What MarshalCloud does with it
- Your bill, from a cost and usage export delivered to a bucket in your own account, so the dollar figures come from your own data and not an estimate.
- What you are running: servers, storage, databases, load balancers, containers and clusters, certificates and DNS health checks.
- Security settings: public buckets, sign-in and access-key hygiene, encryption defaults, audit logging, and the findings of AWS's own scanners where you already pay for them.
- AWS's own cost advice: Compute Optimizer, Cost Optimization Hub, Trusted Advisor and Savings Plans data.
What it never does
- The read role can only describe, list and get. It cannot create, change or delete anything in your account.
- It is never granted permission to read a secret's value, your log contents, or the prompts and responses of an AI model.
- Fixes need a second, separate role you choose to install. Never installing it is a supported way to use MarshalCloud, and every fix still waits for a person to approve it.
- Your credentials are not held: the default connection is a role you own plus a secret External ID, not keys we store.
Read-only is the default everywhere. A fix is drafted, priced and explained, and then waits for a person to approve it. The whole access path is on Security and access.
Which plan includes it
Every plan, including Free. What changes is how many AWS accounts: 1 on Free, 2 on Startup, 10 on Growth, 50 on Scaled. See every plan limit.
How to connect it
- Start a connection in MarshalCloud. It gives you a CloudFormation link and an External ID unique to your organisation, so a leaked role name is not access.
- Run the stack in your own AWS account. You can read every permission it grants line by line first. It creates the read-only role and a billing export bucket that stays yours.
- Paste the role's ARN back into MarshalCloud. To revoke, delete the stack: our access ends immediately.
Questions
- Is the AWS connection read-only?
- Yes. The role the CloudFormation template creates can only describe, list and get. It cannot create, change or delete anything, it is never given permission to read a secret's value or your log contents, and it can only be assumed with an External ID unique to your organisation.
- Can MarshalCloud change something in my AWS account?
- Only if you install a second, separate role for fixes, and only after a person approves that specific fix. The fix role's permissions mirror the reviewed action list exactly, nothing wider. Never installing it is a supported way to use MarshalCloud.
- Which plan includes AWS?
- Every plan, including Free. Free covers one AWS account, Startup two, Growth ten and Scaled fifty.