The average organization wastes somewhere between 27% and 32% of its cloud spend on idle resources, oversized instances, and orphaned storage, according to the most recent FinOps Foundation benchmark. For a team spending $50,000 a month on AWS or GCP, that's $160,000 to $190,000 a year quietly leaking out before anyone notices a thing.
Most engineering teams don't have a cost problem because they're careless — they have a cost visibility problem. Nobody can optimize what they can't see, and most cloud bills are opaque by design: thousands of line items, dozens of services, and no obvious owner for any of it.
The instinct when cloud bills get big is to hand the problem to finance. That's the wrong move. Finance can read a bill, but they can't tell you whether that forgotten staging cluster is safe to delete or whether that oversized RDS instance is load-bearing. Cost governance that works lives with engineering, because engineering is the only group that understands what's actually running and why.
The FinOps Foundation's model breaks the discipline into three phases that repeat continuously: Inform (make cost visible and attributable), Optimize (act on what you can see), and Operate (make cost awareness part of how the team normally works, not a quarterly fire drill).
Tagging is where most FinOps efforts die. Teams roll out a tagging policy, enforcement is inconsistent, and six months later half the resources still have no owner tag. The fix is to make tags structurally required, not a style guideline:
{
"tagPolicy": {
"tags": {
"team": { "tag_value": { "@@assign": ["platform", "payments", "growth", "data"] } },
"environment": { "tag_value": { "@@assign": ["production", "staging", "dev"] } },
"cost-center": { "tag_value": { "@@assign": ["eng-infra", "eng-product"] } }
},
"enforced_for": {
"ec2:instance": { "@@assign": ["team", "environment", "cost-center"] },
"rds:db": { "@@assign": ["team", "environment", "cost-center"] }
}
}
}
Pair the tag policy with a hard enforcement rule: any resource created without the required tags gets flagged by a scheduled Lambda or Cloud Function and either auto-tagged from the creating IAM role's known team mapping, or shut down after a grace period. Tagging that depends on humans remembering is tagging that will fail.
Three categories account for most avoidable cloud spend, in order of how often they're ignored:
| Waste category | Typical detection effort | Typical savings |
|---|---|---|
| Idle/orphaned resources | Low — native cloud tooling | 5–10% of total spend |
| Oversized instances | Medium — needs utilization history | 10–20% of compute spend |
| Missing committed-use discounts | Low — one-time analysis | 30–60% of steady-state compute |
Static budget alerts ("notify me at 80% of monthly budget") are nearly useless — by the time you hit 80%, the money's already spent. Anomaly detection based on day-over-day and week-over-week deviation catches problems while they're still small:
resource "aws_budgets_budget" "anomaly_watch" {
name = "daily-spend-anomaly"
budget_type = "COST"
limit_amount = "500"
limit_unit = "USD"
time_unit = "DAILY"
notification {
comparison_operator = "GREATER_THAN"
threshold = 150
threshold_type = "PERCENTAGE"
notification_type = "ACTUAL"
subscriber_email_addresses = ["platform-team@example.com"]
}
}
A threshold like this catches the misconfigured autoscaling group that spun up 40 extra instances overnight — the kind of incident that costs real money if it isn't caught until the monthly bill arrives.
The teams that sustain cost discipline don't do it through a quarterly all-hands review — they bake cost visibility into tools engineers already use. Two patterns do most of the work:
Showback in the PR, not in a dashboard nobody opens. A CI check that estimates the monthly cost delta of a Terraform plan — even a rough one — puts the number in front of the person making the decision, at the moment they're making it.
Budgets as code, reviewed like any other infrastructure change. Treating budget thresholds and tag policies as Terraform resources (as above) means changes go through the same PR review as everything else, instead of living in a console nobody audits.
| Phase | Focus |
|---|---|
| Weeks 1–2 | Enforce tagging policy; run a one-time audit for idle/orphaned resources |
| Weeks 3–6 | Rightsize based on 30-day utilization history; purchase committed-use discounts for steady-state workloads |
| Weeks 7–12 | Stand up anomaly detection; add cost estimation to the CI pipeline; establish a monthly showback review per team |
None of this requires a dedicated FinOps hire or an expensive third-party platform to start — native cloud tooling covers the first 80% of the work. What it requires is treating cost the same way you'd treat any other production concern: visible, owned, and reviewed continuously rather than discovered in arrears.
If your cloud bill has become a mystery nobody on the team can fully explain, talk to us — we can help you build the tagging, visibility, and governance to bring it back under control.