AWS Cost Anomaly Router
Where AWS Cost Anomaly Detection alerts go, what they cost, and who owns the answer. Read-only operator surface over the AWS primitives — no production credentials, no actions, no decisions made on your behalf. Built for the conversation that happens before the action.
When AWS flags a cost spike, this page shows which team owns it, how much it is likely to cost if nobody reacts, and whether anyone has acknowledged it yet. It only reads AWS billing and anomaly data — it cannot change anything in your account.
Think of this as a dashboard that watches for surprise AWS bills, tells you who is responsible for fixing them, and how urgent each one is — without being able to touch your actual AWS account.
Active anomaly lanes
| Anomaly | Service | Severity | Owner | Status |
|---|---|---|---|---|
| Cross-region S3 egress spike | s3 · us-east-1 → eu-west-1 | HIGH | platform-eng | routed · awaiting ack |
| NAT gateway egress sustained | vpc/natgateway · us-east-2 | MED | network-eng | acked · investigating |
| GuardDuty findings burn-rate | guardduty + s3 | HIGH | sec-ops | ownership-pending |
| CloudTrail data event volume | cloudtrail · audit-account | LOW | sec-ops | acked · within tolerance |
| EKS pod cost outlier | eks · prod-east | MED | platform-eng | backfill in progress |
FinOps ownership map
| Account | Tag-policy compliance | Budget owner | Last anomaly |
|---|---|---|---|
| platform-prod | 94% | Daisy Park | 6h ago |
| data-prod | 88% | Daisy Park | 1d ago |
| sandbox-eng | 63% | unowned | 11h ago |
| audit-account | 100% | sec-ops shared | 4h ago |
| ml-training | 79% | Rivka Vance | 2d ago |
What this is — and what it isn't
What it is: a read-only operator surface that sits next to AWS and answers the four questions every operating exec asks before they decide — what's open, who owns it, what's it cost, and where's the evidence. Synthetic data only — the structure is what's portable; the numbers in this preview are made up.
What it isn't: not a AWS replacement, not a control plane, not a write-path. The AWS platform stays the source of truth. This surface just makes the operating posture legible — to the operator, the auditor, the board — without forcing them to pivot through a vendor console first.
Compliance framing: readiness/evidence/posture/controls language only. Never "compliant" or "certified" — those words require an external audit and current attestation, which the surface itself does not provide.