Cost & FinOps
LiveUIMCPCloud Cost Sentinel
Find removable cloud resources and cut your bill — with the evidence behind every call.
What it does
Cloud Cost Sentinel scans your cloud account for waste — idle, unattached, and forgotten resources quietly billing you every month — and returns a ranked list of what's safe to remove. Every finding comes with the evidence behind it, so you can act with confidence. It only ever reads: it changes nothing on your account.
How it works
Step 1
Connect a role
Create a read-only cross-account role with an ExternalId and paste the Role ARN. No credentials are stored, and you can revoke access anytime.
Step 2
Run a scan
Sentinel assumes the role for short-lived credentials, inspects your resources across regions, then discards the credentials.
Step 3
Review findings
Get a ranked list — removable, investigate, or keep — each with a confidence score, estimated monthly savings, and the evidence.
Step 4
Act & track
Remove what's safe, investigate the rest, and re-scan to track savings over time. Results are yours until you delete them.
What you get
A ranked list you can act on.
A representative scan result. Findings mirror the tool's real output — verdict, confidence, estimated monthly savings, and evidence.
| Resource | Region | Verdict | Confidence | Est. savings / mo | Evidence |
|---|---|---|---|---|---|
| Unattached EBS volume · vol-0a1b2c | ap-south-1 | Safe to remove | 96% | $42 |
|
| Unused Elastic IP · 13.234.x.x | eu-west-1 | Safe to remove | 99% | $4 |
|
| Idle EC2 · t3.large (api-staging) | us-east-1 | Investigate | 71% | $61 |
|
| RDS snapshot · prod-2023-backup | ap-south-1 | Keep | — | — |
|
Coverage
Sentinel looks across your account for the usual sources of silent spend:
Starts with AWS. Azure and GCP coverage are on the way.
Safe by design
Read-only, always
Sentinel only reads. It never stops, deletes, or modifies anything — every action is a recommendation for you to take.
No stored credentials
A scoped cross-account role with an ExternalId, assumed for short-lived credentials at scan time. Nothing long-lived is kept, and you can revoke it instantly.
Your results, isolated
Findings are stored per tenant, never shared across tenants, and kept only until you delete them.
For agents
Hand it to your agent.
Cloud Cost Sentinel is available on the TomorrowCentral MCP server, so an agent can run scans and read findings under your scoped role — the same tool your team uses in the console.
Connect your agentsAsk your agent
“Scan my AWS account and summarise what's safe to remove, with the monthly savings.”
FAQ
Can it delete resources on its own?
No. Sentinel is read-only and advisory. It surfaces what's safe to remove and the evidence; you (or your own tooling) decide and act.
What permissions does it need?
A read-only cross-account IAM role with an ExternalId — the standard, scoped way to grant least-privilege access. You create it, and you can revoke it anytime.
Do you store my credentials?
Never. We assume your role for short-lived credentials during a scan and discard them. Only connection metadata (like the Role ARN) is retained so you can re-scan.
Which clouds are supported?
AWS today, with Azure and GCP coming. The tool is built to be multi-cloud.
How much does it cost?
Free to start — no credit card required. If a tool has paid usage, it's disclosed before you incur it.
Need a private deployment or a customization of this tool? itmtb Technologies can build it.
Talk to us