AWS Cost Investigation
When a material AWS cost change needs a defensible explanation. Receive a written investigation with evidence, ownership, limits, and sequenced next actions.
Explore the investigationEnterprise AWS Cost Investigation
Mission FinOps is an independent investigation practice for enterprise AWS teams. When leadership needs an answer and engineering and finance have different explanations, I complete the investigation the dashboard started.
Why did EC2 spend increase 18.4% in us-east-1?
Regional data transfer growth driven by a new cross-AZ replication job deployed 2026-05-08. Owner untagged.
Confidence: High View the full investigationServices
Start with a cost question. Choose the engagement based on what your team needs from the answer.
When a material AWS cost change needs a defensible explanation. Receive a written investigation with evidence, ownership, limits, and sequenced next actions.
Explore the investigationWhen your team needs repeatable cost data, ownership, reporting, and governance inside the systems it already uses.
Build internal capabilityWhen your team wants to learn the investigation method by working through a real AWS cost question alongside Mission FinOps.
Investigate togetherWhen an approved customer needs targeted help connecting new billing evidence to architecture, ownership, and business decisions.
Continue the relationshipCloud cost investigations should produce evidence, not opinions. Every material conclusion should be traceable to its source, open to challenge, and clear about what remains unknown.
Open-source tooling
Kulshan is the open-source AWS cost evidence CLI built by Mission FinOps. It runs locally, uses read-only AWS access, and collects repeatable evidence from AWS cost and usage data.
Read-only by construction. The published IAM policy contains zero write actions.
Technical proof of the investigation practice, not a platform you have to buy.
Built for teams where cloud cost data doesn't belong in another SaaS.
Banks • Government • Healthcare • Telecom
I have spent twenty years following the same problem from the network cable to the CFO's spreadsheet.
My path into FinOps didn't start with cloud. It started with hardware, teaching, and years of designing enterprise networks before I moved into AWS.
At AWS, I worked with large enterprise customers. Many were not simply running multiple AWS accounts. They operated multiple AWS Organizations, multiple payer accounts, and in some cases separate Cloud Centers of Excellence for different business units. Cost questions crossed finance, engineering, architecture, procurement, and governance.
In 2019, I was querying AWS Cost & Usage Reports directly with Athena SQL, building custom reporting pipelines, and helping engineering and finance answer questions from raw billing data. Often, the answer was not in the bill alone. Networking explained data transfer. Architecture explained usage growth. Governance explained ownership. Finance explained whether any of it mattered.
Kulshan wasn't built because I wanted to build a CLI. It was built because, after answering the same cost questions for years, I realized the investigation itself could be repeatable.
That is why I built Kulshan around evidence instead of dashboards. Dashboards tell you that costs changed. Evidence explains why.
The first generation of FinOps helped us see cloud costs.
The next generation needs to explain them.
Today, Mission FinOps exists because organizations do not need another dashboard. They need faster, evidence-backed explanations they can defend in front of engineering, finance, and leadership.
Operating metric
MTTE measures how long it takes to produce a defensible explanation for a material cost change.
Detection tells a team that something moved. Explanation connects that movement to the technical, financial, and ownership evidence behind it. Alerts create attention. Explanations support decisions.
MTTE is the operating metric Mission FinOps uses to evaluate investigation quality and shape how Kulshan is built.
Why now
AI systems are beginning to interpret cloud operations and cost data. Before an enterprise trusts an explanation or recommendation, the underlying evidence should remain under enterprise control and be independently inspectable. Models can assist interpretation. They should not become the source of truth.
Every engagement starts with a conversation. Some teams need a single cost investigation. Others need help building an internal FinOps capability. Every environment is different.
Email two sentences: what changed, and what decision is waiting on the answer.