Skip to content
Cloudreason

Cloud cost allocation and tagging: making the bill mean something

Nobody owns a number they cannot see. Allocation is what turns a bill into accountability.

Cost Allocation · AWS + Azure + Google Cloud

Published

Every FinOps capability rests on one question: who spends what, on which thing, and is it worth it? If the bill cannot be split truthfully across teams, products and environments, then optimisation has no owner, commitments have no baseline and finance has no forecast. Allocation is unglamorous, it sits among the foundational capabilities of the FinOps Foundation’s framework, and it is the foundation everything else stands on.

Structure first, tags second

The coarsest allocation instrument is the account boundary: AWS accounts, Azure subscriptions and Google Cloud projects. Spend lands in them unavoidably, no tag required, which makes a well-designed account structure the most reliable allocation you will ever get. Separating production from non-production, and major products from each other, at the account level answers the biggest questions before a single tag is written.

Tags then carry the finer grain. The mistake almost every organisation makes is aspiration: a tagging standard with fifteen keys, three of them mandatory in theory, none enforced in practice. Allocation needs a small set that is actually present:

  • Owner: the team, not a person who will leave
  • Environment: production, staging, development
  • Service or product: the thing the business would recognise
  • Cost centre: the code finance already uses

Enforce them where resources are created: validation in your infrastructure-as-code pipelines, AWS tag policies and service control policies, Azure Policy, and organisation policy on Google Cloud. Tags added retrospectively in a spreadsheet are archaeology, not allocation.

Measure the untagged, relentlessly

Untagged spend is the honest metric of an allocation practice. Track it as a percentage, publish it, and drive it under 5%. Two mechanisms do most of the work: blocking untagged resources at deployment, and a monthly sweep in which everything unattributed is assigned to a named owner for correction. Note that some spend is never taggable, such as certain support charges and data transfer line items; allocate it by an agreed rule rather than pretending it does not exist.

From reporting to behaviour

Allocation only earns its keep when the numbers reach the people who cause them:

  • Showback puts each team’s spend in front of that team and its leadership every month. In our experience this alone changes behaviour: engineers fix what they can see, and nobody wants to lead the waste table. The storage line is usually the first thing they attack.
  • Chargeback goes further and bills the spend to team budgets. It creates the strongest incentives and the most politics; adopt it only once showback numbers are trusted.
  • Unit economics is the mature end point: cost per customer, per transaction, per tenant. It converts the bill from a scary total into a business metric, and it is the number that makes cloud cost conversations rational. A rising bill with falling cost per transaction is success, not a problem.

The raw material for all of this is the billing data itself: the Cost and Usage Report with Cost Categories on AWS, cost exports on Azure, and the BigQuery billing export on Google Cloud. The tooling layer on top matters less than the discipline underneath.

Whose job is this?

Allocation fails as a side project because it sits between finance, who own the money, and engineering, who own the resources. Someone has to own the join. Inside our Managed FinOps retainer that is us: we build and enforce the allocation model, run the monthly numbers, and train your teams until the discipline lives in your organisation rather than in a consultant. Day one of the Cloud Cost Health Check is precisely this exercise, mapping where the money goes, so if you cannot currently answer that question, that is the place to start.

← Managed FinOps at Cloudreason

Frequently asked questions

How many tags do we actually need?

Fewer than most tagging standards specify. Four enforced tags, typically owner, environment, service and cost centre, answer almost every allocation question that matters. A five-page tagging policy that nobody follows allocates nothing; a four-tag policy enforced at deployment allocates everything.

What is the difference between showback and chargeback?

Showback reports each team's cloud cost to them and to their leadership; chargeback actually bills it to their budget. Showback changes behaviour surprisingly well on its own and is far cheaper politically, so we almost always start there. Chargeback is worth its overhead once numbers are trusted and material.

How should shared costs be allocated?

Simply and transparently. Shared platform, networking and support costs can be split evenly, proportionally to each team's direct spend, or by a usage driver such as request count. Proportional splitting is the sensible default. The method matters less than everyone knowing what it is; clever formulas that nobody understands breed disputes, not accountability.

What percentage of untagged spend is acceptable?

Get it under 5% and keep it there. Above that, every report carries an asterisk large enough to argue with. The practical route is enforcement at creation through infrastructure-as-code validation and platform tag policies, plus a monthly sweep that assigns everything unattributed to a named owner for correction, not to a bucket labelled miscellaneous.

Want to know what your estate should cost?

The Cloud Cost Health Check answers that in three days: fixed scope, fixed price, and a plan you can act on with or without us.