Prepare a cloud audit: checklist
A good audit starts before the first API call. Prepare scope and access.
1. List cloud accounts
Azure subscriptions, AWS accounts, GCP projects, OVHcloud/Scaleway projects — with a named owner.
2. Create a read-only identity
Minimal roles, no write, secret stored outside chat. Document rotation.
3. Align FinOps and security
One exit priority: what to fix this week, cost and risk together.
4. Define the report format
Require resource, rationale, priority, action. Reject raw alert dumps.
