Add one read-only role and you get cost visibility and savings recommendations too.

  • ✓ No credit card required
  • ✓ No changes in AWS to get started
  • ✓ Read-only, no access keys stored
AWS notifications as they arrive — every customer, mixed
✉️ [Action Required] RDS certificate rotation✉️ ElastiCache maintenance scheduled✉️ Your AWS invoice is available✉️ [Retirement] EC2 instance stop/start required✉️ Lambda runtime deprecation notice✉️ S3 will require TLS 1.2 for all connections✉️ AWS Health: degraded performance in ap-northeast-1✉️ New features for Amazon CloudWatch✉️ [Action Required] RDS certificate rotation✉️ ElastiCache maintenance scheduled✉️ Your AWS invoice is available✉️ [Retirement] EC2 instance stop/start required✉️ Lambda runtime deprecation notice✉️ S3 will require TLS 1.2 for all connections✉️ AWS Health: degraded performance in ap-northeast-1✉️ New features for Amazon CloudWatch
⬇Sabaki explains each one and identifies the customer and account
Acme Inc.1234-5678-9012
🔴RDS certificate needs rotatingDue Aug 15 — requires a restart
🔵Your invoice is available
Borealis Ltd.2345-6789-0123
🟠ElastiCache maintenance scheduledJul 21, 03:00 — brief failover
🔵S3 will require TLS 1.2Check batch jobs on old SDKs
Internal3456-7890-1234
🟠EC2 instance retirementStop and start to move hardware
🔕Marketing mail muted automatically
Sound familiar?

The more customers you have, the less anyone reads AWS email

Notices pile up unread

Maintenance windows, certificate renewals, instance retirements. They arrive dense and look alike, so the one that needed action is found late.

Which customer is this about?

The notice names a 12-digit account ID. Someone looks it up in a spreadsheet, every time, to find out whose project it is.

It lives in one person's inbox

Whoever noticed it dealt with it. The team never knew, the customer was never told, and nothing can be handed over.

Giving a tool credentials feels wrong

Handing access keys to a third-party service is uncomfortable. When the account belongs to your customer, more so.

Forgotten resources keep billing

The test EC2 instances and EBS volumes are probably still there, but with this many accounts nobody gets around to checking.

Hard to explain to anyone

“Why is it higher than last month?” “What will next month be?” Each time someone asks, the research starts from zero.

Sort — the mail hub

Forward one notice, and they start landing in their customer's lane

Nothing changes in AWS. Sabaki verifies, explains and sorts whatever is forwarded to your dedicated address, then delivers it.

  1. 1

    Forward

    AWS mail goes to an address issued per group — by a forwarding rule in your mailbox, or forwarded by hand when you want it.

  2. 2

    Verify

    The DKIM signature shows whether AWS really sent it. Mail that claims to be AWS without one is not delivered.

  3. 3

    Explain

    What is happening, what it affects and what to do by when, in a few plain sentences.

  4. 4

    Sort

    The forwarding address and the account IDs and ARNs in the body identify the customer and the account.

  5. 5

    Deliver

    To a per-customer inbox, and to Slack or email. Marketing mail is left out.

Sender verification

Every message shows whether AWS's DKIM signature checked out. Mail that names AWS as the sender with nothing to back it up is treated as spoofed and not delivered.

Summary and explanation

AI (Claude on Amazon Bedrock) summarizes each notice and sets a severity and a deadline. One read tells you what is happening, what it affects and what to do. In English or Japanese, chosen per customer.

Customer and account matching

Account IDs and ARNs in the body are matched against the accounts filed under each group. A new ID is linked with one click, and recognized from then on.

An inbox per customer

Folders, stars, search and bulk actions. Filter past notices and their handling by customer, account and status.

Slack and email delivery

Delivered automatically to a different destination per customer. Email for customers who do not use Slack. Marketing mail is off by default.

Response ledger

Who handled what, and when. Marking something “no action needed” requires a reason, so the record stands up at handover and when a customer asks.

Forwarding instructions for Gmail / Microsoft 365 are in the help pages.

Next step — cost visibility

Add one read-only role for costs and savings recommendations

One click in CloudFormation creates a read-only role. Sabaki finds resources nobody is using, estimates what each costs per month, and AI proposes what to do about each. The 60-second demo below shows it from connection to recommendation.

Waste, with a price on it

Unattached EBS volumes and Elastic IPs, idle EC2 and RDS instances, in every region where you have had spend in the last 30 days — each with a monthly estimate at public On-Demand rates from the AWS Pricing API.

AI proposes the fix

AI (Amazon Bedrock) ranks the findings and writes the steps to resolve them. Runs once when you connect, then every night.

All of it on Free

The kinds of waste detected and the recommendations themselves are the same on the free plan as on paid ones. Industry surveys (Flexera and others) estimate that a little under 30% of cloud spend is wasted.

Sabaki — OnboardingDemo playing

Step 1 of 3

Sign up

Sign in instantly with your Google account

Continue with Google

Step 2 of 3

Connect AWS

Create the role with one click in CloudFormation

AWSCloudFormation
SabakiCloudReadOnly
CREATE_IN_PROGRESS0%

Step 3 of 3

Paste the role ARN

The server runs a connection test

Verifying sts:AssumeRole…

Analyzing

Multi-region scan

Regions with real spend are found through Cost Explorer

us-east-1
  • us-east-1Scanning…
  • ap-northeast-1Waiting
  • eu-west-1Waiting
  • ap-southeast-1Waiting

Findings

Savings candidates found

AI writes the steps to resolve each one

  • CRITICAL
    vol-0a3c9f1e — 180 GB unattached EBS volume
    +$18.00/mo
  • HIGH
    i-07b2d14f — EC2 at 3% CPU for 14 days
    +$42.60/mo
  • HIGH
    eipalloc-0c91… — 4 unused Elastic IPs
    +$14.40/mo
  • MEDIUM
    mydb-staging — RDS instance with no connections for 7 days
    +$36.50/mo

Total

Possible monthly savings

$0.00/mo

Estimate if all 4 recommendations are applied

Share

With your team, and with the customer

Get sorted notices and costs out of one person's mailbox. Invite members, decide who sees which groups, and give customers a read-only view of their own.

Seats

Add members with an invitation link. Owner, admin and member roles.

Groups and visibility scopes

Group AWS accounts and notices by customer, and limit what each member can see.

Client share view

Issue a read-only view to the customer. The answer to “what happened with that notice?” becomes a URL.

Free for one person. Paid plans start where sharing starts (pricing).

Getting started

Three steps, none of them in AWS

1

Sign in with Google

No password to set. Signing up takes about 30 seconds.

2

Add a customer and forward their notices

Forward AWS notifications to the address issued for that customer. Nothing changes on the AWS side. Steps for Gmail and Microsoft 365 are in the help pages. You can also skip the rule and forward just the notices you want explained.

3

Work from Slack and the inbox

Forwarded notices arrive explained within minutes. Deal with them and record it in the ledger.

📈

Next step: add costs with a read-only role

One click in CloudFormation creates a read-only role, and cost trends, waste detection and savings recommendations appear. Use notifications only, costs only, or both.

Pricing

Simple pricing

Notification explanations and the inbox, cost visibility and savings recommendations are complete on every plan. The four plans differ in how far you share — with your team and your customers. Pay yearly and get two months free.Prices are in US dollars and exclude tax; any tax that applies is added at checkout. The 14-day free trial is for workspaces subscribing to a paid plan for the first time.

Free

$0

1 person, 1 AWS account

  • Notification explanations and inbox, in real time
  • Full cost visibility and savings recommendations
  • 7 days of history
  • All one person needs
Start free

Team

$19/mo

3 people, unlimited accounts ($190 billed yearly)

  • Slack and email delivery
  • Visibility scopes
  • Unlimited AWS accounts
  • 30 days of history
Try free for 14 days
Popular

Business

$49/mo

10 people, unlimited accounts ($490 billed yearly)

  • Everything in Team
  • Client share view
  • Per-customer Slack and email routing
  • 90 days of history
Try free for 14 days

Pro

$149/mo

Unlimited members ($1,490 billed yearly)

  • Everything in Business
  • Per-service breakdown for Organizations member accounts
  • Advanced analysis (right-sizing, RI and Savings Plans) and client proposal documents
  • 1 year of history
Try free for 14 days
Compare plansFreeTeamBusinessPopularPro
Monthly priceTwo months free when billed yearly (about 17% off). Tax is added at checkout where it applies$0$19$49$149
Yearly priceBilled once a year$0$190$490$1,490
Free trialEvery feature, free for 14 days, on a workspace's first paid subscription—14 days14 days14 days
Notification explanations and inboxAWS notices summarised and explained as they arrive✓✓✓✓
Cost visibility and savings recommendationsWaste detection with monthly estimates, cost trends and AI recommendations — complete on every plan✓✓✓✓
AWS account connectionsAccounts you can connect with a read-only role1UnlimitedUnlimitedUnlimited
SeatsPeople you can invite to the dashboard1310Unlimited
RolesOwner, admin and member (not applicable to Free, which has one seat)—✓✓✓
Slack and email deliveryNotices delivered automatically to your team's channel or to chosen email addresses, routed to a different Slack channel or address per customer—1 channelPer-customer routingMultiple workspaces
GroupsFile AWS accounts and notices by customer or product. A forwarding address is issued to each group✓✓✓✓
Visibility scopesLimit which groups each member can see—✓✓✓
Client share viewA read-only portal where your customer sees their own cost charts and notices——✓✓
Advanced analysisRight-sizing and RI / Savings Plans recommendations (AWS's own, fetched nightly) and client-facing proposal documents (PDF and CSV)———✓
Inbound mail limitsForwarded messages analyzed and delivered (per address per hour / per workspace per day)30/hr · 50/day60/hr · 300/day120/hr · 1,000/day300/hr · 3,000/day
History and filtersHow far back notices and their handling records go (filter by customer, account and status)7 days30 days90 days1 year, with export
Start freeTry TeamTry BusinessTry Pro

For larger deployments, invoicing or SSO, get in touch.

Security

We never hold your AWS access keys

Notifications arrive by mail forwarding and nothing else. Costs are read through STS AssumeRole with an ExternalId, read-only. Sabaki has no technical means to change or delete anything in your customers' AWS accounts.

  • ✓
    Mail arrives by forwarding only

    You do not move the root mailbox to Sabaki. Addresses are unguessable random strings, and stopping the forward ends the connection immediately.

  • ✓
    No access keys stored

    Only the role ARN is kept. The trust policy requires an ExternalId condition.

  • ✓
    Read-only IAM policy

    Describe, Get and List actions on Cost Explorer, EC2, RDS, ELB, S3, CloudWatch and Organizations. No permission to change or delete exists.

  • ✓
    Disconnect whenever you like

    Delete the IAM role in the customer's account and access stops at once.

  • ✓
    A registered company behind it

    Run by Noriva LLC, Tokyo. Support in English and Japanese; invoices on request.

# Trust policy on the role in your customer's account
{
  "Effect": "Allow",
  "Principal": {
    "AWS": "arn:aws:iam::638954280170:root"
  },
  "Action": "sts:AssumeRole",
  "Condition": {
    "StringEquals": {
      "sts:ExternalId": "<your-uuid>"
    }
  }
}

# The permissions policy allows Describe / Get / List only
# Nothing that writes, changes or deletes
FAQ

Frequently asked questions

Does explaining notifications require changes on the AWS side?▾

No. You only forward AWS notifications to the dedicated address Sabaki issues. A forwarding rule works, and so does forwarding by hand when needed.

You never hand over your root email to Sabaki; stop forwarding and the connection ends immediately.

How do you tell which customer and account a notification belongs to?▾

Account IDs and ARNs in the notification body are extracted and matched against the accounts filed under each group.

An account ID seen for the first time is shown as unlinked; link it to a group once and it is recognised from then on. You can also assign accounts by hand from the AWS accounts page.

Where do notifications go? Is Slack required?▾

No. Notifications can go to a Slack channel, an email address, or both.

Destinations can differ per client, and an email destination receives nothing until its owner confirms it. Customers who do not use Slack can be served as they are.

Do you really not need access keys?▾

Yes. Sabaki uses AWS STS AssumeRole to temporarily assume a read-only IAM role that you create. Access keys and secret keys are never sent or stored.

The role's trust policy allows only Sabaki's AWS account together with the External ID issued to your workspace, which also covers the confused-deputy problem.

How much can I expect to save?▾

Industry surveys (Flexera's State of the Cloud, among others) estimate that just under 30% of cloud spend goes to unused or oversized resources. Results depend on your environment.

With the current checks (unattached EBS volumes, unused Elastic IPs, idle EC2 and RDS) 5–15% of monthly AWS spend typically surfaces. On Pro, AWS's own right-sizing, Reserved Instance and Savings Plans recommendations are imported into the list too.

Can I cancel at any time?▾

Yes, at any time. Cancel with one click, keep using the plan until the end of the period, and move to Free automatically. There are no cancellation fees.

Setup steps and day-to-day questions are in the help pages.

If this helps, pass it on to someone who needs it.

Start by forwarding one notice.

No credit card. No changes in AWS. Sort your notifications from today, and add cost visibility whenever you add the read-only role.