Skip to main content Skip to content

Cost graph

Understand how ZopNight prices and attributes every resource-day of spend, then trace, export, and troubleshoot it from Costs → Flow and Costs → Reports.

7 min read

The Cost Graph is ZopNight’s view of your cloud spend. It joins your billing data, synced daily, to the live resource inventory so every dollar can be attributed to a team and a tag, and spend that matches no resource is tracked as unattributed rather than dropped. The Cost Flow Sankey, anomaly detection, showback, budgets, and every recommendation’s dollar figure read from the same data.

Costs → Flow page: the Provider → Account → Type → Team layout picker, Savings and Unattributed teams toggles, and date range above the total spend for the period, the top cost driver, and the Sankey diagram with Export CSV and Export PNG

Costs → Flow: the period’s spend traced provider → account → type → team, with the top cost driver called out.

Before you start

  • At least one connected cloud account. See Cloud accounts.
  • Billing data access, for billed cost. AWS Cost Explorer or a CUR 2.0 export, Google BigQuery billing export, or Azure Cost Management. Without it, ZopNight prices resources at rack rate. See Cloud permissions.
  • A role with the report:view policy to open Costs → Reports and Costs → Flow. See Scopes.

How it works

Billed cost or rack rate

Cost is chosen per resource per day. Where your billing data (AWS Cost Explorer or CUR 2.0, Google BigQuery, Azure Cost Management) has a line for that resource-day, ZopNight uses the billed cost. Where it doesn’t (billing not connected for that account, or the bill has not landed yet), it uses the rack rate from the provider’s pricing API. Once the billing line arrives, the billed cost replaces the rack-rate figure.

How attribution works

Each cost record is attributed across two dimensions:

  • Team: resolved per resource from your organisation’s team and resource bindings (see Showback).
  • Tag: derived from cloud tags or labels, with an optional Smart Tag policy deriving a consistent value for untagged resources.

A resource owned by more than one team (for example, a Kubernetes cluster running several teams’ workloads) has its daily cost split equally across the owning teams.

How the Cost Graph powers findings

Every savings finding is priced from the same cost data:

  1. The rule fires against the inventory and its metrics.
  2. The resource’s cost is read from the Cost Graph: billed cost where your billing data covers it, rack rate otherwise.
  3. The saving is computed from that cost for the specific change (for example, the running hours a schedule removes, at the resource’s effective hourly rate).
  4. Where no honest figure can be computed, the finding is advisory and carries no dollar amount rather than an invented one.

Trace spend with Cost Flow

The Cost Flow Sankey is a four-column flow diagram that traces each dollar of spend through four dimensions. The default layout is:

Terminal window
Provider → Account → Type → Team

Five other layout presets pivot the same data through different dimension chains (e.g. Provider → Account → Service → Team, Provider → Region → Type → Team, Account → Type → Resource → Team).

  1. Open Costs → Flow

    Pick the date range. The header shows the period’s total spend and the top cost driver.

  2. Pick a layout

    Choose the four columns from the layout picker. Switching layout clears any active drill-down.

  3. Drill in

    Click any node or link to narrow the chart. Each click writes a breadcrumb chip, so you can back out one column at a time.

  4. Turn on overlays

    Toggle Savings to mark reclaimable spend, or Unattributed teams to highlight spend with no owning team.

See Reports overview for the full layout list and the Savings overlay behaviour.

Export cost data

Cost reports export as CSV from Costs → Reports, covering the visible period, dimensions, and filters. Report exports run in the background and finish with a short-lived signed download link. Costs → Flow also offers Export CSV and Export PNG for the current view. Dashboards have no export of their own.

Seven-dimension anomaly detection

The Cost Graph runs anomaly detection across seven dimensions once a day (20:55 UTC). Each check compares spend with its 7-day rolling average and also runs a z-score test; the higher severity of the two wins.

DimensionWhat is compared
Org-wideTotal spend against the 7-day rolling average.
Cloud accountOne account’s spend against its own 7-day average.
Resource typeSpend on one resource type against its own average.
Resource groupA group’s spend against its own average.
ResourceAn individual resource’s daily cost (capped at the top 10 per org per day to avoid noise).
TeamA team’s allocated spend, with redistribution suppression when costs shift between teams with net change under 20%.
Azure resource group and tenantSpend under one Azure resource group, or one Azure tenant, against its own average.

Severity bands are warning (30–150% above baseline), critical (150–500%), and emergency (>500%). Every anomaly carries a root-cause tag: instance resize, new resource, reservation expiry, schedule failure, or unscheduled usage increase. Anomalies are reached from the anomaly banner on Costs → Reports (View All). Notifications are configured separately, per dimension and severity. See Cost anomalies for the full detail.

Dashboard presets

The Cost Graph ships four dashboard presets:

PresetBuilt for
ExecutiveLeadership.
EngineeringThe teams running the infrastructure.
FinOpsCost owners.
All WidgetsEvery widget, for evaluating what’s available before you compose your own.

See Dashboards for the full preset and widget behaviour.

Troubleshooting

Figures for the last few days changed

Billing exports lag, and each daily billing sync re-reads the most recent days. When a billing line lands for a resource-day that was priced at rack rate, the billed cost replaces it. Older days settle once the provider finalises the bill.

A resource shows rack rate instead of billed cost

Its cloud account has no billing data connected, or the bill for that day has not arrived yet. The choice is made per resource per day, so one account without billing does not affect the others. Grant billing read access as described in Cloud permissions.

Team or tag totals add up to less than the headline spend

The headline reconciles with your invoice, so it includes billing lines that match no discovered resource (data transfer, taxes, fees, and services ZopNight doesn’t discover). Team and tag breakdowns only count attributed spend, by design. The difference is the unattributed amount.

Anomalies appear but nobody was notified

Detection always runs, whether or not a notification channel exists. Notifications are a separate, optional layer: subscribe a channel to the anomaly dimensions and severities you care about in Settings → Notifications → Channels & Alerts.

Next steps

Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·