Integration · Cloud
AWS
Read-only visibility into your AWS inventory and costs — no changes, ever.
Read-only
Only ever reads
You approve a least-privilege, read-only connection. Lizrd sees what it needs to find savings — and nothing more. Revoke anytime.
Connect AWS · IAM role
Read-only
Granted
- ec2:Describe*
- rds:Describe*
- s3:GetBucket*
- ce:GetCostAndUsage
Never granted
- *:Create*
- *:Modify* / Update*
- *:Delete* / Terminate*
You approve the exact CloudFormation. Revoke anytime.
What Lizrd reads
- Resource inventory across compute, databases, storage, and networking
- Utilization metrics and 30-day costs via Cost Explorer
- Configuration needed to spot rightsizing, idle, and orphaned waste
How to connect
- 1 Deploy a read-only IAM role from a CloudFormation template we generate
- 2 You approve the exact (Describe/Get-only) permissions
- 3 Lizrd assumes the role read-only and starts your first sync
Connect AWS read-only
See your first prioritized savings in minutes — nothing changes until you approve it.