What CloudWise Accesses in Your AWS Account
CloudWise uses read-only IAM permissions to analyze your costs. No data is modified. No resources are changed. Every permission shown here is parsed directly from our public CloudFormation templates.
No signup required to view this page.
Monitoring Permissions (Read-Only) — All Tiers
Granted by the CUR monitoring CloudFormation stack. All actions are read-only.
Loading permissions from template…
Remediation Permissions — Agentic+ Tier (Optional)
This is a separate, optional CloudFormation stack — only deployed if you opt into the Agentic tier. All actions require
aws:PrincipalTag/cloudwise-action: remediation. Sessions are 15 minutes, never cached. One-click revoke — delete the remediation stack at any time.Remediation Role Permissions
Write permissions for AI-powered remediation. Deployed as a separate stack with session-tag conditions and a hardcoded action allow-list.
Loading permissions from template…