First-time setup: what to do after you sign up
Once you have signed up, there is one thing to do next: forward AWS's notification emails to the address Sabaki issues for you. That much takes ten minutes at best, and from then on every notification lands in the inbox with a summary and an explanation of what it means. Delivery destinations, team invitations and the cost connection can be added later, when you need them.
Last updated: 2026-09-22
The whole route
Steps 1 to 4 are the required ones. Once they are done, the notifications are readable. In step 3 you choose between creating a forwarding rule and forwarding by hand (the rule is not required). Step 5 is the day-to-day use, and steps 6 to 8 are only for those who need them. There is a small progress indicator, “Setup”, at the top right of the dashboard; pressing it opens a checklist in this same order. Finished items are ticked off by themselves, and once they all are, the indicator disappears. Even after it has gone, you can open the checklist whenever you like from “Show setup progress” in the help menu at the bottom left.
Nothing has to change on the AWS side unless you do step 8, the cost connection. For mail forwarding alone, there is no need to open the AWS console.
Name your workspace
The first time you sign in, you are asked for a name for the workspace. Put in your company name or your team name. You can change it later in “Settings”, which opens from the account name at the bottom left. This name is what the people you invite to your team see, and it appears on the proposal you hand to your customer.
Issue the forwarding address
Open “AWS Accounts” in the left menu, choose the “Groups” tab at the top of the page and press “Add group”. A group is the unit notifications are gathered into: one per customer, one per department, or a single one for your own company — whichever suits. Creating it issues a forwarding address (@in.sabaki.cloud) that belongs to that group.
If you connected an AWS account first, one group has already been created for you. Open that same “Groups” tab and the forwarding address is there.
Decide how to forward: by hand, or with a rule
There are two ways and either is fine. If you are just trying it out, forwarding by hand is quicker.
Forwarding by hand: leave your mailbox as it is and forward to the address from step 2, one at a time, only the notifications you want explained. Use your mail client's ordinary “Forward”. As long as the original is in the body, it is classified (avoid “Forward as attachment”: the original cannot be read that way). Nothing has to be configured, and there is no Gmail forwarding confirmation to complete.
Putting a rule in: in the mailbox that receives AWS's notifications, create a rule that automatically forwards mail whose sender is AWS to the address from step 2. Nothing gets forgotten that way, so this is the one to choose if you want to be sure of catching notifications with a deadline. There is no need to change where the root account's mail is received.
Gmail sends a confirmation email when you register a forwarding address. That confirmation arrives in Sabaki's inbox, and opening it shows an approval button. Press it, and create the filter in Gmail afterwards.
- Gmail / Google Workspace: in the help, “How do I forward from Gmail / Google Workspace?”
- Microsoft 365 / Outlook: in the help, “How do I forward from Microsoft 365 / Outlook?”
Check the first notification in the inbox
Forward one AWS notification you already have to the forwarding address. In about a minute it appears in the “Inbox” with its summary. Opening it shows the explanation, the severity, the deadline, the AWS account ID and the original message.
Mail you forward by hand is marked “Unverified”. That says it arrived by a route where AWS's signature cannot be checked, and it is not a fault: if you are going to keep forwarding by hand, that is the normal state. Mail that arrives through an automatic forwarding rule (and through Outlook's “Redirect”) is shown with the signature verified.
If nothing arrives, see “Notifications are not arriving. What should I check?” in the help.
Work through the notifications
From here on it is the day-to-day use. The inbox is shared by everyone in the workspace: the moment one person handles something, it shows on everyone's screen.
- Handling status: open the notification and press “Handled” or “No action needed”. “No action needed” requires a memo
- Memos: write what you checked and what you decided, then press “Save”. A memo on its own can be left too
- Clearing up: “Archive” what you have read, and “Delete” what you do not need, which goes to the trash. Anything in the trash is deleted permanently after 30 days
- Finding things: there is the search box at the top, and filters by group, by AWS account, by handling status and by “With a memo”
- When the AI's explanation is wrong: tell us from the link below the explanation
Deliver to Slack or emailTeam plan and above
Press the account name at the bottom left to open “Settings” and register an Incoming Webhook URL under “Slack notifications”: every time a notification arrives, its summary and explanation are posted to Slack. A different channel can be set for each group as well. Register a recipient under “Email notifications” and they arrive by email too; the recipient is sent a confirmation email, and nothing is delivered until it is approved.
Only the summary and the explanation Sabaki generates are delivered; the original message is not.
Invite your teamTeam plan and above
Under “Team” in “Settings” (which opens from the account name at the bottom left), create an invitation link and hand it over. There are two roles, Admin and Member. A member's visible groups can be limited, which is what to use when you want different people looking after different customers.
See the costsOptional
Start from “Connect AWS account” in the left menu. Create one read-only IAM role in your AWS account and you can see monthly spend, the per-service breakdown and savings recommendations. The role can be created in a single operation from the CloudFormation button. Sabaki never writes anything on the AWS side and holds no access keys. Delete the role and the connection stops, whenever you like.
The first analysis starts as soon as the account is connected, and within a few minutes the results appear under “Recommendations”, beside “Cost” in the left menu. After that it refreshes by itself every day.
What changes from plan to plan
The Free plan covers one seat, one AWS account and an inbox that reaches 7 days back from arrival. The summaries and explanations, the handling status and memos, cost visibility, and the detection of unused resources with its savings recommendations are all on Free too. Delivery to Slack and email and team invitations start at Team. Right-sizing, Reserved Instance and Savings Plans recommendations, and the per-service breakdown for Organizations member accounts, are on Pro. The detail is on the pricing page.
The progress is on the dashboard
Press “Setup” at the top right and a checklist opens in the same order as this guide. Finished items are ticked off by themselves.
Related questions
Related guides
If this helps, pass it on to someone who needs it.
