# Welcome to Pump!

The fastest way to cut your cloud bill - without touching your infrastructure.

Pump is a cloud cost optimization platform that combines AI-driven commitment management, infrastructure recommendations, real-time cost visibility, and security across AWS, GCP, and Azure.&#x20;

### How Pump Works - In 30 Seconds

Pump sits between you and your cloud provider as an optimization and billing layer. Here's the short version:

1. **Connect Your Cloud:** Link your AWS, GCP, or Azure accounts. Pump starts analyzing immediately, no agents to install, no infrastructure changes, no engineering lift required.
2. **Savings, Visibility, Intelligence:** View all your cloud spend in one place. Pump automatically flags cost anomalies and security gaps while covering baseline savings through AI-driven commitment purchasing and group buying power.
3. **Optimization & Confidence:** Track savings over time, keep forecasts and compliance accurate, and stay audit-ready with continuous security posture monitoring. Pump optimizes in the background so your team can focus on building.

### Still have questions?

Reach out to our team at <support@pump.co> - we typically respond within a few hours!


# Introduction

Pump is a cloud cost optimization platform that helps companies reduce their AWS, GCP, and Azure spend! We combine AI-driven commitment management, infrastructure recommendations, real-time cost visibility, and cloud security scanning into a single tool that takes less than 10 minutes to set up.

Pump is free to use. How are we free, you may ask? We earn revenue through our cloud providers, not from your savings. Unlike our competitors, we don't take a cut of what you save, so every dollar we help you reclaim goes straight back to your bottom line.

Whether you're a startup spending $5K a month on cloud or an enterprise managing $500K+ across multiple providers, Pump gives your engineering and finance teams the visibility, automation, and savings they need to keep cloud costs under control.

**Who Pump is for**

Pump is built for engineering teams, DevOps leads, and finance teams managing cloud infrastructure. It works best for organizations spending $5,000 or more per month across any combination of AWS, GCP, and Azure.

**What Pump does**

Pump has three products. Each works independently, and they complement each other when used together.

| Product         | What it does                                                                                                                                                                                   |
| --------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Pump Save**   | Automates cloud cost optimization through commitment management and infrastructure recommendations. Handles RI/SP/CUD purchasing, tracks utilization, and surfaces right-sizing opportunities. |
| **Pump View**   | Real-time spend observability. Dashboards, cost breakdowns by service, account, region, and tag. Budgets, alerts, end-of-month forecasts, and reports.                                         |
| **Pump Secure** | Vulnerability scanning, compliance monitoring, and automated pentesting. Surfaces actionable security findings with severity ratings.                                                          |

**Supported cloud providers**

| Cloud | Save         | View         | Secure       |
| ----- | ------------ | ------------ | ------------ |
| AWS   | Full support | Full support | Full support |
| GCP   | Full support | Full support | Coming soon  |
| Azure | Full support | Full support | Coming soon  |

**How Pump accesses your data**

Pump requests read-only access to your billing and usage data. The specific mechanism varies by provider:

| Provider | Access method                                        | What Pump reads                                                                                                            |
| -------- | ---------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------- |
| AWS      | Cross-account IAM role (deployed via CloudFormation) | Cost Explorer, Cost and Usage Reports, resource inventory (EC2, RDS, ElastiCache, Redshift, OpenSearch), Compute Optimizer |
| GCP      | OAuth consent + per-project service account          | BigQuery billing export, project metadata, Cloud Billing account data                                                      |
| Azure    | Service principal (app registration + client secret) | Cost Management reports, Consumption usage details, resource groups, billing profiles                                      |

The only write permissions Pump uses are for purchasing commitments (RIs, Savings Plans, CUDs) on your behalf, and only when you explicitly enable that capability.


# The Three Products

Pump is built around three core products, each designed to address a different dimension of cloud cost management.

#### Pump Save

Pump Save is the cost optimization engine. It's the product that actually reduces your cloud bill through automated commitment purchasing and infrastructure recommendations.

If you're here because you want to spend less on cloud, Pump Save is where the savings come from.

**Key capabilities:**

* **Commitment Manager:** Automated purchasing and lifecycle management of Reserved Instances, Savings Plans, and Committed Use Discounts across AWS, GCP, and Azure
* **Infrastructure Recommendations:** AI-generated suggestions for rightsizing, modernization, and idle resource elimination

***

#### Pump View

Pump View is the cost visibility and analytics layer. It gives engineering and finance teams a shared, real-time view of cloud spend across all providers — with the filtering, reporting, and alerting tools needed to understand where money is going and why.

**Key capabilities:**

* **Playground:** An interactive cost explorer with flexible filtering, grouping, and drill-down across services, accounts, regions, teams, and resources
* **Reports:** Preset and custom reports that can be scheduled and shared with stakeholders
* **Annotations:** Tag your cost timeline with deploys, incidents, team changes, and other events to explain spending patterns in context
* **Anomaly Detection & Budget Alerts:** Automated detection of unusual spending spikes with configurable alert channels (email, Slack, and more)
* **Integrations:** Native connections to AWS, GCP, Azure, GitHub, OpenAI, Cursor, Datadog, ClickHouse, and many more

***

#### Pump Secure

Pump Secure is a free cloud security scanning tool that assesses your infrastructure against industry-standard frameworks, including the AWS Well-Architected Framework, SOC 2, and HIPAA, and surfaces critical vulnerabilities in minutes.

**Key capabilities:**

* **Automated Security Scanning:** Run hundreds of security checks against your cloud infrastructure in under 10 minutes
* **Framework Coverage:** Assessments mapped to AWS Well-Architected Framework, SOC 2, and HIPAA compliance requirements
* **Pass/Fail Reporting:** Clear, actionable results showing which checks passed and which need attention
* **Remediation Guidance:** Prioritized recommendations for addressing critical issues, with step-by-step guidance

*Current availability: Pump Secure is fully available for AWS. GCP and Azure support is coming soon.*


# Supported Cloud Providers

Pump works across the three major public cloud platforms: Amazon Web Services (AWS), Google Cloud Platform (GCP), and Microsoft Azure. This page provides a clear breakdown of which Pump features are available on each provider, so you know exactly what to expect when you connect your accounts.

| Feature                            | AWS                   | GCP                                 | Azure                          |
| ---------------------------------- | --------------------- | ----------------------------------- | ------------------------------ |
| **Pump Save**                      | ✅ Full support        | ✅ Full support                      | ✅ Full support                 |
| **Commitment Manager**             | ✅ RIs + Savings Plans | ✅ Resource-Based + Spend-Based CUDs | ✅ Reservations + Savings Plans |
| **Infrastructure Recommendations** | ✅ Available           | 🔜 Coming soon                      | 🔜 Coming soon                 |
| **Pump View**                      | ✅ Full support        | ✅ Full support                      | ✅ Full support                 |
| **Playground & Filters**           | ✅ Available           | ✅ Available                         | 🔜 Coming soon                 |
| **Reports**                        | ✅ Available           | ✅ Available                         | 🔜 Coming soon                 |
| **Annotations**                    | ✅ Available           | ✅ Available                         | 🔜 Coming soon                 |
| **Anomaly Detection & Alerts**     | ✅ Available           | ✅ Available                         | 🔜 Coming soon                 |
| **Pump Secure**                    | ✅ Full support        | 🔜 Coming soon                      | 🔜 Coming soon                 |

#### What Pump Manages on AWS

**Commitment types:**

* **Reserved Instances (RIs):** Capacity reservations for specific instance types in specific regions.
* **Savings Plans:** Flexible commitment-based discounts that apply across instance families, regions, and even compute services. Available as Compute Savings Plans, Database Savings Plans, and EC2 Instance Savings Plans.

**Infrastructure Recommendations:**

* **Rightsizing:** Identifies EC2 instances that are over-provisioned relative to actual CPU, memory, and network utilization, and recommends smaller instance types.
* **Modernization:** Flags instances running on older-generation families (e.g., m4, c4) and recommends upgrading to newer, more cost-efficient families (e.g., m7i, c7g).
* **Idle Instance Detection:** Surfaces instances with consistently near-zero utilization so you can terminate or scale down resources you're paying for but not using.

**Security Scanning (Pump Secure):**

* Full assessment against the AWS Well-Architected Framework
* SOC 2 and HIPAA compliance mapping
* Hundreds of automated security checks completed in under 10 minutes

#### What Pump Manages on GCP

**Commitment types:**

* **Resource-Based Committed Use Discounts (CUDs):** Discounts tied to specific machine types and regions. Ideal for predictable workloads with consistent resource requirements.&#x20;
* **Spend-Based Committed Use Discounts (CUDs):** Flexible discounts based on a minimum hourly spend commitment, applicable across eligible GCP services.

**Cost Visibility (Pump View):**

* Full support for the Playground, Reports, Annotations, and Anomaly Detection
* BigQuery billing data integration for detailed cost breakdowns

**Coming soon on GCP:**

* Infrastructure Recommendations (rightsizing, modernization, idle resource detection)
* Pump Secure (security scanning and compliance assessment)<br>

#### What Pump Manages on Azure

**Commitment types:**

* **Azure Reservations:** Capacity reservations for specific resource types (VMs, SQL Database, Cosmos DB, and more) in specific regions.
* **Azure Savings Plans:** Flexible compute discounts that apply across VM families, regions, and Azure compute services. Available as Compute Savings Plans with up to 65% savings.

**Cost Visibility (Pump View):**

* Full support for the Playground, Reports, Annotations, and Anomaly Detection
* Native Azure billing data integration

**Coming soon on Azure:**

* Infrastructure Recommendations (rightsizing, modernization, idle resource detection)
* Pump Secure (security scanning and compliance assessment)


# How Pump Works

## How Pump Works

Pump reduces your cloud costs through multiple levers, each targeting a different layer of your spend. This page explains the billing model, how savings are generated, and what each optimization mechanism does.

**The billing model**

Pump is a licensed solutions provider for AWS, GCP, and Azure. When you join Pump, your cloud billing routes through Pump. You receive invoices from Pump instead of your cloud provider directly. Your infrastructure, workloads, and configurations are untouched.

| Provider | How it works                                                                                                               |
| -------- | -------------------------------------------------------------------------------------------------------------------------- |
| AWS      | Your account joins a Pump-managed billing organization. You receive invoices from Pump instead of AWS.                     |
| GCP      | Your Cloud Billing account is managed under Pump's billing relationship. You receive invoices from Pump instead of Google. |
| Azure    | Your subscriptions are billed through Pump's billing relationship. You receive invoices from Pump instead of Microsoft.    |

### How Pump reduces your costs

Pump optimizes your cloud spend through multiple levers. Each targets a different layer of cost, and they work together to maximize your savings.

**Commitment Management (AWS, GCP, Azure)**

Cloud providers offer significant discounts when you commit to a certain level of usage over one or three years, in the form of Reserved Instances (AWS), Savings Plans (AWS), and Committed Use Discounts (GCP/Azure). The challenge is that purchasing these commitments correctly requires continuous analysis of usage patterns, expiration timelines, and coverage gaps. Pump handles this for you.

For AWS, Pump provides a full commitment lifecycle: usage analysis, purchase execution, utilization and coverage tracking, forward planning, and renewal management. Your account team works with you to determine how purchases are reviewed and executed.

For GCP and Azure, Pump generates commitment recommendations based on your usage patterns. You review each recommendation and decide whether to proceed.

All commitments are purchased in your own cloud account. Pump does not pool commitments across customers. Each commitment belongs to you and remains in your account, even if you leave Pump.

**Infrastructure Recommendations (AWS)**

Pump analyzes your running AWS resources and identifies idle or oversized infrastructure. Each recommendation includes the specific resource, the suggested change (resize, terminate, or modify), estimated monthly savings, and an implementation command you can run. You review and apply changes yourself.

**Enterprise Agreement Support (AWS, GCP, Azure)**

For organizations with significant cloud spend, Pump supports EDP (AWS), cross-service PPA (GCP), and Enterprise Agreement (Azure) negotiations. Pump's team brings deep experience across these processes to help you secure better terms with your cloud provider.

**Coming soon**

Two additional optimization mechanisms are in development:

* **Kubernetes Auto-Scaling:** Optimizes pod-level CPU and memory sizing using histogram-based analysis. Recalibrates horizontal scaling parameters.
* **Spot Autoscaling:** Automated spot instance management for fault-tolerant workloads, handling bidding strategy, interruption handling, and fallback to on-demand capacity.

### How savings are measured

Pump calculates savings by comparing your actual billed cost to a reconstructed on-demand baseline:

```
original_cost = actual_cost + pump_attributed_savings + pre_existing_savings
```

Where:

* **actual\_cost** is what you pay on your invoice
* **pump\_attributed\_savings** are savings from commitments Pump purchased (Savings Plans + Reserved Instances + optimized rates)
* **pre\_existing\_savings** are savings from commitments you had before joining Pump

The savings figure shown in your dashboard reflects gross cloud provider savings. Pump's fee is billed separately and is not deducted from the displayed savings number.

Currently, the headline savings number reflects commitment management savings. Right-sizing and infrastructure recommendations are tracked separately in the Recommendations section.

### What Pump needs from you

To get started, Pump requires two things:

1. **Read-only access** to your billing and usage data (or a CSV upload for an initial estimate). Pump never accesses your infrastructure, application code, or customer data.
2. **Billing partner authorization** to purchase commitments on your behalf and issue your cloud invoices.


# Quick Start

This guide walks you through signing up for Pump, connecting your first cloud account, and seeing your savings estimate. Most configurations take under five minutes.

### Prerequisites

Before you start, make sure you have:

| Provider | What you need                                                                                                         |
| -------- | --------------------------------------------------------------------------------------------------------------------- |
| AWS      | An AWS IAM user or root credentials for the account you want to connect. Permission to launch a CloudFormation stack. |
| GCP      | A Google account with access to your GCP billing console. Access to Google Cloud Shell.                               |
| Azure    | An Azure account with permission to create app registrations and assign RBAC roles. Access to Azure Cloud Shell.      |

You do not need to make any infrastructure changes, install any agents, or modify your workloads.

**Step 1: Sign up**

1. Go to [app.pump.co](https://app.pump.co/) and create an account.
2. Verify your email address by clicking the link sent to your inbox.
3. Enter your name, job title, company name, company size, and country.

After completing these steps, you land in the Pump dashboard with sample data. The onboarding wizard opens automatically to guide you through connecting your cloud account.

**Step 2: Run a savings estimate**

The savings estimate is free and requires only read-only access (or a CSV upload). It shows projected savings before you commit to anything.

Click **Estimate savings** in the onboarding wizard, then select your cloud provider.

#### AWS

You have two options:

**Option A: Grant read-only access (recommended)**

1. The wizard generates a CloudFormation Quick-Create Stack URL pre-filled with Pump's read-only IAM role template.
2. Click the link. It opens your AWS Console.
3. Review the stack parameters and click **Create stack**.
4. The stack deploys a cross-account IAM role with read-only permissions (Cost Explorer, CUR, resource inventory). Pump is automatically notified when the stack completes.
5. Pump generates your savings estimate. This typically takes a few minutes.

**Option B: Upload CSVs**

1. In your AWS Console, go to **Cost Explorer** and download two CSV exports: "Costs by Service" and "Costs by Usage Type."
2. Upload both files in the wizard.
3. Pump generates your estimate from the uploaded data.

#### GCP

1. The wizard prompts you to upload a GCP billing history CSV.
2. Export your billing data from the GCP Console and upload it.
3. Pump generates your savings estimate.

#### Azure

You have two options:

**Option A: Automatic (service principal)**

1. Open Azure Cloud Shell and run the command shown in the wizard to create a service principal:

bash

```bash
az ad sp create-for-rbac --name pump
```

1. Paste the resulting JSON (appId, password, tenant) into the wizard.
2. Enter your subscription IDs. The wizard provides a command to list them:

bash

```bash
az account list --query"[?state=='Enabled'].id" -o tsv|paste -sd, -
```

1. Run the Pump-provided script in Cloud Shell to assign the "Billing Reader" role per subscription.
2. Pump verifies access and generates your estimate.

**Option B: Upload CSV**

1. In the Azure Portal, go to **Cost Management + Billing** and download your usage file for the last 3 months.
2. Upload the file in the wizard.
3. Pump generates your estimate from the uploaded data.

### Step 3: Review your estimate and join Pump

Once your savings estimate is ready, the wizard shows your projected savings. If you want to proceed:

1. **Billing partner agreement.** Confirm that you agree to have Pump become your billing partner. This means Pump will handle your cloud billing (you receive invoices from Pump instead of directly from your cloud provider).
2. **Terms of Service and Privacy Policy.** Review and accept.
3. **Grant billing permissions.** This step varies by provider:
   * **AWS:** Launch a second CloudFormation stack that deploys an Auto-Pilot IAM role with commitment-purchasing permissions (Reserved Instances, Savings Plans).
   * **GCP:** Complete a Google OAuth consent flow to authorize Pump's billing access.
   * **Azure:** Run the Pump-provided Autopilot script in Cloud Shell to assign commitment-purchasing roles (Reservations Contributor, Savings Plan Contributor/Purchaser).
4. **Company details.** Enter your company profile, including business identification (EIN, GSTIN, or equivalent for your country).
5. **Payment method.** Add a payment method for Pump invoices.

Your application is submitted. Once approved, Pump begins optimizing your cloud spend.

#### AWS: Standalone vs Organization

If you are connecting an AWS account, the wizard asks whether your account is part of an AWS Organization.

* **Standalone account (not in an AWS Organization):** Continue through the self-serve flow described above.
* **Part of an AWS Organization:** The wizard routes you to schedule a meeting with a Pump solutions architect, since organization-linked accounts require assisted setup.

### Step 4: Configure commitment management

After your application is approved, your Pump account team works with you to determine how commitments are managed for your account. This includes how recommendations are reviewed, how purchases are executed, and how renewals are handled.

### What happens next

Once connected, Pump begins pulling your historical cost data and optimizing your cloud spend. The depth of historical data varies by provider (see the connection guides for details).

From here, you can:

| Action                                                                  | Where                                    |
| ----------------------------------------------------------------------- | ---------------------------------------- |
| Invite your team                                                        | Navigate to **Settings → Team → Invite** |
| Explore your spend data                                                 | Open **Pump View** dashboards            |
| Review security findings                                                | Open **Pump Secure**                     |
| Connect additional cloud accounts                                       | Navigate to **Settings → Integrations**  |
| Connect third-party services (Anthropic, OpenAI, GitHub, Datadog, etc.) | Navigate to **Settings → Integrations**  |


# Account Setup

This page covers everything after your initial signup: inviting your team, understanding roles and permissions, and completing your business identification.

**Creating your account**

When you sign up at [app.pump.co](https://app.pump.co/), Pump creates your account using your email address. If someone from your company has already created a Pump account, you may be invited to join their existing company workspace instead of creating a new one.

How it works:

* If you sign up with no existing invitation, Pump checks your email domain. If no company exists for that domain, a new company workspace is created and you become the Admin.
* If a company already exists for your email domain, you are not automatically added. An existing Admin must invite you.
* If you were invited via email before signing up, you are automatically added to that company when you create your account.

**Inviting team members**

Admins can invite teammates from **Settings → Team → Invite**.

1. Enter the teammate's email address.
2. Select a role (see Roles and Permissions below).
3. Click **Invite**. The teammate receives an email with a signup link.

When the invited user signs up, they are automatically added to your company workspace. All invited users start with Member-level access. To grant Admin access, an existing Admin must promote them after they join (see below).

### Roles and permissions

Pump has three role types visible in the team management UI.

| Role                | What they can do                                                                                                                                                                                                 |
| ------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Admin**           | Full access to all Pump features. Can invite and remove team members. Can promote or demote other users to/from Admin. Can manage integrations, billing, and company settings.                                   |
| **Member / Viewer** | Full read access to all Pump features, including dashboards, recommendations, and security findings. Cannot manage team members or modify admin-level settings.                                                  |
| **Finance**         | Receives invoice emails and has visibility into billing data. This is not a separate access role. Any team member can be designated as a Finance contact by adding their email to the invoice distribution list. |

**Changing roles**

* **Promoting to Admin:** An existing Admin navigates to **Settings → Team**, finds the team member, and toggles their Admin status.
* **Designating a Finance contact:** Navigate to **Settings → Billing** and add the team member's email to the invoice email list.
* **Removing a team member:** An Admin navigates to **Settings → Team** and removes the member.

**How roles are assigned**

* The first user to create a company workspace automatically becomes Admin.
* All invited users join as Members.
* Role changes happen after the user has joined, not at invite time.

### Multi-company access

Pump supports belonging to multiple company workspaces with a single login. If you are a member of more than one company (for example, a consultant managing multiple clients), you can switch between them from the account menu. Each company workspace is fully independent with its own cloud connections, billing, and team members.

### Business identification

After completing onboarding, Pump prompts you to provide your business identification. This appears as a notification in the sidebar.

| Country         | Required fields                                          |
| --------------- | -------------------------------------------------------- |
| United States   | EIN (Employer Identification Number)                     |
| India           | CIN (Corporate Identification Number) and GSTIN          |
| Other countries | Business ID number and tax code (varies by jurisdiction) |

To complete this, navigate to **Settings → Company** and fill in the business identification fields.

**Onboarding requirements**

Joining Pump as a billing partner requires two things:

1. **All outstanding cloud bills must be paid.** Pump cannot onboard accounts with unpaid balances.
2. **Minimum $5,000/month cloud spend.** Pump Save is designed for organizations at this spend level and above. Pump View is available regardless of spend level.


# Joining via CTA

Some customers have organizational or security constraints that require a different onboarding path. In these cases, we can onboard via a **Consent to Assign (CTA)** agreement. A CTA allows the ownership and billing of the AWS management account to be assigned to Pump so we can fully manage billing and savings on your behalf.

#### Step 1: Discovery

Pump will first review your setup on a discovery call to confirm whether CTA is the right fit. This option is available at Pump’s discretion and not offered to all customers.

During this step, you’ll deploy a read-only stack and run a savings estimate to evaluate the potential value of joining Pump.

#### Step 2: CTA

Once you’re ready to move forward, Pump will share the CTA agreement.

As part of this process:

* You’ll update the root user email address of the AWS management account to a Pump-provided address.
* Pump will update the billing details of the management account.

#### Step 3: Onboarding

You’ll deploy the autopilot stack to allow Pump access to billing and savings optimization.

That’s it! Pump takes it from there 🚀

After the CTA is completed, your AWS account will show a **distributor discount** in the AWS console. This is a standard AWS construct that’s only available when working with an AWS Partner like Pump.

Importantly:

* This distributor discount is **not a separate discount provided to customers**.
* The discount primarily goes to our distributor, Ingram Micro , with a portion flowing back to Pump.
* Your pricing, savings, and billing with Pump remain exactly as agreed. There is no impact to your usage, invoices, or transparency. To see the accurate balance, exclude the distributor discount.

**Root access exception:**&#x20;

* For larger AWS customers, Pump can in select cases arrange a root exception — letting you keep your existing root user email, password, and MFA instead of transferring them during onboarding, if that better fits your org structure. This is evaluated case by case, so check with your Pump account team to see if applicable.


# Billing and Payments

To avoid breaking the bank, **Pump is 100% free.** Instead, we (as a cloud reseller) make our tiny margin from AWS, GCP, and Azure! Pump is a **net positive** by helping you save money on your cloud costs for free.

As soon as you join Pump, your cloud usage (AWS/GCP/Azure) starts being billed to us. Our finance team sends you an invoice based on your cloud usage data on **the third day of every month.** Two days later, if you're on autopay, we'll charge your preferred payment method.

To Surface Invoices:

1. Go to your organization's [**invoice dashboard**](https://app.pump.co/invoices).
2. View the outstanding invoices, and to select a specific invoice, select "**View\_pdf**."

<figure><img src="/files/y1DNksTSos2t1qC1h7mk" alt=""><figcaption></figcaption></figure>

**Adding a Payment Method**

1. Go to your organization's [**billing preferences**](https://app.pump.co/settings/billing).
2. Click "Add payment method"

<figure><img src="/files/7axDjcLJyWMCdLxDBQCe" alt=""><figcaption></figcaption></figure>

**Payment Methods**

Invoices to Pump can be paid with a bank account via [GoCardless](https://gocardless.com/), wire transfer via ACH, SWIFT, or  Credit Card. We support direct debit for the US, UK, the Euro zone, Australia, Canada and 30 other countries. TLDR: We support payment methods for customers across the globe!&#x20;

We do offer customers the option to pay via credit card. For credit card, we add a 2.9% fee since we are a free product and are charged a 2.9% fee for credit card.

Please include your **Company ID** (it can be found [**here**](https://app.pump.co/settings/company)) and **Month(s)** you are paying for in the memo line. Once paid, feel free to confirm with our accounts recievable team (<finance@pump.co>) or find the updated invoice state [**here**](https://app.pump.co/invoices).

Find payment instructions here: <https://help.pump.co/getting-started/billing-info/supported-payment-methods>

<table data-view="cards"><thead><tr><th></th><th></th><th></th><th data-hidden data-card-cover data-type="files"></th></tr></thead><tbody><tr><td><p></p><p><strong>Have further questions?</strong></p></td><td>Feel free to reach out <strong>bills@pump.co</strong></td><td></td><td><a href="/files/13UqdAyuznCQKhe86pFF">/files/13UqdAyuznCQKhe86pFF</a></td></tr><tr><td></td><td><strong>Reconcile AWS Invoices?</strong></td><td>Learn more how to <a href="/pages/jZ7ASh73Lh3I1CEshIyY"><strong>compare invoices</strong></a>.</td><td><a href="/files/F2TYkLdjLQtLoxMSm5G1">/files/F2TYkLdjLQtLoxMSm5G1</a></td></tr><tr><td></td><td><strong>Reconcile GCP Invoices?</strong></td><td>Learn more how to compare invoices.</td><td><a href="/files/3gZdehWtWqYBunwiawp5">/files/3gZdehWtWqYBunwiawp5</a></td></tr></tbody></table>


# Billing Process

## **How Billing Works** <a href="#undefined" id="undefined"></a>

Pump acts as a licensed solutions provider for AWS, GCP, and Azure. Instead of paying your cloud provider directly, you pay Pump. Your cloud usage, credits, and commitments all flow through a single billing relationship per provider.

### **The solutions provider model**&#x20;

When you connect a cloud account to Pump, your account moves under Pump's solutions provider umbrella:

| Provider | How billing works                                                                                                                 |
| -------- | --------------------------------------------------------------------------------------------------------------------------------- |
| AWS      | Your account joins a Pump-managed AWS Organization. Pump becomes the payer account.                                               |
| GCP      | Your billing account becomes a sub-account under Pump's solutions provider billing.                                               |
| Azure    | Pump operates through Ingram Micro as a Microsoft CSP indirect solutions provider. Your subscription billing routes through Pump. |

You receive a separate invoice for each cloud provider. If you use AWS and GCP through Pump, you will receive two invoices.

### Invoice timing

Invoices are published on the 5th **of each month** for the prior month's usage. Two days later, if you are on autopay, Pump charges your preferred payment method. Payment terms are **net 7**.

### What your invoice includes

Each invoice shows your cloud usage for the billing period, including any savings Pump generated on your behalf. The invoice reflects your actual cloud costs after Pump-attributed savings (commitment management, optimized rates) have been applied.

### Viewing invoices

Navigate to **Settings > Billing** or go directly to [app.pump.co/invoices](https://app.pump.co/invoices). Select any invoice and click **View PDF** to download it.

### Cloud credits

If you have existing AWS, GCP, or Azure credits, Pump can typically work with you to ensure those credits are honored. Pump generally onboards customers whose credits are near exhaustion or already used. If you have a significant credit balance remaining, reach out to the Pump team to discuss timing before connecting your account.

***

## &#x20;<a href="#undefined" id="undefined"></a>


# First Month Billing

Your first month on Pump involves two invoices. This is a one-time occurrence during the transition from paying your cloud provider directly to paying through Pump.

### What to expect

| Invoice                         | From              | When                       | What it covers                                                             |
| ------------------------------- | ----------------- | -------------------------- | -------------------------------------------------------------------------- |
| Prorated cloud provider invoice | AWS / GCP / Azure | End of your first month    | Usage from the start of the billing cycle through the date you joined Pump |
| Prorated Pump invoice           | Pump              | 3rd of the following month | Usage from the date you joined Pump through the end of the billing cycle   |

After these first two invoices, all invoices for cloud usage will come from Pump only.

***

**Setting up autopay**

Navigate to [app.pump.co/settings/billing](https://app.pump.co/settings/billing) to set up automatic payments. This ensures your Pump invoices are paid on time without manual action.

***

**Historical Data**

Your historical cloud spend data from before joining Pump is available as a CSV download at [app.pump.co/settings/integrations](https://app.pump.co/settings/integrations). Spend data since joining Pump is visible on your Pump dashboard at [app.pump.co/dashboard](https://app.pump.co/dashboard).

It takes approximately 48 hours for historical data to populate after joining. If you do not see data after 48 hours, contact <support@pump.co>.<br>

***

**Payment Methods**

Pump accepts multiple payment methods to accommodate customers globally. To add or update your payment method, navigate to Settings > Billing or go to [app.pump.co/settings/billing](https://app.pump.co/settings/billing).


# Supported Payment Methods

Pump accepts multiple payment methods to accommodate customers globally. To add or update your payment method, navigate to Settings > Billing or go to app.pump.co/settings/billing. We support direct debit for the US and a few international countries at the moment.

We also offer customers the option to pay via credit card. For credit card, we add a 3% fee since we are a free product and are charged a 3% fee for credit card.

**Available Methods**

| Method                       | Provider   | Fee            | Notes                                                                      |
| ---------------------------- | ---------- | -------------- | -------------------------------------------------------------------------- |
| Bank transfer (direct debit) | GoCardless | None           | Supported in US, UK, Euro zone, Australia, Canada, and 30+ other countries |
| ACH (domestic wire)          | Direct     | None           | US bank accounts                                                           |
| SWIFT / International wire   | Direct     | None           | 35 supported currencies                                                    |
| Credit / Debit card          | Stripe     | 2.9% surcharge | USD only. The surcharge covers card processing fees.                       |

**SWIFT/International Wires**

{% tabs %}
{% tab title="USD only" %}
Follow the instructions below to send an international wire!

Step 1: Enter beneficiary bank information

<table data-header-hidden><thead><tr><th width="247.30859375"></th><th></th><th data-hidden></th></tr></thead><tbody><tr><td>SWIFT/BIC code</td><td>CLNOUS66BRX</td><td></td></tr><tr><td>Bank name</td><td>Column NA - Brex</td><td></td></tr><tr><td>Bank address</td><td>1 Letterman Drive, Building A, Suite A4-700, San Francisco, CA 94129</td><td></td></tr></tbody></table>

Step 2: Enter intermediary bank information

| SWIFT/BIC code | CHASUS33                               |
| -------------- | -------------------------------------- |
| Bank name      | JPMorgan Chase Bank N.A.               |
| Bank address   | 383 Madison Avenue, New York, NY 10179 |

Step 3: Enter beneficiary information

| Beneficiary name           | Pump Billing Inc                   |
| -------------------------- | ---------------------------------- |
| Beneficiary account number | 809107555228681                    |
| Beneficiary address        | 1 Otis St, San Francisco, CA 94103 |
| {% endtab %}               |                                    |

{% tab title="All supported currencies except USD" %}

<table data-header-hidden><thead><tr><th width="199.09375"></th><th></th><th data-hidden></th></tr></thead><tbody><tr><td>Account Name</td><td>Counter Inc</td><td></td></tr><tr><td>SWIFT Code</td><td>SXPYDKKK</td><td></td></tr><tr><td>Account Number IBAN</td><td>0040574598</td><td></td></tr><tr><td>Bank Name</td><td>Banking Circle S.A.</td><td></td></tr></tbody></table>

If you'd like to be invoiced in your local currency, please let us know during onboarding. Pump follows USD mid-market conversion rates with a 1% markup.

Please include your Company ID (found at [app.pump.co/settings/company](https://app.pump.co/settings/company)) and the month(s) you are paying for in the memo line. Once paid, confirm with [bills@pump.co](mailto:finance@pump.co) or check the updated invoice state at [app.pump.co/invoices](https://app.pump.co/invoices).
{% endtab %}
{% endtabs %}

<details>

<summary><strong>Local Currency Supported</strong></summary>

If you'd like to be invoiced in your local currency, please let us know during onboarding. We follow USD mid-market conversion rates for these 35 currencies with a 1% markup.

* Australian Dollar (AUD)
* Israeli Shekel (ILS)
* Romanian Leu (RON)
* Bahrain Dinar (BHD)
* Japanese Yen (JPY)
* Saudi Riyal (SAR)
* Bulgarian Lev (BGN)
* Kenyan Shilling (KES)
* Singapore Dollar (SGD)
* Canadian Dollar (CAD)
* Kuwait Dinar (KWD)
* South African Rand (ZAR)
* Chinese Yuan (CNY)
* Malaysian Ringgit (MYR)
* Swedish Krona (SEK)
* Czech Koruna (CZK)
* Mexican Peso (MXN)
* Swiss Franc (CHF)
* Danish Krone (DKK)
* New Zealand Dollar (NZD)
* Thai Baht (THB)
* Euro (EUR)
* Norwegian Krone (NOK)
* Turkish Lira (TRY)
* Hong Kong Dollar (HKD)
* Omani Rial (OMR)
* Ugandan Shilling (UGX)
* Hungarian Forint (HUF)
* Philippine Peso (PHP)
* UK Sterling (GBP)
* Indian Rupee (INR)
* Polish Zloty (PLN)
* United Arab Emirates Dirham (AED)
* Indonesian Rupiah (IDR)
* Qatar Rial (QAR)

</details>

**ACH/Domestic Wires**

<table data-header-hidden><thead><tr><th width="235.86328125">Name</th><th></th><th data-hidden></th></tr></thead><tbody><tr><td>ABA Routing Number</td><td>121145349</td><td></td></tr><tr><td>Account Number</td><td>494174434445569</td><td></td></tr><tr><td>Account Type</td><td>Business Checking</td><td></td></tr><tr><td>Recipient/Beneficiary name</td><td>Pump Billing Inc</td><td></td></tr><tr><td>Beneficiary Address</td><td>1 Otis St, San Francisco, CA 94103</td><td></td></tr><tr><td>Bank Name</td><td>Column NA - Brex</td><td></td></tr><tr><td>Bank Address</td><td>1 Letterman Drive Building A, Suite A4-700, San Francisco, CA 94129</td><td></td></tr></tbody></table>

<details>

<summary>Supported Currencies</summary>

By GoCardless - Bank Transfer

USD

CAD

AUD

GBP

DKK

EUR

NZD

By Stripe - Credit and Debit card

USD

By Wire

Australian Dollar (AUD)

Israeli Shekel (ILS)

Romanian Leu (RON)

Bahrain Dinar (BHD)

Japanese Yen (JPY)

Saudi Riyal (SAR)

Bulgarian Lev (BGN)

Kenyan Shilling (KES)

Singapore Dollar (SGD)

Canadian Dollar (CAD)

Kuwait Dinar (KWD)

South African Rand (ZAR)

Chinese Yuan (CNY)

Malaysian Ringgit (MYR)

Swedish Krona (SEK)

Czech Koruna (CZK)

Mexican Peso (MXN)

Swiss Franc (CHF)

Danish Krone (DKK)

New Zealand Dollar (NZD)

Thai Baht (THB)

Euro (EUR)

Norwegian Krone (NOK)

Turkish Lira (TRY)

Hong Kong Dollar (HKD)

Omani Rial (OMR)

Ugandan Shilling (UGX)

Hungarian Forint (HUF)

Philippine Peso (PHP)

UK Sterling (GBP)

Indian Rupee (INR)

Polish Zloty (PLN)

United Arab Emirates Dirham (AED)

Indonesian Rupiah (IDR)

Qatar Rial (QAR)

By Wire for Indian Customers - ICICI

Indian Rupee (INR)

</details>

**Credit/Debit Card**

We do offer customers the ability to pay via credit card. We add a 2.9% fee since we are a free product and are charged a 2.9% fee for credit cards.


# Supported Currencies

By GoCardless - Bank Transfer

USD

CAD

AUD

GBP

DKK

EUR

NZD

By Stripe - Credit and Debit card

USD

By Wire

Australian Dollar (AUD)

Israeli Shekel (ILS)

Romanian Leu (RON)

Bahrain Dinar (BHD)

Japanese Yen (JPY)

Saudi Riyal (SAR)

Bulgarian Lev (BGN)

Kenyan Shilling (KES)

Singapore Dollar (SGD)

Canadian Dollar (CAD)

Kuwait Dinar (KWD)

South African Rand (ZAR)

Chinese Yuan (CNY)

Malaysian Ringgit (MYR)

Swedish Krona (SEK)

Czech Koruna (CZK)

Mexican Peso (MXN)

Swiss Franc (CHF)

Danish Krone (DKK)

New Zealand Dollar (NZD)

Thai Baht (THB)

Euro (EUR)

Norwegian Krone (NOK)

Turkish Lira (TRY)

Hong Kong Dollar (HKD)

Omani Rial (OMR)

Ugandan Shilling (UGX)

Hungarian Forint (HUF)

Philippine Peso (PHP)

UK Sterling (GBP)

Indian Rupee (INR)

Polish Zloty (PLN)

United Arab Emirates Dirham (AED)

Indonesian Rupiah (IDR)

Qatar Rial (QAR)

By Wire for Indian Customers - ICICI

Indian Rupee (INR)


# Money Back Guarantee

{% hint style="info" %}
Pump is the only company with a ***real*** money back commitment in form of AWS credits capped to the **entire AWS bill.**
{% endhint %}

If Pump over-commits on your behalf (purchasing Savings Plans, Reserved Instances, or Committed Use Discounts that result in unused capacity), you are eligible for a credit covering the entire amount of lifetime loss. Credits are issued for the following month, based on your lifetime savings with Pump.

### How the guarantee works

| Detail            | Explanation                                                                                                                                                    |
| ----------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| What triggers it  | Overcommitment resulting from unused Savings Plans, Reserved Instances, or Committed Use Discounts that Pump purchased on your behalf within any 30-day period |
| What you receive  | Cloud credits (AWS or GCP) for the next month equal to the entire amount of lifetime loss                                                                      |
| Credit cap        | Credits are capped at your entire cloud spend bill                                                                                                             |
| Calculation basis | Based on your lifetime savings with Pump                                                                                                                       |

### What this means

You cannot lose money by joining Pump. If Pump makes an overcommitment mistake, Pump credits you for the loss. The credit cap is your entire cloud bill, not just Pump's fees.

### What the guarantee does not cover

The money back guarantee does not apply to overcommitment made by you or any third party that also optimizes your cost savings. It covers only commitments purchased by Pump on your behalf.

### Terms

Full terms are available at [pump.co/legal](https://pump.co/legal).


# Invoice Verification or Errors

Please contact <bills@pump.co> for any questions relating to invoices

Interest is charged on late bills at a rate of 1.5% monthly


# Invoices for Indian Customers

Please include the Invoice number in the wire transfer to ICICI

Please email <bills@pump.co> if you have any questions.

To remit funds

Bank Name: ICICI Bank

IFSC Code: ICIC0001942

Account Name: PUMP BILLING TECHNOLOGIES INDIA PRIVATE LIMITED

Account Number: 721205000403


# Invoices from AWS

Your invoices can be accessed from your AWS management console on the billing dashboard. From your AWS management account, head over to Billing Dashboard > Bills. The charges will be on the 'Charges by Services' Tab and the Pump Savings will be on the 'Savings' Tab.

As we (Pump) handle your invoices since joining Pump, the same invoice would be posted on our platform - in the [Invoices tab](https://app.pump.co/invoices) during the first week of each month. Please note that these invoices reflect the same charges from AWS; **Pump does not mark up or add any additional fees to your usage costs**.

Additionally, you will see a line item called 'Pump Savings' which reflects the amount that Pump has saved you so far!

![image.png](https://d3vl36l12sfx26.cloudfront.net/6bacbab4-dff1-4b53-b5f8-bea49f26ab4a%2F1720910754351-image.png?Expires=253370764800\&Signature=lSl1ObAIX0XwTgbPUiIzm3ErrIFo6-wqnpljcJxJ~kOSAkHDjxMVKVM0MKC10TfIkLGuy3ZBOo0olCdWKD~9UD9A0gX6w0NBWOlrt4TtOfvVINMXzUcpTBELBUNt1xIV3Xxrc~Ba0H-gfb2T8ZxqvTO31u8iOa~oHf9Z-zbVF9pheYbYyfMw2oqZNadpuM2AoRmYb8E9jB7mEtHm9rM4qrsWbP9a9TARvaMkzALTMh5iMv0~ZY0chqvzkNomLdgJS5AsX16I9I~f-0nsqkbcMruYuHK0z8iTctGc0GlCbqcEWKucm1OAWWqZ9NFYAVS20xBKnhlQLv2VkQDTIk~9yg__\&Key-Pair-Id=K3NV4LZ47N8M46)


# Billing FAQ

## Frequently Asked Questions <a href="#undefined" id="undefined"></a>

**Q: Do I still pay AWS/GCP/Azure directly?**

A: No. Once connected, Pump handles your cloud billing. You pay Pump, and Pump pays your cloud provider.

**Q: I got 2 bills, one from AWS and one from Pump. What do I do?**

A: If you joined Pump in the middle of the month, you will get two bills. One bill will be from AWS (the time from the start of the month to right before you joined Pump), and one bill will be after you joined Pump, and we will invoice that on <https://app.pump.co/invoices>. This is because when you joined Pump, we started incurring your charges. From now on, starting next month, you will only receive a bill from Pump. If you have any further questions, please reach out to <bills@pump.co>.

**Q: Will I see my existing Reserved Instances or Savings Plans on my invoice?**

A: Yes. Existing commitments carry over. Pump optimizes around them and reflects their savings on your invoice.

**Q: What happens if I miss a payment?**

A: Reach out to the Pump team as soon as possible. Pump continues paying your cloud provider on your behalf, so timely payment is important to maintain uninterrupted service. Interest is charged on late bills at a rate of 1.5% monthly.

Pump also offers financing options through our partners Gynger and Capchase. Please contact <bills@pump.co> for more information.&#x20;

**Q: Can I get a receipt for each payment?**&#x20;

A: Yes. Invoices and receipts are available in Settings > Billing.

**Q: When do you post invoices?**

A: We post invoices usually between the 3rd and 5th of every month. It can be found here: <https://app.pump.co/invoices>. If you have any further questions, please reach out to <bills@pump.co>.

**Q: Is there a way I can verify that my invoice is correct?**

A: There are several ways you can check if the [invoice](https://app.pump.co/invoices) on the invoices tab is the correct number. You have access to cost explorer and can look on the Pump Dashboard or on Cost Explorer and verify accordingly. If you have any further billing-related questions, please reach out to <bills@pump.co>.

**Q: My invoice doesn't have GST on it?**

A: For customers using Amazon Web Services India Private Limited (AWS India), paying GST is required. If you are an Indian-company and have an invoice that doesn't have GST, please be sure to email <bills@pump.co> to add the GST. Soon, we are adding a feature to be self serve, but at the moment, you will need to reach out.

**Q: I have AWS credits, and I still received an email saying my invoice is unpaid**

A: If you go to the [credits page](https://app.pump.co/settings/credits) of our app, you should be able to see how many AWS credits you have. If you believe this number is inaccurate or you cannot load the page (this means that you have $0 in credits), then please reach out to the salesperson you onboarded with, and they can resolve the issue shortly. If you self-onboarded, please reach out to <bills@pump.co>.

**Q: We have a pop-up saying we have unpaid invoices, but we’re supposed to have connected our bank. Is there something missing?**

A: There are a few scenarios that could apply here.

1\. The first scenario is simply that you are in the interim period between when we post your monthly invoice (3rd or 4th of each month) and when we trigger the charge, between 24-48 hours afterwards. This period has been created to allow you time to review your invoice before autopay charges you. If this is the case, and only the current, monthly invoice is listed as unpaid in your invoices tab of the Pump dashboard (<https://app.pump.co/invoices>), then no action needs to be taken on your part.

2\. The second scenario is that you had unpaid invoices existing at the time when you connected your bank. If that is the case, then you can reach out to \[<support@pump.co>]\(<mailto:support@pump.co>) to alert us of the change. This will also protect you from going to collections.

3\. The third scenario is that there is a problem with the bank connection. Please double check to ensure that all details have been inputted correctly (<https://app.pump.co/invoices>), and reach out to \[<support@pump.co>]\(<mailto:support@pump.co>) for assistance.

**Q: What if I see errors or have questions about my invoice?**

A: Please contact <bills@pump.co> for any questions relating to invoices. Interest is charged on late bills at a rate of 1.5% monthly


# Paying India Goods and Services Tax (GST)

### How to Add Your GST Number <a href="#undefined" id="undefined"></a>

**Step One:** Go to [Settings](https://app.pump.co/settings) --> [Company](https://app.pump.co/settings#company)

**Step Two:** Add a Tax Identification Number (TIN)

**Step Three:** Click Save

### About Paying GST <a href="#undefined" id="undefined"></a>

For customers using Amazon Web Services India Private Limited (AWS India), paying GST is required. As an AWS Reseller of AWS India Private Limited, we work with Ingram Micro as our authorized distributor in India. All purchases made by customers in India go through us and Ingram. Because Ingram is an India-registered entity, they’re required to charge GST as per local tax laws. Even though Pump is a US-based company, the involvement of a local reseller makes the sale a domestic transaction, which means GST applies.

### I have a US Entity, Do I have to Pay GST? <a href="#undefined" id="undefined"></a>

Even if you have a non-Indian entity (like a US company that pays the bills), you must have your account be created through AWS Inc, and not AWS India. You must still pay GST if you are using **AWS India**. Ask <support@pump.co> if you are using AWS India or AWS Inc.


# Real Customers, Real Success Stories

Here are some **PUMP**ed customers we have saved on their AWS bill:

* We saved [**Smartlead**](https://www.smartlead.ai/) **25% on AWS** in their first month with Pump!
* We saved [**Arc Boats**](https://arcboats.com/) **30%** **on AWS** in their first month with Pump!
* We saved [**Reality Defender**](https://www.realitydefender.com/) **28% on AWS** in their first month with Pump!
* We saved [**Terra**](https://tryterra.co/) **$3,200** using Pump!
* We saved [**Finsera**](https://finsera.com/) more than **$2,000/mo** with Pump!

<figure><img src="/files/PSgpjGGo4eE1V1a04Rfz" alt=""><figcaption><p>This is a real customer dashboard depicting that the customer was spending ~$6500, and ended up spending under $3,000!</p></figcaption></figure>

This is a real customer that was spending \~$6500 before they joined Pump. When they joined Pump, it took a few days, and then by their first full month with Pump, they spent under $3,000! (you read that right, all thanks to Pump)

Pump's goal is to help customers reduce their on-demand spend, and we do this by scanning their infrastructure with our autopilot model, and creating / executing recommendations on SPs/RIs with the focus of optimizing your AWS spend for free.

🎉 You could be the next success story, feel free to [**sign up today in minutes**](broken://pages/GMB7yXWUWPFpcQTl6Gyi)! 🎉


# Account Management

## Account Management

This page covers how to manage your Pump account after onboarding: inviting team members, managing roles, updating company settings, and working with multiple companies.

### Team management

**Inviting team members**

Admins can invite teammates from **Settings > Team > Invite**.

1. Enter the teammate's email address.
2. Select a role (Admin, Viewer, or Finance).
3. Click **Invite**.

The teammate receives an email with a signup link. When they create their account, they are automatically added to your company workspace as a Member. Role upgrades happen after they join (see "Changing roles" below).

**Roles and permissions**

Pump has three role types visible in the team management UI.

| Role                | What they can do                                                                                                                                                                                                      |
| ------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Admin**           | Full access to all Pump features. Can invite and remove team members, promote or demote other users to/from Admin, and manage integrations, billing, and company settings.                                            |
| **Member / Viewer** | Full read access to all Pump features, including dashboards, recommendations, and security findings. Cannot manage team members or modify admin-level settings.                                                       |
| **Finance**         | Not a separate access role. Any team member can be designated as a Finance contact, which adds them to the invoice email distribution list. They receive invoice notifications and have visibility into billing data. |

**How roles are assigned**

The first user to create a company workspace automatically becomes Admin. All invited users join as Members, regardless of the role selected at invite time. Role changes to Admin or Finance happen after the user has joined.

**Changing roles**

| Action                       | How to do it                                                                                               |
| ---------------------------- | ---------------------------------------------------------------------------------------------------------- |
| Promote to Admin             | An existing Admin navigates to **Settings > Team**, finds the team member, and toggles their Admin status. |
| Designate as Finance contact | Navigate to **Settings > Billing** and add the team member's email to the invoice email list.              |
| Remove a team member         | An Admin navigates to **Settings > Team** and removes the member.                                          |

**How invitations work**

When you invite someone, Pump creates a pending membership and sends an email. If the invitee already has a Pump account, they can accept the invitation to join your company. If they do not have an account, the email link takes them through the signup flow, and they are automatically added to your company when they complete it.

If someone signs up with the same email domain as your company but was not invited, they are not automatically added. An Admin must send them an invitation.

### Company settings

**Company profile**

Navigate to **Settings > Company** to view and update your company profile. This includes your company name, size, country, and business identification fields.

**Business identification**

After onboarding, Pump prompts you to provide your business identification. This appears as a notification in the sidebar.

| Country         | Required fields                                          |
| --------------- | -------------------------------------------------------- |
| United States   | EIN (Employer Identification Number)                     |
| India           | CIN (Corporate Identification Number) and GSTIN          |
| Other countries | Business ID number and tax code (varies by jurisdiction) |

To complete this, navigate to **Settings > Company** and fill in the business identification fields. This is not a hard gate on using Pump, but completing it helps ensure your billing is properly configured.

**Multi-company access**

Pump supports belonging to multiple company workspaces with a single login. If you are a member of more than one company (for example, a consultant managing multiple clients), you can switch between them from the account menu.

Each company workspace is fully independent with its own cloud connections, billing, team members, and settings.

**Multi-factor authentication**

MFA is optional and can be enabled per user. To enable MFA:

1. Navigate to your account settings.
2. Toggle MFA on.

When enabled, you will be prompted for a second factor during login. MFA is enforced at the identity provider level (Auth0).

### Connecting cloud accounts

Cloud account connections are managed from **Settings > Integrations**. You can connect multiple cloud providers (AWS, GCP, Azure) and third-party services (Anthropic, OpenAI, GitHub, Datadog, Cursor, ClickHouse Cloud) to a single company workspace.

For setup instructions, see the connection guides:

| Provider | Guide            |
| -------- | ---------------- |
| AWS      | Connecting AWS   |
| GCP      | Connecting GCP   |
| Azure    | Connecting Azure |

Third-party integration setup is covered in the Integrations section.

### Payment and billing settings

Payment methods and invoice settings are managed from **Settings > Billing**. Pump accepts credit card, ACH (bank transfer), and wire transfer.

For details on how Pump's billing works, see Billing and Payments.

### Deleting your account

To disconnect from Pump and close your account, contact Pump support at [support.pump.co](https://support.pump.co/).


# FAQ

### General

<details>

<summary>How does Pump work?</summary>

Pump is a licensed cloud solutions provider for AWS, GCP, and Azure. When you connect your cloud account, Pump becomes your billing partner and purchases Reserved Instances, Savings Plans, and Committed Use Discounts on your behalf at optimized rates. You receive a single invoice from Pump instead of paying your cloud provider directly. Your infrastructure, workloads, and configurations are untouched.

</details>

<details>

<summary>How is Pump free?</summary>

Pump's  is free because Pump earns revenue as a cloud solutions provider. By consolidating customers under a single billing umbrella, Pump accesses volume-tier pricing from cloud providers. The savings generated by this pricing advantage are split between you and Pump. You pay nothing extra beyond your cloud usage.

</details>

<details>

<summary>Who is Pump for? </summary>

Pump is built for engineering teams, DevOps leads, and finance teams managing cloud infrastructure across AWS, GCP, and Azure. Pump Save has the most impact for organizations spending $5,000 or more per month. Pump View (spend visibility) is available at any spend level.

</details>

<details>

<summary>How long does setup take? </summary>

Most configurations take under five minutes. AWS standalone accounts connect via a one-click CloudFormation stack. GCP and Azure require running a short script in Cloud Shell. AWS Organization accounts require assisted setup with the Pump team.

</details>

<details>

<summary>When will I see savings?</summary>

Most customers see savings within their first week after connecting. Pump begins analyzing your usage immediately and generates commitment recommendations based on your historical data.

</details>

<details>

<summary>What AWS services are supported?</summary>

We work with a variety of AWS services, including:

* Amazon EC2
* Amazon RDS
* Amazon ECS
* Amazon ElastiCache
* AWS Lambda
* Amazon OpenSearch Service
* Amazon SageMaker
* Amazon Redshift
* Amazon DynamoDB
* EC2 Data Transfer
* AWS MediaLive
* Amazon S3
* Amazon CloudWatch

We are the only company that covers such an extensive list of AWS services.

</details>

<details>

<summary>What permissions am I handing off?</summary>

Our permissions are at the billing layer only. We ask you to join our AWS organization and use only IAM roles and permissions to perform all the required cost optimizations and AWS APIs to enable these savings.

We cannot start or stop an instance, and only operate on the billing layer.

</details>

<details>

<summary>Do I risk our actual AWS environment because of Pump?</summary>

Pump would have ZERO ability to modify your environment. There is zero-touch to your infrastructure; thus, there is no chance for any server downtime or interruptions to your developer workflows!

</details>

<details>

<summary>What is the minimum monthly AWS spend needed? Is there a maximum?</summary>

We work with companies with over $5000/mo. spend to all the way to the millions.

</details>

<details>

<summary>What cloud services do you support?</summary>

We support Amazon Web Services (AWS), Google Cloud Platform (GCP), and Microsoft Azure. Our platform is designed to optimize, secure, and provide visibility across all these major cloud environments.

</details>

<details>

<summary>I have more questions. Where can I find answers?</summary>

We'd love to help! Email us at <support@pump.co> or text us at 650.468.0297 for the fastest response from the team.

</details>

### Savings

<details>

<summary>We already have Reserved Instances and Savings Plans. Will Pump conflict with them?</summary>

No. Pump detects your existing commitments and optimizes around them. It will not duplicate or conflict with what you already have. As your existing commitments expire, Pump factors the freed capacity into future recommendations.

</details>

<details>

<summary>We have an Enterprise Discount Program (EDP) or Private Pricing Agreement (PPA). Is Pump compatible?</summary>

Yes. Pump works alongside longer term Enterprise Agreements across AWS, GCP and Azure. Pump's commitment management operates on top of these programs. Please contact your account manager for more information.&#x20;

</details>

<details>

<summary>We spend less than $5,000/month. Can we still use Pump?</summary>

Yes. Pump View (dashboards, cost breakdowns, alerts, forecasts) is available on the Base tier at any spend level. Pump Save's commitment management has the most impact at $5,000/month or above, since that is where commitment discounts become meaningful.

</details>

<details>

<summary>How are savings calculated?</summary>

Pump calculates savings as the difference between what you would have paid at on-demand rates and what you actually paid with Pump's commitment management in place. The savings number on your dashboard reflects gross savings. Pump's fee (for the Enterprise tier) is billed separately and is not subtracted from the displayed number.

</details>

<details>

<summary>Do commitments belong to me or to Pump?</summary>

All commitments Pump purchases land in your own cloud account. Pump does not pool commitments across customers. If you leave Pump, your commitments remain in your account and run off on their original expiration schedule.

</details>

### Security&#x20;

<details>

<summary>What permissions does Pump need?</summary>

Pump requires read-only access to your billing and usage data. The specific mechanism varies by provider: a cross-account IAM role for AWS, OAuth consent plus a per-project service account for GCP, and a service principal for Azure. Pump never accesses your application data, source code, infrastructure configurations, secrets, or logs. See the Security and Trust page for a full breakdown.

</details>

<details>

<summary>Does Pump modify my infrastructure?</summary>

No. Pump cannot create, modify, start, stop, or terminate any cloud resource. The only write action Pump performs is purchasing commitments (Reserved Instances, Savings Plans, Committed Use Discounts) when you enable Autopilot, and only after you explicitly authorize billing partner access.

</details>

<details>

<summary>Is Pump SOC 2 certified?</summary>

Yes. Pump is SOC 2 Type II certified. Audit reports are available on request. Contact your account team or reach out through [support.pump.co](https://support.pump.co/).

</details>

<details>

<summary>Does Pump store my cloud credentials?</summary>

No. For AWS, Pump assumes a cross-account IAM role using temporary STS tokens. For GCP, OAuth tokens handle project discovery and per-project access is granted to a Pump-managed service account. For Azure, Pump authenticates via a service principal using OAuth2 client credentials. For third-party integrations, API keys are stored encrypted and used only for pulling usage data.

</details>

### Billing&#x20;

<details>

<summary>How does Pump's billing work?</summary>

Pump acts as a licensed cloud solutions provider. When you join Pump, your cloud billing routes through Pump. You receive a separate invoice from Pump for each connected cloud provider. Invoices are published on the 3rd of each month for the prior month's usage. Payment terms are net 7.

</details>

<details>

<summary>Do I still pay my cloud provider directly?</summary>

No. Once connected, Pump handles your cloud billing. You pay Pump, and Pump pays your cloud provider on your behalf.

</details>

<details>

<summary>We have cloud credits. Does Pump work with credits?</summary>

Yes. Pump generally onboards customers whose credits are near exhaustion or already used. If you have a significant credit balance remaining, reach out to the Pump team to discuss timing before connecting your account.

</details>

<details>

<summary>What payment methods does Pump accept?</summary>

Pump accepts credit card, ACH (bank transfer), and wire transfer. Payment methods are managed from Settings > Billing.

</details>

### Offboarding

<details>

<summary>Can I leave Pump at any time?</summary>

Yes. There are no contracts or lock-in periods. You can disconnect from Pump whenever you want.

</details>

<details>

<summary>What happens to my commitments if I leave?</summary>

Existing commitments (Reserved Instances, Savings Plans, Committed Use Discounts) remain in your cloud account and run off naturally on their original expiration schedule. Nothing is canceled early. Your cloud resources, configurations, and data are unaffected.

</details>

<details>

<summary>How do I offboard?</summary>

Contact Pump support at [support.pump.co](https://support.pump.co/). Your billing reverts to direct (you pay your cloud provider instead of Pump), and you can delete the Pump IAM roles, service principals, or IAM grants from your cloud account at any time.

</details>


# How Pump Save Works

## Pump Save

Pump Save reduces your cloud spend across AWS, GCP, and Azure. It combines automated commitment purchasing with infrastructure-level recommendations to capture savings at multiple layers of your cloud bill.

All savings mechanisms work together. They target different types of waste and complement each other rather than competing.&#x20;

### How Pump Save reduces your costs

Pump Save works across three areas:

1. **Save > Commitments (AWS)** provides a full commitment lifecycle for AWS accounts: usage analysis, purchase execution, utilization and coverage tracking, forward planning, and renewal management. Our account team works with you to determine how purchases are reviewed and executed.
2. **Save > Commitments (GCP, Azure)** generates commitment recommendations based on your usage patterns. You review each recommendation and decide whether to proceed.
3. **Save > Infrastructure (AWS)** analyzes your running AWS resources and identifies idle, oversized, or underutilized infrastructure. You review each recommendation and apply changes yourself using the provided commands. No infrastructure changes are made automatically.

All commitments are purchased in your own cloud account. Pump does not pool commitments across customers.

Both are available today. Two additional mechanisms are coming soon:

| Mechanism               | What it does                                                                                        | Status                 |
| ----------------------- | --------------------------------------------------------------------------------------------------- | ---------------------- |
| Save > Commitments      | Full commitment lifecycle: analysis, purchasing, tracking, renewal management                       | Available (AWS)        |
| Save > Commitments      | Generates commitment recommendations for review and approval                                        | Available (GCP, Azure) |
| Save > Infrastructure   | Identifies idle/oversized resources with actionable resize, modernization, and termination commands | Available (AWS)        |
| Kubernetes Auto-Scaling | Optimizes pod CPU and memory sizing, recalibrates horizontal scaling                                | Coming soon            |
| Spot Autoscaling        | Automated spot instance management for fault-tolerant workloads                                     | Coming soon            |

### How savings are calculated

Your savings dashboard shows a single number representing how much Pump has saved you. This includes all savings attributed to Pump across active mechanisms, displayed as the difference between what you would have paid at on-demand rates and what you actually paid.

Pump's fee (for the Enterprise tier) is billed separately and is not subtracted from the displayed savings number. Your invoice shows usage, savings, and fees as distinct line items.

### Commitments belong to you

Every commitment Pump purchases lands in your own cloud account. Pump does not pool commitments across customers. If you leave Pump, your existing commitments remain in your account and active until their expiration date.&#x20;

### Getting started

To start saving, connect your cloud account and run a savings estimate. No billing commitment is required to see your estimated savings.


# Savings Estimate

## Savings Estimate

A savings estimate shows you how much Pump can save on your cloud spend before you make any billing commitment. It runs using either read-only API access or a CSV upload, so nothing changes in your cloud account.

### How to run a savings estimate

You can generate an estimate during onboarding or at any time afterward. The process differs slightly by cloud provider.

#### AWS

You have two options:

**Option A: CSV upload (no permissions required)**

1. Sign in to the AWS Console.
2. Navigate to **Cost Explorer**.
3. Export two CSV files:
   * Your cost and usage data for the time range requested
   * Your existing Reserved Instance and Savings Plan inventory
4. In Pump, select **AWS** as your provider and choose **Upload CSV**.
5. Upload both files.
6. Pump generates your estimate within a few minutes.

**Option B: Read-only API access**

1. In Pump, select **AWS** as your provider and choose **Connect account**.
2. Follow the prompts to deploy a CloudFormation stack that creates a read-only IAM role in your account.
3. Once the role is active, Pump pulls your Cost Explorer data directly and generates the estimate.

The read-only approach provides a more detailed estimate because Pump can access granular usage data beyond what the CSV exports contain.

#### GCP

1. In Pump, select **GCP** as your provider.
2. Upload your billing history CSV (exported from the GCP Console billing page).
3. Pump generates your estimate based on your historical usage patterns.

#### Azure

1. In Pump, select **Azure** as your provider.
2. Upload your Azure usage file for the last 3 months (downloaded from the Azure portal).
3. Pump generates your estimate based on your usage data.

### What the estimate shows

Your savings estimate includes:

| Data point                     | What it means                                                                                    |
| ------------------------------ | ------------------------------------------------------------------------------------------------ |
| **Projected monthly savings**  | The estimated dollar amount Pump can save you per month based on your current usage              |
| **Savings percentage**         | Projected savings as a percentage of your current on-demand spend                                |
| **Commitment recommendations** | The specific RIs, Savings Plans, or CUDs that Pump would purchase to achieve these savings       |
| **Coverage analysis**          | How much of your eligible spend would be covered by commitments vs. remaining at on-demand rates |

The estimate is based on your historical usage. Actual savings may vary as your usage patterns change.

### What happens after the estimate

The estimate is informational. To start saving, you need to:

1. Agree to have Pump act as your billing partner (solutions provider relationship).
2. Accept the Terms of Service and Privacy Policy.
3. Grant billing-level permissions (this is the step that enables Pump to purchase commitments).
4. Enter your company details and payment method.

None of these steps happen automatically. The estimate does not commit you to anything.

### How long estimates take

| Provider | CSV upload    | API-based                                          |
| -------- | ------------- | -------------------------------------------------- |
| AWS      | A few minutes | A few minutes after CloudFormation stack completes |
| GCP      | A few minutes | N/A (CSV only for estimate)                        |
| Azure    | A few minutes | N/A (CSV only for estimate)                        |

### Troubleshooting

**Q: Why does my estimate show $0 in savings?** \
A: This typically means your current spend is already well-committed or your usage volume is below the threshold where commitment discounts are meaningful. Pump Save has the most impact at $5,000/month or more in cloud spend.

**Q: Why was my CSV rejected?**\
A: Ensure you are uploading the correct file format. For AWS, you need two specific Cost Explorer exports (Pump provides instructions during the upload flow). For GCP and Azure, you need the billing/usage file from the respective portal, not a custom export.&#x20;


# Overview Page

The Savings Dashboard (Overview) is your central view of how much Pump has saved you. It shows total savings, savings over time, and breakdowns by service or account.

### Reading your savings summary

The top of the dashboard displays your headline savings number. This represents the total amount Pump has saved you, calculated as the difference between what you would have paid at on-demand rates and what you actually paid with Pump's commitment management in place.

Key metrics on the dashboard:

| Metric              | What it shows                                                                                   |
| ------------------- | ----------------------------------------------------------------------------------------------- |
| **Commitments**     | Cumulative dollar amount saved since you joined Pump                                            |
| **Past savings**    | Savings through methods outside of Pump's services, such as previously held SPs/RIs and credits |
| **Savings rate**    | Your savings as a percentage of total eligible spend                                            |
| **Saved with Pump** | Savings attributed to Pump in the current billing period                                        |

### Savings over time

The default timeline view shows your savings trend by month. Use this to track whether your savings are growing, stable, or declining as your usage changes.

A declining savings rate may indicate that your workload mix has shifted and your commitments need rebalancing. Review your pending recommendations in Commitments.

### Savings by service and account

The breakdown view lets you see where your savings are concentrated:

| Breakdown        | What it shows                                                                                                                                                    |
| ---------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **By service**   | Cloud services that generate the most savings, such as EC2, RDS, and Compute Engine.                                                                             |
| **By account**   | Savings distribution across cloud accounts. Use the graph's filter to select accounts.                                                                           |
| **More filters** | <p><strong>Anomalies:</strong> Services with detected spend anomalies.<br><strong>Commitments:</strong> Services with additional commitment recommendations.</p> |

This helps you identify areas where you are well-optimized and areas where additional commitment coverage could capture more savings.

### Understanding the numbers

A few things to keep in mind when reading the dashboard:

**Savings reflect Pump-attributed optimization.** The number includes savings from commitments that Pump recommended and executed, as well as savings from pre-existing commitments that Pump detected and is tracking.

**Pump's fee is billed separately.** The savings number on the dashboard is gross savings. If you are on the Enterprise tier, your Pump fee appears as a separate line item on your invoice, not as a deduction from savings.

**Infrastructure Recommendations savings are tracked separately.** If you apply an Infrastructure Recommendation (for example, downsizing an oversized EC2 instance), the resulting cost reduction appears in your overall cloud bill but is not rolled into the Commitment Planner savings number on this dashboard. You can view Infrastructure Recommendation impact on the Recommendations page.

### Data freshness

Savings data refreshes as your cloud provider processes billing data. For most providers, this means a delay of up to 24 hours for the most recent data point. Historical data for the current month may adjust slightly as the cloud provider finalizes billing at month-end.

When you first connect, Pump backfills historical data so you can see your cost baseline. Backfill depth varies by provider:

| Provider | Backfill depth           |
| -------- | ------------------------ |
| AWS      | Up to 12 months          |
| GCP      | 7 days (routine refresh) |
| Azure    | Up to 90 days            |


# Commitments

The Save > Commitments page is Pump's automated system for purchasing and managing cloud provider discount instruments. It analyzes your usage, recommends optimal commitments, executes purchases (or surfaces them for your approval), and tracks utilization over the lifetime of each commitment.

### What the Commitment page does

Cloud providers offer significant discounts when you commit to a minimum level of usage for one or three years. The tradeoff is complexity: choosing the right commitment type, sizing it correctly, timing purchases around existing commitments, and managing renewals. The Commitment page handles all of this.

Specifically, it:

1. Analyzes your historical usage patterns across services, regions, and accounts.
2. Computes optimal commitment purchases that maximize coverage without over-committing.
3. Projects forward coverage as existing commitments expire.
4. Allows for scheduling of future commitment purchases.
5. Executes purchases in your account upon request.
6. Tracks utilization percentage, coverage percentage, and wasted commitment cost.
7. Flags upcoming expirations and manages the renewal cycle.

### Commitment types by cloud provider

Each cloud provider offers different discount instruments. Pump supports all major commitment types across AWS, GCP, and Azure.

#### AWS

| Commitment type                                        | Typical discount         | Best for                                                                                 |
| ------------------------------------------------------ | ------------------------ | ---------------------------------------------------------------------------------------- |
| EC2 Reserved Instances                                 | 30% to 72% vs. on-demand | Steady-state EC2 workloads in a known instance family and region                         |
| RDS/ElastiCache/Redshift/OpenSearch Reserved Instances | 25% to 65% vs. on-demand | Databases and caches with predictable, consistent usage                                  |
| Compute Savings Plans                                  | 20% to 66% vs. on-demand | Flexible compute across EC2, Lambda, and Fargate regardless of instance family or region |
| EC2 Instance Savings Plans                             | 30% to 72% vs. on-demand | EC2 workloads locked to a specific instance family in a specific region                  |
| SageMaker Savings Plans                                | Up to 64% vs. on-demand  | Consistent SageMaker training or inference workloads                                     |

Discount percentages vary based on term length (1-year vs. 3-year), payment option (No Upfront, Partial Upfront, All Upfront), and instance type. Longer terms and more upfront payment yield deeper discounts.

#### GCP

| Commitment type         | Typical discount         | Best for                                                                             |
| ----------------------- | ------------------------ | ------------------------------------------------------------------------------------ |
| Resource-based CUDs     | 37% to 70% vs. on-demand | Predictable Compute Engine workloads where you know the vCPU and memory requirements |
| Spend-based (Flex) CUDs | 28% to 46% vs. on-demand | Mixed compute footprints spanning VMs, GKE, and Cloud Run                            |

GCP CUDs do not require upfront payment. You are billed monthly for your committed amount regardless of actual usage. 3-year terms offer the deepest discounts, with resource-based CUDs on Compute Engine reaching up to 70% off on-demand.

#### Azure

| Commitment type                          | Typical discount             | Best for                                                                  |
| ---------------------------------------- | ---------------------------- | ------------------------------------------------------------------------- |
| Reserved VM Instances                    | 37% to 72% vs. pay-as-you-go | Stable VMs running in a known region and instance family                  |
| Azure Savings Plans for Compute          | 11% to 65% vs. pay-as-you-go | Flexible compute across instance families, regions, and operating systems |
| Reserved Capacity (SQL, Cosmos DB, etc.) | Up to 65% vs. pay-as-you-go  | Database and storage workloads with predictable capacity needs            |

Azure Reservations offer the deepest discounts but require specifying an instance family and region. Savings Plans are more flexible but discount percentages are lower, particularly on 1-year terms.

### How a commitment moves through the Commitment Planner

The commitment lifecycle in Pump follows these steps:

1. **Recommendation generated.** Pump analyzes your usage and recommends optimal commitments. View recommendations under **Planned** → **Take action**.
2. **Review.** Select **Add to plan** to review recommendations. Select **Buy selected** to approve them.
3. **Purchase executed.** Pump purchases the commitment in your cloud account.
4. **Tracking.** Pump tracks utilization, coverage, and savings throughout the commitment term and visualizes this on the platform alongside the active commitment.&#x20;
5. **Expiration approaching.** Pump sends renewal notifications as the commitment nears its end date.
6. **Renewal decision.** Mark the commitment as **Renew** or **Do not renew**. Pump creates a new recommendation from current usage when you renew.

{% hint style="info" %}
CUD renewals are not currently supported. When a GCP CUD expires, Pump creates a new recommendation.
{% endhint %}

### What Pump accesses

The Commitment Planner requires the following permissions depending on your mode:

| Mode                           | AWS                                                                    | GCP                                                                                   | Azure                                                                           |
| ------------------------------ | ---------------------------------------------------------------------- | ------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------- |
| Read-only (savings estimate)   | Cost Explorer read, Reserved Instance describe, Savings Plans describe | BigQuery billing export read, Compute Engine viewer                                   | Cost Management read, Billing Reader                                            |
| Autopilot (purchase execution) | All read-only permissions + RI/SP purchase permissions                 | All read-only permissions + BigQuery Resource Admin, Compute Future Reservation Admin | All read-only permissions + Reservations/Savings Plan Contributor and Purchaser |

Pump never modifies your infrastructure, workloads, or configurations. Purchase permissions are limited to commitment instruments only.

### Existing commitments

If you already have active Reserved Instances, Savings Plans, or CUDs when you connect to Pump, our commitment engine detects them and optimizes around them. It will not duplicate or conflict with your existing commitments. As your existing commitments expire, Pump factors the freed capacity into future recommendations.


# Infrastructure

The Infrastructure recommendations engine analyzes your running cloud resources and identifies opportunities to reduce waste. It surfaces specific, actionable changes you can make to your infrastructure, each with estimated monthly savings and implementation commands.

This is an advisory feature. Pump does not modify your infrastructure. You review each recommendation and decide whether to apply it.&#x20;

### What it analyzes

Pump evaluates utilization data across the following AWS resource types:

| Resource type     | What Pump checks                                                                  |
| ----------------- | --------------------------------------------------------------------------------- |
| EC2 instances     | CPU utilization, memory utilization, network throughput relative to instance size |
| RDS instances     | CPU utilization, database connections, storage throughput                         |
| EBS volumes       | IOPS usage, throughput, attachment status                                         |
| ElastiCache nodes | CPU utilization, memory usage, connection count                                   |

For each resource, Pump classifies it into one of three categories:

| Classification          | Meaning                                                                                                           |
| ----------------------- | ----------------------------------------------------------------------------------------------------------------- |
| **Idle**                | The resource has minimal or no utilization. It may be safe to terminate.                                          |
| **Oversized**           | The resource is running well below its capacity. A smaller instance type would handle the workload at lower cost. |
| **Appropriately sized** | Current utilization is within a healthy range for the instance type. No action needed.                            |

### What a recommendation includes

Each recommendation provides:

1. **The resource.** Service type, instance ID, region, and current configuration.
2. **The finding.** What Pump detected (idle, oversized, or a specific inefficiency).
3. **The recommended action.** Resize to a specific instance type, terminate, or modify a configuration.
4. **Estimated monthly savings.** The projected cost difference between current and recommended configurations.
5. **Implementation command.** A copy-pasteable AWS CLI command you can run to apply the change.

### How to use recommendations

Navigate to the Infrastucture page in Pump under Save.&#x20;

For each recommendation:

1. Review the resource details and current utilization data.
2. Evaluate the recommended change against your operational requirements. Pump bases recommendations on utilization patterns, but lacks the workload context needed to fully assess usage trends (upcoming traffic spikes, seasonal patterns, compliance requirements).
3. If you agree with the recommendation, copy the provided CLI command and run it in your cloud environment.
4. If you disagree, dismiss the recommendation.

### How this differs from the Commitment Planner

The Commitment Planner and Infrastructure Recommendations target different layers of cloud cost:

|                   | Commitment Planner                                         | Infrastructure Recommendations                     |
| ----------------- | ---------------------------------------------------------- | -------------------------------------------------- |
| What it optimizes | Pricing (paying less for the same resources)               | Sizing (using fewer or smaller resources)          |
| How it works      | Purchases discount instruments (RIs, SPs, CUDs)            | Surfaces resize/terminate actions for you to apply |
| Automation        | Can execute automatically once recommendation is requested | Advisory only. You apply changes manually          |
| Risk profile      | Financial commitment with defined term                     | Infrastructure change that may affect performance  |

Both mechanisms contribute to your overall savings. Commitment-level savings reduce the per-unit price of what you run. Infrastructure savings reduce what you run in the first place.

### Troubleshooting

**Q: Why don't I see any recommendations yet?**\
A: Infrastructure recommendations require sufficient utilization history to generate meaningful findings. If you connected recently, allow a few days for data collection before recommendations appear.

**Q: Why does this recommendation seem wrong for my workload?**\
A: Pump bases recommendations on observed utilization patterns. If your workload has characteristics that the utilization data doesn't capture (planned growth, periodic batch jobs, compliance minimums), dismiss the recommendation. Dismissed recommendations are excluded from future cycles.


# Kubernetes Auto-Scaling

**Status: Coming soon**

Kubernetes Auto-Scaling will optimize pod-level resource allocation and horizontal scaling parameters across your Kubernetes clusters.

### What it will do

Most Kubernetes clusters run with resource requests and limits set once at deploy time and never revisited. This leads to significant over-provisioning: pods requesting far more CPU and memory than they actually use, and horizontal scaling thresholds that don't reflect real demand patterns.

Pump's Kubernetes Auto-Scaling will address this by:

1. **Analyzing pod utilization.** Pump collects CPU and memory usage histograms per pod over time, similar to the approach used by the Kubernetes Vertical Pod Autoscaler (VPA).
2. **Computing optimal sizing.** Based on observed usage patterns, Pump computes a "desired state" for each pod's resource requests and limits.
3. **Gradual right-sizing.** Rather than applying changes all at once, Pump uses a staged approach to reduce resource allocations incrementally, reducing the risk of performance impact.
4. **HPA/KEDA recalibration.** Pump evaluates your horizontal scaling thresholds and recommends adjustments to better match actual demand curves.

### How it relates to other Pump Save mechanisms

Kubernetes Auto-Scaling targets a different layer of waste than the Commitment Planner or Infrastructure Recommendations:

| Mechanism                      | Layer                                                         |
| ------------------------------ | ------------------------------------------------------------- |
| Commitment Planner             | Pricing: pay less per unit of compute                         |
| Infrastructure Recommendations | VM sizing: run smaller or fewer VMs                           |
| Kubernetes Auto-Scaling        | Pod sizing: use less compute per pod within your existing VMs |

These stack additively. Smaller pods mean fewer required nodes, which means your commitment coverage stretches further.

### When it will be available

Kubernetes Auto-Scaling is currently in limited availability. If you're interested in early access, contact your account team or reach out to <support@pump.co>.&#x20;


# Spot Autoscaling

**Status: Coming soon**

Spot Autoscaling will automate the use of cloud provider spot/preemptible instances for fault-tolerant workloads, capturing the deepest available discounts for interruptible compute.

### What it will do

Spot instances (AWS), preemptible VMs (GCP), and spot VMs (Azure) offer discounts of 60% to 90% compared to on-demand pricing. The tradeoff is that the cloud provider can reclaim these instances at any time when capacity is needed elsewhere.

Pump's Spot Autoscaling will manage this tradeoff by:

1. **Identifying eligible workloads.** Analyzing your running workloads to determine which can tolerate interruption (batch processing, CI/CD, stateless web tiers, data pipelines).
2. **Managing spot lifecycle.** Handling instance bidding, interruption notices, and automatic replacement.
3. **Diversifying across pools.** Spreading spot usage across multiple instance types and availability zones to reduce interruption risk.

### How it relates to other Pump Save mechanisms

| Mechanism                      | Layer                                                                     |
| ------------------------------ | ------------------------------------------------------------------------- |
| Commitment Planner             | Pricing: discounts on committed, predictable usage                        |
| Infrastructure Recommendations | Sizing: right-size or eliminate underused resources                       |
| Kubernetes Auto-Scaling        | Pod sizing: reduce compute per pod                                        |
| Spot Autoscaling               | Instance type: shift eligible workloads to the cheapest available compute |

Spot savings apply on top of right-sizing. A workload that has been right-sized and moved to spot instances captures savings at both layers.

### When it will be available

Spot Autoscaling is currently in development. If you're interested in early access, contact your account team or reach out to <support@pump.co>.


# Discount Prices by Cloud Provider

Cloud providers offer significant discounts when you commit to a minimum level of usage for one or three years. The Commitments engine automatically purchases and manages these commitments on your behalf. This page lists the standard discount ranges by provider and commitment type.

All percentages below are relative to on-demand (pay-as-you-go) pricing. Actual discounts vary based on instance type, region, term length, and payment option. Longer terms and more upfront payment yield deeper discounts.

### AWS

| Commitment type                      | 1-year discount | 3-year discount | Applies to                                                    |
| ------------------------------------ | --------------- | --------------- | ------------------------------------------------------------- |
| EC2 Reserved Instances (Standard)    | 30% to 40%      | Up to 72%       | EC2 instances in a specific family and region                 |
| EC2 Reserved Instances (Convertible) | 20% to 30%      | Up to 66%       | EC2 instances with flexibility to change family               |
| Compute Savings Plans                | 20% to 30%      | Up to 66%       | EC2, Lambda, Fargate across any region or family              |
| EC2 Instance Savings Plans           | 30% to 40%      | Up to 72%       | EC2 instances in a specific family and region                 |
| RDS Reserved Instances               | 25% to 40%      | Up to 65%       | RDS databases (MySQL, PostgreSQL, Aurora, SQL Server, Oracle) |
| ElastiCache Reserved Nodes           | 25% to 35%      | Up to 55%       | ElastiCache for Redis and Memcached                           |
| Redshift Reserved Nodes              | 25% to 35%      | Up to 65%       | Amazon Redshift clusters                                      |
| OpenSearch Reserved Instances        | 25% to 35%      | Up to 55%       | Amazon OpenSearch Service domains                             |
| SageMaker Savings Plans              | 20% to 30%      | Up to 64%       | SageMaker training and inference                              |

AWS discounts vary further by payment option:

| Payment option  | Discount level     | Cash flow impact                                                  |
| --------------- | ------------------ | ----------------------------------------------------------------- |
| No Upfront      | Lowest discount    | No upfront cost. Billed hourly at the discounted rate.            |
| Partial Upfront | Mid-range discount | Pay a portion upfront, remainder billed hourly at a reduced rate. |
| All Upfront     | Highest discount   | Pay the full term upfront. No hourly charges.                     |

### GCP

| Commitment type                        | 1-year discount | 3-year discount | Applies to                                                   |
| -------------------------------------- | --------------- | --------------- | ------------------------------------------------------------ |
| Resource-based CUDs (general purpose)  | 37%             | Up to 55%       | Compute Engine VMs with specific vCPU and memory in a region |
| Resource-based CUDs (memory-optimized) | 37%             | Up to 70%       | M1, M2, M3 memory-optimized VMs                              |
| Spend-based (Flex) CUDs                | 28%             | 46%             | VMs, GKE, Cloud Run, and other eligible compute              |
| GKE Autopilot CUDs                     | 20%             | 45%             | GKE Autopilot clusters                                       |
| Cloud SQL CUDs                         | 25%             | Up to 52%       | Cloud SQL instances                                          |

GCP CUDs do not require upfront payment. You are billed monthly for your committed amount regardless of actual usage.

Flex CUDs cover a broad range of compute services under a single commitment, including Compute Engine VMs, GKE Standard and Autopilot clusters, and Cloud Run services with instance-based billing.

### Azure

| Commitment type               | 1-year discount | 3-year discount | Applies to                                              |
| ----------------------------- | --------------- | --------------- | ------------------------------------------------------- |
| Reserved VM Instances         | 37% to 46%      | 60% to 72%      | VMs in a specific family and region                     |
| Savings Plans for Compute     | 11% to 33%      | 32% to 65%      | Compute across families, regions, and operating systems |
| Azure SQL Reserved Capacity   | 25% to 35%      | Up to 65%       | Azure SQL Database and Managed Instance                 |
| Cosmos DB Reserved Capacity   | 20% to 30%      | Up to 65%       | Azure Cosmos DB throughput                              |
| Azure Database for PostgreSQL | 25% to 35%      | Up to 65%       | PostgreSQL Flexible Server                              |

Azure Reservations can be combined with Azure Hybrid Benefit (AHB) for Windows Server or SQL Server workloads. AHB converts on-premise licenses with active Software Assurance into Azure compute discounts. When stacked, combined savings on Windows VMs can reach up to 80%.

### How to read these ranges

The low end of each range typically represents a 1-year commitment with no upfront payment (or the most flexible commitment type). The high end represents a 3-year commitment with full upfront payment (or the most specific commitment type).

Pump's Commitments recommendation engine evaluates your usage and selects the commitment type, term, and payment option that maximizes your savings while minimizing over-commitment risk. You do not need to navigate these options yourself.

### These numbers are approximate

Discount percentages are based on published cloud provider pricing as of mid-2026 and represent typical ranges across common instance types and regions. Exact discounts depend on your specific configuration. Your Savings Estimate will show the projected savings for your actual workload.


# AWS Reserved Instance and Savings Plan Policy Changes (2025)

Effective June 1, 2025, AWS updated its Reserved Instance and Savings Plan policies. The changes affect how Managed Service Providers, Solution Providers, and solutions providers share commitments across multiple customer accounts. Specifically, sharing RI and SP commitments across multiple customer accounts is no longer permitted.

### Impact on Pump customers

Pump customers are not affected by this change. Pump does not pool or share commitments across customers. Every commitment Pump purchases lands in your own cloud account and is keyed to your account ID.

### Why Pump customers are already compliant

| AWS policy requirement                                          | Pump's existing practice                                                                     |
| --------------------------------------------------------------- | -------------------------------------------------------------------------------------------- |
| RIs and SPs must be used for a single end customer's AWS usage  | Every commitment Pump purchases is scoped to your account. No sharing across customers.      |
| Sharing commitment pools across customer accounts is prohibited | Pump does not maintain shared commitment pools. Each customer's commitments are independent. |

### What this means for you

No action is required. Your existing commitments and Pump's optimization approach are fully aligned with the updated AWS policies. You can continue using Pump with no changes to your setup.

### Questions

If you have questions about these policy changes and how they relate to your account, contact your Pump account manager or reach out to <support@pump.co>.


# How Pump View Works

## How Pump View Works

Pump View is a spend observability layer that pulls billing data from every provider and service you connect, then surfaces it in one place. Instead of switching between the AWS Billing Console, GCP Billing Reports, Azure Cost Management, and individual dashboards for services like Anthropic or Datadog, you query everything from a single interface.

### What Pump View includes

| Feature        | What it does                                                                                                                                                                                     |
| -------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Playground     | Interactive query builder for exploring spend across all connected providers and services. Filter by service, account, region, SKU, usage type, and more using dropdown filters or SQL querying. |
| Reports        | Save any Playground query as a recurring report. Schedule delivery via email or Slack.                                                                                                           |
| Annotations    | Pin notes to your cost timeline to explain spikes, deployments, or team changes.                                                                                                                 |
| Budgets        | Set monthly spend caps scoped to specific accounts or services. Get alerted at custom thresholds.                                                                                                |
| Anomaly Alerts | Automated detection of unusual spend changes. Configurable alert channels.                                                                                                                       |
| Forecasting    | End-of-month spend projections at P50 and P90 confidence levels.                                                                                                                                 |
| Allocations    | Allocate costs using tags.                                                                                                                                                                       |

### What data Pump View pulls

Pump View ingests billing and usage data from every provider and integration you connect. It does not access infrastructure, workloads, or configurations.

| Provider | Data source                                     | Historical backfill on first connect |
| -------- | ----------------------------------------------- | ------------------------------------ |
| AWS      | Cost Explorer API, Cost and Usage Reports (CUR) | Up to 12 months                      |
| GCP      | BigQuery billing export                         | \~7 days                             |
| Azure    | Cost Management detailed cost reports           | Up to 90 days                        |

Third-party integrations (Anthropic, OpenAI, GitHub, Datadog, Cursor, ClickHouse Cloud) pull usage and cost data through each service's API. See [Integrations](/integrations/anthropic) doc for setup details per service.

Data refreshes daily across all providers.

### Multi-provider visibility

When you connect multiple cloud providers and third-party services, Pump View aggregates all of that spend into a unified view. The Playground lets you query across providers in a single session, so you can compare cloud costs alongside your Anthropic token spend or Datadog host charges without switching tools.

This is useful for teams managing workloads across clouds, or teams whose AI and DevOps tooling costs are growing alongside traditional infrastructure spend.

### How to get started

1. Connect at least one cloud provider or third-party service. See Getting Started help doc for the full setup flow.
2. Once connected, navigate to **View** in the left sidebar.
3. Pump backfills your historical data automatically. For AWS, this means up to 12 months of cost history is available immediately after connection.

No additional configuration is required. View is available on all Pump subscription tiers.


# Playground

## Playground and Filters

The Playground is Pump View's interactive workspace for exploring cloud spend. It combines a query builder, visualization controls, and a data table so you can slice your costs by any dimension and spot trends or anomalies.

Navigate to **View > Playground** in the left sidebar.

### Query builder

The query builder sits at the top of the Playground. It follows a structured format:

**Select all from** \[dimension] **in** \[provider] **Where** \[filters]&#x20;

SQL Querying is also available to filter.&#x20;

#### Breakdown dimensions

The first dropdown controls how your spend is grouped. Available dimensions:

| Dimension   | What it shows                                                                      |
| ----------- | ---------------------------------------------------------------------------------- |
| Service     | Spend grouped by cloud service (e.g., Amazon EC2, Cloud Run, Azure VMs)            |
| Account     | Spend grouped by linked account or project                                         |
| Region      | Spend grouped by cloud region (e.g., us-east-1, europe-west1)                      |
| Resource    | Spend grouped by individual resource ID                                            |
| SKU         | Spend grouped by SKU or line-item description                                      |
| Usage Type  | Spend grouped by usage category (e.g., DataTransfer, Storage, Compute)             |
| Charge Type | Spend grouped by charge category (e.g., on-demand, reserved, spot, tax)            |
| Commitment  | Spend grouped by commitment instrument (RI, SP, CUD)                               |
| Marketplace | Spend grouped by AWS/GCP/Azure marketplace purchases                               |
| Provider    | Spend grouped by cloud provider, useful when you have multiple providers connected |

#### Filters

Click **+ Add filter** to narrow results. Filters use the same dimensions listed above. For example, you can select "Service" as your breakdown and add a filter for "Region = us-east-1" to see per-service spend in a specific region.

Multiple filters can be combined. Each filter supports multi-select, so you can include or exclude specific values.

#### Provider scope

The **in \[provider]** dropdown scopes your query to a specific provider (AWS, GCP, Azure) or across all connected providers. When you have multiple clouds connected, you can query across all of them in a single view.

### Visualization modes

#### Standard (Bar)

The default view is a bar graph. Displays a stacked bar or line chart of total spend over your selected time range, broken down by whatever dimension you chose. The data table below the chart shows the full breakdown with sortable columns.

#### Line&#x20;

Select **Line** in the visualization drop down at the top right to switch from stacked bars to a line chart of total spend over your selected time range, broken down by whatever dimension you chose. This is the clearest way to spot trends and inflection points over time, especially when comparing multiple services or accounts that would otherwise clutter a stacked bar view.

Each line represents one value within your selected breakdown dimension. The data table below the chart shows the same sortable breakdown as in Standard view.

#### Top Movers

Toggle **Top Movers** in the top-right toolbar to switch to a waterfall chart that highlights what changed between two time periods. This is the fastest way to answer "what drove my cost increase (or decrease) this month?"

Top Movers compares two periods side by side and sorts every item by absolute change. The chart shows increases in red (above the zero line) and decreases in green (below the zero line). The table below displays each item with its absolute dollar change and percent change.

For example, if you select a 30-day window, Top Movers compares the previous 30 days against the 30 days before that, then ranks every service by how much its cost moved.

#### Pie&#x20;

Toggle **Pie** to see your spend for the selected time range as a proportional breakdown by dimension. This is the fastest way to answer "what's my spend mix?" rather than "how has my spend changed?"

Pie view works best with a small number of segments. If your breakdown dimension has many distinct values (for example, Resource or SKU), consider narrowing with a filter first, or switch to Bar or Line for a more readable view.

#### Sankey&#x20;

Toggle **Sankey** to see your spend as flows between dimensions — for example, how spend moves from provider to account to service. This view is useful for understanding how cost flows through your organization's structure rather than just how much each individual item costs.

Each node represents a value within a dimension, and the width of each connecting flow represents the dollar amount moving between them. Sankey is most useful when you have at least two breakdown dimensions to compare (for example, Account and Service) rather than a single flat list.

### Time range

Use the time range controls in the toolbar:

| Option | What it covers             |
| ------ | -------------------------- |
| 1D     | Last 1 day                 |
| 7D     | Last 7 days                |
| 30D    | Last 30 days               |
| 3M     | Last 3 months              |
| Custom | Pick a specific date range |

### Forecasting

The **Forecast** dropdown in the toolbar projects your end-of-month spend based on current trends. Two confidence levels are available:

| Level | What it means                                                                                                      |
| ----- | ------------------------------------------------------------------------------------------------------------------ |
| P50   | Median projection. Your spend is equally likely to land above or below this number.                                |
| P90   | Conservative projection. 90% chance your actual spend will be at or below this number. Useful for budget planning. |

The forecast engine is labeled in the toolbar (e.g., "Engine: statsforecast"). Forecast lines appear as dotted extensions beyond your current data on the chart.

### Saving a query as a report

Any Playground view can be saved as a report. Click **New Report** next to the Playground header to save the current query, filters, time range, and visualization settings. Give it a name, and select **Save** in the upper right hand corner to save to the Reports tab. See Reports article for details on scheduling and sharing.&#x20;


# Reports

Reports let you save any Playground query and schedule it for recurring delivery. Instead of manually checking the Playground for cost updates, you can have Pump send a summary to your inbox or a Slack channel on a set cadence.

Navigate to **Reports** in the left sidebar to view saved reports.

### Creating a report

1. Open **Playground** and build the query you want to track. Set the breakdown, filters, time range, and visualization.
2. Select **New Report** beside the Playground header.
3. Name the report, then select **Save** in the upper-right corner. The report appears under **Reports** in the sidebar.
4. In the reports list, select the three-dots on the far right of the screen, then select **Subscribe**. Choose a delivery cadence and method (email or Slack) to have the report sent directly to you automatically.

The report captures your full query configuration: dimension, filters, provider scope, time range, and whether you're using Standard or Top Movers view.

### Scheduling delivery

Reports can be scheduled for recurring delivery to email, Slack, or both.

| Setting    | Options                             |
| ---------- | ----------------------------------- |
| Frequency  | Daily, weekly, or monthly           |
| Channels   | Email, Slack                        |
| Recipients | Any team member with a Pump account |

To add a Slack channel as a delivery method, your team needs the Slack integration configured.  Select **Subscribe** on a report, then follow the setup prompts to connect Slack.

Recipients must have an active Pump account. Reports cannot be shared with external users who do not have access to your Pump workspace.

### Managing reports

The Reports page lists all saved reports for your organization. From here you can:

* Edit the underlying query by opening a report in the Playground
* Adjust the delivery schedule or recipients
* Pause or delete a report
* Manually trigger a one-time send

### Opening a report in the Playground

Every saved report includes a link back to the Playground with the same query loaded. This lets you start from a report's baseline view and drill deeper, adjust filters, or change the time range without modifying the saved report itself.


# Annotations

Annotations let you pin notes to specific dates on your cost timeline. Use them to document events that explain cost movements, like a new service deployment, a traffic spike, a pricing change, or a team restructuring.

When someone on your team investigates a cost spike weeks later, the annotation is already there with context.

### Adding an annotation

Annotations are added manually. To create one:

1. Open the **Playground** or pre-made report and navigate to the date range where the event occurred.
2. Click the + below the bar on a singular day.&#x20;
3. Enter a description of the event (e.g., "Migrated search indexing to OpenSearch," "Black Friday traffic spike," "Added 3 new dev accounts").
4. Save the annotation.

Annotations are visible to everyone on your team. They appear as markers on the cost timeline in both the Playground and in generated reports.

### When to use annotations

Annotations are most useful when cost changes are driven by business decisions or operational events that billing data alone cannot explain. Common use cases:

| Event type     | Example annotation                                      |
| -------------- | ------------------------------------------------------- |
| Deployment     | "Deployed new ML inference pipeline on p4d instances"   |
| Traffic event  | "Product Hunt launch, 5x normal traffic"                |
| Team change    | "Onboarded data team, 4 new accounts added"             |
| Pricing change | "Switched RDS from on-demand to reserved"               |
| Incident       | "Redis cluster failover, 12 hours on backup instances"  |
| External       | "AWS price reduction for S3 Standard effective March 1" |

### Annotations vs. Anomaly Alerts

Annotations are manual and retrospective. You add them to explain something that already happened.

Anomaly Alerts are automatic and proactive. Pump detects unusual spend and notifies you. See [Anomalies and Budget Alerts](/pump-view/anomalies-and-budget-alerts) for details.

The two features complement each other: an anomaly alert tells you something changed, and an annotation records why.


# Anomalies and Budget Alerts

Pump View provides two ways to stay ahead of unexpected spend: **Budget Alerts** for tracking against a known target, and **Anomaly Alerts** for catching spend changes you did not anticipate.

### Budget Alerts

Budgets let you set a monthly spend cap for specific accounts or services and get notified when spend approaches or exceeds that cap.

#### Creating a budget

Navigate to **View > Budgets** in the left sidebar, then click **New budget**.

| Field               | Description                                                                                                                                                                                                   |
| ------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Name                | A label for this budget (e.g., "Data platform monthly budget"). Optional. Defaults to the scope if left blank.                                                                                                |
| Scope               | Which accounts and services this budget watches. Use the Account and Service dropdowns to narrow the scope, or leave both set to "All" for a company-wide budget.                                             |
| Budget              | The monthly dollar amount this budget tracks against. The dialog shows last month's spend for the selected scope as a reference point. Click "Set as budget" to use last month's spend as the starting value. |
| Thresholds & alerts | One or more percentage thresholds that trigger notifications. Each threshold has its own recipient list.                                                                                                      |
| Approval policy     | Optional. Require sign-off before changes or breach-driven raises take effect.                                                                                                                                |

#### How thresholds work

Each budget supports multiple thresholds. A common setup:

| Threshold | Purpose                                                                                                     |
| --------- | ----------------------------------------------------------------------------------------------------------- |
| 75%       | Early warning. Notify the engineering lead so the team can investigate before the budget is fully consumed. |
| 100%      | Budget reached. Notify finance and leadership.                                                              |

Each threshold tier alerts only its own tagged recipients. If no recipients are tagged for a threshold, the alert goes to everyone in your company.

#### Alert channels

Budget alerts can be delivered via email and Slack. Recipients must have an active Pump account.

### Anomaly Alerts

Anomaly Alerts notify you when Pump detects unusual spend patterns across your connected providers. Unlike budgets (which require you to define a target), anomaly detection works automatically based on your historical spend data.

When Pump identifies a significant deviation from expected spend, it sends an alert to your configured channels. The alert includes the affected service or account, the magnitude of the change, and a link to investigate in the Playground.

#### Configuring anomaly alerts

Anomaly alert settings are available under [**Organization settings > Notifications**](https://app.pump.co/settings#notifications). You can configure which channels receive anomaly notifications (email, Slack, or both).

#### Investigating an anomaly

When you receive an anomaly alert:

1. Click the link in the notification to open the relevant time range in the Playground.
2. Use the **Top Movers** view to identify which services or accounts drove the change.
3. Add an Annotation to document what caused the anomaly for future reference.

### Budget Alerts vs. Anomaly Alerts

|                | Budget Alerts                                                   | Anomaly Alerts                                                  |
| -------------- | --------------------------------------------------------------- | --------------------------------------------------------------- |
| Trigger        | You define a dollar threshold                                   | Pump detects deviations from expected patterns                  |
| Best for       | Known cost targets (e.g., "don't exceed $50K/month on compute") | Catching unexpected changes you would not have set a budget for |
| Setup required | Create a budget with scope and thresholds                       | Minimal. Configure notification channels.                       |
| Scope          | Scoped to specific accounts and/or services                     | Across all connected providers                                  |

Both alert types can be delivered to email and Slack. Using both together gives you coverage for planned limits and unplanned surprises.


# How Pump Secure Works

Pump Secure continuously scans your AWS environment against industry-standard security and compliance frameworks. It surfaces misconfigurations, vulnerabilities, and compliance gaps, ranked by severity, so your team can prioritize what to fix first.

### What Pump Secure Does

Pump Secure runs automated checks across your AWS resources and maps the results to the compliance frameworks you select. Each check evaluates a specific security control (for example, "Ensure there are no publicly accessible RDS instances") and reports whether your resources pass or fail.

Results are organized into a dashboard that shows:

| Dashboard element  | What it shows                                                                                                        |
| ------------------ | -------------------------------------------------------------------------------------------------------------------- |
| Framework cards    | Each active framework displayed as a card with a pass/fail status and percentage score                               |
| Severity breakdown | A summary of all failed checks grouped by severity: Critical, High, Medium, Low                                      |
| Trend over time    | A stacked area chart showing how your total findings have changed over days and weeks                                |
| Findings table     | Every individual check with its name, failed count, passed count, severity level, and which frameworks it applies to |

### How Scanning Works

Pump Secure uses the PUMP\_SECURE IAM role deployed to your AWS account. This role grants read-only access to security-relevant AWS services, including EC2, RDS, S3, IAM, VPC, ECS, EKS, CloudTrail, SecurityHub, GuardDuty, and others.

Scans are non-intrusive. Pump never modifies your infrastructure, creates resources, or writes data to your account. The PUMP\_SECURE role includes the AWS-managed `SecurityAudit` policy plus a custom `PumpSecure` policy that covers additional read-only actions across services like Bedrock, ECR, EFS, Lambda, and API Gateway.

### Supported Cloud Providers

Pump Secure is currently available for AWS. GCP and Azure support is not yet available.

### What Pump Secure Is Not

Pump Secure runs compliance checks and configuration audits. It does not perform active penetration testing, network intrusion testing, or exploit simulation. The "Pump Pentest for AWS" framework option in the framework picker is a Pump-curated set of compliance checks, not an automated pentest.

### Key Concepts

**Framework.** A collection of security controls defined by an industry standard or regulatory body. Examples: AWS Well-Architected Framework, CIS Controls, HIPAA, SOC 2, ISO 27001. Pump Secure supports 39 frameworks. You choose which ones to activate.

**Check.** A single security control that evaluates one aspect of your AWS configuration. A check can map to multiple frameworks. For example, "Ensure no security groups allow ingress from 0.0.0.0/0 to MySQL port 3306" may appear under CIS, AWS Well-Architected, and MITRE ATT\&CK simultaneously.

**Finding.** The result of running a check against a specific resource. A finding is either passed or failed.

**Severity.** Each failed finding is classified as Critical, High, Medium, or Low based on the potential security impact.


# Setting Up Secure

Pump Secure requires a dedicated IAM role in your AWS account. This role is separate from the read-only and Autopilot roles used by Pump Save. Setup takes a few minutes using an AWS CloudFormation stack.

### Prerequisites

Before setting up Pump Secure, you need:

| Requirement                      | Details                                                                                        |
| -------------------------------- | ---------------------------------------------------------------------------------------------- |
| An AWS account connected to Pump | Your account must already be linked via the standard Pump onboarding flow                      |
| AWS Console access               | You need permission to deploy CloudFormation stacks and create IAM roles in the target account |

### Step 1: Start the Secure Setup

Navigate to **Security** in the Pump sidebar. If the PUMP\_SECURE role has not been deployed yet, you will see a prompt to connect your account for security scanning.

Click **Enable Pump Secure**. Pump generates a pre-filled CloudFormation Quick-Create Stack URL specific to your account.

### Step 2: Deploy the CloudFormation Stack

Clicking the setup link opens the AWS Console with a pre-configured CloudFormation stack. The stack creates a single IAM role with two components:

**AWS-managed policy:** `SecurityAudit` (read-only access to security-relevant AWS services).

**Custom policy (`PumpSecure`):** Additional read-only permissions covering services not included in `SecurityAudit`, such as:

| Service category       | Example permissions                                                                          |
| ---------------------- | -------------------------------------------------------------------------------------------- |
| Compute and containers | `ec2:Describe*`, `ecs:Describe*`, `eks:Describe*`, `lambda:GetFunction*`                     |
| Databases              | `rds:Describe*`, `elasticache:Describe*`, `redshift:Describe*`, `dynamodb:GetResourcePolicy` |
| Storage and data       | `s3:GetAccountPublicAccessBlock`, `ecr:GetRegistryScanningConfiguration`, `backup:List*`     |
| Security services      | `securityhub:GetFindings`, `securityhub:BatchImportFindings`, `macie2:GetMacieSession`       |
| Networking             | `ec2:GetEbsEncryptionByDefault`, `ec2:GetSnapshotBlockPublicAccessState`                     |
| Logging and monitoring | `cloudtrail:GetInsightSelectors`, `cloudwatch:Get*`, `logs:FilterLogEvents`                  |
| Identity               | `cognito-idp:GetUserPoolMfaConfig`, `ds:Describe*`                                           |
| API access             | `apigateway:GET` (scoped to REST APIs and HTTP APIs only)                                    |

**The role also includes:**

A trust policy that allows Pump's AWS account to assume the role using `sts:AssumeRole`, gated by an External ID unique to your connection. No other AWS account or principal can assume this role.

A `PumpPingResource` (CloudFormation Custom Resource) that notifies Pump when the stack deployment completes. This triggers automatic activation.

Review the stack details in the AWS Console, then click **Create stack**.

### Step 3: Automatic Activation

Once the CloudFormation stack completes, the `PumpPingResource` notifies Pump that the role is ready. Pump Secure activates automatically. No additional steps are required in the Pump UI.

Your first scan begins shortly after activation. Initial results typically appear within minutes.

### What Pump Secure Can and Cannot Access

**Can access (read-only):**

| Category               | What Pump reads                                                                                                                         |
| ---------------------- | --------------------------------------------------------------------------------------------------------------------------------------- |
| Resource configuration | EC2 instances, security groups, RDS instances, S3 bucket policies, ECS/EKS clusters, Lambda functions, VPC settings, IAM configurations |
| Security service data  | SecurityHub findings, GuardDuty results, CloudTrail insight selectors, Macie session status                                             |
| Compliance metadata    | Backup policies, encryption settings, public access configurations, network ACLs                                                        |

**Cannot access and never requests:**

| Category               | Details                                                                                                              |
| ---------------------- | -------------------------------------------------------------------------------------------------------------------- |
| Data at rest           | No access to S3 object contents, database records, application data, or secrets                                      |
| Write operations       | No ability to create, modify, or delete any resource in your account                                                 |
| Infrastructure changes | No ability to launch instances, modify security groups, or change configurations                                     |
| Billing permissions    | The PUMP\_SECURE role does not include Cost Explorer or billing access (those belong to the separate read-only role) |

### Troubleshooting

**Stack creation failed.** The most common cause is insufficient IAM permissions in your AWS account. You need `iam:CreateRole`, `iam:PutRolePolicy`, `iam:AttachRolePolicy`, and `cloudformation:CreateStack` permissions. Check the CloudFormation Events tab for the specific error.

**Scans not appearing after deployment.** Allow a few minutes for the first scan to complete. If no results appear after 15 minutes, check that the CloudFormation stack status is `CREATE_COMPLETE` in the AWS Console. If the stack is still in progress or failed, review the Events tab for errors.

**Role already exists error.** If you previously deployed and then deleted a Pump Secure stack, the IAM role name may still be reserved. Contact Pump support to generate a new stack URL with a fresh role name.&#x20;


# Frameworks

Pump Secure supports 39 compliance and security frameworks. You choose which frameworks to activate, and Pump runs the corresponding checks against your AWS environment. A single check can map to multiple frameworks, so activating additional frameworks does not necessarily increase scan time.

### Browsing and Activating Frameworks

To manage your active frameworks:

1. Navigate to **Secure** in the Pump sidebar.
2. Click **Manage** next to the "Frameworks" heading at the top of the dashboard.
3. The framework picker opens, showing all 39 available frameworks with toggle switches.
4. Enable the frameworks you want to scan against, then click **Save**.

The **AWS Well-Architected Framework** is enabled by default and marked as "Recommended." You can disable it or add any combination of the other 38 frameworks.

Changes take effect on the next scan cycle. New frameworks will show results once the next scan completes.

### Available Frameworks

#### AWS-Native Frameworks

| Framework                                  | Description                                                                                                                          |
| ------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------ |
| AWS Well-Architected Framework             | AWS best practices for building secure, high-performing, resilient, and efficient infrastructure. Recommended by Pump as a baseline. |
| AWS Account Security Onboarding            | Security checks for newly created or recently connected AWS accounts.                                                                |
| AWS Audit Manager Control Tower Guardrails | Controls aligned with AWS Control Tower governance rules.                                                                            |
| AWS Foundational Security Best Practices   | AWS-curated set of foundational security controls.                                                                                   |
| AWS Foundational Technical Review          | Checks aligned with the AWS Foundational Technical Review (FTR) for AWS Partner solutions.                                           |

#### CIS Controls

| Framework        | Description                                        |
| ---------------- | -------------------------------------------------- |
| CIS Controls 1.4 | Center for Internet Security Controls version 1.4. |
| CIS Controls 1.5 | CIS Controls version 1.5.                          |
| CIS Controls 2.0 | CIS Controls version 2.0.                          |
| CIS Controls 3.0 | CIS Controls version 3.0.                          |
| CIS Controls 6.0 | CIS Controls version 6.0.                          |

#### NIST Frameworks

| Framework               | Description                                                                 |
| ----------------------- | --------------------------------------------------------------------------- |
| NIST 800 171 Revision 2 | Protecting Controlled Unclassified Information (CUI) in nonfederal systems. |
| NIST 800 53 Revision 4  | Security and privacy controls for federal information systems.              |
| NIST 800 53 Revision 5  | Updated security and privacy controls (current revision).                   |
| NIST CSF 1.1            | NIST Cybersecurity Framework version 1.1.                                   |
| NIST CSF 2.0            | NIST Cybersecurity Framework version 2.0 (current).                         |

#### PCI DSS

| Framework | Description                                                 |
| --------- | ----------------------------------------------------------- |
| PCI 3.2.1 | Payment Card Industry Data Security Standard version 3.2.1. |
| PCI 4.0   | PCI DSS version 4.0 (current).                              |

#### ISO Standards

| Framework      | Description                                                      |
| -------------- | ---------------------------------------------------------------- |
| ISO 27001 2013 | Information security management systems (2013 edition).          |
| ISO 27001 2022 | Information security management systems (2022 edition, current). |

#### FedRAMP

| Framework                                     | Description                                                      |
| --------------------------------------------- | ---------------------------------------------------------------- |
| FedRAMP Low Revision 4                        | Federal Risk and Authorization Management Program, Low baseline. |
| FedRAMP Moderate Revision 4                   | FedRAMP Moderate baseline.                                       |
| FedRAMP 20x Key Security Indicators (KSI) Low | FedRAMP 20x KSI Low baseline.                                    |

#### Healthcare and Life Sciences

| Framework                | Description                                                               |
| ------------------------ | ------------------------------------------------------------------------- |
| HIPAA                    | Health Insurance Portability and Accountability Act security controls.    |
| GxP Title 21 CFR Part 11 | FDA regulations for electronic records and signatures.                    |
| GxP EU Annex 11          | EU GMP Annex 11 for computerized systems in pharmaceutical manufacturing. |

#### Financial Services

| Framework                                                  | Description                                                        |
| ---------------------------------------------------------- | ------------------------------------------------------------------ |
| Federal Financial Institutions Examination Council (FFIEC) | IT security standards for US financial institutions.               |
| Reserve Bank of India (RBI)                                | Information security guidelines for Indian financial institutions. |
| SOC 2                                                      | Service Organization Control 2 trust services criteria.            |

#### Government and Public Sector

| Framework                                               | Description                                                              |
| ------------------------------------------------------- | ------------------------------------------------------------------------ |
| Cybersecurity and Infrastructure Security Agency (CISA) | US federal cybersecurity best practices.                                 |
| Esquema Nacional de Seguridad (ENS)                     | Spain's national security framework for public sector.                   |
| KISA ISMS-P 2023                                        | Korea Internet & Security Agency information security management system. |
| KISA ISMS-P 2023 Korean                                 | KISA ISMS-P 2023 (Korean language version).                              |
| SecNumCloud 3.2                                         | French ANSSI cloud security qualification framework.                     |

#### Cloud Security Frameworks

| Framework                                          | Description                                            |
| -------------------------------------------------- | ------------------------------------------------------ |
| Cloud Computing Compliance Criteria Catalogue (C5) | German BSI cloud security standard.                    |
| Common Cloud Controls (CCC)                        | Cross-cloud security control framework.                |
| CSA Cloud Controls Matrix (CCM) 4.0                | Cloud Security Alliance control framework version 4.0. |

#### Threat Intelligence

| Framework     | Description                                                       |
| ------------- | ----------------------------------------------------------------- |
| MITRE ATT\&CK | Adversary tactics and techniques mapped to AWS security controls. |

#### Data Protection

| Framework                                 | Description                                |
| ----------------------------------------- | ------------------------------------------ |
| General Data Protection Regulation (GDPR) | EU data protection and privacy regulation. |

#### Pump-Curated

| Framework            | Description                                                                                                                                                                                      |
| -------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Pump Pentest for AWS | A Pump-curated set of security checks focused on common AWS misconfigurations that would be flagged in a penetration test. This is a compliance-check framework, not an active penetration test. |

### How Frameworks Relate to Checks

Each framework consists of a set of checks. Many checks appear across multiple frameworks. For example, a check like "Ensure no security groups allow ingress from 0.0.0.0/0 to MySQL port 3306" might map to CIS Controls, AWS Well-Architected, MITRE ATT\&CK, and others simultaneously.

In the findings table, the **Frameworks affected** column shows which of your active frameworks each check maps to. This helps you prioritize: a finding that affects five active frameworks is typically more urgent than one that affects a single framework.

### Choosing Frameworks

If you are not sure which frameworks to activate, start with the **AWS Well-Architected Framework** (enabled by default). It provides broad coverage of AWS security best practices without being tied to a specific regulatory requirement.

Add additional frameworks based on your compliance obligations:

| If you need to comply with     | Activate                                             |
| ------------------------------ | ---------------------------------------------------- |
| SOC 2 audit requirements       | SOC 2                                                |
| HIPAA for healthcare data      | HIPAA                                                |
| PCI DSS for payment processing | PCI 3.2.1 or PCI 4.0 (depending on your audit cycle) |
| US federal requirements        | FedRAMP Low or Moderate, NIST 800 53, CISA           |
| EU data protection             | GDPR                                                 |
| ISO certification              | ISO 27001 2022                                       |
| General security hardening     | CIS Controls 3.0 or 6.0, MITRE ATT\&CK               |


# Security Standards and Compliance

Pump Secure maps its checks to 39 compliance and security frameworks. This page explains the major standards, who they apply to, and how Pump Secure helps you track compliance posture against each one.

### How Pump Secure Uses Standards

Pump Secure does not certify your organization as compliant with any standard. Compliance certification requires formal audits, policy documentation, and organizational controls that extend beyond infrastructure configuration.

What Pump Secure does: it continuously checks your AWS resource configurations against the technical controls specified by each standard and reports which controls pass and which fail. This gives you a real-time view of your technical compliance posture and helps you identify gaps before an audit.

### Standards by Category

#### General Cloud Security

**AWS Well-Architected Framework**\
The AWS Well-Architected Framework defines best practices across six pillars: operational excellence, security, reliability, performance efficiency, cost optimization, and sustainability. Pump Secure checks the security pillar controls. This is the default framework enabled for all Pump Secure users and provides the broadest coverage of common AWS misconfigurations.

**Who needs it:** Everyone running workloads on AWS. No regulatory requirement, but widely adopted as a baseline.

**CIS Controls (versions 1.4 through 6.0)**\
The Center for Internet Security (CIS) Controls are a prioritized set of actions to protect organizations and data from known cyber attack vectors. Pump Secure supports multiple versions so you can match the version required by your organization's security policy or audit scope.

**Who needs it:** Organizations that follow CIS benchmarks as part of their security program. Common in enterprises, government contractors, and organizations subject to third-party security assessments.

**MITRE ATT\&CK**\
MITRE ATT\&CK is a knowledge base of adversary tactics and techniques based on real-world observations. Pump Secure maps AWS configuration checks to ATT\&CK techniques, helping you understand which attack patterns your current configuration is exposed to.

**Who needs it:** Security teams focused on threat-informed defense. Useful for red team/blue team exercises and threat modeling.

#### Regulatory Compliance

**SOC 2**\
SOC 2 (Service Organization Control 2) evaluates an organization's controls related to security, availability, processing integrity, confidentiality, and privacy. Pump Secure checks align with the Trust Services Criteria, focusing on the technical controls an auditor would evaluate.

**Who needs it:** SaaS companies, cloud service providers, and any organization that handles customer data and undergoes SOC 2 audits.

**HIPAA**\
The Health Insurance Portability and Accountability Act requires safeguards for protected health information (PHI). Pump Secure checks cover the technical safeguard requirements, including access controls, audit controls, integrity controls, and transmission security.

**Who needs it:** Healthcare providers, health plans, healthcare clearinghouses, and their business associates that handle PHI.

**PCI DSS (versions 3.2.1 and 4.0)**\
The Payment Card Industry Data Security Standard protects cardholder data. Pump Secure checks map to the technical requirements for network security, access control, vulnerability management, and monitoring.

**Who needs it:** Any organization that stores, processes, or transmits credit card data. PCI 4.0 is the current version; 3.2.1 is supported for organizations still transitioning.

**GDPR**\
The General Data Protection Regulation governs data protection and privacy for individuals in the EU. Pump Secure checks focus on the technical measures required for data protection, including encryption, access controls, and data integrity.

**Who needs it:** Any organization that processes personal data of EU residents.

#### US Government and Federal

**FedRAMP (Low, Moderate, 20x KSI Low)**\
The Federal Risk and Authorization Management Program standardizes security assessment for cloud services used by US federal agencies. Pump Secure maps checks to FedRAMP baselines at different impact levels.

**Who needs it:** Cloud service providers seeking FedRAMP authorization or federal agencies evaluating cloud vendor security.

**NIST 800 53 (Revisions 4 and 5)**\
NIST Special Publication 800-53 provides a catalog of security and privacy controls for federal information systems. Revision 5 is the current version. Pump Secure checks map to the technical controls in this catalog.

**Who needs it:** US federal agencies, government contractors, and organizations that use NIST as their control framework.

**NIST Cybersecurity Framework (CSF 1.1 and 2.0)**\
The NIST CSF provides a voluntary framework for managing cybersecurity risk. It is organized around five functions: Identify, Protect, Detect, Respond, and Recover. Pump Secure checks map to the Protect and Detect functions.

**Who needs it:** Any organization looking for a structured approach to cybersecurity risk management. Widely adopted across industries.

**CISA**\
The Cybersecurity and Infrastructure Security Agency publishes best practices for securing critical infrastructure. Pump Secure checks align with CISA's technical guidance.

**Who needs it:** US critical infrastructure operators and organizations following federal cybersecurity guidance.

#### Financial Services

**FFIEC**\
The Federal Financial Institutions Examination Council provides IT security standards for financial institutions regulated by US banking agencies.

**Who needs it:** US banks, credit unions, and financial institutions subject to federal examination.

**Reserve Bank of India (RBI)**\
The RBI publishes information security guidelines for banks and financial institutions operating in India.

**Who needs it:** Financial institutions regulated by the Reserve Bank of India.

#### International and Regional

**Esquema Nacional de Seguridad (ENS)**\
Spain's national security framework for public administration and organizations providing services to the Spanish public sector.

**Who needs it:** Organizations operating in or providing services to Spanish government entities.

**KISA ISMS-P 2023**\
The Korea Internet & Security Agency's information security management system certification standard. Available in both English and Korean.

**Who needs it:** Organizations operating in South Korea or seeking KISA certification.

**SecNumCloud 3.2**\
The French ANSSI (National Cybersecurity Agency) qualification framework for cloud service providers.

**Who needs it:** Cloud providers seeking French government security qualification.

**Cloud Computing Compliance Criteria Catalogue (C5)**\
The German Federal Office for Information Security (BSI) standard for cloud security.

**Who needs it:** Organizations providing cloud services in Germany or to German government entities.

#### Cloud Security Frameworks

**CSA Cloud Controls Matrix (CCM) 4.0**\
The Cloud Security Alliance's control framework for cloud computing, organized into 17 domains covering everything from application security to supply chain management.

**Who needs it:** Organizations seeking alignment with CSA best practices or preparing for CSA STAR certification.

**Common Cloud Controls (CCC)**\
A cross-cloud security control framework designed to provide consistent security evaluation across different cloud providers.

**Who needs it:** Multi-cloud organizations looking for a unified control framework.

#### Healthcare and Life Sciences

**GxP Title 21 CFR Part 11**\
US FDA regulations governing electronic records and electronic signatures in pharmaceutical and medical device manufacturing.

**Who needs it:** Pharmaceutical companies, medical device manufacturers, and biotech firms subject to FDA oversight.

**GxP EU Annex 11**\
EU GMP Annex 11 requirements for computerized systems used in pharmaceutical manufacturing.

**Who needs it:** Pharmaceutical manufacturers operating under EU GMP regulations.

### Reading Your Compliance Results

For each active framework, the Pump Secure dashboard shows:

| Element            | What it means                                                                                                                    |
| ------------------ | -------------------------------------------------------------------------------------------------------------------------------- |
| Pass/Fail badge    | Whether any checks under this framework have failed. "Passed" means all checks passed. "Failed" means at least one check failed. |
| Percentage score   | The percentage of checks that passed. A score of 97% means 97% of applicable checks passed.                                      |
| Findings breakdown | In the findings table, the "Frameworks affected" column shows which active frameworks each failed check maps to.                 |

A high score on one framework does not guarantee a high score on another. Frameworks vary in scope and strictness. An account that scores 97% on AWS Well-Architected may score 65% on HIPAA because HIPAA includes controls that the Well-Architected Framework does not cover.

### Limitations

Pump Secure evaluates **technical infrastructure controls only**. Most compliance standards also require:

| Compliance area         | What Pump Secure does not cover                                         |
| ----------------------- | ----------------------------------------------------------------------- |
| Organizational policies | Written security policies, incident response plans, employee handbooks  |
| Process controls        | Change management procedures, access review cadences, vendor management |
| Physical security       | Data center access, device management, physical media handling          |
| Training                | Security awareness training, role-based training programs               |
| Audit artifacts         | Evidence collection, control narratives, management assertions          |

Use Pump Secure findings as one input to your compliance program, not as a substitute for the full program.

#### **Additional Review**&#x20;

**AWS AI Readiness Assessment**

Alongside the Pump Secure compliance frameworks, Pump can run an AI readiness assessment for customers building or planning generative AI and ML workloads on AWS. This maps to AWS's own guidance for AI workloads: the AWS Well-Architected Generative AI Lens and Machine Learning Lens, which extend the standard Well-Architected Framework Review across all six pillars (operational excellence, security, reliability, performance efficiency, cost optimization, and sustainability) with AI-specific best practices covering model selection, data architecture, prompt engineering, and responsible AI. Pump maps its checks to the relevant lens controls and reports pass/fail status the same way it does for other frameworks, giving customers a clear view of whether their AWS environment (IAM scoping, data handling, encryption, logging, Bedrock/SageMaker configuration, etc.) is ready to support AI workloads before they scale usage.

**Who needs it:** Any organization building, evaluating, or scaling generative AI or ML workloads on AWS — including teams using Bedrock, SageMaker, or self-hosted foundation models. It's especially relevant for teams past the prototype stage and moving toward production, since that's typically when gaps in data governance, model access controls, and cost/scaling architecture start to matter. No regulatory body mandates this the way SOC 2 or HIPAA audits do, but it's increasingly expected by risk and compliance stakeholders — and often by customers or investors doing diligence on a company's AI usage — as evidence that AI systems were built on a reviewed architectural foundation rather than assembled ad hoc.&#x20;

For more information and to be connected to a Pump Solutions Architect, reach out to your Pump Account Manager or <support@pump.co>.&#x20;


# Onboarding

There are several ways in which customers can onboard to AWS, depending on their existing AWS org controls, number of accounts being moved, and&#x20;


# Standard Onboarding

Guides for connecting AWS accounts to Pump, including standard onboarding, multi-account architectures, SSO migration, and management account access.

## Connecting AWS

Pump connects to your AWS account using a cross-account IAM role deployed via CloudFormation. The initial connection grants read-only access to your cost and usage data.

### Prerequisites

| Requirement     | Details                                                |
| --------------- | ------------------------------------------------------ |
| AWS account     | Active account with billing access                     |
| IAM permissions | Ability to create CloudFormation stacks and IAM roles  |
| Pump account    | Sign up at app.pump.co and complete email verification |

### How the connection works

Pump uses AWS's cross-account role pattern. When you deploy the CloudFormation stack, it creates an IAM role in your account that trusts Pump's AWS account. Each connection uses a unique External ID to ensure only Pump can assume the role.

Pump never stores your AWS credentials. Every data request uses temporary STS tokens obtained by assuming the role you created.

### Step 1: Deploy the CloudFormation stack and run a savings estimate

This step grants Pump read-only access to your cost and usage data and generates your savings estimate. Nothing is purchased, and no billing relationship is created at this stage.

1. In the Pump onboarding wizard, select **Connect AWS**.
2. Pump generates a pre-filled CloudFormation Quick-Create URL unique to your account (with your External ID embedded).
3. Click the link to open the AWS Console.
4. Scroll down, check the acknowledgment box, and click **Create stack**.
5. The stack creates:
   * An IAM role with read-only permissions (see Permissions reference below)
   * A custom resource (`Custom::PumpPingResource`) that notifies Pump when the stack completes
6. When the stack finishes, Pump is automatically notified and begins pulling your cost data.
7. Pump generates your savings estimate. This typically takes a few minutes.

The estimate shows how much Pump could have saved you based on your historical usage. If the numbers look good and you are interested in onboarding, proceed to Step 2.

#### Alternative: Estimate from CSV (no permissions required)

If you want to see a savings estimate before granting any AWS access, you can upload Cost Explorer CSVs instead.

1. In the Pump onboarding wizard, select **Estimate savings from CSV**.
2. In your AWS Console, navigate to **Cost Explorer** and export two CSV files:
   * Monthly cost data (last 12 months)
   * Daily cost data (last 3 months)
3. Upload both CSV files to Pump.
4. Pump generates your savings estimate within minutes.

The CSV path provides a directional estimate. The CloudFormation path provides a more detailed estimate because Pump can access granular usage data beyond what CSV exports contain. After reviewing a CSV-based estimate, you can proceed to deploy the CloudFormation stack to connect your account.

#### Alternative: Terraform deployment

If your organization manages infrastructure as code with Terraform, Pump provides a Terraform module as an alternative to CloudFormation. Contact your Pump representative for the module.

### Step 2: Standalone vs. Organization

Pump asks whether your AWS account is part of an AWS Organization.

| Account type                                             | What happens                                                                                                                                                      |
| -------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Standalone account** (not in an Organization)          | Self-serve setup continues. You complete the remaining steps in the wizard.                                                                                       |
| **Organization account** (member of an AWS Organization) | Pump routes you to book a meeting with the Pump team. Organization setups require coordination with your management account and are handled with a Pump engineer. |

### Step 3: Authorize Pump as your billing partner

This step transitions Pump from read-only access to billing partner access. Pump becomes the payer account for your AWS usage.

1. In the Pump wizard, review the billing partner agreement.
2. Accept the Terms of Service and Privacy Policy.
3. Pump deploys an updated IAM role with Autopilot permissions (see Permissions reference below). This adds the ability to purchase commitments (Reserved Instances and Savings Plans) on your behalf.
4. Complete your company details and payment method.

After this step, your account is connected. Pump begins managing your commitments and generating savings.

### What Pump accesses

#### Data Pump reads

| Data source                                            | What Pump pulls                               | How it's used                                        |
| ------------------------------------------------------ | --------------------------------------------- | ---------------------------------------------------- |
| Cost Explorer API                                      | Spend by service, account, region, usage type | Cost visibility, savings calculations, forecasting   |
| Cost and Usage Reports (CUR)                           | Line-item billing data from S3                | RI/SP utilization tracking, detailed cost breakdowns |
| Organizations API                                      | Account structure, organizational units       | Multi-account cost aggregation                       |
| EC2/RDS/ElastiCache/Redshift/OpenSearch Describe calls | Instance types, sizes, utilization metadata   | Right-sizing recommendations                         |
| Compute Optimizer                                      | Resource utilization recommendations          | Infrastructure optimization analysis                 |
| Pricing API                                            | On-demand and commitment pricing              | Savings calculations                                 |
| Reserved Instance/Savings Plan details                 | Existing commitments, utilization, coverage   | Commitment management and renewal planning           |

#### Data Pump never accesses

Pump does not access your application data, infrastructure configurations, S3 bucket contents, IAM users or credentials, CloudWatch logs, or any data outside of billing and resource metadata. Pump cannot create, modify, start, stop, or terminate any AWS resources.

The only write action Pump performs is purchasing commitments (Reserved Instances and Savings Plans) when Autopilot is enabled, and only after you have authorized billing partner access.

### Historical data backfill

When you first connect, Pump backfills up to 12 months of historical cost data from Cost Explorer. CUR-based data backfills from the beginning of your account's billing history.

Ongoing data refreshes happen automatically on a rolling basis.

### Permissions reference

#### Read-only role

Deployed during Step 1. Grants visibility into cost and usage data.

| Permission group       | Actions                                                                        |
| ---------------------- | ------------------------------------------------------------------------------ |
| Cost Explorer          | `ce:Get*`, `ce:List*`                                                          |
| Cost and Usage Reports | `cur:Describe*`, `cur:List*`                                                   |
| Organizations          | `organizations:Describe*`, `organizations:List*`                               |
| EC2                    | `ec2:DescribeInstances`, `ec2:DescribeReservedInstances*`                      |
| RDS                    | `rds:DescribeDBInstances`, `rds:DescribeReservedDBInstances*`                  |
| Redshift               | `redshift:DescribeClusters`, `redshift:DescribeReservedNodes*`                 |
| ElastiCache            | `elasticache:DescribeCacheClusters`, `elasticache:DescribeReservedCacheNodes*` |
| OpenSearch             | `es:DescribeDomains`, `es:DescribeReservedInstances*`                          |
| Savings Plans          | `savingsplans:Describe*`                                                       |
| Pricing                | `pricing:*`                                                                    |

#### Autopilot role

Deployed during Step 3. Includes all read-only permissions plus commitment purchasing.

| Additional permissions | Actions                                               |
| ---------------------- | ----------------------------------------------------- |
| EC2 purchases          | `ec2:PurchaseReservedInstancesOffering`               |
| RDS purchases          | `rds:PurchaseReservedDBInstancesOffering`             |
| Savings Plans          | `savingsplans:*` (includes purchase and modification) |

#### Pump Secure role (optional)

Deployed separately if you enable Pump Secure. Grants read-only access to security-related services.

| Permission group   | Actions                                               |
| ------------------ | ----------------------------------------------------- |
| Security services  | SecurityHub, GuardDuty, CloudTrail, Macie (read-only) |
| Resource inventory | EC2, RDS, ECS, EKS Describe calls                     |

#### Pump Infra role (optional)

Deployed separately for infrastructure analysis features.

| Permission group   | Actions                                 |
| ------------------ | --------------------------------------- |
| Compute Optimizer  | `compute-optimizer:*` (read-only)       |
| Resource inventory | EC2, Lambda, RDS, ECS Describe/Get/List |
| CloudWatch         | Read-only metrics access                |

### Troubleshooting

#### CloudFormation stack failed to create

Verify that your IAM user or role has permissions to create CloudFormation stacks and IAM roles. The stack requires `iam:CreateRole`, `iam:PutRolePolicy`, and `cloudformation:CreateStack` at minimum.

#### Pump is not receiving data after stack creation

The CloudFormation stack includes a custom resource that notifies Pump on completion. If this notification fails (due to network restrictions or Lambda execution limits), contact Pump support at support.pump.co.

#### Organization setup is not self-serve

AWS Organization accounts require coordination between your management account and Pump. If you selected "Organization" during onboarding, a Pump team member will reach out to schedule the setup.


# Multi-Account Setup

If your company runs multiple AWS accounts within an AWS Organization, setup requires coordination with the Pump team. This page covers the options for connecting multi-account environments to Pump.

### Before you start

Run a savings estimate using your management account first. The management account provides the most complete view of your organization's spend and gives Pump an accurate baseline for savings projections.

To confirm which account is your management account, navigate to **AWS Console > Organizations > Accounts** and look for the account labeled "Management account."

\[SCREENSHOT NEEDED: AWS Organizations accounts page showing management account designation]

### Choosing your onboarding path

How you connect depends on your current AWS Organization setup. There are three paths.

| Path                           | Best for                                                                                       | Setup method                                   |
| ------------------------------ | ---------------------------------------------------------------------------------------------- | ---------------------------------------------- |
| **Join Account(s)**            | Organizations with a single active account, no SSO, and no cross-account dependencies          | Self-serve after dissolving your existing org  |
| **Join With Pre-Existing Org** | Organizations with SSO, cross-account logging, or complex multi-account configurations         | Assisted setup with a Pump solutions architect |
| **Consent to Assign (CTA)**    | Organizations with security or compliance constraints that require a different ownership model | Assisted setup at Pump's discretion            |

### Path 1: Join Account(s)

This path is recommended if you do not have SSO configured for your AWS Organization and do not have cross-account communication dependencies (shared logging, centralized security, cross-account IAM roles).

An AWS account can only belong to one Organization at a time. To join Pump's Organization, you first dissolve your existing one.

#### Steps

1. Log in to the AWS Console using your management account.
2. Navigate to **Organizations > Settings**.
3. Click **Delete organization**.
4. All member accounts become standalone accounts.
5. For each standalone account, follow the standard Pump onboarding flow (deploy the CloudFormation stack, authorize Pump as billing partner).

\[SCREENSHOT NEEDED: AWS Organizations Settings page with Delete Organization button]

To add multiple standalone accounts to Pump, navigate to **Settings > Integrations > New Account** in the Pump dashboard and deploy a CloudFormation stack for each account.

#### What to evaluate before dissolving your org

Dissolving an AWS Organization affects several services. Review each before proceeding.

| Area                            | Impact                                                                                                                                         |
| ------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------- |
| Access control                  | If you have SSO configured through AWS IAM Identity Center, dissolving the org will disrupt SSO access. Do not use this path if SSO is active. |
| Cross-account logging           | Centralized CloudTrail, AWS Config, or security logging may stop working if they depend on the org structure.                                  |
| Service Control Policies (SCPs) | All SCPs are removed when the org is dissolved. Any access restrictions enforced by SCPs will no longer apply.                                 |
| Consolidated billing            | Member accounts begin accruing charges independently until they join Pump's org.                                                               |
| Organizational Units (OUs)      | OU structure is lost. Pump can recreate your OU structure within its org if needed.                                                            |

If any of these apply to your environment, use Path 2 instead.

### Path 2: Join With Pre-Existing Org

This path is for organizations with SSO, cross-account configurations, or other dependencies that make dissolving the org impractical.

This is an assisted process. Contact the Pump team by booking a call, sending a message via Slack, or emailing <support@pump.co> to discuss the setup.

#### How it works

1. Pump provisions a new AWS Organization for your company.
2. Your accounts are moved into the Pump-managed org.
3. You run a Pump-provided script to export your existing organization infrastructure, including SSO configuration (IAM Identity Center), Resource Access Manager (RAM) shares, SCPs, and other org-level policies.
4. You are provided a delegated administrator account within the new org. You run an import script as the delegated admin to restore your org-level configuration.
5. Pump recreates your OU structure within the new org.

#### What you retain

| Access                  | Details                                                  |
| ----------------------- | -------------------------------------------------------- |
| Delegated admin account | Full access to org-level management services             |
| Root access             | You maintain root access over all of your accounts       |
| SSO                     | Restored via the export/import process (see SSO on Pump) |

### Path 3: Consent to Assign (CTA)

See the dedicated Joining via CTA page for this path.

### Adding accounts after initial setup

Once your initial setup is complete, you can add additional AWS accounts to Pump at any time.

1. Navigate to **Settings > Integrations > New Account** in the Pump dashboard.
2. Deploy a new CloudFormation stack for each account, following the same process as initial onboarding.

Each account requires its own CloudFormation stack and IAM role.

### StackSets for bulk deployment

If you manage many AWS accounts, Pump supports CloudFormation StackSets to deploy the IAM role across multiple accounts in a single operation. This avoids deploying individual stacks per account.

Contact your Pump representative for StackSet configuration. The StackSet deploys the same read-only (and optionally Autopilot) IAM role to every target account in your org.


# Joining via CTA

Some organizations have security or compliance constraints that require a different onboarding model. In these cases, Pump can onboard your AWS account through a Consent to Assign (CTA) agreement. CTA transfers the ownership and billing of your AWS management account to Pump so Pump can fully manage billing and savings optimization on your behalf.

CTA is offered at Pump's discretion and is not available to all customers.

### When CTA is used

CTA is typically used when:

| Scenario                                                                  | Why CTA fits                                                                                  |
| ------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------- |
| Organizational security policies prevent joining another AWS Organization | CTA transfers management account ownership rather than moving member accounts between orgs    |
| Compliance requirements dictate specific billing ownership structures     | CTA formalizes the billing relationship at the account ownership level                        |
| The standard multi-account onboarding paths are not feasible              | CTA provides an alternative when Path 1 (dissolve org) and Path 2 (import org) cannot be used |

### How the CTA process works

#### Step 1: Discovery

Pump reviews your setup on a discovery call to confirm whether CTA is the right fit.

During this step, you deploy a read-only CloudFormation stack and run a savings estimate to evaluate the potential value of joining Pump. This is the same read-only flow used in standard onboarding.

#### Step 2: CTA agreement

Once you decide to move forward, Pump shares the CTA agreement. As part of this process:

1. You update the root user email address of the AWS management account to a Pump-provided address.
2. Pump updates the billing details of the management account.

#### Step 3: Onboarding

You deploy the Autopilot CloudFormation stack to grant Pump access to billing and savings optimization. This is the same Autopilot role used in standard onboarding.

After the CTA is completed, Pump manages your billing and commitment purchases.

### Distributor discount

After the CTA is completed, your AWS account will show a distributor discount in the AWS Console. This is a standard AWS construct that appears when working with an AWS Partner.

Key details about the distributor discount:

| Detail                   | Explanation                                                                                                                         |
| ------------------------ | ----------------------------------------------------------------------------------------------------------------------------------- |
| What it is               | A standard AWS billing line item applied to accounts managed by an AWS Partner                                                      |
| Who receives it          | The discount primarily flows to Ingram Micro (Pump's distribution partner), with a portion flowing back to Pump                     |
| Impact on your pricing   | None. Your pricing, savings, and billing with Pump remain exactly as agreed.                                                        |
| How to read your balance | Exclude the distributor discount line item when comparing your actual costs. The discount does not represent savings passed to you. |

### What does not change

Your infrastructure, workloads, and configurations are unaffected by the CTA process. You retain full control of your AWS resources. The CTA changes billing ownership and management account root credentials only.


# Management Account Access

When your AWS account joins Pump's Organization, Pump creates a role called PumpCustomerAccess in your organization's management account. This role gives your team direct access to organization-level

### What the PumpCustomerAccess role provides

The role grants read/write access to organization-level services only. This includes:

| Service category        | Examples                                                                |
| ----------------------- | ----------------------------------------------------------------------- |
| Security and compliance | AWS CloudTrail, AWS Config, Amazon Inspector                            |
| Cost management         | Cost allocation tags, billing preferences                               |
| Organization services   | Other organization-wide features that require management account access |

### What the role does not provide

The PumpCustomerAccess role is scoped to organization-level services. It does not allow:

| Restriction       | Details                                                                                                              |
| ----------------- | -------------------------------------------------------------------------------------------------------------------- |
| Resource creation | You cannot create EC2 instances, Lambda functions, ECS tasks, or any other resources in the management account       |
| IAM access        | You cannot modify IAM users, roles, or policies in the management account                                            |
| SSO management    | IAM Identity Center (formerly AWS SSO) is managed through the delegated administrator account, not through this role |

Your existing account-level and billing-level setup is not affected by this role.

### How to access the management account

1. Confirm your IAM user or role is in a child account of the management account.
2. Confirm your user or role has the `sts:AssumeRole` permission.
3. Find your Management Account ID: navigate to **AWS Organizations > Dashboard > Management Account ID**.
4. In the AWS Console, click your username in the top-right corner.
5. Click **Switch Role**.
6. Enter:
   * **Account ID:** your Management Account ID
   * **Role name:** `PumpCustomerAccess`
7. Click **Switch Role**.

You now have access to organization-level services through the management account.

### Restricting access

By default, any user in a child account with `sts:AssumeRole` permission can switch into the PumpCustomerAccess role. If you want to restrict access to specific accounts, users, or groups, contact Pump and the team can apply tighter trust policy constraints.

### Viewing exact permissions

The full policy document for the PumpCustomerAccess role is available at:

<https://pump-public-readonly.s3.us-west-2.amazonaws.com/PumpCustomerManagementAccess>


# Downloading Your AWS Cost Explorer History

When you join Pump's AWS Organization, your AWS Cost Explorer data resets. This is standard AWS behavior: Cost Explorer history does not carry over when an account moves to a new billing organization.

Pump backfills and retains your historical cost data within the Pump dashboard. However, if you want to keep a copy of your raw AWS Cost Explorer data for your own records, download it before completing the onboarding process.

This takes about 2 minutes.

### Steps

1. Log in to the AWS Console.
2. Navigate to **Billing and Cost Management** (search for it in the console search bar).
3. In the left menu, scroll near the bottom and select **Cost Management Preferences**.
4. Click the **Cost Explorer** tab (second tab from the left).
5. Check the box for **Enable 38 months of past cost and usage data**.
6. Click **Save**, then confirm by clicking **Save** again in the popup.
7. In the left menu, click **Cost Explorer** (just below Cost Usage Analysis).
8. In the top right of the Cost Explorer page, open the **Date Range** selector.
9. Click **More** at the bottom right of the date range popup.
10. Select **3 years** of data.
11. Click **Download CSV** (button located below the graph on the right).

### When to do this

Download your Cost Explorer history before completing Step 3 (Authorize Pump as billing partner) of the AWS onboarding flow. Once your account joins Pump's Organization, the Cost Explorer history in the AWS Console resets.

### What Pump retains

Pump backfills up to 12 months of historical cost data from Cost Explorer when you first connect. CUR-based data backfills from the beginning of your account's billing history. Your full cost history is available in the Pump View dashboards after onboarding.

The CSV download is an optional backup for your own records, not a requirement for using Pump.


# AWS Role Deployment and Permissions

## Role Permissions <a href="#undefined" id="undefined"></a>

Pump only takes permissions at a billing level, so customers retain full control of their accounts and cloud services.

Pump operates through 2 types of roles: Read-only and Auto-pilot.

#### Read Only Role <a href="#undefined" id="undefined"></a>

This role is used during the initial [onboarding step (Step 1)](https://help.pump.co/getting-started/step-1-view-estimate). It requires read-only permissions to access up to one year of historical billing data (via Cost Explorer) and your AWS infrastructure metadata (such as the Redshift cluster you are using and whether it is already covered by reserved instances). After ingesting this data, Pump's billing engine calculates optimal savings. Once a user is fully onboarded, the read-only role is used again to display cost and savings on the Pump dashboard, helping users monitor their current spending and the savings achieved by Pump.

The specific permissions associated with the Read-only role can be found in the dropdown below.

[Read-only Role JSON](https://pump-public-readonly.s3.us-west-2.amazonaws.com/pump-readonly.json)

```plaintext
{
  "Parameters": {
    "PumpID": {
      "Description": "The Pump customer ID that syncs your account. Please don't change or share this.",
      "MinLength": "1",
      "Type": "String"
    },
    "PumpExternalID": {
      "Description": "The Pump external ID that authenticates your account. Please don't change or share this.",
      "MinLength": "1",
      "Type": "String"
    },
    "PumpIamRole": {
      "Description": "The Pump IAM role that has permission to your account.",
      "MinLength": "1",
      "Type": "String"
    },
    "PumpPingbackArn": {
      "Description": "The arn used to communicate back to Pump.",
      "MinLength": "1",
      "Type": "String"
    },
    "PumpRoleType": {
      "Description": "The type of the role Pump is creating.",
      "MinLength": "1",
      "Type": "String"
    },
    "AccountState": {
      "Description": "The current state of the account.",
      "MinLength": "0",
      "Type": "String"
    }
  },
  "Resources": {
    "CrossAccountRole": {
      "Type": "AWS::IAM::Role",
      "Properties": {
        "AssumeRolePolicyDocument": {
          "Statement": [
            {
              "Effect": "Allow",
              "Principal": {
                "AWS": {
                  "Ref": "PumpIamRole"
                }
              },
              "Action": [
                "sts:AssumeRole"
              ],
              "Condition": {
                "StringEquals": {
                  "sts:ExternalId": {
                    "Ref": "PumpExternalID"
                  }
                }
              }
            }
          ]
        },
        "Path": "/",
        "Policies": [
          {
            "PolicyName": "PumpBillingReadOnly",
            "PolicyDocument": {
              "Version": "2012-10-17",
              "Statement": [
                {
                  "Action": [
                    "account:GetContactInformation",
                    "account:ListRegions",
                    "athena:GetCapacityAssignmentConfiguration",
                    "athena:GetCapacityReservation",
                    "athena:ListCapacityReservations",
                    "athena:ListTableMetadata",
                    "bedrock:GetProvisionedModelThroughput",
                    "bedrock:ListProvisionedModelThroughputs",
                    "ce:Get*",
                    "ce:List*",
                    "cur:Describe*",
                    "cur:List*",
                    "organizations:Describe*",
                    "organizations:List*",
                    "iam:GetPolicyVersion",
                    "iam:ListPolicies",
                    "freetier:GetFreeTierUsage",
                    "pricing:DescribeServices",
                    "pricing:GetAttributeValues",
                    "pricing:GetProducts",
                    "pricing:ListPriceLists",
                    "savingsplans:Describe*",
                    "servicequotas:Get*",
                    "servicequotas:List*",
                    "taxsettings:Get*",
                    "taxsettings:List*",
                    "ec2:DescribeInstances",
                    "ec2:DescribeReservedInstances",
                    "ec2:DescribeReservedInstancesListings",
                    "ec2:DescribeReservedInstancesModifications",
                    "ec2:DescribeReservedInstancesOfferings",
                    "ec2:GetCapacityReservationUsage",
                    "ec2:GetReservedInstancesExchangeQuote",
                    "redshift:DescribeReservedNodeOfferings",
                    "redshift:DescribeReservedNodes",
                    "redshift:DescribeClusters",
                    "redshift:DescribeReservedNodeExchangeStatus",
                    "redshift:GetReservedNodeExchangeConfigurationOptions",
                    "redshift:GetReservedNodeExchangeOfferings",
                    "rds:DescribeReservedDBInstances",
                    "rds:DescribeDBInstances",
                    "rds:DescribeDBClusters",
                    "rds:DescribeReservedDBInstancesOfferings",
                    "elasticache:DescribeReservedCacheNodesOfferings",
                    "elasticache:DescribeServerlessCaches",
                    "elasticache:DescribeReservedCacheNodes",
                    "elasticache:DescribeCacheClusters",
                    "es:DescribeDomainNodes",
                    "es:DescribeReservedElasticsearchInstanceOfferings",
                    "es:DescribeReservedElasticsearchInstances",
                    "es:DescribeReservedInstanceOfferings",
                    "es:DescribeElasticsearchDomain",
                    "es:DescribeDomains",
                    "es:DescribeDomain",
                    "es:DescribeElasticsearchDomains",
                    "es:DescribeReservedInstances",
                    "medialive:ListReservations",
                    "medialive:DescribeReservation",
                    "medialive:ListClusters",
                    "medialive:DescribeCluster",
                    "medialive:DescribeNode",
                    "medialive:ListOfferings",
                    "medialive:DescribeOffering",
                    "medialive:ListNodes",
                    "memorydb:DescribeReservedNodesOfferings",
                    "memorydb:DescribeClusters",
                    "memorydb:DescribeReservedNodes",
                    "dynamodb:DescribeReservedCapacityOfferings",
                    "dynamodb:DescribeReservedCapacity"
                  ],
                  "Resource": "*",
                  "Effect": "Allow"
                }
              ]
            }
          }
        ]
      }
    },
    "PumpPingResource": {
      "Type": "Custom::PumpPingResource",
      "DeletionPolicy": "Retain",
      "Version": "1.0",
      "Properties": {
        "ServiceToken": {
          "Ref": "PumpPingbackArn"
        },
        "RoleArn": {
          "Fn::GetAtt": [
            "CrossAccountRole",
            "Arn"
          ]
        },
        "PumpID": {
          "Ref": "PumpID"
        },
        "ExternalID": {
          "Ref": "PumpExternalID"
        },
        "AccountID": {
          "Ref": "AWS::AccountId"
        },
        "RoleType": {
          "Ref": "PumpRoleType"
        },
        "AccountState": {
          "Ref": "AccountState"
        }
      }
    }
  },
  "Outputs": {
    "RoleArn": {
      "Value": {
        "Fn::GetAtt": [
          "CrossAccountRole",
          "Arn"
        ]
      },
      "Description": "The ARN value of the Cross-Account Role with IAM read-only permissions. Add this ARN value to Pump."
    }
  }
}
```

#### Auto-pilot Role <a href="#undefined" id="undefined"></a>

This role is employed after the[ final onboarding step](https://help.pump.co/getting-started/step-1-view-estimate). It includes all the permissions from the read-only role, as well as additional read-only permissions for collecting service usage metadata, such as compute instance metadata. Note that Pump does not collect application data or user data—only usage metadata is collected. In addition to gathering usage metadata, the auto-pilot role also requires permission to buy and sell reserved instances and savings plans. Pump's AI algorithms process the usage metadata and manage cost commitments on behalf of users.

The specific permissions associated with the Auto-pilot role can be found in the dropdown below.

[Auto-pilot Role JSON](https://pump-public-readonly.s3.us-west-2.amazonaws.com/pump-auto-pilot.json)

```plaintext
{
  "Parameters": {
    "PumpID": {
      "Description": "The Pump customer ID that syncs your account. Please don't change or share this.",
      "MinLength": "1",
      "Type": "String"
    },
    "PumpExternalID": {
      "Description": "The Pump external ID that authenticates your account. Please don't change or share this.",
      "MinLength": "1",
      "Type": "String"
    },
    "PumpIamRole": {
      "Description": "The Pump IAM role that has permission to your account.",
      "MinLength": "1",
      "Type": "String"
    },
    "PumpPingbackArn": {
      "Description": "The arn used to communicate back to Pump.",
      "MinLength": "1",
      "Type": "String"
    },
    "PumpRoleType": {
      "Description": "The type of the role Pump is creating.",
      "MinLength": "1",
      "Type": "String"
    },
    "AccountState": {
      "Description": "The current state of the account.",
      "MinLength": "0",
      "Type": "String"
    }
  },
  "Resources" : {
    "CrossAccountRole" : {
      "Type" : "AWS::IAM::Role",
      "Properties" : {
        "AssumeRolePolicyDocument" : {
          "Statement" : [{
            "Effect" : "Allow",
            "Principal" : {
              "AWS" : {"Ref": "PumpIamRole"}
            },
            "Action" : [
              "sts:AssumeRole"
            ],
            "Condition" : {
              "StringEquals" : {
                "sts:ExternalId" : {"Ref": "PumpExternalID"}
              }
            }
          }]
        },
        "Path": "/",
        "Policies" : [
          {
            "PolicyName": "PumpOrgInvite",
            "PolicyDocument": {
              "Version": "2012-10-17",
              "Statement": [
                {
                  "Action": [
                    "organizations:Describe*",
                    "organizations:List*",
                    "organizations:AcceptHandshake",
                    "iam:CreateServiceLinkedRole"
                  ],
                  "Resource": "*",
                  "Effect": "Allow"
                }
              ]
            }
          },
          {
            "PolicyName": "PumpReadOnly",
            "PolicyDocument": {
              "Version": "2012-10-17",
              "Statement": [
                {
                  "Action": [
                    "account:GetContactInformation",
                    "account:ListRegions",
                    "athena:GetCapacityAssignmentConfiguration",
                    "athena:GetCapacityReservation",
                    "athena:ListCapacityReservations",
                    "athena:ListTableMetadata",
                    "bedrock:GetProvisionedModelThroughput",
                    "bedrock:ListProvisionedModelThroughputs",
                    "ce:*",
                    "cur:*",
                    "organizations:Describe*",
                    "organizations:List*",
                    "iam:GetPolicyVersion",
                    "iam:ListPolicies",
                    "freetier:GetFreeTierUsage",
                    "pricing:DescribeServices",
                    "pricing:GetAttributeValues",
                    "pricing:GetProducts",
                    "pricing:ListPriceLists",
                    "savingsplans:Describe*",
                    "servicequotas:Get*",
                    "servicequotas:List*",
                    "taxsettings:Get*",
                    "taxsettings:List*",
                    "ec2:DescribeInstances",
                    "ec2:DescribeReservedInstances",
                    "ec2:DescribeReservedInstancesListings",
                    "ec2:DescribeReservedInstancesModifications",
                    "ec2:DescribeReservedInstancesOfferings",
                    "ec2:GetCapacityReservationUsage",
                    "ec2:GetReservedInstancesExchangeQuote",
                    "redshift:DescribeReservedNodeOfferings",
                    "redshift:DescribeReservedNodes",
                    "redshift:DescribeClusters",
                    "redshift:DescribeReservedNodeExchangeStatus",
                    "redshift:GetReservedNodeExchangeConfigurationOptions",
                    "redshift:GetReservedNodeExchangeOfferings",
                    "rds:DescribeReservedDBInstances",
                    "rds:DescribeDBInstances",
                    "rds:DescribeDBClusters",
                    "rds:DescribeReservedDBInstancesOfferings",
                    "elasticache:DescribeReservedCacheNodesOfferings",
                    "elasticache:DescribeServerlessCaches",
                    "elasticache:DescribeReservedCacheNodes",
                    "elasticache:DescribeCacheClusters",
                    "es:DescribeDomainNodes",
                    "es:DescribeReservedElasticsearchInstanceOfferings",
                    "es:DescribeReservedElasticsearchInstances",
                    "es:DescribeReservedInstanceOfferings",
                    "es:DescribeElasticsearchDomain",
                    "es:DescribeDomains",
                    "es:DescribeDomain",
                    "es:DescribeElasticsearchDomains",
                    "es:DescribeReservedInstances",
                    "medialive:ListReservations",
                    "medialive:DescribeReservation",
                    "medialive:ListClusters",
                    "medialive:DescribeCluster",
                    "medialive:DescribeNode",
                    "medialive:ListOfferings",
                    "medialive:DescribeOffering",
                    "medialive:ListNodes",
                    "memorydb:DescribeReservedNodesOfferings",
                    "memorydb:DescribeClusters",
                    "memorydb:DescribeReservedNodes",
                    "dynamodb:DescribeReservedCapacityOfferings",
                    "dynamodb:DescribeReservedCapacity"
                  ],
                  "Resource": "*",
                  "Effect": "Allow"
                }
              ]
            }
          },
          {
            "PolicyName": "PumpAutoPilot",
            "PolicyDocument": {
              "Version": "2012-10-17",
              "Statement": [
                {
                  "Action": [
                    "athena:CancelCapacityReservation",
                    "athena:CreateCapacityReservation",
                    "athena:DeleteCapacityReservation",
                    "athena:PutCapacityAssignmentConfiguration",
                    "athena:UpdateCapacityReservation",
                    "bedrock:CreateProvisionedModelThroughput",
                    "bedrock:DeleteProvisionedModelThroughput",
                    "bedrock:UpdateProvisionedModelThroughput",
                    "cloudfront:CreateSavingsPlan",
                    "cloudfront:UpdateSavingsPlan",
                    "dynamodb:PurchaseReservedCapacityOfferings",
                    "ec2:AcceptReservedInstancesExchangeQuote",
                    "ec2:CancelReservedInstancesListing",
                    "ec2:CreateReservedInstancesListing",
                    "ec2:DeleteQueuedReservedInstances",
                    "ec2:ModifyReservedInstances",
                    "ec2:PurchaseHostReservation",
                    "ec2:PurchaseReservedInstancesOffering",
                    "ec2:CreateTags",
                    "elasticache:PurchaseReservedCacheNodesOffering",
                    "es:PurchaseReservedInstanceOffering",
                    "es:PurchaseReservedElasticsearchInstanceOffering",
                    "medialive:PurchaseOffering",
                    "rds:PurchaseReservedDbInstancesOffering",
                    "redshift:AcceptReservedNodeExchange",
                    "redshift:PurchaseReservedNodeOffering",
                    "savingsplans:*",
                    "servicequotas:RequestServiceQuotaIncrease",
                    "support:*",
                    "budgets:Describe*",
                    "budgets:View*",
                    "budgets:List*",
                    "autoscaling:Describe*",
                    "autoscaling:GetPredictiveScalingForecast",
                    "application-autoscaling:Describe*",
                    "application-autoscaling:GetPredictiveScalingForecast",
                    "application-autoscaling:ListTagsForResource",
                    "autoscaling-plans:GetScalingPlanResourceForecastData",
                    "autoscaling-plans:DescribeScalingPlans",
                    "autoscaling-plans:DescribeScalingPlanResources",
                    "memorydb:PurchaseReservedNodesOffering",
                    "memorydb:TagResource"
                  ],
                  "Resource": "*",
                  "Effect": "Allow"
                }
              ]
            }
          }
        ]
      }
    },
    "PumpPingResource" : {
      "Type" : "Custom::PumpPingResource",
      "DeletionPolicy" : "Retain",
      "Version" : "1.0",
      "Properties" : {
        "ServiceToken" : {
          "Ref": "PumpPingbackArn"
        },
        "RoleArn" : {
          "Fn::GetAtt": [ "CrossAccountRole", "Arn" ]
        },
        "PumpID" : {
          "Ref": "PumpID"
        },
        "ExternalID": {
          "Ref": "PumpExternalID"
        },
        "AccountID": {
          "Ref": "AWS::AccountId"
        },
        "RoleType": {
          "Ref": "PumpRoleType"
        },
        "AccountState": {
          "Ref": "AccountState"
        }
      }
    }
  },
  "Outputs" : {
    "RoleArn" : {
      "Value" : {"Fn::GetAtt": [ "CrossAccountRole", "Arn" ]},
      "Description" : "The ARN value of the Cross-Account Role with IAM read-only permissions. Add this ARN value to Pump."
    }
  }
}
```

## Role Deployment <a href="#undefined" id="undefined"></a>

Pump automates cross-account role deployment using [AWS CloudFormation](https://aws.amazon.com/cloudformation/) (CFN) and, more specifically, "[quick-create links.](https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/cfn-console-create-stacks-quick-create-links.html)" These links enable Pump to pass a CFN template along with user-specific parameters, such as the cross-account role, external ID, Pump ID, and more.

Users only need to click the quick-create link and then click "deploy" to have the role deployed to their AWS account. The CFN templates are stored publicly, allowing users to review them before agreeing to the deployment. These can be viewed in the section above.

#### Viewing, Deleting, and Redeploying Roles <a href="#undefined" id="undefined"></a>

Pump gains billing-level access to your accounts through IAM roles. You can view any active role in the IAM console on the AWS platform.

Roles can also be deleted at any time from the IAM console. Deleting a role will not affect the status of your workloads or interrupt access to cloud resources. However, **deleting or editing roles** **will cause** **Pump to lose visibility on your cloud usage and interrupt your savings services**.

In the event that you accidentally delete our role or need to deploy an additional role, role deployments can be done through our platform for existing customers. To deploy a role from our platform, begin by navigating to Settings > Integrations. Click the three dots next to the account you wish to deploy a role to, and select which role you wish to deploy.

During deployment, after role creation, a list of properties is sent to Pump's management account:

* Pump ID
* Cross-account role ARN
* Pump external ID
* User's account ID
* Role type (read-only or auto-pilot)

#### Access Management <a href="#undefined" id="undefined"></a>

**Restricted Access**

Pump adheres to AWS security best practices rigorously. We restrict the cross-account role for use only by Pump's management account with the correct external ID.

**Read-only permissions**

We also limit permissions so that Pump can only access your billing data and infrastructure metadata, which does not include any application data or user data. An example of the information we extract from your infrastructure metadata is as follows:

> Six t2.micro on-demand instance types have been running continuously for the past 8 months, with consistent network traffic and an average CPU utilization of over 60%. Based on the last 4 months of AWS marketplace RI listing data, we can determine that t2.micro liquidity is high (it will take little time to sell this instance back to the marketplace). We recommend starting a 3-year, no-upfront RI order for 6 t2.micro instances and using algorithms to find the best deals for all 6 instances in the marketplace.

Beyond that, Pump can only buy or sell reserved instances on your behalf.

**App authentication and authorization**

Pump uses Auth0 as our authentication platform, which is compliant with nearly all security certifications, such as GDPR, HIPAA, ISO27018, SOC II, ISO27001, etc. You can read [more](https://auth0.com/security) here.

**Security auditing**

Pump engages third-party companies to conduct regular penetration testing to identify any potential security risks. Additionally, we are in the process of obtaining SOC II certification.

#### Other Housekeeping and Permissions

**Cloudformation stacks created**

Do not delete the CloudFormation stacks that were created during the initial onboarding. We use the permissions granted during then that helps us purchase and sell RIs/Savings plan on your behalf.&#x20;

<figure><img src="/files/jSutATHlDaCeLoxMxB7g" alt=""><figcaption></figcaption></figure>

If you have any further questions, please contact us at <support@pump.co>

**Should I purchase RIs or savings plans in future**

Pump is 100% responsible for all the purchase decisions we make on your behalf. That means you have no financial risk when it comes to commitments. If you don't end up using a savings plan or RI that we purchased for you, Pump provides a money-back guarantee after 30 days of no use in the form of an AWS credit.&#x20;

If you were to make these purchases on your own, Pump would not take responsibility, and the risk would be on you. We strongly recommend that you avoid doing this.

**Spinning up an AWS service or discontinuing one**

Pump AI continuously scans your purchase history and tries to forecast your future spend. While AI can do its job well, we recommend that you inform us of your plans in advance (if possible) so that we can be even more efficient with our commitments. You can leave us a message on the chat or email us at <support@pump.co>. We will soon embed this feature in the product itself to make it more convenient.

#### Additional Info

If CloudFormation deployments do not work for your infrastructure, we also offer deployments on Terraform. Please contact our support team for more information at <support@pump.co>


# SSO on Pump

If your AWS Organization uses SSO through IAM Identity Center (formerly AWS SSO), Pump migrates your SSO configuration to the new Pump-managed organization as part of the onboarding process. This is a guided process with a Pump solutions architect.

### Overview

When you join Pump with a pre-existing AWS Organization, Pump provisions a new org and provides you with a delegated administrator account. Your SSO configuration (users, groups, permission sets) is exported from your current org and imported into the new one.

Total time: approximately 30 to 45 minutes on a call with a Pump solutions architect, plus about 5 minutes of preparation beforehand.

### Before the call (approximately 5 minutes)

1. Provide Pump with an email address to use for the root user of the delegated administrator account.
2. Specify the AWS region where you want SSO enabled.
3. Pump provisions the new organization with the delegated admin account and SSO enabled in your specified region.
4. Log in to the delegated admin account using the email you provided. Use the "forgot my password" flow to set a password.

### On the call (30 to 45 minutes)

| Step                               | What happens                                                                                                                                                                    |
| ---------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| 1. Export existing SSO             | While screen-sharing, log into your current management account and run an export script in IAM Identity Center. This downloads your current users, groups, and permission sets. |
| 2. Import to new org               | Log into the new delegated administrator account and run an import script to upload your users, groups, and permission sets into the new organization.                          |
| 3. Third-party IdP (if applicable) | If you use a third-party identity provider (Okta, Azure AD, Google Workspace, etc.), create a new SAML or SCIM application that points to the new IAM Identity Center instance. |
| 4. Test                            | Verify SSO access by logging in through your identity provider and confirming access to your accounts.                                                                          |

### After migration

Your SSO works exactly as before. Users log in through the same identity provider, access the same accounts, and have the same permission sets. The only difference is that IAM Identity Center now runs in the Pump-managed organization's delegated admin account instead of your previous management account.

### Important notes

IAM Identity Center is managed through the delegated administrator account, not through the PumpCustomerAccess role on the management account. If you need to make changes to SSO configuration after migration (adding users, modifying permission sets), log into the delegated admin account.


# Using Pump

Welcome to Pump! We have two modes of achieving savings... manual, and autopilot, both are designed to save you money on your AWS!

**🤖Autopilot** is where we handle 100% of your FinOps decisions from the day you join our organization, providing savings without financial risk of commitment.

**🎛️Manual** is where you get the recommendations from **Pumps Risk Engine🧪** on our dashboard, and can make choices based on that.

**The best thing?** You can [**switch the modes**](https://app.pump.co/recommendations) whenever you decide to change, and it's always free! 🎉

The nice thing about Pump, is for low risk recommendations, we take on the risk ([**as per our terms**](https://help.pump.co/getting-started/how-pump-works/money-back-guarantee))! This means you can unlock savings instruments, with lower risk, **all for free**. We offer a 30-day money-back guarantee on purchases; if unused within 30 days, we'll allocate them to other customers, sell them in the marketplace, or provide the equivalent in AWS credits as a last resort. **At the end of the day, you cannot lose money with Pump,** because if we make a mistake, we cover it.

**How much can you save with Pump?** It depends on the recommendations our model generates, based on your usage, but some customers see 50-60%, while others achieve a modest 10-30% (**all for free**)!

Our model generates recommendations here automatically, but you can also always click **Regenerate**.

<figure><img src="/files/Qh4YfDLh4xRE9RQbQCp0" alt=""><figcaption></figcaption></figure>

If you are on manual mode, in order to achieve savings, it's important to click request for recommendations you want to approve, and click block for recommendations you wish not to pursue.&#x20;

Does this sound exciting? [**Check out our Savings Summary**](/aws/using-pump/savings-summary)**!** All your doing is providing read-only level permission to Pump.


# Savings Summary

### Your estimated savings

In minutes, for free, you can see your savings estimate on what we can realistically save you despite your past purchases with reserved instances and savings plans. We calculate this based on your current AWS usage and estimate how much you could save further with Pumps model **for free**.

<figure><img src="/files/4ytJSrL1WDfj9DaGkL9r" alt=""><figcaption></figcaption></figure>

### Your actual savings

*(for current customers)* This is the amount Pump has actually saved you in total vs your historical baseline AWS spending once you have joined! &#x20;

This number will usually increase over time as our model better understands and adapts to your unique spending patterns. It includes all savings from Pump only whether for compute or elsewhere.

<figure><img src="/files/6ZMYKDLnQt9e5lFyrF9F" alt=""><figcaption><p>This is a real customer that saved $6,000 in 30 days.</p></figcaption></figure>


# Past Savings

When you sign up with Pump, our savings model (🤖) analyzes your AWS account spend and excludes services/instances already covered by reserved instances or savings plans, making the estimated savings quite accurate, with no strings attached to join us for free!

If you do decide to 'join Pump' we'll ensure that you achieve 100% coverage, even if your usage grows or if you decide, like some of our customers, to sell your own EC2 reserved instances in the marketplace and earn more savings from us instead.

Pump can handle 100% of your FinOps decisions (if you so choose), providing savings without financial risk of commitment. We also offer a 30-day money-back guarantee on purchases; if unused within 30 days, we'll allocate them to other customers, sell them in the marketplace, or provide the equivalent in AWS credits as a last resort per our policy.

### Have Past Credits? No Problem!

If you have AWS credits, no problem! We can support customers with or without AWS credits. If you have AWS credits and would like to join Pump's organization, please let us know when you self-serve.&#x20;

<figure><img src="/files/w1XvoTh8y2kQrjNl3RGj" alt=""><figcaption></figcaption></figure>


# Reserved Instances

### What are Reserved Instances (RIs)?

AWS Reserved Instances are a way to save money on many computing resources on Amazon Web Services (AWS). With RIs, customers can reserve compute capacity for a specific period (typically one or three years) and receive a significant discount on the hourly charge for that instance type. This can result in cost savings of up to 75% compared to on-demand prices. Essentially, RIs enable customers to prepay for computing capacity and in return, receive a lower cost per hour for that capacity. The best part? You can also buy reserved instances that are "no upfront" meaning there isn't a huge charge at the beginning, and instead, you pay a monthly rate to AWS, still at a discount.

### When are RIs billed?

RIs are billed on your account on the 1st of each month at 12am UTC, just like monthly rent, (except you are saving money 🤑). Therefore, if you or our model has purchased RIs, you may see a big spike in your cost explorer at the beginning of each month.&#x20;

<figure><img src="/files/zAFTmBgHjDTKp9P5xryO" alt=""><figcaption><p>Notice the spikes on the first of each moth? Those are from RI charges. In the month of March this RI is not consumed (hence no Pump savings), and hence Pump sold that RI in the next 30 days. </p></figcaption></figure>

### What happens to the RIs I purchased in the past?

When an account joins a different organization, AWS adjusts the RI billing for the remainder of the month. This is the scenario that occurs when an account joins us. Rest assured that the 1st of the month RI billing is reset, and AWS only bills you for those RIs from the 1st of the month to the day you join Pump. Pump will bill you for the rest of the month.

You can see the RIs purchased by you categorized separately from those bought by Pump.

<figure><img src="/files/PUnSkbRuVELfwDvEU2t5" alt=""><figcaption></figcaption></figure>

### Where can I see my savings from the RIs on AWS console?

To view your savings from Reserved Instances (RIs) on the AWS console, you can use the Cost Explorer tool.&#x20;

1. Sign in to the AWS Management Console > Cost Explorer > RI Coverage tab (on the left hand side)&#x20;
2. Choose the time period you want to view (e.g., last month, last quarter, custom date range).
3. In the "Savings Plans and Reserved Instances" section, you'll see a breakdown of your RI utilization and savings. You can see the number of RI hours used, the effective hourly rate, and the total savings in dollars.

By using the Cost Explorer, you can get a better understanding of how much money you're saving with your RIs and how effectively you're utilizing them. This can help you make informed decisions about future RI purchases and optimize your cloud spending.

Additionally, Pump makes it simple to track RI savings on the Pump app for anyone to directly understand their savings from this category.


# Savings Plans

## What are Savings Plans?

AWS Savings Plans is a pricing model that allows users to commit to a certain amount of usage of EC2 instances or Fargate containers over a one or three year term, in exchange for a discount on the on-demand rate of those resources. It is a flexible and easy-to-use way to save up to 72% on AWS compute usage.

## What do Savings Plans Cover?

|                               | **Savings Plan TypeCovered Services**             |
| ----------------------------- | ------------------------------------------------- |
| **Compute Savings Plan**      | EC2 (any instance type), AWS Lambda, AWS Fargate  |
| **EC2 Instance Savings Plan** | EC2 (specific instance family in a chosen region) |
| **SageMaker Savings Plan**    | SageMaker ML instances                            |

## What if I had Savings Plans from the past?

If you have Savings Plans from the past, those Savings Plans will continue to apply to your eligible usage, and you will continue to receive the associated discounts until the end of their term.

Any unused Savings Plan spend from past Savings Plans will also continue to be available to offset eligible usage charges within the same instance family, size, and region covered by the Savings Plan. If you have previously purchased Savings Plans, we will make our best effort to allocate them to our customers, but we cannot guarantee that we will be able to do so.

## What happens to my unused savings plan spend?

If you have Savings Plans from the past, those Savings Plans will continue to apply to your eligible usage, and you will continue to receive the associated discounts until the end of their term.

Any unused Savings Plan spend from past Savings Plans will also continue to operate as normal and be able available to offset eligible usage charges within the same instance family, size, and region covered by the Savings Plan. If you have previously purchased Savings Plans, we will make our best effort to allocate them to our customers, but we cannot guarantee that we will be able to do so.

## Where do I see these savings on AWS console?

To see the savings you have made with AWS Savings Plans > Cost Explorer console > Savings Plans tab, which will show you a breakdown of your savings by plan, region, and usage type.&#x20;

You can also view your savings in the AWS Billing and Cost Management dashboard, where you can download a Savings Plans utilization report to get a detailed breakdown of your usage and savings.

## What is this Savings Plan field in my Pump Dashboard?

<figure><img src="/files/phIQMF9G87e9vDOlLGiZ" alt=""><figcaption></figcaption></figure>

As we buy you Savings Plans, your on-demand AWS spend composition will decrease while your savings plans spend will increase. A good example is if you previously had $1,000 in AWS on-demand spend, and we bought you a savings plan with a 50% discount rate to cover $800 on-demand spend. Your Pump Dashboard would now show on-demand spend of just $200, while there would be a $400 dollar savings plan line item in your dashboard. In conclusion, we saved you $200.


# Payments

Invoices to Pump can be paid with a bank account via [GoCardless](https://gocardless.com/), wire transfer via ACH, SWIFT, or Credit Card. We support direct debit for US and a few international countries at the moment. TLDR: We support payment methods for customers across the globe!&#x20;

We do offer customers the option to pay via  credit card. For credit card, we add a 3% fee since we are a free product and are charged a 3% fee for credit card.

&#x20;SWIFT Code: CMFGUS33 Account Number: 8305310325 Bank Name: Community Federal Savings Bank Bank Address: , US SWIFT&#x20;

**Beneficiary Name:** Pump Billing Inc

**Beneficiary Address:** 1390 Market St, San Francisco, CA 94102

Go to [**this page to see payment instructuions**](/getting-started/billing-and-payments/supported-payment-methods).


# Credit FAQ

**Question:** I have existing credits, can I use them with Pump?

**Answer:** Yes! We will be able to work with you.

**Question:** I just got an email about an invoice, but I have credits, where did they go?

**Answer:** If you believe you have credits not applied to your invoice, please email <billing@pump.co>.

**Question:** I believe I got the wrong amount of credits

**Answer:** You can see how many credits you have here: <https://app.pump.co/settings/credits>. If you don't believe this is the correct amount, be sure to check with the Account Executive who onboarded you.

**Question:** I got new credits after joining Pump

**Answer:** If you were awarded credits after joining Pump, Congrats! Please be sure to send proof to us, like a screenshot of the credits in the AWS console.

* Step 1: Go to the AWS Management Console
* Step 2: Go to [**Billing and Cost Management**](https://us-east-1.console.aws.amazon.com/costmanagement/home#/home)
* Step 3: Go to "Credits" on the left menu.

You should be able to send a screen recording of the credits there.


# Savings

{% hint style="info" %}
Pump is the only company that brings additional volume tier discounts covering most of the services a\
typical engineering team relies on.
{% endhint %}

Below is a list of AWS services that we arbitrage for our customers -

<table><thead><tr><th valign="top">AWS Services Pump Saves</th></tr></thead><tbody><tr><td valign="top">EC2</td></tr><tr><td valign="top">RDS</td></tr><tr><td valign="top">ECS</td></tr><tr><td valign="top">ElastiCache</td></tr><tr><td valign="top">Lambda</td></tr><tr><td valign="top">OpenSearch</td></tr><tr><td valign="top">SageMaker</td></tr><tr><td valign="top">RedShift</td></tr><tr><td valign="top">DynamoDB</td></tr><tr><td valign="top">EC2 Data Transfer*</td></tr><tr><td valign="top">MediaLive*</td></tr><tr><td valign="top">S3*</td></tr><tr><td valign="top">CloudWatch*</td></tr></tbody></table>

| GCP Services Pump Saves         |
| ------------------------------- |
| Compute Engine                  |
| BigQuery                        |
| Kubernetes Engine               |
| Cloud Run                       |
| Cloud Memorystore for Redis     |
| Cloud Memorystore for Memcached |
| Google Cloud VMware Engine      |
| Spanner                         |
| Dataflow                        |
| Bigtable                        |
| CloudSQL                        |
| AlloyDB for PostgreSQL          |


# Invoices from AWS

Your invoices can be accessed from your AWS management console on the billing dashboard. From your AWS management account, head over to Billing Dashboard > Bills. The charges will be on the 'Charges by Services' Tab and the Pump Savings will be on the 'Savings' Tab.

<figure><img src="/files/zgAGCFFTNrQFq0L1R86A" alt=""><figcaption></figcaption></figure>

As we (Pump) handle your invoices since joining Pump, the same invoice would be posted on our platform - in the [**Invoices tab**](https://app.pump.co/invoices) during the first week of each month. Please note that these invoices reflect the same charges from AWS; **Pump does not mark up or add any additional fees to your usage costs**.&#x20;

Additionally, you will see a line item called 'Pump Savings' which reflects the amount that Pump has saved you so far!

**You can also use AWS Cost Explorer to verify your costs:**

* Go to the AWS Management Console.
* Go to Billing and Cost Management with the signed in account.
* On the left menu, select "Cost Explorer"
* Make sure to set the correct date range, and under charge type, exclude credits.

<figure><img src="/files/RvHPtUEDOrZV9NPqD73I" alt=""><figcaption><p>Example of AWS Cost Explorer</p></figcaption></figure>

**Then, you can compare to your Pump Invoice:**

<figure><img src="/files/ooOZs7xPjx4ecE7Ol84e" alt=""><figcaption></figcaption></figure>


# Leaving Pump's AWS Organization

You can request a 30-day notice to disconnect from Pump at any time. There are no contracts or lock-in periods. This page covers what happens when you leave and how the process works.

> **Note:** If your offboarding involves a Consent to Assign (CTA) process, it can only be processed during a specific window each month (typically between the 10th and 20th, though the exact dates vary). Contact your Pump account team to confirm the current window.

### What happens when you leave

| Area                 | What happens                                                                                                                                                                  |
| -------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Existing commitments | Reserved Instances and Savings Plans that Pump purchased remain in your AWS account. They run off naturally on their original expiration schedule. Nothing is canceled early. |
| Billing              | Your billing relationship reverts to direct. You pay AWS instead of Pump.                                                                                                     |
| Cloud resources      | All your AWS resources, configurations, and data remain exactly as they are. Pump never modifies infrastructure.                                                              |
| IAM roles            | You can delete the Pump IAM roles (read-only, Autopilot, Pump Secure, Pump Infra) from your account at any time after disconnecting.                                          |
| Pump dashboards      | Your historical cost data in Pump's dashboards is no longer accessible after disconnection. Download any reports you need before offboarding.                                 |
| SSO                  | If Pump migrated your SSO during onboarding, you will need to migrate it back to your own org or set up a new IAM Identity Center instance. Coordinate with the Pump team.    |

### How to leave

1. Contact Pump support at <support@pump.co> or your Account Manager.
2. The Pump team coordinates the transition, including:
   * Removing your account from Pump's AWS Organization
   * Your account becomes standalone and responsible for its own billing
   * Ensuring any active commitment renewals are handled appropriately
3. Once your account is standalone, you can optionally create your own AWS Organization or join another one.

### Leaving a previous org to join Pump

If you are joining Pump and need to leave your current AWS Organization first, the process is:

1. Log in to the AWS Console.
2. Click your account name in the top-right corner and select **Organization**.
3. Scroll to the bottom of the page and click **Leave organization**.
4. Confirm. Your account becomes standalone and responsible for its own billing.
5. As a standalone account, you can now join Pump through the standard onboarding flow.

This process only applies to member accounts leaving an existing org. If you are the management account of an org, see the Multi-Account Setup page for the correct path.


# Getting Started with GCP

Pump connects to your GCP account in two stages: an OAuth consent for project discovery, and an optional Cloud Shell script that grants per-project access for commitment management. Pump acts as a GCP solutions provider, meaning your billing account becomes a sub-account under Pump.

### Prerequisites

| Requirement  | Details                                                                        |
| ------------ | ------------------------------------------------------------------------------ |
| GCP account  | Active account with at least one project and a billing account                 |
| Permissions  | Owner or Billing Administrator on the billing account you want to connect      |
| Pump account | Sign up at [app.pump.co](https://app.pump.co/) and complete email verification |

### How the connection works

Pump's GCP connection has two layers:

1. **OAuth consent** grants Pump read-only access to list your GCP projects. This is how Pump discovers your environment.
2. **Service account IAM grant** (optional) gives Pump per-project access to BigQuery and Compute Engine for commitment management and cost analysis.

Pump never stores your Google credentials. OAuth tokens are used for project discovery only. Per-project access is granted to a Pump-managed service account through standard GCP IAM.

### Step 1: Run a savings estimate (optional)

Before connecting programmatically, you can generate a savings estimate using a CSV upload.

1. Log in to Pump and select **GCP** as your cloud provider.
2. Select **Estimate savings from CSV**.
3. In the Google Cloud Console, navigate to **Billing → Reports** and export your billing history as a CSV.
4. Upload the CSV to Pump.
5. Pump generates your savings estimate within minutes.

After reviewing the estimate, you can proceed to connect your account.

### Step 2: Google OAuth consent

This step grants Pump read-only access to discover your GCP projects.

1. In the Pump onboarding wizard, click **Connect GCP**.
2. Google's OAuth consent screen opens. Pump requests the following scopes:

| Scope                            | What it does                        |
| -------------------------------- | ----------------------------------- |
| `openid`                         | Verifies your identity              |
| `userinfo.email`                 | Reads your email address            |
| `userinfo.profile`               | Reads your profile name             |
| `cloudplatformprojects.readonly` | Lists your GCP projects (read-only) |

1. Review the permissions and click **Allow**.
2. Pump lists your GCP projects. No billing data is accessed at this stage.

### Step 3: Per-project IAM setup (optional, recommended)

This step grants Pump access to a specific project for commitment management and cost analysis. It runs a Pump-provided script in Google Cloud Shell.

1. In the Pump wizard, select the project you want to connect.
2. Pump opens Google Cloud Shell with a pre-loaded script (`pump-autopilot.sh`).
3. Review the script. It does the following:
   * Enables the BigQuery API and Compute Engine API on your project
   * Grants Pump's service account three IAM roles on that specific project:

| IAM role                               | Purpose                                                  |
| -------------------------------------- | -------------------------------------------------------- |
| `roles/bigquery.resourceAdmin`         | Access to BigQuery billing export data for cost analysis |
| `roles/compute.viewer`                 | Read-only access to Compute Engine resource metadata     |
| `roles/compute.futureReservationAdmin` | Ability to manage Committed Use Discounts (CUDs)         |

1. Run the script. When it completes, it sends a webhook notification back to Pump to confirm the setup.

This step is **skippable**. If you skip it, Pump can still provide cost visibility through the billing export, but commitment management features will not be available for that project.

#### Running the script for multiple projects

If you have multiple GCP projects, repeat Step 3 for each project you want Pump to manage. Each project requires its own IAM grant.

### Step 4: Authorize Pump as your billing partner

This step transitions your GCP billing relationship so that Pump acts as your solutions provider.

1. In the Pump wizard, review the billing partner agreement.
2. Accept the Terms of Service and Privacy Policy.
3. Your GCP billing account is linked as a sub-account under Pump's solutions provider account.
4. Complete your company details and payment method.

After this step, Pump manages your billing. You receive a single invoice from Pump instead of paying Google directly.

#### How GCP solutions provider billing works

Pump participates in Google's Cloud solutions provider program. When you authorize Pump as your billing partner:

* Your GCP billing account becomes a sub-account under Pump.
* Your existing projects, resources, and configurations are not affected.
* You receive one invoice from Pump that covers your GCP usage.

### What Pump accesses

#### Data Pump reads

| Data source             | What Pump pulls                                             | How it's used                                      |
| ----------------------- | ----------------------------------------------------------- | -------------------------------------------------- |
| Cloud Resource Manager  | Project listing, project metadata                           | Environment discovery                              |
| Cloud Billing API       | Billing account details, project-to-billing-account mapping | Billing management                                 |
| BigQuery Billing Export | Standard and detailed billing schemas (line-item costs)     | Cost visibility, savings calculations, forecasting |
| Compute Engine Metadata | Instance types, sizes (via `roles/compute.viewer`)          | Right-sizing analysis                              |

#### Data Pump never accesses

Pump does not access your application data, Cloud Storage bucket contents, source code, IAM policies, secrets, or Cloud Logging data. Pump does not use Cloud Asset Inventory, Terraform, Deployment Manager, or Workload Identity Federation.

The only write actions Pump performs are purchasing Committed Use Discounts when enabled, and only for projects where you have granted the `roles/compute.futureReservationAdmin` role.

### Historical data backfill

Pump's routine data refresh uses a 7-day lookback window. For initial onboarding, broader historical data is available through the BigQuery billing export, which contains your full billing history as configured in your GCP project.

The BigQuery billing-export dataset ID is registered by the Pump team during onboarding. This step is not currently self-serve.

### Troubleshooting

#### OAuth consent failed or was denied

If you accidentally denied the OAuth request, return to the Pump wizard and click **Connect GCP** again. Pump will re-initiate the OAuth flow.

#### Cloud Shell script did not complete

If the `pump-autopilot.sh` script fails, check that:

* The BigQuery API and Compute Engine API are enabled on your project.
* Your user account has sufficient permissions to grant IAM roles (typically `roles/resourcemanager.projectIamAdmin`).
* Your project is not restricted by an organization policy that blocks external service account grants.

If the script completed but Pump does not show the project as connected, the webhook notification may have failed. Contact Pump support at [support.pump.co](https://support.pump.co/).

#### Billing account cannot be linked

If your billing account is already managed by another solutions provider, it cannot be linked to Pump simultaneously. Contact Pump support to discuss migration options.


# Getting Started with Azure

Pump connects to your Azure tenant using a service principal with client credentials. You create the service principal and assign RBAC roles using the Azure CLI. Pump operates through Ingram Micro for Azure as a Microsoft CSP indirect solutions provider.

### Prerequisites

| Requirement  | Details                                                                                                                               |
| ------------ | ------------------------------------------------------------------------------------------------------------------------------------- |
| Azure tenant | Active Azure AD tenant with at least one subscription                                                                                 |
| Permissions  | Ability to create service principals (`az ad sp create-for-rbac`) and assign RBAC roles at the subscription or management group level |
| Azure CLI    | Access to Azure Cloud Shell or a local `az` CLI installation                                                                          |
| Pump account | Sign up at [app.pump.co](https://app.pump.co/) and complete email verification                                                        |

### How the connection works

Pump authenticates to your Azure tenant using a service principal (app registration) with a client secret. You create this service principal and grant it specific RBAC roles. Pump uses the standard OAuth2 client-credentials flow to access your billing and cost data.

Each Azure tenant is connected as a single entity in Pump. If your tenant contains multiple subscriptions, Pump discovers and tracks all of them automatically.

### Step 1: Run a savings estimate

Before connecting programmatically, you can generate a savings estimate using a CSV upload.

1. Log in to Pump and select **Azure** as your cloud provider.
2. Select **Estimate savings from CSV**.
3. In the Azure Portal, navigate to **Cost Management + Billing → Cost analysis** and export your usage data for the last 3 months as a CSV.
4. Upload the CSV to Pump.
5. Pump generates your savings estimate within minutes.

After reviewing the estimate, you can proceed to connect your tenant.

### Step 2: Create a service principal

This step creates the identity Pump uses to access your tenant.

1. Open **Azure Cloud Shell** (or your local terminal with `az` CLI).
2. Run the following command:

bash

```bash
az ad sp create-for-rbac --name pump
```

1. The command outputs a JSON object with the following fields:

json

```json
{"appId":"xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx","displayName":"pump","password":"xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx","tenant":"xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx"}
```

1. Copy these values. You will enter them in the Pump wizard:

| Field      | Maps to                 |
| ---------- | ----------------------- |
| `appId`    | Application (client) ID |
| `password` | Client secret           |
| `tenant`   | Tenant ID               |

1. In the Pump onboarding wizard, enter the three values and submit.

### Step 3: Assign read-only RBAC roles

This step grants Pump visibility into your billing and cost data.

Run the following commands in Azure Cloud Shell. Replace `{subscription-id}` with each subscription you want Pump to monitor:

bash

```bash
az role assignment create\  --assignee{appId}\  --role"Billing Reader"\  --scope /subscriptions/{subscription-id}
```

Repeat for each subscription in your tenant.

| Role           | Scope            | Purpose                                                           |
| -------------- | ---------------- | ----------------------------------------------------------------- |
| Billing Reader | Per subscription | Read-only access to billing data, cost reports, and usage details |

After assigning the role, Pump begins pulling your cost data. Historical data backfill covers up to 90 days from the connection date.

### Step 4: Authorize Pump as your billing partner

This step enables commitment management. Pump assigns additional RBAC roles at the management group or tenant level so it can purchase reservations and savings plans on your behalf.

1. In the Pump wizard, review the billing partner agreement.
2. Accept the Terms of Service and Privacy Policy.
3. Run the Pump-provided role assignment scripts in Azure Cloud Shell. These assign:

| Role                         | Scope                      | Purpose                                                            |
| ---------------------------- | -------------------------- | ------------------------------------------------------------------ |
| Pump Autopilot Role (custom) | Management group or tenant | Commitment purchase actions specific to Pump's optimization engine |
| Reservations Contributor     | Management group or tenant | Manage Azure Reserved VM Instances                                 |
| Savings Plan Contributor     | Management group or tenant | Manage Azure Savings Plans                                         |
| Reservations Purchaser       | Management group or tenant | Purchase new Azure Reserved VM Instances                           |
| Savings Plan Purchaser       | Management group or tenant | Purchase new Azure Savings Plans                                   |

1. Complete your company details and payment method.

After this step, your tenant is fully connected. Pump manages your commitments and generates savings.

#### How Azure solutions provider billing works

Pump operates through Ingram Micro for Azure as a Microsoft Cloud Solution Provider (CSP) indirect solutions provider. When you authorize Pump as your billing partner:

* Your Azure subscriptions continue to work as before. No resources or configurations change.
* Pump negotiates volume pricing and manages commitment purchases on your behalf.
* You receive one invoice from Pump that covers your Azure usage.

### What Pump accesses

#### Data Pump reads

| Data source                   | What Pump pulls                                    | How it's used                            |
| ----------------------------- | -------------------------------------------------- | ---------------------------------------- |
| Cost Management API           | Detailed cost reports (generateDetailedCostReport) | Cost visibility, savings calculations    |
| Consumption API               | Usage details by subscription                      | Usage analysis, forecasting              |
| Resource Groups               | Resource group listing                             | Subscription and environment mapping     |
| Billing API                   | Billing accounts, profiles, reservation details    | Billing management                       |
| Reservation/Savings Plan APIs | Existing commitment details, utilization           | Commitment tracking and renewal planning |

#### Data Pump never accesses

Pump does not access your application data, Azure Key Vault secrets, storage account contents, source code, Azure Monitor logs, or Active Directory user data beyond the service principal. Pump does not use Azure Resource Graph, certificate-based authentication, federated credentials, or storage-account-based cost exports.

The only write actions Pump performs are purchasing reservations and savings plans when Autopilot roles are granted.

### Historical data backfill

When you first connect with read-only access, Pump backfills up to 90 days of historical cost data. The backfill is chunked into 7-day jobs to avoid API rate limits. If your account is discovered automatically (via resource group detection), the initial backfill window is 30 days.

Ongoing data refreshes use a rolling 7-day window.

### Troubleshooting

#### Service principal creation failed

Verify that your Azure AD user has the `Application Administrator` or `Global Administrator` role. The `az ad sp create-for-rbac` command requires permission to create app registrations.

#### Role assignment failed

Verify that your user has `Owner` or `User Access Administrator` on the target subscription. The `Billing Reader` role assignment requires permission to manage RBAC at that scope.

#### Pump is not receiving cost data

After assigning the Billing Reader role, it can take up to 30 minutes for Azure to propagate the role assignment. If data still does not appear after an hour, verify the role assignment with:

bash

```bash
az role assignment list --assignee{appId} --subscription{subscription-id}
```

If the role is listed but Pump still shows no data, contact Pump support at [support@pump.co](https://support.pump.co/).

#### Multi-subscription tenants

Pump automatically discovers all subscriptions in a connected tenant. You do not need to add subscriptions individually. However, the Billing Reader role must be assigned per subscription. If a subscription is missing from your Pump dashboard, check whether the role has been assigned to it.


# Azure Role Deployment and Permissions

## Role Permissions <a href="#undefined" id="undefined"></a>

Pump only requests billing-level access in Azure, allowing customers to retain full administrative control over their Azure subscriptions and services.

Pump operates through 2 types of roles: Read-only and Auto-pilot.

#### Read Only Role <a href="#undefined" id="undefined"></a>

This role is used during the initial [onboarding step (Step 1)](https://help.pump.co/getting-started/step-1-view-estimate). It requires read-only permissions to access up to one year of historical billing and usage data via Azure Cost Management and Consumption APIs. This includes visibility into your resource groups, reservation coverage, and infrastructure metadata (e.g., whether your workloads are already utilizing savings plans).

Pump's optimization engine uses this data to calculate ideal savings opportunities. Once onboarding is complete, the read-only role continues to be used to display costs and savings within the Pump dashboard.

[Read-only Role JSON](https://pump-public-readonly.s3.us-west-2.amazonaws.com/azure-autopilot.json)

```plaintext
{
  "properties": {
    "roleName": "Pump Autopilot Role",
    "description": "Custom role for Pump to manage costs",
    "assignableScopes": [
      "/subscriptions/"
    ],
    "permissions": [
      {
        "actions": [
          "Microsoft.BillingBenefits/savingsPlanOrders/read",
          "Microsoft.BillingBenefits/savingsPlanOrders/action",
          "Microsoft.BillingBenefits/savingsPlanOrders/write",
          "Microsoft.BillingBenefits/savingsPlanOrders/savingsPlans/read",
          "Microsoft.BillingBenefits/savingsPlanOrders/savingsPlans/write",
          "Microsoft.BillingBenefits/savingsPlanOrders/*/action",
          "Microsoft.Capacity/*/read",
          "Microsoft.Capacity/*/action",
          "Microsoft.Capacity/*/write",
          "Microsoft.Billing/*/read",
          "Microsoft.Billing/billingProperty/read",
          "Microsoft.Consumption/*",
          "Microsoft.CostManagement/*",
          "Microsoft.Resources/subscriptions/resourceGroups/read"
        ],
        "notActions": [],
        "dataActions": [],
        "notDataActions": []
      }
    ]
  }
}
```

#### Auto-pilot Role <a href="#undefined" id="undefined"></a>

The Autopilot role builds on the Read-only role, with additional permissions to manage billing commitments like Reserved Instances and Savings Plans. This role is required after the [final onboarding step](broken://pages/UFHNV0EAbhbLAAHcXEbW).

Pump's AI models use this role to:

\- Read service usage metadata (like VM and capacity data)

\- Purchase and manage savings plans on your behalf

\- Maintain visibility over usage patterns to ensure continuous optimization

Important: Pump never collects application-level data or user data-only metadata related to service usage.

[Auto-pilot Role JSON](https://pump-public-readonly.s3.us-west-2.amazonaws.com/azure-autopilot.sh)

```plaintext
# Check if required parameters are provided
if [ $# -lt 2 ]; then
    echo "Usage: $0 <subscription_id> <service_principal_id>"
    echo "Example: $0 4d89996e-150a-464a-845e-e5ef5f190784 93d2af31-a8b3-4cef-86db-b762aa337c22"
    exit 1
fi

# Set variables from parameters
SUBSCRIPTION_ID="$1"
SERVICE_PRINCIPAL_ID="$2"
ROLE_NAME="Pump Autopilot Role"

echo "Using Subscription ID: $SUBSCRIPTION_ID"
echo "Using Service Principal ID: $SERVICE_PRINCIPAL_ID"

# Check if the role already exists
EXISTING_ROLE=$(az role definition list --name "$ROLE_NAME" --query "[].name" -o tsv)
if [ -n "$EXISTING_ROLE" ]; then
    echo "Role '$ROLE_NAME' already exists. Skipping creation."
else
    # Create the custom role definition
    echo "Creating custom role definition..."
    az role definition create --role-definition '{
      "Name": "'"$ROLE_NAME"'",
      "Description": "Custom role for Pump to manage costs",
      "AssignableScopes": [
        "/subscriptions/'"$SUBSCRIPTION_ID"'"
      ],
      "Actions": [
        "Microsoft.BillingBenefits/savingsPlanOrders/read",
        "Microsoft.BillingBenefits/savingsPlanOrders/action",
        "Microsoft.BillingBenefits/savingsPlanOrders/write",
        "Microsoft.BillingBenefits/savingsPlanOrders/savingsPlans/read",
        "Microsoft.BillingBenefits/savingsPlanOrders/savingsPlans/write",
        "Microsoft.BillingBenefits/savingsPlanOrders/*/action",
        "Microsoft.Capacity/*/read",
        "Microsoft.Capacity/*/action",
        "Microsoft.Capacity/*/write",
        "Microsoft.Billing/*/read",
        "Microsoft.Billing/billingProperty/read",
        "Microsoft.Consumption/*",
        "Microsoft.CostManagement/*",
        "Microsoft.Resources/subscriptions/resourceGroups/read"
      ],
      "NotActions": [],
      "DataActions": [],
      "NotDataActions": []
    }'

    # Check if role creation was successful
    if [ $? -ne 0 ]; then
        echo "Error: Failed to create custom role definition."
        exit 1
    fi

    sleep 2
fi

# Assign the custom role to the service principal
echo "Assigning custom role to service principal..."
az role assignment create --assignee "$SERVICE_PRINCIPAL_ID" --role "$ROLE_NAME" --scope "/subscriptions/$SUBSCRIPTION_ID"

echo "Success: Role creation and assignment complete!"
```

## Role Deployment <a href="#undefined" id="undefined"></a>

If the Pump role is accidentally deleted or needs to be updated:

1\. Log in to the Pump platform.

2\. Navigate to: Settings > Integrations

3\. Click the three-dot menu next to your Azure subscription.

4\. Select the role type (Read-only or Autopilot) and redeploy using the script provided.

## Terraform Support <a href="#undefined" id="undefined"></a>

If your infrastructure is Terraform-based and CLI execution is not suitable, Pump also supports Terraform-based deployments. Please contact <support@pump.co> for more information.


# Anthropic

Bring your Anthropic API spend into Pump View alongside your cloud costs. Pump pulls Claude API token usage, model-level costs, and workspace breakdowns, giving you a single place to track infrastructure and AI spend.

**Setup time:** \~3 minutes

**Access level:** Read-only

***

### Prerequisites

* **An Anthropic Admin API Key.** This key starts with `sk-ant-admin-...` and is different from a standard API key. Only Admin keys have access to billing and usage data.
* **Admin role on your Anthropic Workspace.** Only Admins can generate Admin API keys. If you don't have Admin access, ask your workspace Admin to create the key for you.
* **Billing enabled** on your Anthropic account.

***

### Setup Instructions

#### 1. Create an Admin API Key

1. Log in to the [Anthropic Console](https://console.anthropic.com).
2. Go to the [Admin Keys](https://console.anthropic.com/settings/admin-keys) section (this is separate from the standard API Keys page).
3. Click **Create Key**.
4. Give it a descriptive name (e.g., `Pump Integration`).

#### 2. Copy Your Key

Copy the Admin API key immediately after creation. **It is only displayed once.** If you lose it, you'll need to generate a new one.

#### 3. Connect in Pump

1. In Pump, go to **Settings → Integrations**.
2. Find **Anthropic** and click **Connect**.
3. Paste your Admin API key.
4. Click **Connect**.

#### 4. Verify

Pump validates your key and backfills up to **365 days** of historical usage data. Your Anthropic spend should appear alongside your cloud costs within a few minutes.

***

### What Data Does Pump Pull?

| Data                    | Description                                                   |
| ----------------------- | ------------------------------------------------------------- |
| **Token usage**         | Input and output token counts per model                       |
| **Model costs**         | Spend broken down by Claude model (e.g., Sonnet, Opus, Haiku) |
| **Workspace breakdown** | Costs attributed to individual Anthropic workspaces           |
| **Cache reads**         | Cache read input token costs                                  |
| **Cache creation**      | Ephemeral cache creation costs                                |
| **Web search**          | Costs for web search tool usage                               |
| **Code execution**      | Costs for code execution tool usage                           |

### Frequently Asked Questions

#### I don't see an "Admin" key type when creating a key.

You may not have Admin-level access to your Anthropic workspace. Ask an existing Admin to either grant you Admin permissions or generate the key on your behalf.

#### Can I use a regular API key (sk-ant-api-...)?

No. Standard API keys don't have access to billing or usage data. You need an Admin key (starts with `sk-ant-admin-...`), which is created from the [Admin Keys](https://console.anthropic.com/settings/admin-keys) section of the console.

#### How far back does Pump pull data?

Pump backfills up to 365 days of historical usage data from the date you connect.

#### Is my API key stored securely?

Yes. Pump uses your key with read-only access to fetch billing data. The key is encrypted at rest and is never used to make inference calls or modify your Anthropic account.

#### Can I revoke the key later?

Yes. You can delete the Admin API key from the Anthropic Console at any time. This will disconnect the integration in Pump, and new data will stop syncing.

#### My data isn't showing up after connecting.

* Confirm the key you pasted starts with `sk-ant-admin-...`.
* Check that billing is enabled on your Anthropic account.
* Wait a few minutes. The initial backfill can take a moment depending on usage volume.
* If the issue persists, reach out to <support@pump.co>.


# ClickHouse

Bring your ClickHouse Cloud costs into Pump View. See service-level usage broken down by compute, storage, backup, and data transfer so you can track data warehouse spend alongside your cloud costs.

**Setup time:** \~3 minutes

**Access level:** Read-only

***

### Prerequisites

* **An API Key ID and API Key Secret.** Generated from the ClickHouse Cloud Console under API Keys.
* **Key scoped to your Organization** with a **Developer** role or higher (read-only / viewer access).
* **A paid ClickHouse Cloud plan.** Usage cost data is not available on free-tier plans.

***

### Setup Instructions

#### 1. Create an API Key

1. Log in to [clickhouse.cloud](https://clickhouse.cloud/) as an Organization Admin.
2. Go to **Organization → Settings → API Keys**.
3. Click **New API Key**.

#### 2. Configure and Copy

1. Set the **scope** to **Organization**.
2. Set the **role** to **Developer** or higher.
3. Click **Create**.
4. Copy both the **Key ID** and the **Key Secret**. The secret is only displayed once.

> **Important:** You need both the Key ID and Key Secret. They're used together for authentication. If you lose the secret, you'll need to generate a new key pair.

#### 3. Connect in Pump

1. In Pump, go to **Settings → Integrations**.
2. Find **ClickHouse Cloud** and click **Connect**.
3. Enter your **Key ID** and **Key Secret**.
4. Pump auto-detects your Organization ID.
5. Click **Connect**.

#### 4. Verify

Pump validates via Basic Auth and backfills up to **365 days** of cost data. Your per-service compute, storage, and transfer costs should appear within a few minutes.

***

### What Data Does Pump Pull?

| Data              | Description                                      |
| ----------------- | ------------------------------------------------ |
| **Compute**       | Per-service compute costs (CPU and memory usage) |
| **Storage**       | Data storage costs per service                   |
| **Backup**        | Backup storage and retention costs               |
| **Data transfer** | Network egress and data transfer costs           |

### Frequently Asked Questions

#### What's the difference between the Key ID and the Key Secret?

ClickHouse Cloud uses a two-part credential system. The **Key ID** identifies the key, and the **Key Secret** authenticates it. You need both to connect. Think of them like a username and password.

#### I don't see the API Keys section in my Organization settings.

You may not have Organization Admin access. Only Organization Admins can manage API keys. Ask an existing Admin to create the key for you.

#### What role should I assign to the key?

**Developer** is the minimum role required. It provides read-only access to usage and cost data. You can also use a higher role, but Developer is sufficient and follows the principle of least privilege.

#### Does this work with the ClickHouse Cloud free tier?

No. Usage cost data is only available on paid ClickHouse Cloud plans. If you're on the free tier, the integration won't return cost data.

#### How far back does Pump pull data?

Pump backfills up to 365 days of historical cost data from the date you connect.

#### Does Pump access my ClickHouse databases or query data?

No. Pump only reads organization-level usage and billing data. It cannot access your databases, tables, queries, or any stored data.

#### Can I revoke the key later?

Yes. You can delete the API key from the ClickHouse Cloud Console at **Organization → Settings → API Keys** at any time. This will disconnect the integration in Pump.

#### My data isn't showing up after connecting.

* Confirm you entered both the Key ID **and** the Key Secret (they are separate fields).
* Verify the key is scoped to the **Organization** level (not a single service).
* Ensure the key role is Developer or higher.
* Check that you're on a paid ClickHouse Cloud plan.
* Wait a few minutes for the initial backfill.
* If the issue persists, reach out to <support@pump.co>.

***

### Need Help?

Contact <support@pump.co> with any questions.


# Linear

Connect Pump to Linear to turn cloud cost anomalies and infrastructure reccomendations into actionable engineering work. Create and manage Linear issues directly from Pump, assign issues to teammates, and track remediation progress without leaving your cloud dashboard.

**Setup time:** \~1–2 minutes

***

### Overview

Pump's Linear integration bridges cloud optimization with engineering execution. Instead of manually copying anomalies into your issue tracker, you can create and manage Linear issues directly from Pump.

Whether you're responding to a cloud cost anomaly or assigning a infrastructure recommendations, Pump keeps your engineering workflow and cloud operations synchronized.

> **Note:** Linear is a work tracking integration. Pump does **not** read Linear usage or billing data.

***

### Prerequisites

Before connecting Linear, you'll need:

* Access to the Linear workspace you want to connect
* Permission to authorize applications in your Linear workspace
* Browser pop-ups enabled for Pump (required for OAuth authentication)

***

### Setup Instructions

1. In Pump, navigate to **Settings → Integrations**.
2. Find **Linear** and click **Connect with Linear**.
3. Authorize Pump on the Linear OAuth consent screen.
4. Open any cloud cost anomaly
5. Click **Create Linear Issue**.
6. Select:
   * Team
   * Assignee
   * Issue title
   * Issue description
   * Workflow status
7. Click **Create**.

Pump immediately creates the issue in Linear and links it back to the original Pump finding. As your engineering team updates the issue, Pump automatically synchronizes the latest status.

***

### Permissions Pump Requests

| Permission | Why Pump Needs It                                                                                             |
| ---------- | ------------------------------------------------------------------------------------------------------------- |
| **Read**   | Retrieve your Linear teams, workflow statuses, and teammates so issues can be created and assigned correctly. |
| **Write**  | Create Linear issues directly from Pump.                                                                      |

***

### Features

#### Create Linear Issues from Pump

Create a Linear issue directly from:

* Cloud cost anomalies

When creating an issue, you can:

* Select the appropriate Linear team
* Assign the issue to any teammate
* Customize the issue title
* Edit the issue description before submission
* Select the initial workflow status

This allows engineering teams to begin remediation immediately without manually recreating context.

***

#### Assign Findings to Team Members

Assign every anomaly to the appropriate engineer during issue creation.

Assignments remain visible inside Pump, making ownership clear across engineering, operations, and finance teams.

***

#### Live Issue Status Sync

Pump continuously synchronizes with Linear so you can monitor progress without switching tools.

As issues move through your team's workflow, Pump automatically updates the linked finding with the latest Linear status, including both default and custom workflow states.

***

### What Pump Uses Linear For

Pump uses Linear to:

* Create issues from cloud cost anomalies and infrastructure reccomendations
* Prefill issue titles and descriptions with relevant context
* Link every issue back to the originating Pump finding
* Synchronize issue status and assignee automatically

Pump **does not** automatically create issues for every anomaly—you remain in control of which findings become engineering work.

***

### Security & Access

Pump stores OAuth credentials securely using encryption at rest.

The integration only accesses the metadata required to:

* Create Linear issues
* Retrieve teams and workflow statuses
* Keep linked issue status synchronized

To disconnect Linear:

1. Open **Settings → Integrations → Linear** in Pump.
2. Click **Disconnect**.

To completely revoke access, also remove the Pump application from your Linear workspace settings.

***

### Supported Workflows

The Linear integration supports:

* Creating issues for cloud cost anomalies
* Assigning issues to teammates
* Editing issue titles before creation
* Editing issue descriptions before creation
* Selecting the initial workflow status
* Live synchronization of issue status back into Pump

***

### FAQ

#### I don't see any teams when creating an issue.

Confirm you've connected the correct Linear workspace and that your account has access to at least one team.

#### Can I create multiple Linear issues for the same anomaly?

No. Each Pump finding can be linked to a single Linear issue.

#### Does disconnecting Linear revoke access completely?

Disconnecting removes the integration from Pump. To fully revoke access, also remove the Pump app from your Linear workspace settings.


# Cursor

Import your team's Cursor AI usage into Pump View. See which models were used, token counts, per-user costs, and fast vs. slow request breakdowns so you can attribute IDE AI spend to individuals alongside your cloud costs.

**Setup time:** \~3 minutes

**Access level:** Read-only

***

### Prerequisites

* **A Cursor Enterprise plan.** The Admin API is only available on Enterprise plans. Business and Pro plans do not support API key generation.
* **An Admin API Key.** This key starts with `key_...` and must be generated by a Team Admin.
* **Team Admin role.** Only Team Admins can access Team Settings and generate API keys.

***

### Setup Instructions

#### 1. Open API Key Settings

1. Log in to [cursor.com](https://cursor.com/) as a Team Admin on an Enterprise plan.
2. Navigate to **Team Settings → API Keys**.

#### 2. Create and Copy an API Key

1. Click **Create** to generate a new Admin API key.
2. Copy the key immediately. It starts with `key_...`. This key grants read access to team member lists and usage events.

#### 3. Connect in Pump

1. In Pump, go to **Settings → Integrations**.
2. Find **Cursor** and click **Connect**.
3. Paste your Admin API key.
4. Optionally, enter your **Team Name** for display purposes in Pump.
5. Click **Connect**.

#### 4. Verify

Pump authenticates via Basic Auth and backfills up to **365 days** of usage events. Your per-user, per-model AI costs should appear within a few minutes.

***

### What Data Does Pump Pull?

| Data                   | Description                                                            |
| ---------------------- | ---------------------------------------------------------------------- |
| **Model usage**        | Which AI models your team is using (e.g., GPT-4, Claude) and how often |
| **Token fees**         | Token-level costs per model                                            |
| **Per-user costs**     | Spend attributed to individual team members                            |
| **Fast/slow requests** | Breakdown of premium (fast) vs. standard (slow) request usage per user |

### Frequently Asked Questions

#### I don't see an "API Keys" section in Team Settings.

The Admin API is only available on Cursor **Enterprise** plans. If you're on a Business or Pro plan, you won't have access to this feature. Contact Cursor sales to learn about upgrading.

#### Who can generate the API key?

Only Team Admins can access Team Settings and generate API keys. If you're not a Team Admin, ask one to create the key for you.

#### What does the Team Name field do?

It's optional and only used for display purposes in Pump (e.g., labeling the integration in your dashboard). If you leave it blank, Pump will still work.

#### How far back does Pump pull data?

Pump backfills up to 365 days of historical usage events from the date you connect.

#### Can I see which team members are using the most AI?

Yes. Pump breaks down usage by individual team member, so you can see per-user costs, model preferences, and fast vs. slow request ratios.

#### Can I revoke the key later?

Yes. You can delete the API key from Cursor at **Team Settings → API Keys** at any time. This will stop data syncing in Pump.

#### My data isn't showing up after connecting.

* Confirm the key starts with `key_...`.
* Verify you're on a Cursor Enterprise plan.
* Ensure the key was generated by a Team Admin.
* Wait a few minutes for the initial backfill.
* If the issue persists, reach out to <support@pump.co>.


# Slack

## Slack Integration

Connect Pumpbot to Slack so your team can interact with spend data directly from Slack. Ask questions in plain English, use slash commands for common workflows, and receive cloud insights in the channels you already use.

**Setup time:** \~3–5 minutes

***

### Overview

Pumpbot brings your cloud data directly into Slack, allowing your team to ask questions about cloud spend without leaving your workspace.

Ask Pumpbot about:

* Total cloud spend
* Service-level spend breakdowns
* Infrastructure Reccomendations
* Cost anomalies
* Free-form questions about your cloud environment

> **Note:** Pumpbot is separate from Slack notifications for budgets and alerts. Connecting Slack for alerts does **not** enable Pumpbot, and connecting Pumpbot does **not** configure alert notifications.

***

### Prerequisites

Before connecting Pumpbot, you'll need:

* A Pump account with Organization Admin permissions
* Permission to install apps in your Slack workspace (or a Slack administrator who can approve the installation)
* Browser pop-ups enabled for Pump (required for OAuth authentication)

***

### Setup Instructions

1. Navigate to **Organization Settings → Pumpbot** in Pump.

   **Direct link:** <https://app.pump.co/settings#pumpbot>
2. Click **Connect**.
3. Authorize Pumpbot in the Slack OAuth window.
4. In Slack, invite Pumpbot to each channel where you'd like to use it:

   ```
   /invite @pump
   ```
5. Return to Pump and, under **Add a Channel**, select each Slack channel and click **Add**.

Pumpbot only responds in channels that have been added and marked as active.

***

<figure><img src="/files/A1P0u4oCritfOhD6PSCI" alt=""><figcaption></figcaption></figure>

### Permissions Pump Requests

| Permission                              | Why Pump Needs It                                                             |
| --------------------------------------- | ----------------------------------------------------------------------------- |
| **Send messages**                       | Respond to your questions and share cloud spend and anomaly insights in Slack |
| **Upload files**                        | Attach spend charts and visualizations when available                         |
| **View public & private channels**      | Display channels Pumpbot has joined so they can be enabled in Pump            |
| **View messages in channels & threads** | Understand thread context for follow-up questions                             |
| **Receive @mentions**                   | Respond when Pumpbot is mentioned in a Slack channel                          |
| **Slash commands**                      | Enable `/pumpbot` commands and related workflows                              |

***

### Features

#### Ask Questions in Plain English

Pumpbot lets your team query cloud spend data directly from Slack.

Simply ask questions such as:

* "Why did AWS spend increase yesterday?"
* "Which services had anomalies this week?"
* "What are some infrastructure recommendations to reduce my costs?"
* "What's our total cloud spend this month?"

Pumpbot understands follow-up questions, allowing you to drill deeper into your cloud data without switching applications.

***

#### Use Slash Commands

Pumpbot supports slash commands for common cloud management workflows.

Use commands such as:

* `/pumpbot`
* Spend
* Service
* Anomaly
* Glossary

Commands support common reporting periods like **7d**, **30d**, and **MTD**.

***

#### Organization Glossary

Teach Pumpbot your company's internal terminology by defining a glossary.

Once a term is added, Pumpbot remembers its meaning and automatically applies it to future conversations, making responses more accurate and tailored to your organization.

***

#### Threaded Conversations

Continue conversations naturally inside Slack threads.

Pumpbot remembers the context of previous questions, allowing your team to ask follow-up questions without repeating information. Some responses also include charts and visualizations to help explain trends.

***

### What You Can Do

Pumpbot supports a wide range of cloud operations directly from Slack, including:

* Ask cloud cost questions in natural language
* Understand infrasutr
* View total spend and service-level breakdowns
* Investigate cloud cost anomalies
* Receive charts and visualizations when available
* Continue conversations with follow-up questions in Slack threads
* Use slash commands for common workflows
* Customize Pumpbot with your organization's glossary

***

### Security & Access

Pump uses Slack only to send and receive messages and upload files.

Your cloud cost and infrastructure data always comes from your Pump account—not from Slack.

OAuth tokens are encrypted at rest.

To disconnect Pumpbot:

1. Navigate to **Organization Settings → Pumpbot**.
2. Click **Disconnect**.

You can also uninstall the Pump app directly from your Slack workspace settings at any time.

***

### Supported Workflows

The Slack integration supports:

* Asking cloud questions in natural language
* Multi-turn conversations with follow-up questions
* Slash commands for common workflows
* Organization glossary customization
* Threaded Slack conversations
* Secure Slack workspace authentication
* Sharing charts and cloud insights directly in Slack

***

### FAQ

#### My Slack channel doesn't appear in Pump.

Invite Pumpbot into the channel first using:

```
/invite @pump
```

Then refresh the channel list in Pump.

#### The connection seems stuck.

Some Slack workspaces require administrator approval before new apps can be installed.

Ask your Slack administrator to approve Pumpbot, then return to Pump and click **Connect** again.

#### I already connected Slack for alerts. Why doesn't Pumpbot work?

Slack Alerts and Pumpbot are separate integrations.

To use Pumpbot, connect it under **Organization Settings → Pumpbot** and add the channels where you'd like it to respond.

***


# Datadog

Pull estimated and projected costs across all Datadog products into Pump View, including APM, Logs, Infrastructure, RUM, Synthetics, and more. Track your observability spend alongside cloud costs in a single dashboard.

**Setup time:** \~3 minutes

**Access level:** Read-only

***

### Prerequisites

* **An API Key.** Found under Datadog → Organization Settings → API Keys.
* **An Application Key with** `usage_read` and `billing_read` **scope.** The Application Key owner must have an **Admin** or **Billing Admin** role in Datadog.
* **Your Datadog site region.** One of: `us1`, `us3`, `us5`, `eu1`, or `ap1`. Defaults to `us1` if you're not sure.

> **Note:** Datadog requires **two** keys (an API Key and an Application Key). Both are needed for the integration to work.

***

### Setup Instructions

#### 1. Get Your API Key

1. Log in to Datadog as an Admin or Billing Admin.
2. Go to **Organization Settings → API Keys**.
3. Create a new API key or copy an existing one.

#### 2. Create an Application Key

1. Go to **Organization Settings → Application Keys**.
2. Click **New Application Key**.
3. Ensure the key has the `usage_read` and `billing_read` scope.
4. Copy the Application Key.

> **Tip:** If you don't see the option to set scopes, your Datadog role may not have sufficient permissions. You need Admin or Billing Admin.

#### 3. Know Your Site Region

Your Datadog site region determines which API endpoint Pump connects to. If you're unsure, check the URL in your browser when logged into Datadog:

| URL contains        | Region          |
| ------------------- | --------------- |
| `app.datadoghq.com` | `us1` (default) |
| `us3.datadoghq.com` | `us3`           |
| `us5.datadoghq.com` | `us5`           |
| `app.datadoghq.eu`  | `eu1`           |
| `ap1.datadoghq.com` | `ap1`           |

#### 4. Connect in Pump

1. In Pump, go to **Settings → Integrations**.
2. Find **Datadog** and click **Connect**.
3. Enter your **API Key**, **Application Key**, and select your **site region**.
4. Click **Connect**.

#### 5. Verify

Pump validates both keys and fetches your org name, then backfills up to **365 days** of cost data. All Datadog product costs should appear alongside your cloud spend within a few minutes.

***

### What Data Does Pump Pull?

| Data               | Description                                                                 |
| ------------------ | --------------------------------------------------------------------------- |
| **APM**            | Application performance monitoring costs                                    |
| **Logs**           | Log ingestion, indexing, and retention costs                                |
| **Infrastructure** | Host-based infrastructure monitoring costs                                  |
| **RUM**            | Real User Monitoring session costs                                          |
| **Synthetics**     | Synthetic test execution costs                                              |
| **Other products** | Any additional Datadog products on your account (CSPM, CI Visibility, etc.) |

### Frequently Asked Questions

#### What's the difference between an API Key and an Application Key?

In Datadog, **API Keys** authenticate your organization, while **Application Keys** are tied to a specific user and control what data that user can access. Pump needs both: the API Key to identify your org, and an Application Key with `usage_read` and `billing_read` scope to access cost data.

#### I created an Application Key but it doesn't have a scope option.

Scoped Application Keys require a recent Datadog plan. If you don't see scope options, check with your Datadog account rep. Also confirm you have Admin or Billing Admin role, as lower roles may not be able to set billing scopes.

#### How do I find my site region?

Look at the URL when you're logged into Datadog. The default region is `us1` (`app.datadoghq.com`). See the region table above for the full mapping.

#### How far back does Pump pull data?

Pump backfills up to 365 days of historical cost data from the date you connect.

#### Does Pump see my logs, traces, or application data?

No. Pump only accesses billing and cost data via the `usage_read` and `billing_read` scope. It cannot see your logs, APM traces, dashboards, or any application-level data.

#### Can I revoke the keys later?

Yes. You can delete either key from Datadog under **Organization Settings → API Keys** or **Application Keys** at any time. Deleting either key will disconnect the integration.

#### My data isn't showing up after connecting.

* Confirm you provided both an API Key **and** an Application Key (they are different).
* Verify the Application Key has the `usage_read` and `billing_read` scope.
* Check that you selected the correct site region.
* Ensure the Application Key owner has Admin or Billing Admin role.
* Wait a few minutes for the initial backfill.
* If the issue persists, reach out to <support@pump.co>.


# GitHub

Bring your GitHub developer tool spend into Pump View alongside your cloud costs. Pump pulls Copilot seat costs, GitHub Actions minutes, Packages storage, and Codespaces usage so you can see everything in one place.

**Setup time:** \~3 minutes

**Access level:** Read-only

***

### Prerequisites

* **A fine-grained Personal Access Token (PAT).** This token starts with `github_pat_...`. Classic tokens are not supported for this integration.
* **Your GitHub Organization set as the resource owner** on the token. This scopes the token to your org's billing data, not your personal account.
* **Administration and GitHub Copilot Business permissions**, both set to **Read-only** on the token.
* **Your GitHub Organization name.** This is the slug that appears in your GitHub URL (e.g., `github.com/pump-corp` → `pump-corp`).

***

### Setup Instructions

#### 1. Create a Fine-Grained Personal Access Token

1. In GitHub, go to **Settings → Developer settings → Personal access tokens → Fine-grained tokens**.
2. Click **Generate new token**.
3. Under **Resource owner**, select your **Organization** (not your personal account).

> **Note:** If your organization doesn't appear in the dropdown, an org owner may need to enable fine-grained PAT access for the org. Go to **Organization Settings → Personal access tokens → Settings** and allow fine-grained tokens.

#### 2. Set Permissions

Under **Organization permissions**, enable the following (both set to **Read-only**):

* **Administration**
* **GitHub Copilot Business**

You do not need to enable any repository permissions.

#### 3. Generate and Copy the Token

Click **Generate token** and copy it immediately. **It is only displayed once.** The token will start with `github_pat_...`.

#### 4. Connect in Pump

1. In Pump, go to **Settings → Integrations**.
2. Find **GitHub** and click **Connect**.
3. Paste your Personal Access Token.
4. Enter your **Organization name** (the slug, e.g., `pump-corp`).
5. Click **Connect**.

#### 5. Verify

Pump validates your token and backfills up to **365 days** of historical data. Your GitHub spend should appear alongside your cloud costs within a few minutes.

***

### What Data Does Pump Pull?

| Data                  | Description                                                      |
| --------------------- | ---------------------------------------------------------------- |
| **Copilot seats**     | Number of Copilot Business/Enterprise seats and associated costs |
| **GitHub Actions**    | Compute minutes and spend across workflows                       |
| **Packages**          | Storage and data transfer costs for GitHub Packages              |
| **Codespaces**        | Per-user compute and storage costs for GitHub Codespaces         |
| **LFS**               | Git Large File Storage bandwidth and storage costs               |
| **Shared Storage**    | Shared storage costs across Actions and Packages                 |
| **Advanced Security** | GitHub Advanced Security seat costs                              |
| **Marketplace**       | GitHub Marketplace app subscription costs                        |
| **Sponsors**          | GitHub Sponsors contribution costs                               |

### Frequently Asked Questions

#### My organization doesn't appear in the "Resource owner" dropdown.

Your org may not have fine-grained PATs enabled. An org owner needs to go to **Organization Settings → Personal access tokens → Settings** and allow fine-grained tokens. Some orgs also require admin approval for new tokens, so check if your token is pending approval.

#### Can I use a classic Personal Access Token?

No. Classic tokens don't support the granular organization-level permissions Pump needs. You must use a fine-grained token.

#### I set the permissions but Pump says the token is invalid.

Double-check that:

* The **Resource owner** is set to your Organization, not your personal account.
* Both **Administration** and **GitHub Copilot Business** are set to **Read-only** under Organization permissions.
* The token hasn't expired. Fine-grained tokens have a configurable expiration date.

#### How far back does Pump pull data?

Pump backfills up to 365 days of historical data from the date you connect.

#### What happens when my token expires?

Pump will stop syncing new data. You'll need to generate a new fine-grained PAT with the same permissions and reconnect in Pump under **Settings → Integrations**.

#### Can I revoke the token later?

Yes. You can delete the token from GitHub at **Settings → Developer settings → Personal access tokens → Fine-grained tokens** at any time. This will disconnect the integration in Pump.

#### My data isn't showing up after connecting.

* Confirm the token starts with `github_pat_...`.
* Verify the Organization name matches exactly (case-sensitive slug).
* Ensure both required permissions are set to Read-only.
* Wait a few minutes for the initial backfill.
* If the issue persists, reach out to <support@pump.co>.


# OpenAI

Track your organization-level OpenAI API costs inside Pump View. See exactly how much each project, model, and token category (input, output, cached) costs per day, alongside your cloud spend.

**Setup time:** \~3 minutes

**Access level:** Read-only

***

### Prerequisites

* **An Admin API Key.** This key starts with `sk-admin-...` and is different from a standard project key. Only Admin keys have access to billing data.
* **Organization Owner role.** Only Organization Owners can create Admin API keys in OpenAI.
* **A paid OpenAI plan.** Billing data is only available on paid accounts.

> **Important:** Standard project keys (starting with `sk-proj-...`) do **not** have billing access. You must use an Admin key.

***

### Setup Instructions

#### 1. Create an Admin API Key

1. Log in to [platform.openai.com](https://platform.openai.com/) as an Organization Owner.
2. Navigate to **Organization → API Keys → Admin keys**.
3. Click **Create** to generate a new Admin API key.

#### 2. Copy the Key

Copy the key immediately. **It is only displayed once.** The key will start with `sk-admin-...`. Store it somewhere safe before closing the dialog.

#### 3. Connect in Pump

1. In Pump, go to **Settings → Integrations**.
2. Find **OpenAI** and click **Connect**.
3. Paste your Admin API key.
4. Pump auto-detects your organization's name.
5. Click **Connect**.

#### 4. Verify

Pump validates your key via the costs API and fetches your organization name, then backfills up to **365 days** of historical cost data. Your per-project, per-model token costs should appear within a few minutes.

***

### What Data Does Pump Pull?

| Data                  | Description                                                   |
| --------------------- | ------------------------------------------------------------- |
| **Input tokens**      | Token counts and costs for prompt/input tokens per model      |
| **Output tokens**     | Token counts and costs for completion/output tokens per model |
| **Cached tokens**     | Costs for cached prompt tokens (where applicable)             |
| **Embeddings**        | Usage and costs for embedding model calls                     |
| **Project breakdown** | Spend attributed to individual OpenAI projects                |
| **Model breakdown**   | Costs split by model (e.g., GPT-4o, GPT-4, o1)                |
| **Audio**             | Whisper (speech-to-text) and TTS (text-to-speech) costs       |
| **Images**            | DALL-E image generation costs                                 |

### Frequently Asked Questions

#### I don't see the "Admin keys" option in my Organization settings.

You likely don't have the Organization Owner role. Only Owners can view and create Admin keys. Ask an existing Owner to either grant you Owner permissions or create the key on your behalf.

#### Can I use a standard project key (sk-proj-...)?

No. Project keys are scoped to a single project and don't have access to organization-level billing data. You need an Admin key starting with `sk-admin-...`.

#### How far back does Pump pull data?

Pump backfills up to 365 days of historical cost data from the date you connect.

#### Does Pump make inference calls with my key?

No. Pump only uses your Admin key to read billing and usage data. It never makes model inference calls or modifies your OpenAI account.

#### Can I revoke the key later?

Yes. You can delete the Admin API key from the OpenAI platform at any time under **Organization → API Keys → Admin keys**. This will stop data syncing in Pump.

#### My data isn't showing up after connecting.

* Confirm the key starts with `sk-admin-...` (not `sk-proj-...`).
* Verify you have a paid OpenAI account with billing history.
* Wait a few minutes. The initial backfill may take a moment for high-usage accounts.
* If the issue persists, reach out to <support@pump.co>


# Pump's Billing Partner Model

This section is for cloud provider account managers (AWS, GCP, Azure) who want to understand how Pump operates within the partner ecosystem. If you are a Pump customer looking to connect your cloud account, see the "Getting Started" section above.

### What Pump Is

Pump is a cloud cost optimization platform that helps companies get more out of their cloud spend. Pump operates as an authorized solutions provider and channel partner across all three providers, working within each provider's official partner programs.

Pump is not a competitor to cloud providers. Pump helps customers optimize commitment coverage and resource efficiency, freeing up budget that customers typically reallocate into new workloads and expanded cloud usage.

### How the Partnership Works

Pump acts as an authorized billing partner for its customers. When a customer joins Pump, their cloud billing relationship routes through Pump's solutions provider channel. Pump consolidates billing across its customer base, which enables volume-tier pricing that individual customers could not access on their own.

The customer's cloud account, resources, and workloads remain entirely theirs. Pump accesses billing, usage, and infrastructure data to perform cost analysis and commitment optimization.

| What changes                                                                | What does not change                                     |
| --------------------------------------------------------------------------- | -------------------------------------------------------- |
| Billing routes through Pump's solutions provider channel                    | Customer's cloud account ownership                       |
| Customer receives a consolidated invoice from Pump                          | Customer's infrastructure and workloads                  |
| Pump manages commitment purchases (RIs, SPs, CUDs) on the customer's behalf | Customer's direct relationship with their cloud provider |
|                                                                             | Cloud AM's relationship with the customer                |

### Pump's Partner Status

| Provider                    | Partner Program                                                                                                                                                                             | Verification                                                                                                                                                    |
| --------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| AWS                         | AWS Solution Provider Program (Advanced Tier), Authorized Commercial Solutions Provider, Cloud Operations Services Competency, AI Services Competency, AWS Well-Architected Partner Program | [AWS Partner Listing](https://partners.amazonaws.com/partners/0018W00001wuP0XQAU/Pump)                                                                          |
| GCP                         | Google Cloud Partner                                                                                                                                                                        | [GCP Partner Listing](https://cloud.google.com/find-a-partner/partner/pump)                                                                                     |
| Azure                       | Authorized Microsoft Azure Partner                                                                                                                                                          | Available on request                                                                                                                                            |
| Oracle Cloud Infrastructure | OCI Partner                                                                                                                                                                                 | [OCI Partner Listing](https://partner-finder.oracle.com/?CompanyNumber=4-423909260554\&page=shell\&shell=partner-finder\&partner-finder=partner-finder-profile) |
| DataDog                     | Registered Partner                                                                                                                                                                          | Available on request                                                                                                                                            |

Pump is an authorized solutions provider through Ingram Micro for all three providers.

### What Pump Does for Customers

Pump's platform has three product areas. The most relevant to cloud provider AMs is Pump Save, which handles commitment optimization.

| Product     | What it does                                                                                  | Relevance to AMs                                                                                           |
| ----------- | --------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------- |
| Pump Save   | Automated commitment management (RIs, SPs, CUDs), infrastructure right-sizing recommendations | Directly manages the customer's commitment portfolio. Increases commitment coverage and utilization rates. |
| Pump View   | Spend dashboards, cost breakdowns, budgets, alerts, forecasts                                 | Visibility layer only. Gives customers better understanding of their cloud spend.                          |
| Pump Secure | Vulnerability scanning, compliance monitoring, pentesting                                     | Security posture. No impact on billing or AM relationship.                                                 |

### Impact on AM Quota and Attribution

Pump does not take commission from cloud provider AMs. Customer spend that flows through Pump's solutions provider channel still counts toward the AM's quota and attribution. Pump's model is *additive* to the AM relationship, not competitive with it.

### Key Facts for AMs

| Question                                | Answer                                                                                                                                                                                                                                                |
| --------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Does Pump reduce cloud spend?           | Pump optimizes how customers buy commitments (RIs, SPs, CUDs). Savings from better commitment coverage are reallocated into new workloads, expanded usage, or other cloud investments. Total cloud consumption typically stays the same or increases. |
| Does Pump affect customer support?      | No. Customers retain their existing cloud provider support plans and direct support relationships.                                                                                                                                                    |
| Can customers still work with their AM? | Yes. The AM relationship is unchanged. Pump handles billing optimization, not account management.                                                                                                                                                     |
| What happens if a customer leaves Pump? | No contracts. Existing commitments run off naturally on their expiration schedule. Billing reverts to direct.                                                                                                                                         |

### Questions?

If you are a cloud provider AM with questions about a specific customer or about Pump's partner status, contact our partnerships team at <partnerships@pump.co>.


# How Pump Works with AWS

This page is for AWS account managers who want to understand how Pump operates within the AWS ecosystem. For customer-facing setup instructions, see [Connecting Your AWS Account](https://help.pump.co/~/revisions/bmYxZQ0rm63Yiwhd3bzB/aws-joining-pump/standard-onboarding).

### Pump's AWS Partner Status

| Detail              | Value                                                                                                                      |
| ------------------- | -------------------------------------------------------------------------------------------------------------------------- |
| Program             | AWS Solution Provider Program (Advanced Tier)                                                                              |
| Competencies        | Cloud Operations Services Competency, AI Services Competency                                                               |
| Additional programs | Authorized Commercial Solutions Provider, AWS Well-Architected Partner Program                                             |
| Partner listing     | [partners.amazonaws.com/partners/0018W00001wuP0XQAU/Pump](https://partners.amazonaws.com/partners/0018W00001wuP0XQAU/Pump) |
| Distribution        | Ingram Micro                                                                                                               |

### How the AWS Relationship Works

When a customer joins Pump on AWS, their account is invited into a Pump-controlled AWS Organization. Pump becomes the payer account for billing consolidation purposes. The customer's account, resources, workloads, and configurations remain entirely under the customer's control.

Pump uses the AWS Organizations consolidated billing structure to aggregate demand across its customer base, enabling volume-tier pricing.

#### What changes for the customer

| Before Pump                                          | After Pump                                                                           |
| ---------------------------------------------------- | ------------------------------------------------------------------------------------ |
| Customer pays AWS directly                           | Customer receives a consolidated invoice from Pump                                   |
| Customer manages their own RI/SP purchases           | Pump manages commitment purchases on the customer's behalf (if Autopilot is enabled) |
| Customer's account is standalone or in their own Org | Customer's account is a member of Pump's AWS Organization                            |

#### What does not change

The customer retains full ownership and administrative control of their AWS account. The customer's existing AWS support plan remains active and unchanged. The customer's AM relationship is unaffected.

### Permissions Pump Receives

Pump uses an IAM cross-account role with a unique External ID per customer. The role is deployed via a CloudFormation Quick-Create Stack (the customer clicks a link and confirms in the AWS Console). No manual IAM configuration is required.

#### Read-only role (all customers)

Used for cost visibility and optimization analysis. Includes:

| Service                                | Permissions                                               |
| -------------------------------------- | --------------------------------------------------------- |
| Cost Explorer                          | `ce:Get*`, `ce:List*`                                     |
| Cost and Usage Reports                 | `cur:Describe*`, `cur:List*`                              |
| Organizations                          | `organizations:Describe*`, `organizations:List*`          |
| EC2                                    | `ec2:DescribeInstances`, `ec2:DescribeReservedInstances*` |
| RDS, Redshift, ElastiCache, OpenSearch | `Describe*` (reserved instance and cluster metadata)      |
| Pricing                                | `pricing:*`                                               |
| Savings Plans                          | `savingsplans:Describe*`                                  |

#### Autopilot role (customers who opt into automated commitment management)

Includes all read-only permissions above, plus the ability to purchase commitments:

| Service       | Permissions                               |
| ------------- | ----------------------------------------- |
| EC2           | `ec2:PurchaseReservedInstancesOffering`   |
| RDS           | `rds:PurchaseReservedDbInstancesOffering` |
| Savings Plans | `savingsplans:*` (purchase and describe)  |

#### Pump Secure role (customers using Pump Secure)

Read-only security and inventory permissions for vulnerability scanning and compliance monitoring:

| Service                 | Permissions                      |
| ----------------------- | -------------------------------- |
| EC2, RDS, ECS, EKS      | `Describe*` (resource inventory) |
| Security Hub, GuardDuty | Read-only (security findings)    |
| CloudTrail              | Read-only (audit logs)           |
| Macie                   | Read-only (data classification)  |

#### Pump Infra role (customers using infrastructure recommendations)

Read-only compute and performance data for right-sizing analysis:

| Service               | Permissions                       |
| --------------------- | --------------------------------- |
| Compute Optimizer     | `compute-optimizer:*` (read-only) |
| EC2, Lambda, RDS, ECS | `Describe*`, `Get*`, `List*`      |
| CloudWatch            | Read-only (performance metrics)   |

### How Commitments Are Managed

Pump's commitment management engine analyzes the customer's usage patterns, existing RI/SP portfolio, and expiration schedules. It computes optimal commitment purchases per offering type and term.

Commitments purchased by Pump land in the customer's own account. Pump does not pool commitments across customers. Each commitment is keyed to a single customer account ID. If a customer leaves Pump, their commitments remain in their account and run off on their natural expiration schedule.

Customers can choose between two modes:

| Mode      | Behavior                                                                                                     |
| --------- | ------------------------------------------------------------------------------------------------------------ |
| Autopilot | Pump automatically executes recommended commitment purchases. Customer can block individual recommendations. |
| Manual    | Pump generates recommendations. Customer reviews and explicitly approves before any purchase is made.        |

### Impact on AM Quota

Customer spend that flows through Pump still counts toward the AWS AM's quota and attribution. Pump does not take commission from AWS AMs. Pump's solutions provider model is additive to the AM relationship.

### Data Sources Pump Uses

| Source                                       | What Pump reads                             | Purpose                                         |
| -------------------------------------------- | ------------------------------------------- | ----------------------------------------------- |
| Cost Explorer API                            | Daily and monthly cost/usage data           | Cost analysis, dashboards, forecasting          |
| Cost and Usage Reports (CUR)                 | Detailed line-item billing data (S3)        | RI utilization detail, granular cost breakdowns |
| AWS Organizations API                        | Account structure metadata                  | Multi-account visibility                        |
| EC2/RDS/ElastiCache/OpenSearch Describe APIs | Instance types, reserved instance inventory | Right-sizing analysis, commitment planning      |
| AWS Pricing API                              | Current pricing for all services            | Cost optimization calculations                  |

#### Data backfill

On first connection, Pump pulls up to 12 months of historical cost data from Cost Explorer. CUR-based ingestion backfills every calendar month since the account was created. After initial setup, Pump refreshes cost data on a rolling 31-day window.

### SOC 2 Type II

Pump is SOC 2 Type II certified. Audit reports are available on request through <partnerships@pump.co>.

### Questions?

If you have questions about a specific customer's Pump setup or about Pump's AWS partner status, contact <partnerships@pump.co>.


# How Pump Works with GCP

This page is for GCP account managers who want to understand how Pump operates within the Google Cloud ecosystem. For customer-facing setup instructions, see [Connecting Your GCP Account](https://help.pump.co/~/revisions/nqQuS4sCqArty7ozYkOl/gcp/getting-started-with-gcp-1).

### Pump's GCP Partner Status

| Detail          | Value                                                                                                |
| --------------- | ---------------------------------------------------------------------------------------------------- |
| Program         | Google Cloud Partner                                                                                 |
| Partner listing | [cloud.google.com/find-a-partner/partner/pump](https://cloud.google.com/find-a-partner/partner/pump) |
| Distribution    | Ingram Micro                                                                                         |

### How the GCP Relationship Works

When a customer joins Pump on GCP, their billing account becomes a sub-account under Pump's solutions provider billing account. This is the standard Google Cloud solutions provider model. Pump consolidates billing across its customer base, enabling volume-tier pricing.

The customer's GCP projects, resources, workloads, and configurations remain entirely under the customer's control.

#### What changes for the customer

| Before Pump                              | After Pump                                                                                                  |
| ---------------------------------------- | ----------------------------------------------------------------------------------------------------------- |
| Customer pays Google Cloud directly      | Customer's billing account is a sub-account under Pump. Customer receives a consolidated invoice from Pump. |
| Customer manages their own CUD purchases | Pump manages Committed Use Discount purchases on the customer's behalf (if configured)                      |

#### What does not change

The customer retains full ownership and administrative control of their GCP projects. The customer's existing Google Cloud support plan remains active. The customer's AM relationship is unaffected.

### How Connection Works

The customer connection flow has three steps:

1. **OAuth consent.** The customer authorizes Pump to list their GCP projects using read-only scopes (`openid`, `userinfo.email`, `userinfo.profile`, `cloudplatformprojects.readonly`). This gives Pump visibility into the customer's project structure, nothing more.
2. **Per-project IAM grant (optional).** The customer runs a script in Cloud Shell that grants Pump's service account limited permissions on specific projects. This enables commitment optimization for those projects.
3. **Billing account join.** The customer's billing account is linked as a sub-account under Pump's solutions provider billing account. This is the step that activates the solutions provider relationship.

### Permissions Pump Receives

#### OAuth scopes (all customers)

| Scope                                | Purpose                      |
| ------------------------------------ | ---------------------------- |
| `openid`                             | Authentication               |
| `userinfo.email`, `userinfo.profile` | User identification          |
| `cloudplatformprojects.readonly`     | List customer's GCP projects |

#### Per-project IAM roles (customers who run the setup script)

| Role                                   | Purpose                                                                 |
| -------------------------------------- | ----------------------------------------------------------------------- |
| `roles/bigquery.resourceAdmin`         | Access to billing export data for cost analysis                         |
| `roles/compute.viewer`                 | Read-only access to compute instance metadata for right-sizing analysis |
| `roles/compute.futureReservationAdmin` | CUD purchase execution                                                  |

These roles are granted to Pump's service account on a per-project basis. The customer controls which projects Pump has access to.

### How Commitments Are Managed

Pump analyzes the customer's compute usage patterns and existing CUD portfolio using BigQuery billing export data. It calculates optimal Committed Use Discount purchases based on usage trends and existing coverage.

Commitments purchased by Pump are scoped to the customer's own project. Pump does not pool commitments across customers. If a customer leaves Pump, their CUDs remain in their project and run off on their natural expiration schedule.

### Impact on AM Quota

Customer spend that flows through Pump still counts toward the GCP AM's quota and attribution. Pump does not take commission from GCP AMs. Pump's solutions provider model is additive to the AM relationship.

### Data Sources Pump Uses

| Source                  | What Pump reads                         | Purpose                                        |
| ----------------------- | --------------------------------------- | ---------------------------------------------- |
| BigQuery billing export | Standard and detailed billing data      | Cost analysis, dashboards, commitment planning |
| Cloud Resource Manager  | Project listing and metadata            | Multi-project visibility                       |
| Cloud Billing API       | Billing account and project enumeration | Account structure mapping                      |
| Compute Engine API      | Instance metadata (read-only)           | Right-sizing analysis                          |

#### Data backfill

On first connection, Pump pulls up to 35 days of historical billing data from BigQuery. Routine refreshes operate on a 7-day rolling window.

### SOC 2 Type II

Pump is SOC 2 Type II certified. Audit reports are available on request through <partnerships@pump.co>.

### Questions?

If you have questions about a specific customer's Pump setup or about Pump's GCP partner status, contact <partnerships@pump.co>.


# How Pump Works with Azure

This page is for Azure account managers who want to understand how Pump operates within the Microsoft Azure ecosystem. For customer-facing setup instructions, see [Connecting Your Azure Subscription](https://help.pump.co/~/revisions/5URpT9FFn4Jcsx7LTVRt/azure/connecting-azure).

### Pump's Azure Partner Status

| Detail       | Value                              |
| ------------ | ---------------------------------- |
| Program      | Authorized Microsoft Azure Partner |
| Distribution | Ingram Micro                       |

### How the Azure Relationship Works

Pump participates in the Microsoft Cloud Solution Provider (CSP) program as an indirect solutions provider through Ingram Micro. When a customer joins Pump on Azure, Pump manages billing and commitment optimization for the customer's Azure subscriptions.

The customer's Azure tenant, subscriptions, resource groups, and workloads remain entirely under the customer's control.

#### What changes for the customer

| Before Pump                                                       | After Pump                                                                           |
| ----------------------------------------------------------------- | ------------------------------------------------------------------------------------ |
| Customer pays Microsoft directly                                  | Customer receives a consolidated invoice from Pump                                   |
| Customer manages their own reservation and savings plan purchases | Pump manages commitment purchases on the customer's behalf (if Autopilot is enabled) |

#### What does not change

The customer retains full ownership and administrative control of their Azure tenant and subscriptions. The customer's existing Microsoft support plan remains active. The customer's AM relationship is unaffected.

### How Connection Works

The customer connection flow uses a service principal (application registration) approach:

1. **Service principal creation.** The customer runs `az ad sp create-for-rbac --name pump` in Azure Cloud Shell to create a service principal for Pump.
2. **Role assignment.** The customer runs Pump-provided `az` CLI commands to assign specific RBAC roles to the service principal at the subscription or management group level.
3. **Credential registration.** The customer provides the tenant ID, application ID, and client secret to Pump. Pump authenticates using OAuth2 client credentials.

No ARM templates, Bicep files, or Terraform modules are involved. The setup is done entirely through Azure CLI commands.

### Permissions Pump Receives

#### Read-only role (all customers)

| Role                      | Scope            | Purpose                                                   |
| ------------------------- | ---------------- | --------------------------------------------------------- |
| Billing Reader (built-in) | Per subscription | Access to cost and usage data for analysis and dashboards |

#### Autopilot role (customers who opt into automated commitment management)

| Role                                | Scope                      | Purpose                         |
| ----------------------------------- | -------------------------- | ------------------------------- |
| Pump Autopilot Role (custom)        | Management group or tenant | Commitment purchase actions     |
| Reservations Contributor (built-in) | Management group or tenant | Reservation management          |
| Reservations Purchaser (built-in)   | Management group or tenant | Reservation purchase execution  |
| Savings Plan Contributor (built-in) | Management group or tenant | Savings plan management         |
| Savings Plan Purchaser (built-in)   | Management group or tenant | Savings plan purchase execution |

### How Commitments Are Managed

Pump analyzes the customer's Azure usage patterns and existing reservation and savings plan portfolio using the Cost Management API. It calculates optimal commitment purchases based on usage trends and existing coverage.

Commitments purchased by Pump are scoped to the customer's own subscriptions. Pump does not pool commitments across customers. If a customer leaves Pump, their reservations and savings plans remain in their subscriptions and run off on their natural expiration schedule.

Customers can choose between two modes:

| Mode      | Behavior                                                                                                     |
| --------- | ------------------------------------------------------------------------------------------------------------ |
| Autopilot | Pump automatically executes recommended commitment purchases. Customer can block individual recommendations. |
| Manual    | Pump generates recommendations. Customer reviews and explicitly approves before any purchase is made.        |

### Impact on AM Quota

Customer spend that flows through Pump still counts toward the Azure AM's quota and attribution. Pump does not take commission from Azure AMs. Pump's solutions provider model is additive to the AM relationship.

### Data Sources Pump Uses

| Source                                           | What Pump reads                               | Purpose                                   |
| ------------------------------------------------ | --------------------------------------------- | ----------------------------------------- |
| Cost Management API (generateDetailedCostReport) | Detailed cost reports                         | Cost analysis, dashboards                 |
| Consumption API (usageDetails)                   | Usage detail records                          | Commitment planning, utilization analysis |
| Billing API                                      | Billing accounts, profiles, invoice sections  | Account structure mapping                 |
| Resource Groups API                              | Resource group listing                        | Subscription and resource visibility      |
| Reservations/Savings Plan APIs                   | Existing commitment inventory and utilization | Commitment portfolio management           |

#### Data backfill

On first connection with read-only access, Pump pulls up to 90 days of historical cost data (chunked into 7-day jobs). Routine refreshes operate on a 7-day rolling window.

### SOC 2 Type II

Pump is SOC 2 Type II certified. Audit reports are available on request through <partnerships@pump.co>.

### Questions?

If you have questions about a specific customer's Pump setup or about Pump's Azure partner status, contact <partnerships@pump.co>.


# Cloud Provider AM FAQ

These are questions we commonly hear from AWS, GCP, and Azure account managers when their customers start using Pump. If your question is not covered here, contact our partnerships team at <partnerships@pump.co>.

### Is Pump an authorized partner?

Yes. Pump is an authorized solutions provider and channel partner across all three major cloud providers.

| Provider | Program                                                                                                 | Verification                                                                           |
| -------- | ------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------- |
| AWS      | Solution Provider Program (Advanced Tier), Cloud Operations Services Competency, AI Services Competency | [AWS Partner Listing](https://partners.amazonaws.com/partners/0018W00001wuP0XQAU/Pump) |
| GCP      | Google Cloud Partner                                                                                    | [GCP Partner Listing](https://cloud.google.com/find-a-partner/partner/pump)            |
| Azure    | Authorized Microsoft Azure Partner                                                                      | Available on request                                                                   |

Pump distributes through Ingram Micro for all three providers.

### Does customer spend through Pump still count toward my quota?

Yes. Customer spend that routes through Pump's solutions provider channel counts toward your quota and attribution. Pump does not take commission from cloud provider AMs. The solutions provider relationship is additive to your existing account coverage.

### Does Pump reduce my customer's cloud spend?

Pump optimizes how customers purchase commitments (Reserved Instances, Savings Plans, Committed Use Discounts). This improves the customer's cost efficiency per unit of compute. In practice, customers reallocate the savings into new workloads, expanded usage, or other cloud investments, which increases total spend over time.

Pump does not recommend that customers reduce workloads, migrate away from your platform, or switch providers. Pump's right-sizing recommendations help customers match instance types to actual usage, which improves resource efficiency and frees up budget for additional cloud adoption.

### Does Pump affect my customer's support plan?

No. The customer's existing cloud provider support plan (AWS Support, Google Cloud Support, Microsoft Unified Support) remains active and unchanged. Pump does not modify, replace, or interfere with support entitlements.

### Can my customer still work with me directly?

Yes. The AM relationship is completely unaffected by Pump. Customers continue to work with their assigned AM for account strategy, service adoption, technical guidance, and all other account management activities. Pump handles billing optimization and commitment management only.

### How does Pump manage commitments on my customer's behalf?

Pump's commitment management engine analyzes the customer's usage patterns, existing commitment portfolio, and expiration schedules. It calculates optimal purchases for Reserved Instances (AWS), Savings Plans (AWS/Azure), Committed Use Discounts (GCP), and Azure Reservations.

All commitments are purchased within the customer's own account. Pump does not pool commitments across customers. Each commitment is tied to a single customer.

Customers can choose Autopilot mode (Pump executes recommendations automatically, customer can block individual purchases) or Manual mode (customer reviews and approves every purchase before execution).

### What happens if my customer stops using Pump?

No contracts, no lock-in. If a customer decides to leave Pump:

1. Existing commitments (RIs, SPs, CUDs) remain in the customer's account and run off on their natural expiration schedule. Nothing is canceled early.
2. Billing reverts to direct (customer pays the cloud provider directly).
3. The customer retains all their cloud resources, configurations, and data.

The transition is straightforward and does not disrupt the customer's workloads or your AM relationship.

### Does Pump work with customers who have existing commitments?

Yes. Pump's optimization engine accounts for existing RIs, SPs, and CUDs. Pump does not replace or cancel existing commitments. It optimizes new purchases around the customer's current portfolio, filling coverage gaps and improving utilization rates as existing commitments expire.

### Does Pump work with customers on an EDP or PPA?

Yes. Pump is compatible with Enterprise Discount Programs (AWS), Private Pricing Agreements (GCP), and Enterprise Agreements (Azure). Pump's commitment management operates alongside these programs.

### Is Pump SOC 2 certified?

Yes. Pump is SOC 2 Type II certified. Audit reports are available on request. Contact <partnerships@pump.co>.

### How do I get more information?

For any questions not covered here, including questions about specific customer accounts, partner verification, or Pump's security posture, contact our partnerships team at <partnerships@pump.co>. We are happy to set up a call or provide documentation as needed.


# Welcome to Pump University

Welcome to Pump!

{% embed url="<https://youtu.be/Dyzso_vZ2CI>" %}


# Getting Support

While our product is fully self-serve and self-use, we offer high quality and highly knowledgeable support for your AWS or GCP needs.

### Contact us

**Support tickets:** Submit a request at <support@pump.co>. This is the fastest way to reach the Pump support team for technical issues, billing questions, or account help.

**Email:** Reach out to the Pump team directly if you have questions about onboarding, pricing, or partnership inquiries.

**Slack:** Customers with a shared Slack channel can reach their account team directly through Slack.

### What to include in a support request

To help us resolve your issue quickly, include the following when submitting a ticket:

| Information                                                                 | Why it helps                             |
| --------------------------------------------------------------------------- | ---------------------------------------- |
| Your company name                                                           | Identifies your account                  |
| The cloud provider involved (AWS, GCP, Azure, or a third-party integration) | Routes your ticket to the right team     |
| What you were trying to do                                                  | Gives us context on the workflow         |
| What happened instead                                                       | Describes the issue                      |
| Screenshots or error messages                                               | Helps us diagnose without back-and-forth |

### Common issues

**CloudFormation stack failed to create (AWS).** Verify that your IAM user or role has permissions to create CloudFormation stacks and IAM roles. The stack requires `iam:CreateRole`, `iam:PutRolePolicy`, and `cloudformation:CreateStack` at minimum.

**Cloud Shell script did not complete (GCP/Azure).** Check that the required APIs are enabled on your project (GCP) or that your user has sufficient permissions to assign RBAC roles (Azure). See the connection guides for provider-specific troubleshooting.

**Pump is not receiving data after connection.** For AWS, the CloudFormation stack includes a custom resource that notifies Pump on completion. If this notification fails, contact support. For Azure, role assignment propagation can take up to 30 minutes.

**Savings estimate shows $0.** This typically means your current spend is already well-committed or your usage volume is below the threshold where commitment discounts are meaningful. Pump Save has the most impact at $5,000/month or more.

**Missing data for a cloud account or integration.** Verify that the required credentials are still active and that permissions have not been revoked. For third-party integrations, check that your API key has not expired or been rotated.

### Status

For real-time information on Pump service availability, visit the Pump status page. If you are experiencing an issue and the status page shows all systems operational, submit a support ticket so we can investigate.

### Feedback

If you have suggestions for improving Pump or its documentation, let us know through <support@pump.co>. We read every submission.


# AWS Unified Support

## AWS Unified Support

AWS Unified Support is an optional add-on available to Pump customers who want dedicated, 24/7 technical support for their AWS environment. It is not included by default. You need to opt in to activate it.

Pump provides this program through its support partner, **Ingram Micro**, an AWS Premier Tier Services Partner and AWS Partner of the Year (2024). Ingram Micro's AWS-certified engineering team handles all support operations, with direct escalation paths to AWS when needed.

### What you get

Once you opt in, your organization gets access to a fully managed AWS support program with defined SLAs, proactive guidance, and a dedicated support portal.

| Capability              | Details                                                                          |
| ----------------------- | -------------------------------------------------------------------------------- |
| Availability            | 24/7, including weekends and holidays                                            |
| Critical issue response | As fast as 15 minutes (Enterprise plan)                                          |
| Engineering team        | AWS-certified specialists                                                        |
| Ticket management       | Dedicated portal for submissions, tracking, and callbacks                        |
| AWS escalation          | Built-in L3 escalation path directly to AWS support engineers                    |
| Proactive support       | Health checks, Well-Architected reviews, optimization guidance (Enterprise plan) |

### Support plans

There are two plans. Both are billed as a percentage of your AWS spend.

#### Business Plan

Best for customers with moderate or growing AWS usage who need dependable, cost-effective support.

| Feature                                        | Included |
| ---------------------------------------------- | -------- |
| Web access to Cloud Support Engineers          | Yes      |
| Unlimited cases and contacts                   | Yes      |
| Contextual architectural guidance              | Yes      |
| AWS Support Automation runbooks (self-service) | Yes      |
| Engineer pool                                  | Shared   |

#### Enterprise Plan

Best for customers with business-critical or complex workloads requiring advanced technical engagement.

| Feature                                                                       | Included |
| ----------------------------------------------------------------------------- | -------- |
| Everything in Business                                                        | Yes      |
| Designated Technical Account Manager (TAM)                                    | Yes      |
| Deep architectural reviews and proactive workshops                            | Yes      |
| Critical issue SLA under 15 minutes                                           | Yes      |
| Proactive billing support (cost optimization, FinOps guidance, cost analysis) | Yes      |
| Proactive security reviews                                                    | Yes      |
| AWS Countdown engagements                                                     | Yes      |
| Critical event support                                                        | Yes      |

### Response times

| Severity                   | Level         | Initial Response Time        |
| -------------------------- | ------------- | ---------------------------- |
| Business Critical          | Critical (P1) | 15 minutes (Enterprise only) |
| Production Down            | Urgent (P2)   | 1 hour                       |
| Production System Impaired | High (P3)     | 4 hours                      |
| System Impaired            | Medium (P4)   | 12 hours                     |
| General Guidance           | Low (P5)      | 24 hours                     |

### Pricing

AWS Unified Support uses a percentage-of-spend pricing model based on your AWS monthly recurring revenue (MRR). You only pay once you opt in.

#### Business Plan pricing

| Your AWS MRR   | Monthly Rate |
| -------------- | ------------ |
| Up to $165K    | 4.0% to 5.5% |
| $165K to $450K | 4.0% to 5.5% |
| $450K+         | 4.0% to 5.5% |

Best for customers with $10K to $350K in AWS MRR.

#### Enterprise Plan pricing

| Your AWS MRR   | Monthly Rate |
| -------------- | ------------ |
| Up to $200K    | 5.0% to 6.5% |
| $200K to $600K | 5.0% to 6.5% |
| $600K+         | 5.0% to 6.5% |

Best for customers with $360K+ in AWS ARR.

#### Comparison to AWS Direct Support

AWS charges for support using a tiered rate structure that starts at 10% of spend. Opting in through Pump is significantly less expensive.

| Scenario           | AWS Direct Cost (Annual) | Pump Unified Support Cost (Annual) | Approximate Savings |
| ------------------ | ------------------------ | ---------------------------------- | ------------------- |
| $40K/mo AWS spend  | \~$48K (10%)             | \~$26.4K                           | \~45%               |
| $150K/mo AWS spend | \~$180K (10%)            | \~$99K to $117K                    | \~35%               |
| $400K/mo AWS spend | \~$336K (7.85%)          | \~$240K to $288K                   | \~16%               |

#### Commitment options

| Option        | Details                                                              |
| ------------- | -------------------------------------------------------------------- |
| Monthly (MRR) | Start with no long-term lock-in. Recommended for initial evaluation. |
| Annual (ARR)  | Convert after 30 to 90 days for better rates.                        |
| Contracts     | No long-term contracts required to get started.                      |

### How to submit a support ticket

Once you have opted in, submit and manage support tickets through the dedicated support portal operated by Ingram Micro.

1. Log in to the [Unified Support Portal](https://aws.support.ingrammicro.com/).
2. Navigate to the **Support** section.
3. Select your AWS account and click **Submit a request**.
4. Choose the issue type, priority level, and describe your request.
5. For urgent issues, mark the ticket as **High** or **Critical** to trigger faster response times.

Callbacks are available for high-severity issues.

### Escalation path

1. You submit a ticket through the Unified Support Portal.
2. AWS Support Engineers (provided by Ingram Micro) handle the case. They serve as your single point of contact with 24/7 web and callback support.
3. Enterprise customers also receive architectural guidance, proactive Well-Architected Framework (WAF) reviews, and access to a named TAM.
4. When L3 AWS involvement is needed, the support team escalates directly to AWS engineers for resolution.

### How to opt in

AWS Unified Support is not enabled by default. To activate it:

1. Contact your Pump account team to discuss which plan (Business or Enterprise) fits your workload and support needs.
2. Once you select a plan, Pump onboards you to the Unified Support Portal.
3. You can start with a monthly commitment to evaluate the service before committing annually.

Contact your Pump account manager or email <support@pump.co> to get started.


# Security & Access

We are committed to the highest standard of security, which is why...

Pump accesses your cloud billing and usage data to optimize your spend. This page covers what Pump can and cannot access, how your data is protected, and the certifications Pump holds.

**SOC 2 Type II**

Pump is SOC 2 Type II certified. The audit covers security, availability, and confidentiality controls across Pump's infrastructure, data handling, and access management. Audit reports are available on request. Contact your account team or reach out through [support.pump.co](https://support.pump.co/).

**What Pump accesses**

Pump requires access to billing and usage data to generate savings recommendations and provide spend visibility. The specific permissions vary by cloud provider.

| Provider | Access method                                        | What Pump reads                                                                                                                              |
| -------- | ---------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------- |
| AWS      | Cross-account IAM role (deployed via CloudFormation) | Cost Explorer data, Cost and Usage Reports, resource inventory (EC2, RDS, ElastiCache, Redshift, OpenSearch), Compute Optimizer, Pricing API |
| GCP      | OAuth consent + per-project service account          | BigQuery billing export, project metadata, Cloud Billing account data                                                                        |
| Azure    | Service principal (app registration + client secret) | Cost Management reports, Consumption usage details, resource groups, billing profiles                                                        |

For third-party integrations (Anthropic, OpenAI, GitHub, Datadog, Cursor, ClickHouse Cloud), Pump pulls usage and cost data through each service's API using the credentials you provide. See the individual integration pages for details on what each key type accesses.

**What Pump never accesses**

Pump does not access your application data, source code, customer data, infrastructure configurations, secrets, or logs. Specifically:

| Category         | Details                                                                                                                                   |
| ---------------- | ----------------------------------------------------------------------------------------------------------------------------------------- |
| Application data | No access to S3 bucket contents, database records, Cloud Storage objects, Azure Key Vault secrets, or any stored data                     |
| Infrastructure   | No ability to create, modify, start, stop, or terminate any cloud resource                                                                |
| Identity         | No access to IAM users or credentials (AWS), Active Directory users (Azure), or IAM policies (GCP) beyond the service principal Pump uses |
| Logs             | No access to CloudWatch Logs, Cloud Logging, or Azure Monitor logs                                                                        |
| Network          | No access to VPC configurations, firewall rules, or network traffic                                                                       |

The only write action Pump performs is purchasing commitments (Reserved Instances, Savings Plans, Committed Use Discounts) when you explicitly enable Autopilot mode. Even then, Pump can only purchase discount instruments. It cannot modify or terminate any running resource.

**How credentials are handled**

Pump does not store your cloud provider credentials directly.

| Provider | How authentication works                                                                                                                                                         |
| -------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| AWS      | Pump assumes a cross-account IAM role using temporary STS tokens. Your credentials are never stored. Each connection uses a unique External ID so only Pump can assume the role. |
| GCP      | OAuth tokens are used for project discovery. Per-project access is granted to a Pump-managed service account through standard GCP IAM. No Google credentials are stored.         |
| Azure    | Pump authenticates using a service principal (app registration) with a client secret via OAuth2 client-credentials flow. The client secret is stored encrypted.                  |

For third-party integrations, API keys you provide are stored encrypted and used only for pulling usage and cost data from the respective service.

**Read-only by default**

When you first connect a cloud account, Pump deploys a read-only role. This role can only read billing and usage data. It cannot make purchases or modify anything.

Billing-level permissions (the ability to purchase commitments on your behalf) are granted in a separate, explicit step during onboarding. You must actively authorize Pump as your billing partner before any purchasing capability is enabled.

For detailed permission lists by provider, see the connection guides:

| Provider | Connection guide |
| -------- | ---------------- |
| AWS      | Connecting AWS   |
| GCP      | Connecting GCP   |
| Azure    | Connecting Azure |

**Data handling**

Pump processes your billing and usage data to generate savings recommendations, populate dashboards, and calculate forecasts. This data is stored in Pump's infrastructure and is used exclusively for your account's optimization and visibility features.

Pump does not sell, share, or provide your billing data to any third party. Your data is not used to train machine learning models or for any purpose outside of operating your Pump account.

**Pump Secure (optional)**

If you enable Pump Secure, an additional IAM role is deployed to your AWS account with read-only access to security-relevant services (SecurityHub, GuardDuty, CloudTrail, Macie, and resource inventory). This role is separate from the cost optimization roles and has no billing or purchasing permissions.

Pump Secure scans your resource configurations against compliance frameworks (CIS, SOC 2, HIPAA, PCI DSS, NIST, and others) and reports findings. It does not perform active penetration testing, modify security groups, or change any configuration. See the Pump Secure documentation for details.

**Offboarding**

There are no contracts or lock-in periods. You can disconnect from Pump at any time.

When you leave Pump:

| What happens         | Details                                                                                                                                                                                |
| -------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Existing commitments | Reserved Instances, Savings Plans, and CUDs that Pump purchased remain in your cloud account. They run off naturally on their original expiration schedule. Nothing is canceled early. |
| Billing              | Your billing relationship reverts to direct (you pay your cloud provider instead of Pump).                                                                                             |
| Cloud resources      | All your cloud resources, configurations, and data remain exactly as they are. Pump never modifies infrastructure.                                                                     |
| IAM roles            | You can delete the Pump IAM roles from your AWS account, revoke the service principal in Azure, or remove IAM grants in GCP at any time.                                               |
| Pump data            | Your historical cost data in Pump's dashboards is no longer accessible after disconnection.                                                                                            |

The transition does not disrupt your workloads or require any infrastructure changes.

### Compliance certifications

| Certification | Status                                                                                                                                            |
| ------------- | ------------------------------------------------------------------------------------------------------------------------------------------------- |
| SOC 2 Type II | Certified. Report available on request.                                                                                                           |
| AWS Partner   | AWS Solution Provider Program (Advanced Tier), Cloud Operations Services Competency, AI Services Competency, AWS Well-Architected Partner Program |
| GCP Partner   | Google Cloud Partner                                                                                                                              |
| Azure Partner | Authorized Microsoft Azure Partner (CSP indirect solutions provider through Ingram Micro)                                                         |

### Questions

If you have questions about Pump's security posture, data handling, or compliance certifications, contact us at <support@pump.co> or reach out to your account team.


# Cross Account Role

Pump accesses your AWS account via a cross-account role. In line with AWS IAM policy best practices, Pump requests only the [least-privilege permissions](https://docs.aws.amazon.com/IAM/latest/UserGuide/best-practices.html#grant-least-privilege). This means we limit the actions we can take and the resources to which those actions can be applied.

We further enhance security by dividing permissions into two separate roles: the read-only role and the auto-pilot role.

#### Read-only role - <a href="#h_115da0c078" id="h_115da0c078"></a>

This role is used during the initial [onboarding step (Step 1)](https://help.pump.co/getting-started/step-1-view-estimate). It requires read-only permissions [(see the full list here)](https://app.pump.co/pump-read-only-role.json) to access up to one year of historical billing data (via Cost Explorer) and your AWS infrastructure metadata (such as the Redshift cluster you are using and whether it is already covered by reserved instances). After ingesting this data, Pump's billing engine calculates optimal savings. Once a user is fully onboarded, the read-only role is used again to display cost and savings on the Pump dashboard, helping users monitor their current spending and the savings achieved by Pump.

<pre><code><strong>[
</strong>  {
    "PolicyName": "PumpBillingReadOnly",
    "PolicyDocument": {
      "Statement": [
        {
          "Action": [
            "budgets:Describe*",
            "budgets:View*",
            "ce:Get*",
            "ce:Describe*",
            "ce:List*",
            "cur:Describe*",
            "pricing:DescribeServices",
            "pricing:GetAttributeValues",
            "pricing:GetProducts",
            "organizations:Describe*",
            "organizations:List*",
            "savingsplans:Describe*",
            "rds:Describe*",
            "rds:List*",
            "elasticache:List*",
            "elasticache:Describe*",
            "redshift:Describe*",
            "es:Describe*",
            "es:List*"
          ],
          "Resource": "*",
          "Effect": "Allow"
        }
      ]
    }
  }
]
</code></pre>

#### Auto-pilot role - <a href="#h_ed4ce26364" id="h_ed4ce26364"></a>

This role is employed after the[ final onboarding step](https://help.pump.co/getting-started/step-1-view-estimate). It includes all the permissions from the read-only role, as well as additional read-only permissions for collecting service usage metadata, such as compute instance metadata (see the full list of permissions[ here](https://app.pump.co/pump-auto-pilot-role.json)). Note that Pump does not collect application data or user data—only usage metadata is collected. In addition to gathering usage metadata, the auto-pilot role also requires permission to buy and sell reserved instances and savings plans. Pump's AI algorithms process the usage metadata and manage cost commitments on behalf of users.

```
[
  {
    "PolicyName": "PumpOrgInvite",
    "PolicyDocument": {
      "Version": "2012-10-17",
      "Statement": [
        {
          "Action": [
            "organizations:Describe*",
            "organizations:List*",
            "organizations:AcceptHandshake",
            "iam:CreateServiceLinkedRole"
          ],
          "Resource": "*",
          "Effect": "Allow"
        }
      ]
    }
  },
  {
    "PolicyName": "PumpReadOnly",
    "PolicyDocument": {
      "Version": "2012-10-17",
      "Statement": [
        {
          "Action": [
            "budgets:Describe*",
            "budgets:View*",
            "ce:*",
            "ec2:Describe*",
            "ec2:GetCapacityReservationUsage",
            "ec2:GetReservedInstancesExchangeQuote",
            "cloudwatch:Describe*",
            "cloudwatch:Get*",
            "cloudwatch:List*",
            "ecs:Describe*",
            "ecs:List*",
            "eks:Describe*",
            "eks:List*",
            "pricing:DescribeServices",
            "pricing:GetAttributeValues",
            "pricing:GetProducts",
            "servicequotas:Get*",
            "servicequotas:List*",
            "application-autoscaling:Describe*",
            "autoscaling:Describe*",
            "aws-portal:ViewBilling",
            "aws-portal:ViewUsage",
            "consolidatedbilling:List*",
            "consolidatedbilling:Get*",
            "rds:Describe*",
            "rds:List*",
            "elasticache:List*",
            "elasticache:Describe*",
            "redshift:Describe*",
            "redshift:GetReservedNodeExchangeConfigurationOptions",
            "redshift:GetReservedNodeExchangeOfferings",
            "es:Describe*",
            "es:List*",
            "tag:Get*",
            "transfer:Describe*",
            "transfer:List*"
          ],
          "Resource": "*",
          "Effect": "Allow"
        }
      ]
    }
  },
  {
    "PolicyName": "PumpAutoPilot",
    "PolicyDocument": {
      "Version": "2012-10-17",
      "Statement": [
        {
          "Action": [
            "ec2:CreateTags",
            "ec2:AcceptReservedInstancesExchangeQuote",
            "ec2:CancelReservedInstancesListing",
            "ec2:CreateReservedInstancesListing",
            "ec2:DeleteQueuedReservedInstances",
            "ec2:PurchaseHostReservation",
            "ec2:PurchaseReservedInstancesOffering",
            "ec2:ModifyReservedInstances",
            "savingsplans:*",
            "rds:PurchaseReservedDbInstancesOffering",
            "elasticache:PurchaseReservedCacheNodesOffering",
            "redshift:PurchaseReservedNodeOffering",
            "redshift:AcceptReservedNodeExchange",
            "es:PurchaseReservedInstanceOffering",
            "servicequotas:RequestServiceQuotaIncrease",
            "support:*"
          ],
          "Resource": "*",
          "Effect": "Allow"
        }
      ]
    }
  }
]
```

Please contact our support team for more information. <support@pump.co>


# Role Deployment

Pump automates cross-account role deployment using [AWS CloudFormation](https://aws.amazon.com/cloudformation/) (CFN) and, more specifically, "[quick-create links.](https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/cfn-console-create-stacks-quick-create-links.html)" These links enable Pump to pass a CFN template along with user-specific parameters, such as the cross-account role, external ID, Pump ID, and more.

Pump automates cross-account role deployment using AWS CloudFormation (CFN) and, more specifically, "quick-create links." These links enable Pump to pass a CFN template along with user-specific parameters, such as the cross-account role, external ID, Pump ID, and more.

Users only need to click the quick-create link and then click "deploy" to have the role deployed to their AWS account. The CFN templates are stored publicly, allowing users to review them before agreeing to the deployment:

* [Read-only role](https://pump-public-readonly.s3.us-west-2.amazonaws.com/pump-readonly.json)
* [Auto-pilot role](https://pump-public-readonly.s3.us-west-2.amazonaws.com/pump-auto-pilot.json)

(you can read more about these roles in the previous article, [here](https://help.pump.co/security-and-access/cross-account-role))

During deployment, after role creation, a list of properties is sent to Pump's management account:

* Pump ID
* Cross-account role ARN
* Pump external ID
* User's account ID
* Role type (read-only or auto-pilot)

These properties are stored in Pump's database. If the deployment occurs during the last step, Pump will also invite the user's AWS account to join Pump's AWS Organization. If the user already belongs to an organization, this step will fail. We support existing organizations joining Pump on a case-by-case basis. Please contact our support team if this applies to you!

Lastly, we offer manual role deployment for customers who cannot work with CloudFormation.

Please contact our support team for more information. <support@pump.co>

<br>


# Access Management

**Restricted Access**

Pump adheres to AWS security best practices rigorously. We restrict the cross-account role for use only by Pump's management account with the correct external ID.

**Read-only permissions**

We also limit permissions so that Pump can only access your billing data and infrastructure metadata, which does not include any application data or user data. An example of the information we extract from your infrastructure metadata is as follows:

> Six t2.micro on-demand instance types have been running continuously for the past 8 months, with consistent network traffic and an average CPU utilization of over 60%. Based on the last 4 months of AWS marketplace RI listing data, we can determine that t2.micro liquidity is high (it will take little time to sell this instance back to the marketplace). We recommend starting a 3-year, no-upfront RI order for 6 t2.micro instances and using algorithms to find the best deals for all 6 instances in the marketplace.

Beyond that, Pump can only buy or sell reserved instances on your behalf.

**App authentication and authorization**

Pump uses Auth0 as our authentication platform, which is compliant with nearly all security certifications, such as GDPR, HIPAA, ISO27018, SOC II, ISO27001, etc. You can read [more](https://auth0.com/security) here.

**Security auditing**

Pump engages third-party companies to conduct regular penetration testing to identify any potential security risks. Additionally, we are in the process of obtaining SOC II certification.

<br>


# Other Housekeeping

### Cloudformation stacks created

Do not delete the CloudFormation stacks that were created during the initial onboarding. We use the permissions granted during then that helps us purchase and sell RIs/Savings plan on your behalf.&#x20;

<figure><img src="/files/jSutATHlDaCeLoxMxB7g" alt=""><figcaption></figcaption></figure>

If you have any further questions, please contact us at <support@pump.co>

### Should I purchase RIs or savings plans in future

Pump is 100% responsible for all the purchase decisions we make on your behalf. That means you have no financial risk when it comes to commitments. If you don't end up using a savings plan or RI that we purchased for you, Pump provides a money-back guarantee after 30 days of no use in the form of an AWS credit.&#x20;

If you were to make these purchases on your own, Pump would not take responsibility, and the risk would be on you. We strongly recommend that you avoid doing this.

### Spinning up an AWS service or discontinuing one

Pump AI continuously scans your purchase history and tries to forecast your future spend. While AI can do its job well, we recommend that you inform us of your plans in advance (if possible) so that we can be even more efficient with our commitments. You can leave us a message on the chat or email us at <support@pump.co>. We will soon embed this feature in the product itself to make it more convenient.


# Security Standards

As a provider of cloud services, Pump adheres to several cybersecurity frameworks to ensure our customers can operate their digital workloads in a safe and secure environment.

In addition to rigorous adherence to [AWS best security practices](https://docs.aws.amazon.com/IAM/latest/UserGuide/best-practices.html#grant-least-privilege), Pump maintains compliance with several other security frameworks, including:

* SOC 2
* ISO 27001
* GDPR
* AWS Well-Architected Framework

#### **Billing level-only permissions** <a href="#undefined" id="undefined"></a>

We also limit permissions so that Pump can only access your billing data and infrastructure metadata. Pump does not take permissions to view any application data or user data in your workloads.

For information, please see our [Role Deployment and Permissions Page](https://support.pump.co/articles/4053642719-role-deployment).

#### **App authentication and authorization** <a href="#undefined" id="undefined"></a>

Pump uses Auth0 as the authentication provider for users to verify email and log into the platform. Auth0 is compliant with most established security frameworks, and certifications can be viewed on their website [here](https://auth0.com/docs/secure/data-privacy-and-compliance).

#### **Security auditing** <a href="#undefined" id="undefined"></a>

Pump engages third-party companies to conduct regular penetration testing to identify any potential security risks.


# Changing Infrastructure while on Pump

## Overview <a href="#undefined" id="undefined"></a>

When changing your infrastructure to better fit your needs, it is important to note two key factors.

1. Any Reserved Instances that previously applied to your instance that you have changed will no longer apply unless it is the exact same instance (Region, Singe-AZ, family type, etc). This means that any changed instance that previously used an RI, unless there is available on-demand spend to cover it, will now be accruing costs instead of saving you money.
2. If you have an EC2 Compute Savings Plan (SP), if you scale down your EC2 compute instances below the threshold covered by the Savings Plan, you will still accrue the costs of the savings plan while saving on a portion or none of the covered spend. The easiest way to ensure this does not happen is going to your AWS Dashboard > Cost Explorer > Savings Plan Utilization Report. If your coverage report is less than 100%, this means that you are not using every available dollar in your savings plan.

In general you can check which Savings Plans and Reserved Instances you have in the Pump Dashboard > Save Dashboard, where you can see the SPs or RIs attached to your AWS Account. We highly recommend understanding how your infrastructure change interacts with these RIs & SPs before undergoing a major infrastructure transformation.

![Screenshot 2025-03-07 at 11.08.11 AM.png](https://assets.usepylon.com/6bacbab4-dff1-4b53-b5f8-bea49f26ab4a%2F1741374497197-Screenshot2025-03-07at11.08.11AM.png?Expires=253370764800\&Signature=sipVP9844GQ-nov5ekfBcaphVows3fHeLZbcVx4YcMh9N304Uzd-tNf8bkXJd1sC-Fl49bx7WPkdRXWxtRuf~1I4HxnnbnFRzD9t5ssePXqlhEEgoAFewj0PtH~KGfuHJEjrPlgR1zU8nC~ArXm~k7ZmrJBEZFs~x~iVs3kv0xmuEnwXvGW8OZSKqCOJAiivRHyxmiC0teQdqUKZ0-lvg1VECb3HncC6uRwi5nKpTI1G-bK5CHd9DxmoetUObXGfM7SaMITraZmJ33Kso40Kn-YSF0oBAkizqVWlh2pTdlPdUWY528y1skOgXEs-AAusk~OkTS-RZLxf97VOEHGtRg__\&Key-Pair-Id=K3NV4LZ47N8M46)

## Undergoing Infrastructure Change <a href="#undefined" id="undefined"></a>

If you believe that you need to undergo a major transformation and project that you will not be using instances covered by any SPs or RIs attached to your account, please reach out to <support@pump.co>.


# Enroll in Pump Infra Recs \[beta]

We are excited for you to be part of the Pump Infra Recs Beta!\
\
Thanks for being part of the cohort interested. Please follow the steps to deploy a CloudFormation Stack so we can identify infrastructure recommendations like...

**1/** If an instance is over-provisioned&#x20;

**2/** If an instance is idle and can be removed &#x20;

**STEPS TO ENABLE INFRA RECS:**

**Step One:** Go to Integrations Page in the [**SETTINGS**](https://app.pump.co/settings#integrations).

link: <https://app.pump.co/settings#integrations>

**Step Two:** Click the three buttons of the AWS account you are looking to enable infra savings recs.

<figure><img src="/files/GfQ5tIM1qCCCOn5A5IM9" alt=""><figcaption></figcaption></figure>

**Step Three:** Deploy the Stack&#x20;

<figure><img src="/files/WC12k4iSueVmjz4cL7w7" alt=""><figcaption></figcaption></figure>

**Step Four:** Select the blue button after Connecting (deploying) the Cloud Formation Stack.&#x20;

<figure><img src="/files/A1RE40SCj84aIRbN8X2d" alt=""><figcaption></figcaption></figure>

**Step Five:** Click Create Stack.

Then wait for it to be created, and no further action is needed! Thanks for enrolling in the beta, we'll reach out with next steps shortly!


