Prepare a cloud audit: checklist

A good audit starts before the first API call. Prepare scope and access.

1. List cloud accounts

Azure subscriptions, AWS accounts, GCP projects, OVHcloud/Scaleway projects — with a named owner.

2. Create a read-only identity

Minimal roles, no write, secret stored outside chat. Document rotation.

3. Align FinOps and security

One exit priority: what to fix this week, cost and risk together.

4. Define the report format

Require resource, rationale, priority, action. Reject raw alert dumps.

Resources · Early access