FinOps Intelligence
Purpose
Unified cost intelligence skill that identifies savings opportunities, tracks cost trends, and generates chargeback/showback reports by team or project. Answers both "where can we save?" and "who spent what?"
When to use this skill
- User asks "why did our bill go up?"
- User asks for cost optimization or savings opportunities
- User asks "how much did team X spend this month?"
- User asks for chargeback, showback, or cost allocation report
- Monthly proactive cost review or FinOps cadence
Pre-check
Confirm with the user:
- Scope: Which subscriptions to scan (all or specific ones)
- Time range: For trend analysis (default: last 3 months)
- Allocation model (for chargeback): Which tag to use for cost splitting?
cost-centertag (most common)ownerorteamtagapplicationorprojecttag- Resource group naming convention (e.g.,
rg-teamname-*)
- Exclusions: Dev/test subscriptions, sandbox resource groups
Analysis procedure
Step 1: Cost trend overview
Get the big picture using Azure Cost Management.
# Current month cost by service (last 30 days)
az costmanagement query --type ActualCost --timeframe MonthToDate \
--scope "subscriptions/<sub-id>" \
--dataset-aggregation '{"totalCost":{"name":"Cost","function":"Sum"}}' \
--dataset-grouping name="ServiceName" type="Dimension" \
-o table
# Previous month for comparison
az costmanagement query --type ActualCost --timeframe TheLastMonth \
--scope "subscriptions/<sub-id>" \
--dataset-aggregation '{"totalCost":{"name":"Cost","function":"Sum"}}' \
--dataset-grouping name="ServiceName" type="Dimension" \
-o table
If az costmanagement is unavailable, use the REST API:
az rest --method post \
--url "https://management.azure.com/subscriptions/<sub-id>/providers/Microsoft.CostManagement/query?api-version=2023-11-01" \
--body '{"type":"ActualCost","timeframe":"MonthToDate","dataset":{"aggregation":{"totalCost":{"name":"Cost","function":"Sum"}},"grouping":[{"type":"Dimension","name":"ServiceName"}]}}'
Summarize:
- Total spend this month vs. last month (% change)
- Top 5 services by spend
- Top 5 resource groups by spend
- Any spending anomalies (day-over-day spikes > 20%)
Step 2: Orphaned resources (waste)
Find resources consuming cost with no active use.
| Check | Command | Savings signal |
|---|---|---|
| Unattached managed disks | az disk list --query "[?managedBy==null]" |
Disk cost per month |
| Unused public IPs | az network public-ip list --query "[?ipConfiguration==null]" |
~$3.65/month each |
| Stopped but allocated VMs | az vm list -d --query "[?powerState=='VM deallocated']" |
Disk + IP cost still billed |
| Unused App Service plans | az appservice plan list --query "[?numberOfSites==0]" --resource-group <rg> |
Full plan cost |
| Old snapshots (>90 days) | az snapshot list --query "[?timeCreated<'$(date -u -d '90 days ago' +%Y-%m-%dT%H:%M:%SZ)']" |
Storage cost |
| Unused NAT Gateways | az network nat gateway list cross-ref with subnets |
~$32/month each |
| Empty resource groups | az group list then check member count |
Organizational waste |
Note on date handling: Use shell variable substitution for date comparisons:
- Linux/macOS:
$(date -u -d '90 days ago' +%Y-%m-%dT%H:%M:%SZ) - The SRE Agent sandbox runs Linux, so the above syntax is valid.
Step 3: Rightsizing opportunities
Identify over-provisioned resources.
- VMs with low CPU (< 5% avg over 14 days):
Query Azure Monitor metrics for
Percentage CPUacross all VMs - VMs with low memory (< 10% avg): Query Log Analytics for memory counters if available
- Over-provisioned App Service plans: Check CPU and memory % across the plan — if consistently < 20%, suggest downgrade
- Over-provisioned databases: Check DTU/vCore utilization — if < 20%, suggest lower tier
For each, calculate:
- Current SKU and monthly cost
- Recommended SKU and monthly cost
- Estimated monthly savings
Step 4: Reservation & savings plan opportunities
- List VMs running 24/7 for > 30 days — candidates for Reserved Instances (up to 72% savings)
- List databases running 24/7 — candidates for reserved capacity
- Check if Azure Savings Plans could apply to compute spend
Step 5: Storage optimization
- Check storage accounts for access tier usage:
az storage account list --query "[].{name:name, accessTier:accessTier, kind:kind}" -o table - Identify blobs that haven't been accessed in 90+ days — candidates for Cool/Archive tier
- Check for lifecycle management policies — suggest if missing
- Check for redundancy over-provisioning (GRS when LRS would suffice for non-critical data)
Step 6: Cost allocation (chargeback/showback)
Group costs by the user's chosen allocation model.
By tag (preferred):
- Group all resources by the chosen tag value
- Aggregate costs per tag value
- Track untagged resources separately as "Unallocated"
By resource group (fallback):
- Parse resource group names for team/project identifiers
- Group and aggregate accordingly
Shared costs (identify and handle):
- Resources used by multiple teams (e.g., shared AKS cluster, shared networking)
- Flag these separately — suggest allocation keys (even split, usage-based, or headcount-based)
For each team/project:
- This period vs. previous period: $ change and % change
- Top cost driver (which service drove the change?)
- Flag anomalies (> 30% increase without known cause)
Step 7: Efficiency metrics
Calculate per-team efficiency indicators:
- Cost per resource: Total spend / number of resources
- Compute waste ratio: Cost of idle/underutilized resources / total compute cost
- Tag compliance: % of team's resources properly tagged
Accepted exceptions (optional)
If the user provides a list of accepted exceptions, do not flag those items. Instead, note them in the report as Accepted Exception with the reason provided.
Example format the user may provide:
| Check | Reason |
|---|---|
| 2.1 Unattached managed disks | Kept for disaster recovery snapshots, reviewed monthly |
| 3.2 Over-provisioned App Service plans | Pre-scaled for upcoming product launch next week |
| 4.1 Reserved instances | Short-term project, reservations not cost-effective |
When exceptions are provided:
- Skip the flagged checks in scoring
- List them in a separate "Accepted Exceptions" section at the end of the report
- Recalculate the overall score excluding excepted checks
Expected output
Report header (mandatory — use this exact format)
FinOps Cost Optimization & Chargeback Report
| Field | Value |
|---|---|
| Subscription | (name + ID) |
| Report Date | YYYY-MM-DD |
| Total Spend (MTD) | $X,XXX |
| Projected Full Month | $X,XXX |
| Month-over-month Change | +/-$X (+/-X%) |
| Waste Identified (recoverable) | ~$X/month |
| Resource Groups Tracked | N (M with spend) |
| Tag Compliance | X% |
| Issues Found | X Critical, Y High, Z Medium |
Savings breakdown table
| Category | Finding | Current Cost/mo | Savings/mo | Priority | Action |
|---|---|---|---|---|---|
| Orphaned | 3 unattached disks | $45 | $45 | High | Delete or snapshot+delete |
| Rightsizing | 2 VMs at < 5% CPU | $380 | $190 | High | Resize D4s_v5 → B2ms |
| Reservations | 5 VMs running 24/7 | $1,200 | $864 | Medium | 3yr RI |
| Storage | No lifecycle policies | $200 | $80 | Medium | Add cool tier policy |
| TOTAL RECOVERABLE | — | — | ~$X,XXX/mo | — | — |
Cost allocation table
| Team / Project | This Period | Last Period | Change | % Change | Top Service | % of Total |
|---|---|---|---|---|---|---|
| Platform | $5,200 | $4,800 | +$400 | +8.3% | Compute | 32% |
| Product API | $3,800 | $3,100 | +$700 | +22.6% ⚠️ | Databases | 24% |
| Unallocated | $1,300 | $800 | +$500 | +62.5% 🔴 | Mixed | 8% |
| Total | $16,000 | $14,300 | +$1,700 | +11.9% | 100% |
Quick wins (implement today)
Top 3 actions that save the most with the least effort.
Requires planning
Actions that need architecture review or stakeholder approval.
Unallocated cost remediation
List untagged resources with suggested owner and tagging command:
az resource tag --ids <resource-id> --tags team=<team> cost-center=<cc>
Remediation guidance
For each cost finding, include in the output:
- The specific
azCLI command to remediate (suggest only — do not execute) - Use
GetAzCliHelpto validate the command syntax before suggesting - The official Microsoft Learn documentation link
References
- Cost Management: https://learn.microsoft.com/en-us/azure/cost-management-billing/costs/overview-cost-management
- Azure Advisor Cost: https://learn.microsoft.com/en-us/azure/advisor/advisor-cost-recommendations
- Reserved Instances: https://learn.microsoft.com/en-us/azure/cost-management-billing/reservations/save-compute-costs-reservations
- Orphaned Resources: https://learn.microsoft.com/en-us/azure/advisor/advisor-reference-cost-recommendations
Sample output
The following is a redacted example of what the report looks like when run against a subscription.
FinOps Cost Optimization & Chargeback Report
| Field | Value |
|---|---|
| Subscription | contoso-prod-001 (a1b2c3d4-e5f6-7890-abcd-ef1234567890) |
| Report Date | 2026-07-15 |
| Total Spend (MTD) | $12,340 |
| Projected Full Month | $16,450 |
| Month-over-month Change | +$1,700 (+11.5%) |
| Waste Identified (recoverable) | ~$1,179/month |
| Resource Groups Tracked | 14 (12 with spend) |
| Tag Compliance | 78% |
| Issues Found | 2 Critical, 3 High, 4 Medium |
Savings breakdown table
| Category | Finding | Current Cost/mo | Savings/mo | Priority | Action |
|---|---|---|---|---|---|
| Orphaned | 3 unattached disks in rg-app-prod |
$45 | $45 | High | Delete or snapshot+delete |
| Orphaned | 2 unused public IPs | $7 | $7 | Medium | Delete |
| Rightsizing | vm-batch-01 at 3% CPU avg |
$380 | $190 | High | Resize D4s_v5 → B2ms |
| Rightsizing | sql-staging at 8% DTU |
$250 | $125 | Medium | Downgrade S3 → S1 |
| Reservations | 5 VMs running 24/7 for 90+ days | $1,200 | $864 | Medium | 3yr RI |
| TOTAL RECOVERABLE | — | — | ~$1,179/mo | — | — |
Cost allocation table
| Team / Project | This Period | Last Period | Change | % Change | Top Service | % of Total |
|---|---|---|---|---|---|---|
| Platform | $5,200 | $4,800 | +$400 | +8.3% | Compute | 32% |
| Product API | $3,800 | $3,100 | +$700 | +22.6% ⚠️ | Databases | 24% |
| Data Team | $2,700 | $2,600 | +$100 | +3.8% | Storage | 17% |
| Unallocated | $1,300 | $800 | +$500 | +62.5% 🔴 | Mixed | 8% |
| Total | $16,450 | $14,750 | +$1,700 | +11.5% | 100% |
Remediation guidance (sample)
# Delete unattached managed disks
az disk delete --name disk-old-backup-01 --resource-group rg-app-prod --yes
# Resize over-provisioned VM
az vm resize --name vm-batch-01 --resource-group rg-batch-prod --size Standard_B2ms
# Tag unallocated resources
az resource tag --ids /subscriptions/.../resourceGroups/rg-shared/providers/Microsoft.Storage/storageAccounts/stcontososhared --tags team=platform cost-center=CC-1234