Connect an AWS account
The fastest path is the Refine connector stack — one CloudFormation stack, launched from inside Refine, that creates the FOCUS 1.2 billing export, its S3 bucket, and a read-only IAM role in your account. If you already export FOCUS data, skip to the existing-export path below.
Quick setup (recommended)
- In Refine, open
Settings → AWS Accounts → Add Account(the welcome screen’s Connect your AWS account button lands here too) and choose Quick setup. - Click Launch the connector stack. The AWS console opens with the template pre-loaded — it runs in
us-east-1(required for Cost & Usage Data Exports). Tick the IAM acknowledgement and create the stack (~2 minutes). - Open the stack’s Outputs tab and paste into the form:
BucketName→ Source Bucket,RoleArn→ Role ARN. That is everything — the External ID was already carried into the stack by the launch link. No access keys are created and none leave your account: the stack creates a read-only IAM role that only Refine’s AWS account can assume, and only when it presents your External ID. - Save. AWS delivers the first export within about a day; Refine picks it up automatically and notifies you.
Already exporting FOCUS?
Choose I have a FOCUS export in the same form and point Refine at that bucket, with a read-only IAM role Refine can assume — it needs read on that bucket plus billing and security-audit read (that is what the cost and security views run on), savingsplans:DescribeSavingsPlans for when each Savings Plan ends, and cloudwatch:GetMetricData to confirm that a database or cache the bill looks idle for really is. The easiest way to make that role is the same connector stack with ExistingBucketName set to your bucket: it then creates only the role and touches nothing you already have. Re-connecting an account that used the older access-key setup? Use this path. Running the full stack again fails with “Cannot create duplicate export name”, because the export it made the first time is still there. Building the role by hand instead? Its name must start with Refine, and its trust policy must name arn:aws:iam::941275879372:root under the External ID shown on the form.
What access does Refine get?
A read-only IAM role: account-wide billing, security-audit, Savings Plans and CloudWatch-metrics read, plus read access to the export bucket only — no write or admin permissions. Refine never asks for, receives or stores an AWS access key. It assumes the role for an hour at a time, and only by presenting the External ID your stack was created with, so the role cannot be used by anyone else who learns its ARN. To revoke access at any time, delete the role in your AWS console — Refine immediately loses the ability to read, with nothing left over to expire.