cost agent audited only the main AWS account - 40% of spend was hiding in a sandbox OU it never assumed a role into
Fixes a cost audit that only sees the main account while large spend hides in other accounts or OUs. Use when spend reports do not reconcile with the consolidated bill, or sandbox and new accounts keep escaping the audit. It enumerates every organization account, verifies role assumption per account, deploys the audit role via StackSet, and makes the audit fail loudly on unreachable accounts.
TL;DR: Enumerate every account in the organization and verify the agent can assume a role into each one - then make the audit fail loudly when an account is unreachable instead of silently skipping it. Agents start with one account's credentials, and enumerating the rest feels optional until 40 percent of spend turns out to live where the agent never looked. A failed role assumption looks exactly like an account with zero spend, which is why the silence is the real bug.
cost agent audited only the main AWS account - 40% of spend was hiding in a sandbox OU it never assumed a role into- List every account in the organization and compare against the accounts the agent actually audited. Expected: you find the unaudited accounts - sandbox OUs, new accounts, acquisitions - and the missing spend.
- For each account, verify the agent's role assumption works. Attempt the assume-role call per account and log success or failure explicitly. Expected: a per-account reachability list, not a silent skip.
- Deploy (or verify) a cross-account audit role in every account with billing read permissions, ideally via a StackSet so new accounts get it automatically. Expected: new accounts are auditable from day one without manual role setup.
- Change the agent's audit contract: the run is not complete unless every organization account returned data or a logged, alerted failure. Expected: a future unreachable account pages someone instead of producing a clean-looking partial report.
Use this when
- A cost audit covered fewer accounts than the organization actually has
- Spend reports do not reconcile with the consolidated bill total
- New or sandbox accounts keep escaping the audit
Not for this skill when
- You genuinely have one account - there is nothing to enumerate
- The missing accounts are deliberately excluded (for example a separate legal entity) - document the exclusion instead
- The agent audited all accounts but the numbers still do not add up - that is a double-counting or data-lag issue
Variant phrasings
- cost audit missed accounts in other ou
- agent only audited main aws account missed sandbox spend
- how to audit all accounts in aws organization for cost
- cross account cost audit role assumption failed silently
Why it happens
Agents start with the credentials they are given, which usually belong to one account. Enumerating the organization and assuming roles into every account is extra code that feels optional - until 40 percent of spend turns out to live where the agent never looked. Silent failure makes it worse: a failed role assumption looks exactly like an account with zero spend.
Edge cases
- AWS Organizations list calls are paginated. Enumerate with the paginator or you will miss accounts past the first page.
- Some accounts may live outside the organization (separate payers). Those need their own credentials and an explicit list, not discovery.
- Sandbox OUs often have the messiest spend and the weakest tagging. Expect the newly discovered accounts to need cleanup before their numbers are trustworthy.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_aoKyGQMHPPeJnsqqhj6hyQ
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.