Investigation practice5 min read

Mean time to explanation

A working measure for the gap between noticing AWS cost movement and producing a defensible account of it.

Detection is only the beginning

A cost alert tells you that something moved. It does not tell a cloud leader why it moved, who owns it, or what decision is safe. Mean Time to Explanation measures that missing stretch of work.

Define the clock in plain language

MTTE is an internal operating measure, not an AWS standard. Start the clock when a material cost question is accepted for investigation. Stop it when the team has an evidence-backed explanation, a named owner, known limits, and a next action.

Evidence ruleBilling evidence establishes cost and usage. Configuration and operational evidence add context. Business cause remains an inference until the sources support it.

Make fast explanations defensible

Use start and stop events someone else can audit. Track recurring questions separately from novel investigations. Before stopping the clock, record the cost movement, scope, supporting and contradicting evidence, owner, unknowns, and decision.

Speed cannot reward guessing

Do not reward premature certainty. Pause explicitly for missing access or data, and measure explanation quality alongside speed.

Remove collection work, not judgment

Kulshan automates repeatable read-only collection. The gain should be less console-hopping, not removal of human review.

See the investigation workflow

Yuvdeep Singh builds Kulshan and runs AWS cost investigations from Mission, BC. These notes distinguish observation, estimate, and inference.

← Back to Thinking