Note

Published

2026-08-10

Reading

9 min

Data

Public sources

Headline figure

High

Claim

The access appendix, in full

Every credential this studio asks for is read-only, created by you, scoped to a named billing account or export location, and expires on a date you set. This note is the complete list, one row per grant per cloud, plus the retention, insurance, subprocessor and capacity terms that a security reviewer will ask for and that a summary page has no room for.

9Reading · minutes
2026-08-10Published

Topics: method · AWS · Azure · GCP

Built from public provider documentation and sourced research. Worked figures inside are labelled synthetic. No client data was used.

Argument

Why this is a note and not a page

The access page shows the exact IAM policy, the Kubernetes ClusterRole, the Azure role assignments and the gcloud commands, because those are the evidence. Everything below is the appendix a security reviewer works through line by line. It moved here in the W2 pass so the page stays readable and the detail stays complete.

Grant index, by cloud

A grant that is not on this list should be refused. If a request arrives for something absent here, that is either a mistake or a reason to stop.

CloudRole or policyScope
AWSAWSBillingReadOnlyAccess plus the scoped customer policy on /accessAssumed role in the payer account, MFA + external ID + expiry condition
AWSS3 read on the CUR bucket prefixOne bucket, two prefixes
AWSClusterRole cost-mechanic-readOne EKS cluster per engagement
AzureCost Management ReaderBilling account or billing profile
AzureReaderNamed subscriptions only
AzureStorage Blob Data ReaderThe export container
AzureAKS Cluster User + RBAC ReaderOne AKS cluster
AzureMonitoring ReaderThe Azure OpenAI resource
GCProles/billing.viewerBilling account
GCProles/bigquery.dataViewerThe billing export dataset
GCProles/container.clusterViewerProjects in scope, time-bound
GCProles/aiplatform.viewerProjects in scope, time-bound
LLM providersAdmin API key, usage and cost read scopeOne organization, rotated at handover
RepositoryCollaborator invitation, no default-branch writeOnly the repositories you invite
AllWrite, delete, data-plane read, model invocationNot requested, not granted

Azure is the one worth reading twice. Cost Management Reader has to sit at the billing account or billing profile scope rather than the subscription, because unused reservation charges land on the billing profile and not on the subscription that should have consumed them. Subscription-scoped showback therefore hides reservation waste. The waste is real, it is billed, and it is invisible from where most teams look.

Data handling, retention and deletion

Most analysis runs in place, in your own account, against your own export. What follows describes the working copies that do not.

What is copiedCost rows, usage rows, token counts, resource metadata, cluster requests and limits
What never isObject contents, database rows, backups, request or response text
Where it livesOne encrypted location, full-disk encrypted, no sync to a personal cloud drive
Deleted within30 days of handover
Sooner on requestSay the word at the readout: that week, with written confirmation
Rows of customer data heldNone

Commercials of risk

NDA and contractMutual NDA on request, signed first if you prefer. Every SOW carries the access appendix
E&O and general liabilityNo policy in force today, so no certificate exists. If your review requires one, the answer is no
SubprocessorsAnalysis environment, code host, email provider, all named before signature. No export data goes to any model provider

Order of operations: NDA → appendix reviewed → SOW signed → you create the credential → kickoff. The credential is the last step, never the first.

SOC 2: what stands in its place

There is no SOC 2 report and there will not be one this year. Each row below is a control you can verify yourself, in your own console, without taking anything on trust.

Your requirementWhat replaces it
Audited access controlCredentials you create: read-only, MFA, expiring on a date you set
Data-handling assuranceNo data-plane access; the AWS policy denies it explicitly
Vendor-system reviewNo vendor system holds your work. Every artifact is in your repository
Access loggingYour audit log, your named principal, reviewable jointly mid-engagement
Questionnaire responseAnswered in writing, not routed through a sales desk
Strictest settingNo credential at all: you run the published methodology queries yourself and send the aggregate output

Absent, not pending: SOC 2, ISO 27001, a penetration-test report, a compliance team, a certificate of insurance, a named substitute engineer.

Audit us halfway through

Filter your audit log by the principal named in the SOW. Confirm read-only, no s3:GetObject outside the export prefixes, no bedrock:InvokeModel, and no writes. Doing this at the midpoint rather than at the end is the whole point of having it in writing.

Capacity, held against cap

The caps are arithmetic on the hours the work consumes. There is no queue and no waitlist to join.

Cap
Concurrent project engagementsAt most 4
Margin Watch, one or more estatesAt most 4
Margin Watch, reports onlyAt most 6
Named substitute engineerNone. No redundancy claimed

Continuity

TriggerWhat happens, without you asking
From day oneQueries, pipelines, Terraform, harness and methodology live in your repository and account
Unavailable 5 consecutive business daysDelivery and guarantee clocks pause; retainer months prorate automatically
You terminate on that triggerUnearned project fees refunded pro rata, with no negotiation about percentage complete

Five steps on your side, all reversible

  1. Create the credential yourself. Do not accept one from us.
  2. Set the expiry in the policy, not in a calendar reminder.
  3. Scope to one billing account, or to named subscriptions or projects.
  4. Require MFA by condition, and generate a one-time external ID.
  5. Run the revocation check on the last day, and confirm it returned clean.

Sources are listed at the foot of this note with their confidence stated. Medium and low confidence figures say so in the copy.

Every query here runs against a read-only role you create, scope and revoke. Access policy.

Close

Check the arithmetic yourself

The full derivations, with the queries written out so they run under your own read-only credentials, in your own console.