Note
Published
2026-08-10
Reading
9 min
Data
Public sources
Headline figure
High
Claim
The access appendix, in full
Every credential this studio asks for is read-only, created by you, scoped to a named billing account or export location, and expires on a date you set. This note is the complete list, one row per grant per cloud, plus the retention, insurance, subprocessor and capacity terms that a security reviewer will ask for and that a summary page has no room for.
Topics: method · AWS · Azure · GCP
Built from public provider documentation and sourced research. Worked figures inside are labelled synthetic. No client data was used.
Argument
Why this is a note and not a page
The access page shows the exact IAM policy, the Kubernetes
ClusterRole, the Azure role assignments and the gcloud commands, because those
are the evidence. Everything below is the appendix a security reviewer works
through line by line. It moved here in the W2 pass so the page stays readable
and the detail stays complete.
Grant index, by cloud
A grant that is not on this list should be refused. If a request arrives for something absent here, that is either a mistake or a reason to stop.
| Cloud | Role or policy | Scope |
|---|---|---|
| AWS | AWSBillingReadOnlyAccess plus the scoped customer policy on /access | Assumed role in the payer account, MFA + external ID + expiry condition |
| AWS | S3 read on the CUR bucket prefix | One bucket, two prefixes |
| AWS | ClusterRole cost-mechanic-read | One EKS cluster per engagement |
| Azure | Cost Management Reader | Billing account or billing profile |
| Azure | Reader | Named subscriptions only |
| Azure | Storage Blob Data Reader | The export container |
| Azure | AKS Cluster User + RBAC Reader | One AKS cluster |
| Azure | Monitoring Reader | The Azure OpenAI resource |
| GCP | roles/billing.viewer | Billing account |
| GCP | roles/bigquery.dataViewer | The billing export dataset |
| GCP | roles/container.clusterViewer | Projects in scope, time-bound |
| GCP | roles/aiplatform.viewer | Projects in scope, time-bound |
| LLM providers | Admin API key, usage and cost read scope | One organization, rotated at handover |
| Repository | Collaborator invitation, no default-branch write | Only the repositories you invite |
| All | Write, delete, data-plane read, model invocation | Not requested, not granted |
Azure is the one worth reading twice. Cost Management Reader has to sit at the billing account or billing profile scope rather than the subscription, because unused reservation charges land on the billing profile and not on the subscription that should have consumed them. Subscription-scoped showback therefore hides reservation waste. The waste is real, it is billed, and it is invisible from where most teams look.
Data handling, retention and deletion
Most analysis runs in place, in your own account, against your own export. What follows describes the working copies that do not.
| What is copied | Cost rows, usage rows, token counts, resource metadata, cluster requests and limits |
| What never is | Object contents, database rows, backups, request or response text |
| Where it lives | One encrypted location, full-disk encrypted, no sync to a personal cloud drive |
| Deleted within | 30 days of handover |
| Sooner on request | Say the word at the readout: that week, with written confirmation |
| Rows of customer data held | None |
Commercials of risk
| NDA and contract | Mutual NDA on request, signed first if you prefer. Every SOW carries the access appendix |
| E&O and general liability | No policy in force today, so no certificate exists. If your review requires one, the answer is no |
| Subprocessors | Analysis environment, code host, email provider, all named before signature. No export data goes to any model provider |
Order of operations: NDA → appendix reviewed → SOW signed → you create the credential → kickoff. The credential is the last step, never the first.
SOC 2: what stands in its place
There is no SOC 2 report and there will not be one this year. Each row below is a control you can verify yourself, in your own console, without taking anything on trust.
| Your requirement | What replaces it |
|---|---|
| Audited access control | Credentials you create: read-only, MFA, expiring on a date you set |
| Data-handling assurance | No data-plane access; the AWS policy denies it explicitly |
| Vendor-system review | No vendor system holds your work. Every artifact is in your repository |
| Access logging | Your audit log, your named principal, reviewable jointly mid-engagement |
| Questionnaire response | Answered in writing, not routed through a sales desk |
| Strictest setting | No credential at all: you run the published methodology queries yourself and send the aggregate output |
Absent, not pending: SOC 2, ISO 27001, a penetration-test report, a compliance team, a certificate of insurance, a named substitute engineer.
Audit us halfway through
Filter your audit log by the principal named in the SOW. Confirm read-only, no
s3:GetObject outside the export prefixes, no bedrock:InvokeModel, and no
writes. Doing this at the midpoint rather than at the end is the whole point of
having it in writing.
Capacity, held against cap
The caps are arithmetic on the hours the work consumes. There is no queue and no waitlist to join.
| Cap | |
|---|---|
| Concurrent project engagements | At most 4 |
| Margin Watch, one or more estates | At most 4 |
| Margin Watch, reports only | At most 6 |
| Named substitute engineer | None. No redundancy claimed |
Continuity
| Trigger | What happens, without you asking |
|---|---|
| From day one | Queries, pipelines, Terraform, harness and methodology live in your repository and account |
| Unavailable 5 consecutive business days | Delivery and guarantee clocks pause; retainer months prorate automatically |
| You terminate on that trigger | Unearned project fees refunded pro rata, with no negotiation about percentage complete |
Five steps on your side, all reversible
- Create the credential yourself. Do not accept one from us.
- Set the expiry in the policy, not in a calendar reminder.
- Scope to one billing account, or to named subscriptions or projects.
- Require MFA by condition, and generate a one-time external ID.
- Run the revocation check on the last day, and confirm it returned clean.
Sources are listed at the foot of this note with their confidence stated. Medium and low confidence figures say so in the copy.
Every query here runs against a read-only role you create, scope and revoke. Access policy.
Close
More notes
Check the arithmetic yourself
The full derivations, with the queries written out so they run under your own read-only credentials, in your own console.