← All tools

Cost & FinOps

LiveUIMCP

Cloud Cost Sentinel

Find removable cloud resources and cut your bill — with the evidence behind every call.

What it does

Cloud Cost Sentinel scans your cloud account for waste — idle, unattached, and forgotten resources quietly billing you every month — and returns a ranked list of what's safe to remove. Every finding comes with the evidence behind it, so you can act with confidence. It only ever reads: it changes nothing on your account.

How it works

Step 1

Connect a role

Create a read-only cross-account role with an ExternalId and paste the Role ARN. No credentials are stored, and you can revoke access anytime.

Step 2

Run a scan

Sentinel assumes the role for short-lived credentials, inspects your resources across regions, then discards the credentials.

Step 3

Review findings

Get a ranked list — removable, investigate, or keep — each with a confidence score, estimated monthly savings, and the evidence.

Step 4

Act & track

Remove what's safe, investigate the rest, and re-scan to track savings over time. Results are yours until you delete them.

What you get

A ranked list you can act on.

A representative scan result. Findings mirror the tool's real output — verdict, confidence, estimated monthly savings, and evidence.

ResourceRegionVerdictConfidenceEst. savings / moEvidence
Unattached EBS volume · vol-0a1b2cap-south-1Safe to remove96%$42
  • Detached for 38 days
  • No snapshot references it
Unused Elastic IP · 13.234.x.xeu-west-1Safe to remove99%$4
  • Not associated with any instance
Idle EC2 · t3.large (api-staging)us-east-1Investigate71%$61
  • <2% CPU for 30 days
  • No inbound traffic
RDS snapshot · prod-2023-backupap-south-1Keep
  • Held by a compliance retention tag

Coverage

Sentinel looks across your account for the usual sources of silent spend:

Starts with AWS. Azure and GCP coverage are on the way.

Unattached EBS volumes & orphaned snapshots
Idle or oversized EC2 instances
Unused Elastic IPs & load balancers
Idle RDS instances & stale snapshots
Old, unreferenced AMIs
Multi-account, all regions

Safe by design

Read-only, always

Sentinel only reads. It never stops, deletes, or modifies anything — every action is a recommendation for you to take.

No stored credentials

A scoped cross-account role with an ExternalId, assumed for short-lived credentials at scan time. Nothing long-lived is kept, and you can revoke it instantly.

Your results, isolated

Findings are stored per tenant, never shared across tenants, and kept only until you delete them.

For agents

Hand it to your agent.

Cloud Cost Sentinel is available on the TomorrowCentral MCP server, so an agent can run scans and read findings under your scoped role — the same tool your team uses in the console.

Connect your agents

Ask your agent

Scan my AWS account and summarise what's safe to remove, with the monthly savings.

FAQ

Can it delete resources on its own?

No. Sentinel is read-only and advisory. It surfaces what's safe to remove and the evidence; you (or your own tooling) decide and act.

What permissions does it need?

A read-only cross-account IAM role with an ExternalId — the standard, scoped way to grant least-privilege access. You create it, and you can revoke it anytime.

Do you store my credentials?

Never. We assume your role for short-lived credentials during a scan and discard them. Only connection metadata (like the Role ARN) is retained so you can re-scan.

Which clouds are supported?

AWS today, with Azure and GCP coming. The tool is built to be multi-cloud.

How much does it cost?

Free to start — no credit card required. If a tool has paid usage, it's disclosed before you incur it.

Need a private deployment or a customization of this tool? itmtb Technologies can build it.

Talk to us

Try Cloud Cost Sentinel free.