FinOps Center logo
FinOps Center

The AWS Control Plane for AI Cost Governance and Cloud Financial Management

FinOps Center gives your Product Owners, FinOps Leaders, and CFO office complete ownership of every AWS dollar and every AI workload, through structured business process, not engineering dependency. It is the only CFM platform that includes a purpose-built AI FinOps Agent. Deployed on AWS inside your Customer Cloud Estate.

AI Cost Governance for AWS

From business case approval to cost optimization. The complete AI governance lifecycle.

Most teams discover AI spend after the bill arrives. FinOps Center governs it before the first token. Customers come to FinOps Center for AI Cost Governance, and get their complete CFM process in the same platform.

AI workloads live inside your broader AWS environment. So FinOps Center brings your complete CFM governance with it: financial hierarchy, account allocation, workload resource claiming, budget tracking, Spend Card approvals, AWS Programs, Cost Optimization, and Month Close. One platform. One place to own all of it.

THE CONTROL PLANE FOR BUSINESS-OWNED AWS SPENDING

AWS accountsyour financial structure

From accounts to your financial structure

AWS organises your infrastructure. FinOps Center organises your spending. Map your AWS accounts, AI workloads, and resources to the financial hierarchy your business already operates: Business Unit, Department, Portfolio, and Product. Every AI model, every Bedrock invocation, every CFM cost uses your business language, not AWS account IDs or service codes.

unowned AI spendnamed workload owners

From unowned AI spend to named workload owners

Every AI model must be approved and claimed before the first token. Product Owners claim Bedrock models, AgentCore runtimes, and AWS resources directly to their workloads. Once claimed, 100% of that spend is owned by that team from the claim date forward. When Finance asks who is responsible for last month's AI bill, there is always a name and a business case attached.

cost datagoverned business decisions

From cost data to governed business decisions

In the era of AI, the CFO office cannot wait for quarterly reviews to understand what the organization is spending on models. FinOps Center surfaces the right information to the right person at the right level, in real time. A Product Owner sees their workload. A FinOps Leader sees every AI model, every gap, every pending approval. Every decision is a business process step with an owner, a timestamp, and an audit trail.

HOW IT WORKS

FinOps Center, Agent Bill, and Cloud Scal3 Tools: working together.

From login to action in a Linked Account: the complete flow across all three products, inside your Customer Cloud Estate.

1
Login
Business User

Product Owner · FinOps Leader · Cloud Engineer · more

authenticates via
Amazon Cognito

JWT token issued — carries role + hierarchy scope

2
Access & Scope
FinOps Center reads:
Role (Product Owner, FinOps Leader…)
Hierarchy scope (which BU / Dept / Portfolio / Product)
Budget allocation assigned to user
Actions available to this role
3
Two Paths
Application Screen

Business process UI — spend cards, scoreboard, resource claiming, MAP tasks, budget reviews. No AWS console needed.

Spend CardsCFM ScoreboardClaimsMAP Tasks
Ask Bill — QuickChat

Embedded QuickChat opens. Lives inside a Quick Space — role-scoped resource container. User token passes to MCP.

Quick SpaceChat PersonaToken → MCP
Ask Bill connects to two layers simultaneously
Spending Intelligence — Quick Topics
Curated Quick Topic

One per role — Cost Management, AI Cost, Container, SP, Marketplace

Role-Scoped QuickSight Dataset

User-Based RLS enforced — user sees only their allocation scope

Role-Based Athena Query

CUR2 data JOINED with FinOps Center user allocation table

Refresh triggered by CUR load

When CUR lands in S3, Lambda triggers the Athena query refresh → SPICE refreshes → Topics update. New users provisioned in FinOps Center will have the Agent Bill experience after the next CUR-triggered refresh.

S3 CUR landingLambda triggerAthenaSPICEUser RLS
Business Process Actions — MCP + AgentCore
MCP Server

Security token from QuickChat passed to MCP

token validated by
AgentCore Identity + Runtime

OAuth 2.0 user-scoped auth · validates token · routes to tools

FinOps Center Business Processes

AppSync GraphQL → DynamoDB → Lambda — 16 governed actions

executes via
CloudScal3 Tools

Any action requiring access to Linked Accounts

Budget approvalSpend card acceptMAP tagBuy SP
AWS account structure
Management Account
CUR2 enabled → S3 data export replicated to Delegated Admin
CUR2 exportS3 replication

Setup follows CID Guide steps 1 + 2 — no CID required

Delegated Admin Account

FinOps Center + Agent Bill installed here via AWS Marketplace CloudFormation

CognitoAppSyncDynamoDBLambdaS3AthenaQuickSightAgentCore
Linked Accounts

CloudScal3 Tools policies deployed via Control Tower → cross-account IAM roles created

Control TowerCross-acct IAMMAP taggingSavings PlansResource lifecycle

All data processing and business logic runs inside your Delegated Admin Account · nothing leaves your AWS environment

WHAT YOUR TEAM SEES

Business language. Business screens. No AWS console.

Your Product Owners, FinOps Leaders, and Department Managers work in purpose-built interfaces: not AWS Cost Explorer, not raw CUR data, not engineering tooling.

Cloud Spend Cards
Product Owner
Not: AWS Cost Explorer
Cloud Spend Cards

Weekly spend periods routed to the Product Owner for review. Accept if the numbers match expectations — dispute if something looks wrong. No AWS console access required.

Savings Management & Report Card
FinOps Leader
Not: AWS Cost Anomaly Detection
Savings Management & Report Card

Letter-grade CFM Scoreboard with three weighted dimensions. Unrealised savings surfaced as accumulated loss with a one-click bulk-approve action. Recommendation pipeline from Pending → Approved → Implemented.

Agent Bill QuickChat
Any Role
Not: AWS Console Q&A
FinOps Center · Ask Bill
Agent Bill
Agent Bill
Product Owner Space · HR Portal scope
Online

Why is our AI spend so high this week?

Agent Bill

Your AI spend is up 4× this week. The Bedrock model for HR Portal switched from Claude Haiku to Claude Sonnet — cost per request increased from $0.012 to $0.048.

Ask about your AWS spending...
Cost Management Topic · User RLSPowered by Amazon Quick

Embedded in FinOps Center via Amazon QuickSuite. Role-scoped answers grounded in your CUR data. Ask about spend, budgets, MAP credits, or Savings Plans — in plain English.

CORE CAPABILITIES

Every dollar of AWS spend has an owner. Every owner has a workflow.

AI Cost Governance for AWSOverview →

AI Workload Governance

A governed path from business request to running AI workload, before the first token. Product Owners describe the workload and set a budget. The FinOps Lead selects the platform, assigns the model, and approves. Cloud Engineers receive pre-written CLI commands and execute. Agent Bill demystifies the spend in plain language for every stakeholder. Covers Amazon Bedrock, AWS Marketplace Models, and Claude Platform.

See AI Cost Governance

Model Approval & Governance

Every model must be approved for a specific region, a specific set of actions, and a specific workload before the first API call. The Business Request workflow enforces this: governance precedes consumption by design. The FinOps Lead owns the model catalog. No workload uses a model that has not been approved and scoped.

See Workload Onboarding

Weekly AI Spend Cards

Token consumption can spike overnight. FinOps Center generates a Spend Card for every claimed AI workload every week: actuals vs the FinOps Lead's confirmed estimate, broken down by model, token type, and region. Product Owners accept or dispute. Portfolio Owners approve the rollup. Finance gets a chargeback-ready record every week, not every quarter.

See AI Scorecard

AI Governance Maturity

Measures AI governance across four dimensions: Workload Attribution, Model Governance, Estimate Coverage, and Process Efficiency, each rated on a Not Started / Crawl / Walk / Run scale aligned to the FinOps Foundation framework. Every dimension shows current tier, the next advancement move, and what closing the gap is worth in attributed dollars.

See AI Governance Maturity

Allocation Gap Detection

Six gap scenarios detected and surfaced inline: from AI spend with no IAM principal in CUR, to dedicated roles with no Product Owner claim, to models invoked outside their approved scope. Every gap has an inline FinOps Lead action. Every action carries a timestamp, rationale, and the identity of the person who made it. Finance gets an audit trail, not a snapshot.

See Allocation Gaps

Agent Bill: Built-In AI Agent

No other CFM platform includes what FinOps Center ships with by default: a purpose-built AI FinOps Agent connected to your governance processes. Ask why an AI workload spiked, action an Allocation Gap, approve a Business Request, all in plain English, without leaving FinOps Center. Agent Bill is not an add-on. It is part of the product.

Meet Agent Bill
CFM Governance for AWSOverview →

Financial Hierarchy

Your AWS spend mapped to your business structure. Business Unit, Department, Portfolio, and Product. Every allocation, budget, and report uses labels your business teams already understand, not AWS technical identifiers.

See Onboarding & Allocation

Account Allocation

Assign AWS accounts to financial budgets by percentage. Shared accounts split fairly between teams. Dedicated accounts attributed 100%. Every account accounted for from day one.

See Onboarding & Allocation

Workload Resource Claiming

Product Owners claim any AWS resource with an ARN to their workload in FinOps Center. EC2 servers, RDS databases, S3 buckets, and Bedrock AI models. Once claimed, cost follows ownership automatically, every day.

See Onboarding & Allocation

Planning & Budget Tracking

Schedule the approved annual budget across the year by workload-component estimate. Annual and period budgets tracked against actuals in real time: Current Period spend, Current Month spend, available budget, and trend, surfaced at the right level for each role in your business.

See Planning & Scheduling

Spend Governance & Approvals

Two Portfolio Owner approval gates: estimate size before spend is committed, and recurring spend before each period is accepted. No AWS cost is owned without a named business approver. Cloud Spend Cards route weekly actuals to Product Owners for review. The full approval audit trail replaces ad hoc engineering requests with structured governance.

See Spend Governance

AWS Programs

MAP, Credits, and Savings Plans owned by the business, with execution routed to engineering or automated via Cloud Scal3 Tools. MAP-eligible workloads designated by Product Owners. Tagging tasks routed to Cloud Engineers. Credit utilisation and Savings Plan coverage tracked for FinOps Leaders. The full program lifecycle owned by the business, not buried in engineering.

See AWS Programs

Cost Optimization Report Card

A letter-grade CFM Scoreboard across waste elimination, commitment strategy, and resource modernization, adjusted for the effort each recommendation requires. Unrealised savings surfaced as accumulated loss with a one-click bulk-approve action. An improving grade is visible proof of progress. A declining grade is an early warning before the next bill lands.

See Cost Optimization

Month Close & Accrual

Approve spend before the bill is owned, then export business-approved accrual data in the format your system of record requires: CSV for FP&A, structured export for AP and ERP. The FinOps Lead closes the month with a complete allocation record. Finance receives a file that reflects every business decision made during the period, not just the AWS invoice.

See Month Close & Accrual

Agent Bill: Conversational CFM

Ask why a workload exceeded budget, which department is driving spend, how MAP credits are tracking, or whether a Savings Plan approval is pending. Agent Bill knows your FinOps Center hierarchy, your budgets, your workloads, and your history, and responds with context scoped to your role. Embedded in FinOps Center and available on Amazon Quick Desktop. No other CFM platform includes this.

Meet Agent Bill

ROLES AND BUSINESS PROCESS

Built for the roles that exist in your organisation, not the permissions that exist in AWS.

Every person sees the information relevant to them. Every workflow matches what that role actually does.

FinOps Leader

Owns the complete financial picture. Sets governance policy, approves savings recommendations, manages MAP contracts, allocates credits, and tracks org-wide spending against targets.

Product Owner

Owns their workload's AWS resources and spending. Claims resources, creates estimates, reviews and accepts Cloud Spend Cards, and designates workloads as MAP or AI workloads.

Portfolio Owner

Owns the two approval gates: estimate size before spend is committed, and recurring spend before each period is accepted. Every budget decision in the hierarchy flows through this role before it is committed.

Cloud Engineer

Works through structured task queues: MAP tagging, Bedrock inference profile setup, and tag drift remediation. Routed by the platform, not by ad hoc engineering requests.

Department Manager

Sees their department's total spending across all portfolios and products. Tracks budget vs actual. Understands trends without needing AWS access.

DEPLOYED ON AWS: INSIDE YOUR CUSTOMER CLOUD ESTATE

Your spending data never leaves your account.

FinOps Center is a Deployed on AWS solution. It installs directly into your AWS environment via AWS Marketplace and runs entirely within your Customer Cloud Estate. There is no shared multi-tenant infrastructure. No data is transmitted to third-party systems. No external SaaS dependency sits between your business teams and your AWS spending.

Deployed inside your Customer Cloud Estate

Installed via AWS Marketplace and CloudFormation directly into your environment. No shared multi-tenant infrastructure. No data hops to a vendor cloud. Your allocations, approvals, budgets, and workload configurations are stored in your own DynamoDB tables.

Your own Cognito + AppSync

Identity governed by your existing Amazon Cognito user pools. Authorization through your own AWS AppSync layer. Agent Bill's conversational AI runs through your own AgentCore runtime, using the same security controls you already trust. No new auth model to audit.

No third-party data transmission

Every allocation, approval, budget, and report lives in your account. This is cloud financial management that respects the same data governance standards your business applies to everything else in your AWS environment.

Simple, transparent pricing.

Available on AWS Marketplace. Annual plans save up to 20% vs monthly.

FinOps Center Standard

Annual commitment

$25,000/yr
Buy Now
Full Features
Up to 50 Accounts

FinOps Center Enterprise

Annual commitment

$50,000/yr
Buy Now
Full Features
Unlimited Accounts

All plans available on AWS Marketplace. Annual pricing billed upfront.