FAQ
Questions worth asking first.
There is no sales call, so this is the interrogation. The “no” answers are here too — finding out now that we don't do something costs you nothing.
How it compares
The tools you are probably already using, and where this one differs.
- AWS already has Cost Anomaly Detection, and it's free. Why this?
It is a fair question and the honest answer is that AWS's tool is genuinely good at the detection part. Where it tends to lose people is everything around it: an event that stays elevated keeps generating alerts, alerts arrive by email or land in an SNS topic you then have to build the Slack plumbing for, and the findings live apart from anything about what to do next.
CostWarden groups consecutive days of one problem into a single event and tells you once, delivers to Slack, Teams, Google Chat or PagerDuty with no glue code, and puts rightsizing findings on the same screen as the spend. If AWS's alerts already work for your team, keep them — that is a real outcome and not one worth paying to replace.
- How is this different from CloudZero, Vantage or Harness?
They are not one kind of product, so this is not one answer. CloudZero and Harness are FinOps platforms for organizations that have someone whose job is the cloud bill — more capable than this, priced accordingly, and quote-only. Vantage is the honest comparison: it is self-serve, it has a free tier, and if what you want is dashboards and reports on your spend you should go look at it. The difference is what each is for. Vantage is a place you go to; CostWarden is a message that arrives, and the dashboard is the small part. On price the bands cross over depending on your bill — check both against your own rather than taking our word for it.
Detection
Every threshold quoted here is the shipped default. The product page publishes the whole configuration.
- How does it decide something is an anomaly?
Each service is compared against its own recent history for the same weekday — 4 weeks of it — using the median and median absolute deviation rather than the mean. Robust statistics matter here: one bad day in the baseline would drag an average enough to hide the next one.
A day has to clear both a statistical bar and a money bar. On the default Balanced setting the statistical bar is either a 3.5 robust z-score or a 40% increase — one of the two is enough, not both — and the money bar is that the extra spend must be at least $10 and at least 1% of that day's total bill. A service that goes from $2 to $4 has doubled and will not page anyone. If that's too chatty or too quiet for your account, there is one dial on the Alerts page — Quieter, Balanced, or More sensitive — plus an optional "ignore anything under $X/day" floor.
- Will it alert me every day while the problem is still happening?
No. Consecutive flagged days for one service are grouped into a single event, and you hear about the event, not each day. There is a 3-day cooldown, and a long-running event is re-raised only if it escalates another 50% or after 14 days. The dashboard still shows it as active the whole time.
- How quickly will I hear about a spike?
The scan runs daily at 13:00 UTC, and you can trigger one manually any time. The real limit is AWS, not us: Cost Explorer publishes a day's spend roughly 24 to 48 hours late, so the freshest day anyone can analyse is already a day or two old. Nobody detects a spend anomaly in real time from billing data — a tool that claims to is measuring something else.
- Does it work on a brand-new AWS account?
Partially, and it says so. On connecting we pull up to 90 days of history, but the detector needs 4 weeks of same-weekday history before it can judge a day, and at least 3 prior samples for a given weekday. With less than that it stays quiet rather than guessing, and the dashboard tells you it is still accumulating rather than showing you an empty page.
Setup and access
What it needs from your AWS account, and who on your team can do what.
- What do you need from my AWS account?
One read-only IAM role with 5 permissions, which you create and can delete at any time. No agent, no access key, no write permission of any kind. The security page lists the permissions by name and says what each one is for.
- Can my whole team use it?
Yes. An organization has three roles: owners handle billing and members, admins manage the AWS connection and alert channels, and members use the product. Everyone shares one connection and one view. Invitations are currently in-app — you invite an address, and the invite is waiting in their settings once they sign up with it and confirm it.
- Where do alerts go?
Slack, Microsoft Teams, Google Chat and PagerDuty, as many as you want, configured per organization. Anomalies open a PagerDuty incident deduplicated per event, so a two-week problem pages once rather than fourteen times. Daily and weekly digests are never sent to PagerDuty — a summary is not an incident.
- How do I know the alerts are actually arriving?
Every channel records whether its last delivery succeeded. If a webhook starts failing — a revoked app, a deleted channel — the channel is badged as failing with the exact error, and a banner appears on the dashboard. For an alerting product, silence has to mean “nothing is wrong” and never “we stopped being able to tell you”.
Trial and billing
The trial clock, what happens when it runs out, and who takes the payment.
- How does the trial work?
14 days, and the clock starts when your AWS connection first works — not when you sign up. Waiting on someone to approve an IAM role should not eat your evaluation. No card is required to start.
- What happens when the trial ends and I haven't subscribed?
We stop collecting new data, and that is all. The daily scan skips your organization and no new alerts go out, but everything already synced stays exactly where it is and stays readable, with a banner saying why it stopped moving. Nothing is deleted, and subscribing picks it back up on the next run.
- What if a payment fails?
A failed renewal keeps working for 7 days while the card is retried, so an expired card does not cost you a week of alerts. If you cancel, access runs to the end of the period you already paid for rather than stopping that day.
- Who handles payment?
Lemon Squeezy, as Merchant of Record — they handle checkout, tax and invoicing. Card details never reach CostWarden.
What it does not do
Every one of these is a decision with a reason, not a gap waiting to be filled.
- Do you support Azure or Google Cloud?
No, and there is no plan to. AWS only. Doing one cloud properly is the trade being made deliberately; if you are multi-cloud you want a different tool.
- Do you support SSO / SAML?
Not SAML or OIDC. Sign-in is email and password or Google, and two-factor authentication (TOTP) is available in Settings → Account — once enrolled, every page requires the second factor. Organization roles control who can do what.
- Can it shut down or resize things automatically?
No, and this one is a product decision rather than a missing feature. The role we ask for has no write permission at all, which is what makes the request easy to approve. Automatic remediation would require exactly the access this product promises never to hold.
- Can I build my own dashboards or export to BI?
No. The dashboard is opinionated and minimal on purpose — the product is meant to reach you where you already are so you rarely open it. There is no custom dashboard builder and no BI export today.
- Will it buy Reserved Instances or Savings Plans for me?
No. It surfaces rightsizing findings from AWS Compute Optimizer with their estimated monthly saving. Commitment purchasing is a different product with a different risk profile.
Still deciding?
The connection is a read-only role you can delete at any time, and the trial starts when it works — not before.