back to blog
// post

Catch AWS spend drift before the invoice

Victor Grenu·2026-08-23·2 min read

The invoice is a lagging indicator. By the time finance forwards the PDF, the runaway EMR cluster has been up for 19 days. AWS Budgets can fire at a threshold you guessed in January. Cost Anomaly Detection can fire on a shape you do not recognize. Both still live in a console most engineers ignore.

Drift in unusd.cloud is simpler: we watch the spend we already pull for scans, learn what "normal" looks like on your accounts, and flag a rise that does not match that history. A noisy sandbox is not treated like a flat prod billing account. A drop is noted. A spike is the alert.

Forecast is the other half

Cost Explorer's forecast is a single number, late in the month, and it does not give you an end-of-year view. We put a low / mid / high end-of-month estimate on the scan, plus an end-of-year range that follows your actual month-to-month trend, not "MTD times twelve."

That is what a CFO asks in week two: "are we still on the number we booked." A platform manager asks: "which account broke the pattern." Same data, two altitudes. The management report rolls the forecast up. The per-account scan keeps the detail.

What this is not

It is not GuardDuty. A crypto miner can look like drift. You still need security tooling. It is not a promise that every alert is waste. A planned launch will look like a spike. Whitelist and context exist so you are not paged for Black Friday.

Startup plans and above include drift. Forecasting shows up on the scan and on the exec digest. Neither one deletes resources. They tell you to look now, not on the 6th of next month.

Pair this with idle detection. Drift says the number moved. The waste rules say which NAT and which volume. Cost Explorer will not do that pairing.

// try unusd

Stop paying for resources nobody is using.

Connect a read-only role. Digest by email, full web report and Navi in the app - minutes to first scan.

Start free scan