AWS cost visibility and savings recommendations

Connect one read-only IAM role. In a few minutes you see your spend over time and what the resources nobody is using cost per month.

  • Finds idle EC2 and RDS instances, unattached EBS volumes and unassociated Elastic IPs, in every region where you have had spend in the last 30 days, each with a monthly estimate
  • All you hand over is a read-only role: no access keys are registered, and without write permissions nothing can be deleted or purchased on its own
  • Cost visibility and the AI's savings recommendations are complete on the Free plan ($0, 1 AWS account), with no credit card

“Why did the AWS bill go up?” and “where is the waste?” are questions you want answered in actual figures, account by account. One read-only IAM role is all Sabaki needs to show spend over time, find the resources that were left behind, and propose what can be saved. Cost visibility and savings recommendations are complete on the Free plan too.

Last updated: 2026-09-22

What comes into view

Spend for each connected account is read from Cost Explorer data: the month-by-month trend, this month's spend so far, and the breakdown by service. Connect several accounts and you can switch between customers and between accounts, so when someone asks why the bill went up compared with last month, you can answer which service it was.

Alongside that, four kinds of resource that tend to become waste are detected, in every region where you have had spend in the last 30 days: idle EC2 and RDS instances with low CPU use, EBS volumes attached to no instance, and Elastic IPs associated with no resource. A monthly estimate for each is worked out from the public On-Demand rates in the AWS price list, and the AI lays them out as savings recommendations that say why it counts as waste and what to do about it.

Read-only, so connecting is safe

You never hand Sabaki an access key. A read-only IAM role is created in your AWS account, and Sabaki assumes it temporarily with an External ID. The role holds read permissions only: Cost Explorer reads, Describe on EC2, EBS and RDS, and CloudWatch metric reads.

A recommendation stays a recommendation. Sabaki never deletes or purchases resources on its own, and without write permissions it could not. Whether to act on one is for you and your customer to decide after reading it.

What Free covers, and how Pro differs

The Free plan ($0) takes one account, but cost trends, all four detections and the AI's savings recommendations are all there. From Team ($19 per month, tax excluded) the number of accounts is unlimited. Pro ($149) adds AWS's own right-sizing, Reserved Instance and Savings Plans recommendations, pulled in every night, and the per-service breakdown for Organizations member accounts.

Example: the mail that arrives, and what Sabaki shows

The subject and body imitate a real notification. Account IDs and dates are fictional.

The mail that arrives (English)
From
AWS Budgets <no-reply-aws@amazon.com>
Subject
AWS Budgets: monthly-prod has exceeded your alert threshold

Dear AWS Customer,

You requested that we alert you when the actual cost associated with your monthly-prod budget exceeds 80% of the budgeted amount for the current month. The actual cost is USD 2,410.55, which is 80.4% of your USD 3,000.00 budget.

Budget period: 2026-09-01 to 2026-09-30. Account: 123456789012.

What Sabaki shows (English)
Action requiredCompany A (online shop)123456789012 (Company A, production)

The monthly budget monthly-prod in Company A's production account has reached 80% ($2,410.55 of $3,000.00, as of 18 September). At this rate it will go over before the month ends.

80% of the budget has gone with 60% of the month elapsed, so it goes over if nothing changes. Open Sabaki's cost screen, compare Company A's per-service breakdown with last month's, and find which service went up. If the savings recommendations list idle EC2 instances or unattached EBS volumes, their monthly estimate is the concrete room to cut. The fastest route is to give the customer both at once: what went up, and where it can be cut.

A Budgets alert only arrives by mail if a budget is configured on the AWS side. Even without one, Sabaki's cost screen shows spend over time from the moment you connect the account.

When recommendations are updated

An analysis runs once right after an account is connected, then refreshes automatically every night. When you want to check straight away, you can run it by hand with “Re-analyse now” (up to three times a day per account). Each recommendation is tracked as “Open”, “Applied”, “Dismissed” or “Snoozed”, and one still “Open” that the analysis stops detecting becomes “Resolved”. The estimated savings add up on the dashboard.

Getting started

You can connect in three ways: a one-click CloudFormation template, the IAM console, or the CLI. The template is public, so you can check the permissions before applying it. Once connected, the first analysis appears within a few minutes.

Connect one read-only role and the first results come back in minutes

The Free plan covers one account and one seat, with no credit card. All it needs is a read-only IAM role — no access keys, and no write permissions.

Related questions

Related guides

If this helps, pass it on to someone who needs it.