A cost explanation people can inspect.
A worked example of how Mission FinOps frames a cost question, tests an explanation, records uncertainty, and hands the evidence to leadership and engineering. Every account, amount, and resource below is synthetic.
The scenario uses a fake account and the current Kulshan 0.4.2 report artifact as a technical appendix. It is not a customer result or a claim about savings.
Why did network-related spend move?
Decision at stake
Whether the platform team should prioritize a network architecture review before the next finance forecast is approved.
Executive conclusion
The synthetic evidence supports increased NAT Gateway processing as the main contributor. It does not yet prove which application flow created the traffic.
Materiality
The movement is concentrated enough to investigate, but this sample intentionally avoids a savings claim. Remediation value depends on traffic path and workload requirements.
Evidence record
Supporting: service and usage-type movement point toward NAT Gateway data processing rather than an across-the-board EC2 increase.
Contradicting or incomplete: billing data alone does not identify the source workload, destination, or whether the transfer was expected.
Ownership confidence: low until account metadata, tags, network flow evidence, and the relevant platform owner are reconciled.
Next steps: confirm the owning account and workload; inspect traffic paths; test S3/DynamoDB endpoint and cross-AZ hypotheses; then decide whether an architecture change is justified.
How this investigation moved
- Cost Explorer flagged a 34% month-over-month increase concentrated in one account.
- Service breakdown isolated NAT Gateway data processing as the primary contributor.
- Usage-type anomaly detection confirmed the movement was statistically significant (z-score 2.7).
- Checked for contradicting evidence: no VPC Flow Logs available, no tag-based ownership resolved.
- Documented the gap: cannot confirm whether transfer is intra-region or cross-AZ without flow log evidence.
- Recommended next step: enable VPC Flow Logs, reconcile the NAT Gateway ENI to subnet and workload, then re-run.
The investigation stopped at the boundary of available evidence rather than guessing past it.
Report preview
This is what the artifact looks like. The full interactive version is embedded below.
AWS Cost Investigation: Network Spend Movement
Question investigated
Why did network-related spend increase 34% month-over-month in the platform account?
Executive conclusion
NAT Gateway data processing is the primary contributor. Source workload not yet identified.
Supporting evidence
Cost Explorer service breakdown, usage-type anomaly detection (z-score 2.7), NAT Gateway bytes processed.
Contradicting / incomplete
No VPC Flow Log evidence. No tag-based ownership. Cannot confirm whether transfer is intra-region or cross-AZ.
Ownership confidence
Low. Account identified. Workload and team owner not yet resolved from available tag and metadata evidence.
Recommended next step
Enable VPC Flow Logs on the platform VPC. Reconcile NAT Gateway ENI to subnet and workload. Then re-run.
View the full interactive report below · All values are synthetic. This is not a customer result.
Technical appendix: the report above is generated from synthetic fixture data. It demonstrates the evidence inventory available to an investigator; human interpretation turns that inventory into a decision record.