What CloudWise Accesses in Your AWS Account

CloudWise uses read-only IAM permissions to analyze your costs. No data is modified. No resources are changed. Every permission shown here is parsed directly from our public CloudFormation templates.

No signup required to view this page.

Monitoring Permissions (Read-Only) — All Tiers

Granted by the CUR monitoring CloudFormation stack. All actions are read-only.

Loading permissions from template…

Remediation Permissions — Agentic+ Tier (Optional)

This is a separate, optional CloudFormation stack — only deployed if you opt into the Agentic tier. All actions require aws:PrincipalTag/cloudwise-action: remediation. Sessions are 15 minutes, never cached. One-click revoke — delete the remediation stack at any time.

Remediation Role Permissions

Write permissions for AI-powered remediation. Deployed as a separate stack with session-tag conditions and a hardcoded action allow-list.

Loading permissions from template…