Cost Attribution
This page explains how the platform decides which allocation each cloud charge belongs to under the flexible allocation system, and what you can configure to control it.
How a cloud charge finds its allocation
Each line of your cloud provider's billing export is matched against the following, in order. The first match wins.
- Capacity reservation mapping. If the charge belongs to a capacity reservation or capacity block that is mapped on the Reservations page, it bills the reservation's allocation. This overrides everything below: the budget that committed to the reservation pays for what runs on it.
- Resource group tag. Resources the platform creates are tagged with
pw-resource-group-id. The charge bills the allocation that funded that resource group at the time of the charge, using the resource group's allocation history. Resource group admins can change a group's allocation at any time; charges from before the change, including invoices imported later, stay on the previous allocation, and charges after it go to the new one. - Deployment. Charges with no resource group tag but with a platform deployment tag (
pw-deployment-idorsession-id) are matched to the resource group recorded for that deployment. - Project tag (legacy, deprecated). A
projecttag whose value matches the name of one of your managed (USD) allocations, ignoring case, bills that allocation. If two allocations have names that differ only in case, neither matches. - Cloud account default allocation. Anything left over bills the cloud account's default allocation.
- Unattributed. If no default allocation is set, the charge is stored and appears on the cost dashboard, but doesn't count toward any allocation.
Project tag attribution is deprecated
Matching the project tag to an allocation name is a legacy fallback. It is deprecated and will not be supported in a future release. Don't build new billing on it: put resources in resource groups so their costs bill the resource group's allocation, and use the cloud account default allocation for charges that no resource group owns.
Shared cloud accounts work the same way: a charge tagged with a resource group from another organization bills that organization's allocation.
Cloud account default allocation
Some charges never belong to a resource: support plans, taxes, untagged resources, data transfer, or reservation fees you haven't mapped. The default allocation catches them.
- From the Organizations list, select your organization. In the sidebar, under Cloud, click Accounts.
- Open a cloud account and click View billing.
- Click Default Allocation, select an allocation, and save.
To clear it, select no allocation. The allocation must belong to your organization. If another organization provisioned billing for the account, only that organization can set its default.
The Billing Details panel on the same page shows the account's Default Allocation, Allocation Start Date, and Default Billing Username.
Reprocessing
The default allocation and project tags are applied when billing data is processed. If you change the default and then reprocess an earlier period (with Edit Last Update), that period's leftover charges are re-attributed to the new default.
AWS cost allocation tags
AWS only includes a tag in its cost report after the tag is activated as a cost allocation tag, and only for usage from then on. In the AWS Billing console, under Cost allocation tags, activate these user-defined tags:
| Tag | Used for |
|---|---|
PWResourceGroupID | Resource group attribution (step 2) |
PWDeploymentID, SessionID | Deployment attribution (step 3) and real-time estimates |
Project | Project tag attribution (step 4; legacy and deprecated) |
User, GroupID | Usernames and legacy group attribution |
PWResourceName, PWResourceType | Resource names and types in reports |
Azure, Google, and Oracle pass resource tags or labels through their billing exports without extra setup. See Provisioning Billing.
What counts as a charge
- Savings Plans: usage covered by an AWS Savings Plan bills the tagged allocation at its on-demand cost. The Savings Plan's own fees and negations are not billed to allocations.
- Credits, refunds, and discounts (such as EDP discounts) are not deducted from allocations.
- Zero-cost lines are ignored.
Usernames on cost records
Cost records get their user from the resource's user or owner tag, or from the platform user who created the deployment. Records with neither, such as shared account charges, show your organization's default billing username on dashboards and reports. Because it's applied when reports are read, changing the policy relabels past records too.
Timing
- Invoiced costs are imported about every two hours, as soon as your cloud provider publishes them. Providers typically publish usage a few hours to a day after it happens.
- Real-time estimates for running resources are refreshed about every three minutes and count toward an allocation's Estimated amount until the invoice arrives. Resources without a platform deployment tag are never estimated, so untagged and shared charges only appear once invoiced.
- Thresholds are checked on every real-time pass. Thresholds with Use realtime data compare against Estimated; others compare against Used.
Capacity reservations
Reservation and capacity block fees carry no resource tags, so mapping them on the Reservations page is the only way to bill them to a specific allocation. Mappings are supported for AWS, Azure, and Google.