CloudPulse surfaces multi-cloud cost, AI spend, SaaS spend, carbon, and unit economics without writing a single byte into your cloud. The IAM policy your security team approves contains only read actions. The platform itself cannot deviate. It has no write permissions to deviate with.
Read-only is not a stance we describe in a sales deck. It is a property enforced at the IAM layer, the application layer, and the audit layer.
The role you trust to CloudPulse contains only describe / list / get actions across AWS, Azure, OCI, and GCP (in development). The published policy is the policy. No hidden write paths.
Even our own identity surface (user enable / disable / password reset) runs through a dedicated mediator with its own narrow permissions. The main application has no admin identity-mutation rights. The blast radius of a platform compromise is bounded by IAM, not by trust.
Every operator action against customer data writes an audit record with actor, target, reason, and outcome. That includes reads of sensitive recommendations, team-membership changes, and password resets. Customers receive their account’s log on request.
The FinOps market splits cleanly along this line. Tools that auto-apply changes require write permissions; tools that only observe do not. CloudPulse sits in the latter camp, explicitly, by design, and without exception.
| Platform | Cloud-write IAM required? | What that means at the IAM-policy level |
|---|---|---|
| CloudPulse | No | Describe / list / get only. The role you grant cannot stop, modify, tag, terminate, or purchase anything. Customer-cloud writes are not a feature we have switched off; they are a capability we have refused to acquire. Verified by the published role policy and the security audit that runs on every release. |
| Spot (NetApp) | Yes | Auto-applies rightsizing, instance replacement, and spot-fleet management. The role you grant must hold EC2 modify / terminate scope to deliver the product. |
| nOps | Yes | Auto-purchases commitments and applies cost optimisations. Requires write scope on billing-account-level commitment APIs and compute-action APIs. |
| ProsperOps | Yes | Actively manages your commitment portfolio: buying, exchanging, and optimising RIs / Savings Plans on your behalf. Requires commitment-write scope. |
| Harness CCM | Yes | Auto-applies governance policies and remediation actions across the cloud estate. Write scope is the product. |
| CloudZero | No | Read-only on cloud APIs. Complementary on the trust axis. The competitive difference is feature breadth (multi-cloud, AI, SaaS, carbon, repatriation), not trust posture. |
| Vantage | No | Read-only. Same trust-posture camp as CloudPulse and CloudZero. |
| Finout | No | Read-only on customer-cloud APIs. |
| CloudHealth (Broadcom) | Partial | Read by default. Optional remediation modules require write scope, granted per-module, with the security review that implies. |
| Apptio Cloudability (IBM) | Partial | Primarily read. Action-oriented capabilities (TruePlan execution, certain governance flows) extend the IAM footprint when enabled. |
Vendor scopes reflect public IAM-policy documentation and product positioning as of the most recent competitive review. Trust posture changes over time, so ask your prospective vendor for their published IAM policy in writing before comparison.
Every security-team question we have ever been asked has a reproducible answer. The pack is available to CloudPulse customers on request, with no NDA required, in the form your team needs.
Spin up a CloudPulse account in minutes. The role you attach is read-only. No firewall changes. No egress paths. No write permissions to review.