Synopsis
Keep the source material close
A cost explanation may draw on billing records, resource configuration, ownership data, and change history. Those records should remain under the enterprise's control. A polished sentence from a model is not a replacement for them.
Observation
Separate the record from the interpretation
The billing record can show that spend moved. Configuration can show what existed at a point in time. Ownership and change records may explain intent. Keeping those sources distinct makes it possible to challenge an interpretation without losing the underlying facts.
Diagnostics
Leave a trail another investigator can follow
Keep raw evidence separate from normalized findings. Attach the account, region, time window, source, and collection time. Label observations, estimates, and inferences so a reviewer can see where certainty ends.
Limits
Local does not mean uncontrolled
Local software still needs access controls and review. Tags and cost records do not explain business intent.
Kulshan
Make provenance part of the output
Kulshan runs locally with customer credentials and has no AWS write path. Findings carry provenance, evidence IDs, billing-integrity state, and human-review flags.
Keep reading