AWS Cost Anomaly Router
Where AWS Cost Anomaly Detection alerts go, what they cost, and who owns the answer. Read-only operator surface over the AWS primitives — no production credentials, no actions, no decisions made on your behalf. Built for the conversation that happens before the action.
Active anomaly lanes
| Anomaly | Service | Severity | Owner | Status |
|---|---|---|---|---|
| Cross-region S3 egress spike | s3 · us-east-1 → eu-west-1 | HIGH | platform-eng | routed · awaiting ack |
| NAT gateway egress sustained | vpc/natgateway · us-east-2 | MED | network-eng | acked · investigating |
| GuardDuty findings burn-rate | guardduty + s3 | HIGH | sec-ops | ownership-pending |
| CloudTrail data event volume | cloudtrail · audit-account | LOW | sec-ops | acked · within tolerance |
| EKS pod cost outlier | eks · prod-east | MED | platform-eng | backfill in progress |
FinOps ownership map
| Account | Tag-policy compliance | Budget owner | Last anomaly |
|---|---|---|---|
| platform-prod | 94% | Daisy Park | 6h ago |
| data-prod | 88% | Daisy Park | 1d ago |
| sandbox-eng | 63% | unowned | 11h ago |
| audit-account | 100% | sec-ops shared | 4h ago |
| ml-training | 79% | Rivka Vance | 2d ago |
What this is — and what it isn't
What it is: a read-only operator surface that sits next to AWS and answers the four questions every operating exec asks before they decide — what's open, who owns it, what's it cost, and where's the evidence. Synthetic data only — the structure is what's portable; the numbers in this preview are made up.
What it isn't: not a AWS replacement, not a control plane, not a write-path. The AWS platform stays the source of truth. This surface just makes the operating posture legible — to the operator, the auditor, the board — without forcing them to pivot through a vendor console first.
Compliance framing: readiness/evidence/posture/controls language only. Never "compliant" or "certified" — those words require an external audit and current attestation, which the surface itself does not provide.