Permissions Reference
Consolidated view of all cloud provider permissions required by DigiUsher
Overview
DigiUsher needs read-only access to the cost, usage, resource, and metrics data in your cloud environments. This page lists the permissions for each supported cloud provider.
DigiUsher asks for write access only when you enable an optional feature. These features are AWS EC2 scheduling, AWS commitment purchases, and the Azure Terraform flag enable_power_scheduler that starts and deallocates virtual machines.
Cross-Cloud Summary
| Cloud | Identity Type | Authentication | Access Level | Scope |
|---|---|---|---|---|
| AWS | Cross-account IAM Role | STS AssumeRole + ExternalId (temporary tokens) | Read-only | Per-account (root or linked) |
| GCP | Service Account | JSON key | Read-only (viewer roles) | Organization-wide or per-project |
| Azure | App Registration | Client secret | Read-only (Reader role) | Management Group (all subscriptions) |
| OCI | IAM User | API key pair (PEM + fingerprint) | Read-only | Tenancy-wide |
| Alibaba Cloud | RAM User | Access Key ID + Access Key Secret | Read-only (OSS object listing and download) | Single OSS bucket holding the FOCUS export |
| Kubernetes | In-cluster agent (Helm chart) | Agent API token issued by DigiUsher | Read-only (Kubernetes API object metadata and node metrics via ClusterRole) | Per cluster |
Amazon Web Services (AWS)
Access Summary
| Component | Details |
|---|---|
| Identity type | Cross-account IAM Role (no credentials stored in your account) |
| Authentication | STS AssumeRole with ExternalId. Temporary session tokens only |
| Trust relationship | Cross-account IAM role trusting DigiUsher AWS account 058264546051 with ExternalId |
| Base permissions | Read-only across cost, compute, database, storage, networking, security, and organizational metadata |
| Optional permissions | EC2 start and stop, commitment purchases, tag management, and automation. All of these are off by default |
| Data access | The S3 bucket with the Cost and Usage Reports. DigiUsher reads the CUR data only |
| Scope | Single AWS account (root or linked) |
| Capability | What It Provides |
|---|---|
| Billing data | Cost analytics, chargeback and showback, budgeting, forecasting, anomaly detection |
| Resource inventory | Asset discovery, idle resource detection, tag-based cost allocation |
| Optimization recommendations | Rightsizing, commitment analysis (RI/SP), idle resource cleanup |
| Utilization metrics | CPU, memory, network, disk usage for rightsizing analysis |
DigiUsher cannot create, change, or delete an AWS resource. The only exception is an optional write permission that you enable yourself.
Core Permissions (Read-Only)
DigiUsher attaches the IAM policy that follows (DigiUsherCorePermissions) to its IAM role as an inline policy:
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "DigiUsherCostAndBillingPermissions",
"Effect": "Allow",
"Action": [
"ce:Describe*",
"ce:Get*",
"cur:Describe*",
"cur:Get*",
"bcm-data-exports:ListExports",
"bcm-data-exports:GetExport",
"budgets:ViewBudget",
"savingsplans:DescribeSavingsPlans",
"savingsplans:DescribeSavingsPlansOfferings",
"savingsplans:DescribeSavingsPlansOfferingRates",
"invoicing:GetInvoicePDF",
"invoicing:GetInvoiceUnit",
"invoicing:GetInvoiceSummary",
"invoicing:ListInvoiceSummaries",
"invoicing:BatchGetInvoiceProfile",
"pricing:GetProducts"
],
"Resource": "*"
},
{
"Sid": "DigiUsherComputePermissions",
"Effect": "Allow",
"Action": [
"ec2:Describe*",
"autoscaling:Describe*",
"application-autoscaling:Describe*",
"lambda:GetFunction",
"lambda:GetFunctionConfiguration",
"lambda:GetPolicy",
"lambda:GetProvisionedConcurrencyConfig",
"lambda:List*",
"ecs:Describe*",
"ecs:List*",
"eks:Describe*",
"eks:List*",
"elasticloadbalancing:Describe*",
"compute-optimizer:Get*",
"compute-optimizer:UpdateEnrollmentStatus"
],
"Resource": "*"
},
{
"Sid": "DigiUsherDatabasePermissions",
"Effect": "Allow",
"Action": [
"rds:DescribeDBInstances",
"rds:DescribeDBClusters",
"rds:DescribeReservedDBInstances",
"rds:DescribeReservedDBInstancesOfferings",
"rds:ListTagsForResource",
"dynamodb:Describe*",
"dynamodb:List*",
"elasticache:Describe*",
"elasticache:List*",
"es:Describe*",
"es:List*",
"redshift:Describe*",
"redshift:List*",
"docdb:Describe*",
"docdb:List*",
"neptune:Describe*",
"neptune:List*",
"timestream:DescribeEndpoints",
"timestream:DescribeDatabase",
"timestream:DescribeTable",
"timestream:ListDatabases",
"timestream:ListTables",
"dms:Describe*",
"dms:List*",
"memorydb:Describe*",
"memorydb:List*"
],
"Resource": "*"
},
{
"Sid": "DigiUsherStoragePermissions",
"Effect": "Allow",
"Action": [
"s3:GetBucketAcl",
"s3:GetBucketLocation",
"s3:GetBucketPolicyStatus",
"s3:GetBucketPublicAccessBlock",
"s3:GetBucketTagging",
"s3:GetLifecycleConfiguration",
"s3:GetIntelligentTieringConfiguration",
"s3:ListAllMyBuckets",
"elasticfilesystem:Describe*",
"fsx:Describe*",
"glacier:Describe*",
"glacier:List*",
"ecr:Describe*",
"ecr:List*",
"ecr:GetLifecyclePolicy",
"backup:Describe*",
"backup:List*",
"backup:GetBackupPlan"
],
"Resource": "*"
},
{
"Sid": "DigiUsherNetworkingAndCDNPermissions",
"Effect": "Allow",
"Action": [
"cloudfront:GetDistributionConfig",
"cloudfront:ListDistributions",
"route53:List*",
"route53:GetHostedZone",
"apigateway:GET"
],
"Resource": "*"
},
{
"Sid": "DigiUsherDataAndAnalyticsPermissions",
"Effect": "Allow",
"Action": [
"glue:GetJobs",
"glue:GetCrawlers",
"glue:GetDatabases",
"glue:ListJobs",
"glue:ListCrawlers",
"elasticmapreduce:DescribeCluster",
"elasticmapreduce:DescribeInstanceGroups",
"elasticmapreduce:ListClusters",
"elasticmapreduce:ListInstances",
"elasticmapreduce:ListInstanceGroups",
"states:DescribeStateMachine",
"states:ListStateMachines",
"states:ListExecutions",
"athena:List*",
"athena:GetWorkGroup",
"kinesis:Describe*",
"kinesis:List*",
"kafka:Describe*",
"kafka:List*",
"quicksight:List*",
"quicksight:DescribeDashboard",
"quicksight:DescribeAccountSubscription",
"sagemaker:List*",
"sagemaker:DescribeEndpoint",
"sagemaker:DescribeNotebookInstance"
],
"Resource": "*"
},
{
"Sid": "DigiUsherMessagingPermissions",
"Effect": "Allow",
"Action": [
"sqs:List*",
"sqs:GetQueueAttributes",
"sns:List*",
"sns:GetTopicAttributes",
"ses:GetSendQuota",
"ses:ListIdentities",
"mq:Describe*",
"mq:List*",
"events:Describe*",
"events:List*"
],
"Resource": "*"
},
{
"Sid": "DigiUsherMonitoringAndLoggingPermissions",
"Effect": "Allow",
"Action": [
"cloudwatch:Get*",
"cloudwatch:List*",
"cloudtrail:Describe*",
"cloudtrail:GetTrailStatus",
"cloudtrail:List*",
"logs:DescribeLogGroups"
],
"Resource": "*"
},
{
"Sid": "DigiUsherSecurityAndCompliancePermissions",
"Effect": "Allow",
"Action": [
"iam:GetAccessKeyLastUsed",
"iam:GetLoginProfile",
"iam:ListAccessKeys",
"iam:ListUsers",
"sso:List*",
"sso:Describe*",
"identitystore:List*",
"identitystore:Describe*",
"kms:List*",
"kms:DescribeKey",
"secretsmanager:List*",
"secretsmanager:DescribeSecret",
"guardduty:List*",
"guardduty:GetDetector",
"securityhub:GetEnabledStandards",
"securityhub:DescribeHub",
"wafv2:List*",
"wafv2:GetWebACL",
"config:Describe*",
"config:GetDiscoveredResourceCounts"
],
"Resource": "*"
},
{
"Sid": "DigiUsherResourceExplorerPermissions",
"Effect": "Allow",
"Action": [
"resource-explorer-2:Get*",
"resource-explorer-2:List*",
"resource-explorer-2:BatchGetView",
"resource-explorer-2:Search"
],
"Resource": "*"
},
{
"Sid": "DigiUsherRAMPermissions",
"Effect": "Allow",
"Action": [
"ram:GetResourceShares",
"ram:ListResources",
"ram:ListPrincipals"
],
"Resource": "*"
},
{
"Sid": "DigiUsherOrganizationsAndTaggingPermissions",
"Effect": "Allow",
"Action": [
"organizations:DescribeAccount",
"organizations:DescribeOrganization",
"organizations:DescribeOrganizationalUnit",
"organizations:ListAccounts",
"organizations:ListAccountsForParent",
"organizations:ListChildren",
"organizations:ListOrganizationalUnitsForParent",
"organizations:ListParents",
"organizations:ListRoots",
"organizations:ListTagsForResource",
"tag:GetResources",
"tag:GetTagKeys",
"tag:GetTagValues",
"resourcegroups:GetGroup",
"resourcegroups:ListGroups",
"servicequotas:Get*",
"servicequotas:List*"
],
"Resource": "*"
},
{
"Sid": "DigiUsherSustainabilityPermissions",
"Effect": "Allow",
"Action": [
"sustainability:GetCarbonFootprintSummary"
],
"Resource": "*"
},
{
"Sid": "DigiUsherTrustedAdvisorPermissions",
"Effect": "Allow",
"Action": [
"trustedadvisor:Describe*",
"trustedadvisor:Get*",
"trustedadvisor:List*"
],
"Resource": "*"
},
{
"Sid": "DigiUsherMarketplacePermissions",
"Effect": "Allow",
"Action": [
"aws-marketplace:ListEntities"
],
"Resource": "*"
}
]
}S3 CUR Access (Root/Payer Accounts Only)
A second inline policy (DigiUsherS3CURAccess) gives read access to the S3 bucket that holds the Cost and Usage Reports:
Replace YOUR_BUCKET_NAME with your actual bucket name:
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "DigiUsherCURPermissions",
"Effect": "Allow",
"Action": [
"s3:GetObject",
"s3:ListBucket"
],
"Resource": [
"arn:aws:s3:::YOUR_BUCKET_NAME",
"arn:aws:s3:::YOUR_BUCKET_NAME/*"
]
}
]
}S3 Bucket Policy (Billing Services)
The S3 bucket that holds the CUR data needs a bucket policy. This policy lets the AWS billing services write the reports:
Replace YOUR_BUCKET_NAME and YOUR_ACCOUNT_ID with your actual values:
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "AllowBillingServiceAccess",
"Effect": "Allow",
"Principal": {
"Service": [
"billingreports.amazonaws.com",
"bcm-data-exports.amazonaws.com"
]
},
"Action": [
"s3:GetBucketAcl",
"s3:GetBucketPolicy",
"s3:PutObject"
],
"Resource": [
"arn:aws:s3:::YOUR_BUCKET_NAME",
"arn:aws:s3:::YOUR_BUCKET_NAME/*"
],
"Condition": {
"StringLike": {
"aws:SourceArn": [
"arn:aws:cur:us-east-1:YOUR_ACCOUNT_ID:definition/*",
"arn:aws:bcm-data-exports:us-east-1:YOUR_ACCOUNT_ID:export/*"
]
},
"StringEquals": {
"aws:SourceAccount": "YOUR_ACCOUNT_ID"
}
}
}
]
}Optional Permissions
These permissions are off by default. If you need one of them, add it as a separate inline policy on the DigiUsher IAM role.
What DigiUsher CAN Access (Read-Only)
- The cost data and the usage data in S3, which are the CUR exports
- The resource metadata, such as names, types, regions, and tags, of the compute, database, storage, networking, and security services
- The utilization metrics in CloudWatch
- The optimization recommendations of Compute Optimizer and Trusted Advisor
- The information about the Reserved Instances and the Savings Plans
- The hierarchy of the organization, the accounts, and the organizational units
The core policy contains compute-optimizer:UpdateEnrollmentStatus. This action enrolls the account one time, and it enables the recommendations of Compute Optimizer. It does not create, change, or delete your resources. You can remove this permission. Without it, DigiUsher gives no rightsizing recommendations from Compute Optimizer.
What DigiUsher CANNOT Do
- Create, change, or delete an AWS resource. The only exception is an optional write permission that you enable yourself
- Read application data, databases, or the content of your storage. It reads the CUR data only
- Change an IAM policy or a permission
- Read secrets, credentials, or encryption keys
- Read network traffic or the content of your logs
- Buy a product or change the billing configuration. The only exception is the optional permission for commitment purchases
Google Cloud Platform (GCP)
Access Summary
| Component | Details |
|---|---|
| Identity | GCP service account (digiusher-finops). It uses the API only, and it has no Console login |
| Authentication | JSON key. By default it does not expire |
| Access level | Read-only. Every role is a viewer role or a reader role |
| Scope | The whole organization, which DigiUsher recommends, or selected projects |
| Billing | Billing Viewer on a single billing account |
| Data access | The BigQuery billing export dataset only. DigiUsher cannot read another dataset |
| Capability | What It Provides |
|---|---|
| Billing data | Cost analytics, chargeback and showback, budgeting, forecasting, anomaly detection |
| Resource inventory | Asset discovery, idle resource detection, tag-based cost allocation |
| Optimization recommendations | VM rightsizing, CUD/reservation analysis, idle resource cleanup |
| Utilization metrics | CPU, memory, network, disk usage for rightsizing analysis |
DigiUsher cannot create, change, or delete a GCP resource.
Roles and APIs
Billing Account
| Role | Purpose |
|---|---|
Billing Account Viewer | View billing data and cost information |
Organization
| Role | Purpose |
|---|---|
Browser | Browse org/folder/project hierarchy |
Tag Viewer | Read tags for chargeback/showback |
Cloud Asset Viewer | Resource inventory across projects |
Recommender Viewer | Cost optimization recommendations |
Compute Viewer | View CUDs, reservations, and Compute resources |
Cloud SQL Viewer | View Cloud SQL details and commitments |
BigQuery Resource Viewer | View BigQuery resource metadata for recommendations |
Monitoring Viewer | Read utilization metrics |
Project
| Role | Purpose |
|---|---|
BigQuery Job User | Execute billing queries |
BigQuery Read Session User | Efficient parallel data reads via Storage Read API |
Service Usage Consumer | Required for Cloud Asset API calls |
BigQuery Dataset
| Role | Purpose |
|---|---|
BigQuery Data Viewer | Read billing export data |
APIs
These APIs must be enabled in the project that holds the service account:
bigquery.googleapis.comcloudbilling.googleapis.comcloudresourcemanager.googleapis.comiam.googleapis.comcloudasset.googleapis.comrecommender.googleapis.comcompute.googleapis.comsqladmin.googleapis.commonitoring.googleapis.com
What DigiUsher CAN Access (Read-Only)
- The billing data and the cost data in BigQuery
- The resource metadata, such as names, types, regions, labels, and tags
- The utilization metrics for CPU, memory, network, and disk, in Cloud Monitoring
- The optimization recommendations of the Recommender API of Google
- The information about the CUDs and the reservations
- The hierarchy of the organization, the folders, and the projects
What DigiUsher CANNOT Do
- Create, change, or delete a GCP resource
- Read application data, databases, or the content of your storage
- Change an IAM policy or a permission
- Read secrets, credentials, or encryption keys
- Read network traffic or the content of your logs
- Buy a product or change the billing configuration
- Read a BigQuery dataset that is not the billing export dataset
Scope Controls
- To limit the access to selected projects, and not to the whole organization, set
target_project_idsin Terraform - The BigQuery access always covers the billing export dataset only, also with access to the whole organization
- The Billing Viewer role covers one billing account only
Microsoft Azure
Access Summary
| Component | Details |
|---|---|
| Identity | Azure App Registration (DigiUsherApp). It is a service principal, without an interactive login |
| Authentication | Client secret. DigiUsher recommends an expiry of 24 months |
| Access level | Read-only. The Reader role at the level of the Management Group |
| Scope | All subscriptions under the root Management Group |
| Billing | FOCUS cost export from your billing scope: EA, MCA, or MPA |
| Data access | Storage Blob Data Reader on the cost export storage account only |
| Capability | What It Provides |
|---|---|
| Billing data | Cost analytics, chargeback and showback, budgeting, forecasting, anomaly detection |
| Resource inventory | Asset discovery, idle resource detection, tag-based cost allocation |
| Optimization recommendations | Reservation and Savings Plan analysis, idle resource cleanup |
| Utilization metrics | Resource usage for rightsizing analysis |
DigiUsher cannot create, change, or delete an Azure resource. The only exception is the optional Terraform flag enable_power_scheduler, which is off by default. This flag creates a custom role that can start and deallocate virtual machines.
Roles
| Scope | Role | Purpose |
|---|---|---|
| Management Group (root) | Reader | Read-only access to all subscriptions and resources |
| Storage Account | Storage Blob Data Reader | Read FOCUS cost export data |
| Billing scope (EA, Terraform only) | Cost Management Contributor | Create and trigger the FOCUS export at the billing scope |
| Billing account (MCA, Terraform only) | Billing Account Contributor | Create and start the FOCUS export. MCA uses its own billing RBAC |
| Tenant (optional) | Reservations Reader | View reservation details and utilization |
| Tenant (optional) | Savings Plan Reader | View savings plan details and utilization |
The resource provider Microsoft.CostManagementExports must be registered on the subscription that holds the storage account.
What DigiUsher CAN Access (Read-Only)
- The cost data and the usage data in the FOCUS exports in Azure Storage
- The resource metadata, such as names, types, regions, and tags, through the Reader role
- The information about the Reservations and the Savings Plans, when you give that optional access
- The hierarchy of the Management Groups, the subscriptions, and the resource groups
What DigiUsher CANNOT Do
- Create, change, or delete an Azure resource
- Read application data, databases, or the content of your storage. It reads the cost exports only
- Change an IAM policy or a role assignment
- Read secrets, credentials, or encryption keys
- Read network traffic or the content of your logs
- Buy a product or change the billing configuration
Oracle Cloud Infrastructure (OCI)
Access Summary
| Component | Details |
|---|---|
| Identity | OCI IAM user (digiusher-service-user). It uses the API only, and it has no Console password |
| Authentication | API key pair: a PEM private key and a fingerprint |
| Access level | Read-only. Every policy uses the verb read only |
| Scope | Tenancy-wide |
| Billing | Read-only access to cost and usage reports |
| Data access | The Cost and Usage Reports in the cross-tenancy bucket of Oracle, in the FOCUS format only |
| Capability | What It Provides |
|---|---|
| Billing data | Cost analytics, chargeback and showback, budgeting, forecasting, anomaly detection |
| Resource inventory | Asset discovery, idle resource detection, tag-based cost allocation |
| Optimization recommendations | Rightsizing, commitment analysis, idle resource cleanup |
| Utilization metrics | CPU, memory, network, disk usage for rightsizing analysis |
DigiUsher cannot create, change, or delete an OCI resource.
OCI needs the define statement and the endorse statement in a different policy from the Allow statements. Create these two policies at the level of the tenancy, which is the root compartment.
Policy 1: Cost Report Cross-Tenancy Access
This policy gives read access to the cost reporting tenancy of Oracle, for the FOCUS cost reports. The OCID in the statement is the cost reporting tenancy of Oracle. It is the same for every OCI customer.
define tenancy usage-report as ocid1.tenancy.oc1..aaaaaaaaned4fkpkisbwjlr56u7cj63lf3wffbilvqknstgtvzub7vhqkggq
endorse group digiusher-finops-group to read objects in tenancy usage-reportPolicy 2: DigiUsher Access Policy
This policy gives read access to the usage reports, the budget data, the resource metadata, and the monitoring metrics.
Allow group digiusher-finops-group to read usage-report in tenancy
Allow group digiusher-finops-group to read usage-budgets in tenancy
Allow group digiusher-finops-group to read all-resources in tenancy
Allow group digiusher-finops-group to read metrics in tenancyAll policies are read-only. DigiUsher cannot create, change, or delete anything in your environment.
Note
If you remove the last two statements, all-resources and metrics, DigiUsher gives no optimization recommendations, no rightsizing recommendations, and no data from the utilization metrics.
What DigiUsher CAN Access (Read-Only)
- The Cost and Usage Reports in the FOCUS format, in the cross-tenancy bucket of Oracle
- The budget data
- The resource metadata, such as names, types, regions, and tags, through the Resource Search API
- The utilization metrics for CPU, memory, network, and disk, in OCI Monitoring
- The hierarchy of the organization and the compartments
What DigiUsher CANNOT Do
- Create, change, or delete an OCI resource
- Read application data, databases, or the content of your storage
- Change an IAM policy or a permission
- Read secrets, credentials, or encryption keys
- Read network traffic or the content of your logs
- Buy a product or change the billing configuration
DigiUsher Documentation