RosettaHub™ for FinOps
Accountability, with the authority to match
You own the number.
Now you can move it.
The hardest part of the job is not seeing the overspend. It is that seeing it is all you can do. You raise it, you chase it, and the fix depends on someone else finding the time. Enforcement closes that gap.
A budget that arrives
before the money is spent
Reading the bill puts you a month behind the decision that caused it. The same budget, checked at the moment a resource is created, is a different instrument entirely.
Before the launch
A cost estimate is produced for the resource being created, and checked against the budget and the quota for that account.
At the launch
If it would take the account over, the cloud’s own API refuses it. Nothing is created, so nothing is billed.
While it runs
Cost is tracked continuously against budget, and twenty eight kinds of idle resource are detected across the estate.
After it is idle
Machines autostop, orphaned volumes and snapshots are cleaned up, and an exhausted budget can stop the compute in the account.
The account decides
who pays
Tag-based allocation asks every engineer to remember something at the moment they are least interested in remembering it. The account boundary is a fact instead, and it holds whether or not anyone cooperated.
By person and by project
Cost rolls up both ways from the same data, so a team lead and a grant holder can each get the answer they are asking for.
Shared accounts split by weight
Somebody working across two cost centres shows up in both, in proportion, rather than landing entirely on whichever name was most obvious.
Reconciled, with the remainder named
Every run ties back to the invoice, and whatever could not be allocated appears on a list to work through instead of disappearing into an overhead line.
The line item that appeared last year
Model spend, per person,
while it is happening
Token cost is attributed to the person who incurred it and drawn against the same budget as their compute, within about five minutes. More usefully, which models a role may call is a permission, so a limit that is being approached can narrow access rather than only describe the problem afterwards.
See AI cost governance →Nobody hands over the estate
on the first call
Enforcement is the reason to be here, and read-only is where you can start. Access is granted per account and withdrawn by removing the stack.
Read-only
See it
Live cost estimates, allocation, idle detection and compliance scanning. No administrative access, and nothing you run is touched.
Preventive
Stop it
Budgets and quotas enforced at creation, and limits on which regions, services and models each team can reach. Still no administrative access.
Corrective
Fix it
Autostop, cleanup, remediation and account recycling. Acting on something that already exists needs administrative access, granted per account.
Common questions
How do I enforce a cloud budget instead of just being alerted about it?
The budget is evaluated when a resource is created, not when the bill arrives. A launch that would take an account over its budget is refused by the cloud’s own API, so the money is never spent. Alerts still exist, but they stop being the only thing standing between you and an overrun.
How do I allocate cost when tagging is incomplete?
Allocation is by account rather than by tag, so it does not depend on anyone remembering to label a resource. Where an account genuinely is shared, cost is split by weight across cost centres and reconciled back to the bill, with whatever cannot be allocated named rather than quietly absorbed.
Do I need to give up administrative access to get started?
No. The first level is read-only: live cost estimates, allocation, idle resource detection and compliance scanning, with no ability to touch anything you run. Enforcement and remediation are separate levels you switch on per account, when you are ready, and withdraw by removing the stack.
How quickly is AI and model spend reflected?
Token cost is attributed per user and drawn down against the same budget as everything else, within about five minutes. Which models a role may call is a permission, so an approaching limit can restrict access rather than only report the overrun.
Our own cloud accounts run under RosettaOps, on the same budgets and the same enforcement. See how it is deployed and what it can reach.