Resource-birth alerts
Optional EventBridge monitoring for expensive resources at creation time.
Free AWS Waste Scanner
Create a free product account, deploy a read-only CloudFormation stack, and get a one-time review queue for possible bill-surprise risks. Same account, same role, same upgrade path when continuous guardrails and resource-birth alerts are ready.
The scanner setup uses read-only access. It cannot delete resources, stop instances, resize databases, change networking, or remediate workloads. The optional proactive monitor is a separate customer-owned EventBridge rule for selected creation events.
You do not have to take our word for it. Inspect before you connect: the exact read-only IAM role template (CloudFormation) and exactly what it checks. AWS also shows the full template before you create the stack.
Read-only connection
Cloud Cost Clinic creates one UUID external ID for your product account and passes it into the CloudFormation Quick-Create link. After AWS creates the read-only role, enter the 12-digit AWS account ID. Cloud Cost Clinic constructs the fixed role ARN server-side and validates the external ID trust before scanning.
Scanner dashboard
Sign in to load stored scan history.
Scan report
Findings will appear here after the read-only scan runs.
What it checks
The scanner is intentionally narrower than an enterprise FinOps platform. It focuses on common waste signals small AWS accounts miss, then explains what to verify before changing anything.
Optional EventBridge monitoring for expensive resources at creation time.
Review storage that may keep billing even when workloads are gone.
Find IP addresses that deserve owner, DNS, and allowlist checks.
Flag log storage that can grow quietly without a retention policy.
Catch missing billing safeguards before a surprise bill arrives.
Review image cleanup rules before old container images pile up.
Workflow
The backend creates or reuses a UUID external ID tied to your Cloud Cost Clinic product account.
AWS CloudFormation opens with the scanner role template and the external ID already filled in.
Scanner findings end with cost signal, evidence, risk level, and next action. They are not just "looks unused."
Optionally deploy an EventBridge monitor for selected resource-creation events after the first read-only scan works.
FAQ
No. The scanner setup is read-only. Findings are review items that explain what to verify before making any AWS changes.
The role needs a unique external ID so the trust policy is not anonymous. The same product account also keeps the free scan and future continuous monitoring in one upgrade path.
It opens AWS CloudFormation with a small template that creates one read-only IAM role. It does not create NAT Gateways, databases, compute resources, access keys, or remediation permissions.
The optional monitor stack creates one EventBridge rule and one forwarding role for selected CloudTrail resource-creation events. It does not grant remediation permissions or change workloads.
No. It is a lightweight AWS bill-surprise scanner for learners, solo builders, and small teams that want a plain-English review queue.