Evidence architecture5 min read

Keep the evidence inside the enterprise

A practical boundary between AWS evidence, human interpretation, and models that assist without becoming the source of truth.

Keep the source material close

A cost explanation may draw on billing records, resource configuration, ownership data, and change history. Those records should remain under the enterprise's control. A polished sentence from a model is not a replacement for them.

Separate the record from the interpretation

The billing record can show that spend moved. Configuration can show what existed at a point in time. Ownership and change records may explain intent. Keeping those sources distinct makes it possible to challenge an interpretation without losing the underlying facts.

Evidence ruleBilling evidence establishes cost and usage. Configuration and operational evidence add context. Business cause remains an inference until the sources support it.

Leave a trail another investigator can follow

Keep raw evidence separate from normalized findings. Attach the account, region, time window, source, and collection time. Label observations, estimates, and inferences so a reviewer can see where certainty ends.

Local does not mean uncontrolled

Local software still needs access controls and review. Tags and cost records do not explain business intent.

Make provenance part of the output

Kulshan runs locally with customer credentials and has no AWS write path. Findings carry provenance, evidence IDs, billing-integrity state, and human-review flags.

Carry the evidence into the next decision

Yuvdeep Singh builds Kulshan and runs AWS cost investigations from Mission, BC. These notes distinguish observation, estimate, and inference.

← Back to Thinking