Skip to content

AWS cost anomaly detection · agentless

$452 or $9,494The same idle fleet, caught tomorrow morning or caught by the invoice.

CostWarden watches your AWS bill the way an on-call engineer would, if you had one to spare. It learns what each weekday normally costs, and the morning after spend breaks that pattern it tells you which service, how much, and what to resize.

A spike that starts mid-cycle waits about 21 days for an invoice to reveal it. Everything in between is spend nobody chose.

Read-only IAM role. No agents to install. 14-day trial, no card.

ObserveDeviateDetectAlert

Example data, run through the same arithmetic the product uses. The shaded band is the normal range for that weekday.

The problem

Nothing breaks. The bill just gets bigger, quietly, for three weeks.

A memory leak that auto-scales. A viral file on S3. A dev environment nobody turned off in March. None of it pages anyone, because none of it is an outage — it is just money, and money has no alarm.

185,077 points, ten for every dollar of the month.

Averages hide the shape

A fleet that scales with traffic costs less on a Sunday than a Tuesday. A single monthly threshold either fires every weekend or never fires at all — which is why the baseline here is per weekday, per service.

29%of IaaS and PaaS spend is wasted, according to the teams paying for it.

Self-reported estimates from 753 cloud decision-makers, not a measurement anyone took. It is also the default assumption in the calculator below, which is the only reason it is on this page.

Flexera · 2026 State of the Cloud Report

EC2 — Compute is 50% of it.

The invoice is the monitoring

One day of the leak in the example above is $452.10. By the time the bill arrives, $9,494 of it has already been spent.

$4,107 of those dollars sit above the same-weekday normal.

Nobody’s job is the bill

At seed stage there is no FinOps hire — there is one engineer who opens Cost Explorer when something feels off. Watching a dashboard is not a control; it is a hope that someone looks on the right day.

The alert fires on day one: $452 instead of $4,107.

  • 30 days, by serviceTen points = one dollar
  • EC2 — Compute$9,32450%
  • RDS$4,36924%
  • S3$2,12311%
  • Data Transfer$1,89610%
  • CloudWatch$7954%

How it works

Three steps, and the longest one is waiting for a scan.

Create a read-only role. Five minutes, one page.

We give you a trust policy and a permission policy to paste into IAM. You create the role in your account, name it, and paste the ARN back. No keys change hands and nothing gets installed anywhere.

IAM · cross-account role · per-org external ID

It learns what your normal actually looks like.

Cost Explorer gives up 90 days of history per service. From it CostWarden builds a per-service, per-weekday baseline, so a Sunday is compared to Sundays and a fleet that scales with traffic isn’t flagged for doing its job.

90 days backfill · baseline per service per weekday

The morning after a day breaks, you hear about it.

The scan runs daily, against the most recent day AWS has finished settling — Cost Explorer lags a day or two, and a half-settled day would read as a dip. If a service left its normal range you get one message: the service, the amount, the percentage, and what a normal day costs.

Daily scan · Slack, Teams, Google Chat, PagerDuty

The deliverable

The product is a message. There is no dashboard to babysit.

It arrives where the team already is — Slack, Microsoft Teams, Google Chat or PagerDuty, whichever you wire up. Same content, same figures, formatted for each.

Anatomy of one alert

🚨 EC2 spend jumped

$632.40 on Jul 22, 2026 · $452.10 above normal · +251%

Normal for a Wednesday is about $180.30.

Amazon Elastic Compute Cloud - Compute · critical

The amount, and the amount above normal

Two figures, not one. The bill number alone tells you nothing without knowing what the day should have cost — and once an episode has run for a few days, its running total comes with it.

What normal means, spelled out

“Normal for a Wednesday is about $180.30” — so you can disagree with the baseline instead of trusting it.

The service, at the scope it was measured

Cost Explorer’s own service name, so you can reproduce the figure in the console without guessing what we grouped.

A link to the episode, not to a dashboard tour

One click to the day-by-day breakdown and the rightsizing findings for the same account. The message is the product; the page is the detail.

Where it lands

Slack

Incoming webhook into any channel you choose.

#cloud-costs

Microsoft Teams

Workflow webhook, rendered as an Adaptive Card.

adaptive card

Google Chat

Space webhook, rendered as a card.

space webhook

PagerDuty

Events API v2 — for teams that want a real incident.

events v2 · severity

Every plan gets all four, and as many channels as you want. Nothing is held back to create an upgrade.

Dashboard · what the alert links tolast 30 days

Episode total

$4,107

over 9 days, still open

Rightsizing found

$312

per month, across 4 resources

  • i-0a91c4e2f7b3d8051

    m6i.2xlargem6i.xlarge

    $138
  • i-04f7b2a9c1e6d3327

    r6i.xlarger6i.large

    $94
  • vol-0c72e19b4a5f8d6e3

    gp2 · unattached 41 daysdelete

    $46
  • i-0d38e5c7a92b1f460

    c6i.4xlargec6i.2xlarge

    $34

Two different things, deliberately side by side. The anomaly is “something changed today”. The rightsizing list is “this has been wasteful all along” — it comes from AWS Compute Optimizer, and it never pages anyone.

What you get

Six things, and none of them is a dashboard you have to open.

Anomaly detection that knows your week

A per-service, per-weekday baseline with a deviation threshold, not a monthly budget alarm. The band does not chase the spike, which is why the line escapes it.

baseline $180.30 (median, Wednesdays) observed $632.40 → +251%

Rightsizing that never pages you

Compute Optimizer’s EC2 and EBS findings, with the monthly saving AWS itself estimates. Standing waste, listed once, not alerted about daily.

4 findings · −$312/mo estimated m6i.2xlarge → m6i.xlarge

Delivered where the team already is

Slack, Microsoft Teams, Google Chat or PagerDuty, over your own webhook. Add as many as you like — every plan gets all four.

channels 4 available · unlimited delivery health tracked per channel

Read-only, agentless setup

One cross-account IAM role with 5 permissions, plus an external ID unique to your organisation. Revoke it and the connection ends immediately.

ce:GetCostAndUsage compute-optimizer:GetEC2InstanceRecommendations

Useful from the first scan

Ninety days of history come back with the connection, so the baseline exists before you have configured anything. There is a sensitivity dial if you ever want it — three presets, not seven numbers — and the default is the one everything was tuned against.

backfill 90 days sensitivity quiet · balanced · sensitive

Built for AWS, and only AWS

One provider, done properly: Cost Explorer semantics, Compute Optimizer findings, per-service scope. No GCP or Azure — and no roadmap promise that there will be.

metric NetAmortizedCost (after credits) billing currency USD only

Access

5 read-only permissions. Here they are, by name.

A cross-account IAM role your side creates, trusting our account and a per-org external ID. No keys to hand over, no agent to install, and nothing it can change.

What it can read

ce:GetCostAndUsage

Daily cost by service and by linked account — the numbers on your bill, nothing about what produced them.

compute-optimizer:GetEC2InstanceRecommendations

AWS’s own view of which instances are oversized, and what it would resize them to.

compute-optimizer:GetEBSVolumeRecommendations

The same for volumes, including the ones nobody has attached to anything in weeks.

ec2:DescribeInstances

The type, size and state of your instances — their shape, never anything running inside them. Compute Optimizer will not answer about instances the caller cannot list, so without this the recommendation above does not arrive at all.

ec2:DescribeVolumes

The same shape for volumes: type, size, and what each is attached to. Never a byte of what is stored on them.

Plus sts:AssumeRole from our side into that role, proving your organisation’s external ID on every call. Revoke the role and the connection is over the same second.

What it cannot do

Install an agent, a sidecar or anything else in your account.

Write, modify, stop or delete a single resource — the role has no write permission at all.

Read your data, logs, buckets, databases or environment variables.

Reach your account without the external ID issued to your organisation.

Verifiable today

  • Reads AWS Cost Explorer, Compute Optimizer, and the shape of your instances and volumes — nothing else.
  • Delivers over your own Slack, Teams, Google Chat or PagerDuty webhook.
  • Every threshold the detector uses is published, down to the dollar floor.
  • Delete your organisation and every cost row goes with it.

No testimonials or customer logos here on purpose — CostWarden is pre-pilot. This section becomes a quote and a saved-dollars figure once there is a real one to quote.

Price

Three bands you can read in advance, and a ceiling that never moves.

From $39 a month. Above $25,000 of AWS spend the price stops at $179 and stays there — a cost tool should not charge you most in the month you most need it.

Starts at 29%, what cloud teams estimate for their own IaaS and PaaS spend — Flexera, 2026 State of the Cloud Report. Drag it to whatever you actually believe.

Estimated waste, per month
$2,320
Estimated waste, per year
$27,840
CostWarden Team, per year
$948

At this bill you would be on Team — $79/month, the band for AWS spend up to $25,000 a month.

Share of that waste CostWarden costs

3.4%

Recover that much of it and the subscription has paid for itself. CostWarden does not remove waste — it reports the day a service breaks from its normal and shows which resources Compute Optimizer calls over-provisioned. Acting on it stays your call.

Arithmetic you control: bill × share, then × 12. No industry average is applied to your figures except the one shown above, which you can change.

The bands

Starterup to $5,000/mo$39/mo
Teamup to $25,000/morecommended$79/mo
Scaleabove $25,000/mo$179/mo

Your band is a number you can read before you sign up. It does not move when your bill moves inside it, and there is no metered component to model.

Every band includes

  • All four delivery channels, as many as you want
  • Unlimited team members
  • The same detection and the same rightsizing on every band
  • Ninety days of backfill on connection, kept rolling
  • A price ceiling: above $25,000 of spend, $179 is the most you pay

14 days from your first working AWS connection. No card until you decide.

Before you ask

The hard questions, hardest first.

There is no sales call to interrogate, so these are answered here instead of being left for one.

The longer answers
AWS already has cost anomaly detection, and it is free.
It does, it is, and you should turn it on. Three things it will not do: give you a per-weekday baseline per service, put a specific rightsizing fix in the same message, or arrive in the channel your team actually reads. If AWS’s alerts are already working for you, this is not worth $79.
How noisy is it?
One message when an episode starts, and after that only if it escalates — never one a day. A leak running for nine days is one open episode with a running total attached to each message, not nine alerts, and no single scan can send more than 5. That is the difference between a tool you keep and a channel you mute.
What happens after the trial?
14 days from your first working AWS connection. If you do not subscribe, ingestion pauses and your baseline stays put; nothing is deleted for six months, and nothing is charged without you choosing a plan.
Our bill is small. Is this worth it?
Do the arithmetic above rather than trusting this answer. At the cited 29% waste assumption, a year of Starter is covered by anything above about $135 a month of AWS spend — so on that assumption almost any real bill clears it. The honest version of the question is how much waste you believe you have: drag that slider down to 5% and the panel starts telling you no below roughly $800 a month, which is where AWS’s free anomaly alerts and a calendar reminder are the better answer.
Do you support GCP or Azure?
No, and there is no plan to. Cost semantics do not transfer between providers, and a shallow second integration would make the AWS one worse.
Can it fix the problem for me?
No. The role is read-only and will stay read-only — a tool with permission to terminate your instances is a much bigger thing to trust than a tool that tells you which one to look at.

Find out tomorrow morning, not on the invoice.

Connect a read-only role and the next scan tells you whether your spend has broken from its normal — including, quite possibly, that it has not.

Read-only. No agents. 14 days, no card.