
Updated 2026-09-27. Since 2026-09-08 the stack creates a read-only IAM role instead of an IAM user and access key, so there are no longer any credentials to retrieve or paste. This post now describes the role; accounts connected with the earlier access-key version keep working and can move to a role from Settings → Accounts.
Until recently, connecting an AWS account to Refine meant a manual tour through the AWS console: create a billing data export, create a bucket, create an IAM user, scope its policy, copy keys around. Every step was documented — and every step was a place to make a typo.
That's gone. Onboarding is now a CloudFormation quick-create link: one click opens the AWS console with a stack pre-filled, you review the parameters, press Create stack, and a couple of minutes later everything Refine needs exists in your account — created by AWS, in your account, under your control.
What the stack actually creates
We think you should never run a template you haven't read, so here's the inventory:
The template also refuses to run in the wrong region (billing data exports only exist in us-east-1, so the stack checks and tells you rather than failing cryptically) and validates its parameters before creating anything.
What is FOCUS, and why 1.2?
FOCUS — the FinOps Open Cost and Usage Specification — is the FinOps Foundation's open standard for billing data. Instead of every cloud inventing its own column names, FOCUS defines one schema: BilledCost means the same thing everywhere, and so do charge periods, account fields, and service names. AWS supports FOCUS natively through Data Exports.
Refine ingests FOCUS 1.2, the current AWS-supported revision. Standardized billing data is what lets us show you a savings number you can audit, compare months without translation errors, and — as of our new pricing — meter your plan on the exact same BilledCost total you see on your own dashboard.
Already have a FOCUS export? Even faster
Plenty of teams have already set up a FOCUS export for their own analytics. The connect flow now asks which situation you're in: Quick setup (run the stack) or I have a FOCUS export (point Refine at your existing bucket and reader credentials). Either path lands in the same place; the stack is a convenience, not a requirement.
An honest note on permissions
The IAM role the stack creates has read access to billing data and security posture across the account — that's what account-wide cost analysis and security findings require, and we'd rather say so plainly than imply the access is narrower than it is. The full policy is written inline in the template so you can read every line before you create it, and the same description lives on our security page. Revoking access is one deleted role away, at any time, on your side.
What to expect after you connect
One thing worth knowing: AWS delivers the first billing export on its own schedule, typically within a day of the export being created. Refine will show your account as processing until that first delivery lands, then notify you when your data is ready. After that, updates flow continuously.
Ready to try it? Create a free account, click Add Account, and choose Quick setup. The documentation has a step-by-step walkthrough of both paths, including where to find the role's ARN in the stack's outputs.