Skip to content
Refine

Product · AWS Advanced Tier Services Partner

Pin every AWS dollar to an owner

Untagged resource visibility, allocation gap reporting, drift detection, and policy enforcement preview. The FinOps surface that makes showback actually work.

Why tags matter for FinOps

Tags are the spine of cloud cost accountability

FinOps Foundation lists cost allocation as a foundational capability for a reason. Without it, every other FinOps practice — showback, forecasting, anomaly attribution — limps.

Showback Is Impossible

Without consistent CostCenter / Owner / Environment tags, you cannot tell finance which team or product drove the spike. Allocation slides into "Unallocated" — the line that auditors love to flag.

Resources Go Orphaned

An engineer leaves, the resource keeps running. Without an Owner tag, you cannot tell who owns it, who to ask before turning it off, or whether it is still needed.

Drift Is Invisible

Tags get applied at create-time, then drift. Six months later half your dev resources are untagged, your production tagging is 60% compliant, and nobody knows.

What Refine surfaces

Tag Intelligence, Not Just a Tag List

Refine ingests CUR and AWS Tagging APIs across your accounts, then ranks tag gaps by dollar impact — so you fix the $4k/mo orphan before the $10/mo bucket.

Untagged Resource List

Every resource missing your required tags, sortable by monthly spend. The $10/mo S3 bucket is fine; the $4k/mo EC2 instance without an Owner tag is not.

Allocation Gap Report

What percent of monthly spend is properly tagged. Trend over time so you see whether tagging discipline is improving or eroding.

Drift Detection

Resources that were tagged correctly at creation but lost tags through CloudFormation drift, manual edits, or service updates.

Required-Tag Tracking

Configure your required keys (CostCenter, Owner, Environment, Product) and watch per-key compliance climb. Each scan writes the score back, so the trend is the policy’s rather than a moving target.

Refine's Tag Hygiene and Allocation Coverage page for an anonymized account: overall coverage 0.0% against a 95% target, $0.00 of $1,325.75 spend tagged, 606 untagged resources, a note excluding $1,289.49 of untaggable line items from the calculation, and a coverage breakdown by service with EC2, RDS and S3 each at 0% tagged
Coverage as Refine found it on one real account — the tenant is anonymized, the numbers are its own: 0 of 606 resources tagged against a 95% target, with $1,325.75 at risk. The $1,289.49 across 43 line items that cannot carry a tag — data transfer, tax, support, Savings Plans and RIs, Marketplace, per-request metering — is left out of the coverage calculation, and the page says so. Coverage, Compliance, Policy and Remediation are the four tabs; the breakdown switches between service and region.

Untagged Resources, Ranked by Spend

The exact shape of the view you get in the dashboard. Fix the top of the list and your allocation gap collapses.

Untagged resources (sample)

4 resources · $581/mo at risk
ResourceSpend / monthMissing tags

EC2 instance · m5.xlarge

i-0a4f9b3c2e8d1f6e

$142
OwnerCostCenter

RDS instance · db.r5.large

rds-prod-analytics-2

$248
CostCenter

S3 bucket · 8.2 TB

arn:aws:s3:::data-lake-archive

$187
OwnerEnvironmentCostCenter

Elastic IP · unattached

eipalloc-035fa17c9e2b4a17c

$4
OwnerEnvironment

Export the full list to CSV/XLSX for the FinOps ticket queue. Tag from within AWS, and the next sync confirms compliance.

Validate tag policy before you publish

Define your required keys, allowed values, and account-scoped overrides. Refine simulates the policy against current state and tells you exactly which resources will break before you publish.

  • Required-key declarations (CostCenter, Owner, Environment, Product)
  • Per-key allowed-value sets, and a pattern the value must match
  • Optional-but-valid keys — for a key that only applies to some resources
  • Per-service rule scoping, so an S3 rule need not bind EC2
  • Dry-run impact report (compliant / non-compliant per resource)
  • DRAFT until you activate it — a stricter policy fails nobody while you look at it

Policy preview · prod accounts

Dry-run
Total resources scanned12,847
Compliant10,203 (79%)
Non-compliant2,644 (21%)

Top non-compliant

  • EC2 (us-east-1) — 412 resources missing Owner
  • S3 (eu-central-1) — 88 buckets missing CostCenter
  • Lambda (ap-south-1) — 36 functions missing Environment

Apply policy? Compliance climbs to 91% projected after first remediation pass.

Fix hundreds of resources without giving us write access

Growth and up

Select the violations and Refine generates the fix as a file you run: a ready-to-run AWS CLI script, or a Terraform patch for a team whose change process goes through review. You run it with your own credentials.

Why not just do it for you?

Because writing a tag needs tag:TagResources plus a permission per service, and we do not ask for those. Refine onboards with a read-only role, and that boundary is worth more to you than a button — it is also the honest reason we can be given access to a production account on a Friday.

What the file contains

  • One command per resource, with the region resolved for you
  • A header listing the exact permissions the runner needs
  • The resources neither path can address, listed rather than dropped
  • Suggested tag values only where you selected them

Allocation & Showback

Growth and up

Tagging is the means; this is the end. Split the bill by the dimension your org actually organises around, decide what happens to the costs no tag can attribute, and mail each team the number they recognise as theirs.

Split by what you organise around

Allocate by account or service, or by any tag key — team, cost centre, product. The dimension is the report’s, so finance and engineering can each have the cut that makes sense to them from the same bill.

Shared services, seeded then corrected

Refine proposes which services are shared by nature from the ones on your own bill, so the first preview is sensible rather than empty. Then you fix it — every org names these differently, and a silent guess is worse than one you can see.

The preview is the pack

What you see on screen is computed by the same allocator that produces the emailed report. A preview built a second way would let the screen and the pack disagree, which is exactly the thing a chargeback report cannot afford.

Reconciled against the bill

The allocated total is checked back against the source total, so the split adds up to the invoice and any residue is visible rather than absorbed.

Scheduled monthly, per recipient

Pick the day of the month and who receives it. Each team gets its own allocation on a cadence, instead of a quarterly spreadsheet somebody has to remember to build.

CSV out, in a shape finance imports

Summary and per-resource detail export together, so the number in the email and the number in your finance system come from the same run.

What happens to support, tax and data transfer

No tag can attribute them, so every showback tool has to decide something. Refine makes it your decision, per report:

Proportional
each team pays in proportion to its own spend
Even split
every team pays the same share
Fixed %
percentages agreed with finance
Do not allocate
shared cost stays on its own line

Whichever you pick, the allocated total is reconciled back against the source bill — a chargeback number finance can challenge is one you can defend line by line.

Frequently Asked Questions

  • Start with discovery — Refine shows what tags exist where, ranked by spend. Most teams converge on CostCenter / Owner / Environment / Product. Once you pick keys, the policy preview validates them against current state before any enforcement.

Make tags a foundation, not a guilt trip

Connect AWS. See untagged spend in 60 seconds. Free under $2,000/month of AWS spend.

Refine is built and supported by HabileLabs, an AWS Advanced Tier Services Partner.