CloudQuell
Best for Teams whose security review asks "does this need write access?" before granting a role.
Strengths
- Connects with a scoped read-only cross-account IAM role and ingests AWS billing data daily; the published policy grants only read and billing permissions — no iam:* write, no ec2:Modify*/Terminate*, no *:*.
- It never modifies workloads: savings show up as ranked recommendations for your team to act on, not changes made for you. OpenAI, Anthropic and Snowflake connect with scoped API credentials from the Integrations page.
Limitations
- Read-only by design means it will not act on your infrastructure — automated rightsizing or commitment purchases are a write-access tool’s job.
- AWS is generally available; Azure and GCP are in private beta (request access), not generally available.