← Home
← Guides

How to give Creduna read-only access to your AWS account

To review what Claude costs you on Amazon Bedrock, we need to read your usage counters and billing totals. You stay in control: you create the access yourself, in your own AWS account, from a short template you can read before you run it. Nothing is installed, nothing can be changed, and one click removes it.

In short

  • You create one IAM role from a template. It takes about five minutes and needs no command line.
  • The role can only read: cost totals, usage counters and the list of Bedrock models. It cannot see prompts or answers, call models or change anything.
  • The role works only for Creduna’s AWS account, and only together with an External ID that is unique to you.
  • Deleting the stack removes the role and ends our access immediately.

What we can and cannot see

The template creates a single role named CredunaReadOnlyRole. Its permissions are listed in the file in plain text, and they are the only ones we get.

We can readWe cannot
How many tokens each Claude model used, hour by hour (CloudWatch counters)Read your prompts, your answers or your data
What Amazon Bedrock cost you (Cost Explorer totals)Call a model or spend your credits
Which Bedrock models are available in your accountCreate, change or delete any resource
Account names in your AWS Organization, if you use oneSee your application code, logs or databases
Everything in the left column is metadata. None of it contains what your users typed or what Claude answered.

Before you start

  • An AWS login that may create IAM roles through CloudFormation. An administrator has this; if you are not sure, ask whoever manages your AWS account.
  • The message from us with two values: CredunaAccountId (12 digits) and ExternalId (starts with creduna-).
  • About five minutes.

The External ID is a safeguard recommended by AWS for exactly this situation. It makes sure the role answers only to requests made on your behalf, even if someone else knew the role’s address.

Step by step

The six steps at a glance. The drawing is simplified: the real AWS console shows more detail, but the buttons carry the same names.
  1. Download the template

    Save the file creduna-readonly.yaml from the link in our message. You can open it in any text editor: it is about fifty lines and describes one role.

  2. Open CloudFormation

    Sign in to the AWS console, type CloudFormation in the search box at the top and open it. Click Create stack and choose With new resources (standard).

  3. Upload the file

    Under Specify template choose Upload a template file, select creduna-readonly.yaml and click Next.

  4. Fill in three fields

    Stack name: CredunaReadOnly. CredunaAccountId and ExternalId: paste the two values from our message exactly as they are. Click Next.

  5. Leave the options as they are

    The next screen needs no changes. Scroll down and click Next.

  6. Confirm and create

    At the bottom of the review screen tick the box that says AWS CloudFormation might create IAM resources with custom names, then click Submit.

  7. Send us the RoleArn

    Wait until the status reads CREATE_COMPLETE, usually under a minute. Open the Outputs tab and copy the value named RoleArn. Send it to us; it is an address, not a secret.

That is all. We test the access on our side and tell you when the first review is ready.

Check what was created

If you want to see it with your own eyes: in the AWS console open IAM, choose Roles and search for CredunaReadOnlyRole. The Permissions tab lists the six read-only actions above. The Trust relationships tab shows the one account that may use the role and the External ID it must present.

How to remove the access

Open CloudFormation, select the stack CredunaReadOnly and click Delete. The role disappears and our access ends at once. You do not need to tell us first, and nothing else in your account is affected.

Common questions

Can Creduna see my prompts or my customers’ data?

No. The role reads counters and cost totals only. Prompt and answer content is not part of them.

Can Creduna run up costs in my account?

The role cannot call models or create resources. Reading Cost Explorer through its API is billed by AWS at about one cent per request, and a review makes a few of them.

Why do I create the role myself?

So that nothing happens in your account that you did not do. You can read the template first, and you can remove the role without asking anyone.

What is the External ID for?

It ties the role to you. Requests without your External ID are refused by AWS, even when they come from our account.

Which region should I use?

IAM roles are global, so any region works for creating the stack. Tell us which region you run Claude in so we read the right counters.

Sources