Your environment is ready and this address is yours. Before anyone can sign in, an administrator completes the setup below in your own accounts — it creates the read-only access FinOps measures through, and nothing else.
Deploy this CloudFormation template in the AWS account you want FinShift to read. It creates one IAM user granting Describe, List and Get — no write action, no billing access, and no ability to read object or log CONTENT. Then create an access key for that user in the IAM console and send FinShift the key id, the secret and the account id.
Deployed with CloudFormation · needs permission to create an IAM user · about two minutes · AWS shows you exactly what it will create before you confirm. The template deliberately does NOT create the access key: a CloudFormation output is not secret.
Need help? Email Onboarding@SlashZero.ai — we can see exactly which of the steps above is outstanding, and why, without you having to describe it.