Field notes

The Evidence Should Stay With the Enterprise

Something changed in AWS. Before sending sensitive operational context into another platform for interpretation, make sure the underlying evidence remains local, inspectable and under your control.

Kelsey Hightower, the former Google Cloud principal engineer behind Kubernetes adoption and one of the most respected infrastructure voices in the industry, posted that recently. It landed.

I left a personal response:

I'm going Local AI, in a box. If that AI tried to even leave the enterprise guardrails we've built... we nuke it. Simple.

The language was blunt. The concern behind it was not.

This article is not announcing a Mission FinOps AI product. It is explaining why enterprise-controlled evidence must exist before AI interpretation can be trusted.

The important question is not whether an AI provider promises to be safe. The question is whether the enterprise controls the data, the evidence and the trust boundary. It is an architectural decision many enterprise teams are now being asked to make.

Cloud cost investigations contain sensitive context

Something changed in AWS. The bill noticed first.

Now your team needs to explain it. That investigation touches real operational context:

Billing and usage records. Account structures. Resource metadata. Tags that reveal workload ownership. Deployment changes that show what shipped and when. CloudTrail activity that shows who did what. CloudWatch metrics that show what happened next. Internal financial context that maps infrastructure to business units.

Put together, this evidence reveals how the company operates. It shows org structure, deployment cadence, team boundaries, cost allocation strategy and infrastructure decisions.

The question is: where does this investigation happen?

If the answer is "export it to a SaaS platform so their AI can explain it," the enterprise has made a trust decision it may not have intended to make.

Do not make AI the source of truth

An AI-generated answer is only as reliable as the evidence beneath it.

A confident explanation without inspectable evidence is not sufficient for an infrastructure leader who needs to defend the conclusion in a room with finance and engineering leadership.

"The AI said costs went up because of a new deployment" is not an explanation. It is a claim. Without supporting evidence, it cannot be verified, challenged or extended.

We cannot reliably inspect an AI model's private reasoning. We can control what data it receives, what evidence it uses and what actions it is permitted to take. But those controls depend on something existing before the AI arrives: evidence that is collected, stored and inspectable independent of whatever model interprets it.

The order matters. Evidence infrastructure first. Interpretation second.

The architectural pattern

The principles are straightforward:

Collect evidence locally. Keep customer data under customer control. Use read-only access by construction. Separate evidence from interpretation. Preserve evidence trails. Allow humans to inspect findings. Make conclusions reproducible where possible.

None of these principles require AI. They do not reject AI either. They establish the foundation that makes AI conclusions checkable when AI eventually participates.

When an AI system operates on top of inspectable evidence, its conclusions can be checked against that evidence. When interpretation happens inside an external platform without an inspectable evidence trail, the enterprise may be unable to independently reproduce or challenge the conclusion.

What Kulshan does today

Mission FinOps helps infrastructure, engineering, finance and FinOps teams investigate the questions that follow a cost change:

What changed in AWS? Why did the bill increase? Which workloads or infrastructure changes contributed? What evidence supports the explanation? What is the estimated financial impact?

Kulshan is the evidence engine behind those investigations. It is local-first, meaning it runs inside the customer-controlled environment. It is read-only by construction, meaning it collects evidence without modifying infrastructure. It is open source, meaning anyone can inspect how it works. It is evidence-first, meaning its findings remain tied to evidence that people can inspect.

Kulshan produces deterministic, inspectable evidence that humans and AI systems can verify.

Kulshan is not a cost dashboard. It is not an anomaly alert. It is not a Cost Explorer wrapper with a chatbot on top.

It exists because investigating cloud cost changes requires assembling real operational evidence, not staring at a graph and guessing.

Mean Time to Explanation

Alerts tell teams that a number changed. That is detection.

Evidence helps them explain why. That is explanation.

The distance between detection and explanation is where teams lose hours. They context-switch between Cost Explorer, CloudTrail, CloudWatch, tagging, deployment history, internal wikis, Slack threads and tribal knowledge. They assemble the explanation manually every time.

Mean Time to Explanation is the metric that matters for cost investigations. Not how fast the alert fires. How fast the team can produce a defensible explanation of what happened and why. We wrote about MTTE as an operating metric separately.

Stronger evidence infrastructure means a faster, more defensible explanation. It means the VP of Engineering does not wait three days for a cost summary that an analyst assembled by hand. It means finance gets an answer they can trust because the evidence trail is visible.

Evidence before interpretation

Whether the interpretation comes from a human or an AI system, the underlying evidence should remain independently inspectable.

That is the architectural principle. Not "block AI forever." Not "AI is dangerous." Simply: the evidence must exist in a form that can be verified regardless of what interprets it.

If the evidence layer is sound, the enterprise retains the ability to confirm, challenge or extend any conclusion drawn from it. If the evidence was never collected locally, or was only available inside a vendor platform, that ability does not exist.

Keep control of the evidence

Every enterprise team investigating cloud costs faces a version of this decision.

Teams can export operational context into another platform and trust the answer they receive. Or they can retain control of the evidence, inspect the findings directly and decide how that evidence is interpreted.

The AI should come to the enterprise data. The enterprise data should not have to leave for the AI.

That principle is already reflected in how Kulshan and Mission FinOps investigations handle cloud cost evidence today.

Something changed in AWS and your team needs a defensible explanation? Talk to Mission FinOps about an evidence-first AWS cost investigation.

All articles