River
Y CombinatorBacked by Y Combinator
FREE TEMPLATE

Cloud Tagging Strategy Template

Five documents and five sheets, including the ceiling that says how much of your bill a tag can reach at all.

Free download  ·  No account needed

Allocation Ceiling

The bound on the number, computed before anybody picks a target

Filled in first, not last. A target set above the ceiling is a programme that cannot finish, and the year it takes to work that out is spent blaming enforcement.

Four classes, and every dollar goes in exactly one

Tagged and the tag reaches the cost report. Taggable and untagged. Tagged, but the resource type never passes the tag to billing. Structurally untaggable, meaning there is no object to tag at all.

The third class is the one nobody checks

Whether a resource type accepts a tag and whether it hands that tag to the cost report are two separate properties, published in two separate columns. Enforcement cannot change the second one, so it belongs in the ceiling rather than in the backlog.

Two ceilings, because they are two workstreams

Tagging alone is one minus the untaggable and the unreportable. With shared-cost rules it is one minus whatever genuinely has no defensible basis, which is normally tax and credits. Averaging them hides which of the two is short.

The residue, stated once

An amount that will not be allocated to anybody, written down with its reason. Quantified, it is a finished piece of work. Unmentioned, it is what makes people distrust the whole allocation.

Cranmore builds practice-management software for veterinary clinics, and its console reported 78 percent tag coverage. Weighted by spend it was 54 percent, because the resources nobody tags are the expensive ones. Resolved against the team list it was 44.9 percent, because the owner key held 214 distinct values and 31 of them matched a team that still existed. Same month, same tags, three defensible answers to the same question. Only the last one can be invoiced.

Then the ceiling, which every tagging template leaves out. Of the $412,000 monthly bill, $70,040 sat on support, tax, inter-account transfer, marketplace charges and commitment discounts, where no object exists to tag. Another $28,016 sat on resource types that accept tags without passing them to billing, a distinction Azure publishes as a separate column from tag support itself. The draft policy asked for 95 percent. Tagging alone tops out at 83.

The fix was never enforcement. Joining the untagged list against the audit log rather than the account, 1,547 of the 2,605 untagged resources were created by another resource: volumes a node group attached, snapshots a database took. Azure states the same shape plainly, that resources do not inherit tags from a resource group. Those resources carried $48,300 a month. No pipeline default reaches any of it, and no deny policy does either, so the drafted plan would have moved the best-tagged population from 97 percent to 98.

Three coverage numbers, a ceiling 12 points below the target, and 1,547 resources nobody created

Coverage measured three ways, the ceiling, the creation-path join and the delay cost.

One month at Cranmore  ·  $412,000  ·  three coverage numbers from the same tags

What is being countedResultWhere it comes from
Resources carrying every required key78.0%9,237 of 11,842, and the number in the steering deck
Spend carrying a tag that reaches the cost report54.0%$222,480 of $412,000, a 24-point gap
Spend landing on a team that still exists44.9%$185,080, after 183 owner values resolve to nothing

The owner key held 214 distinct values. Thirty-one matched a team. The rest were personal addresses, four spellings of the platform team, two merged teams and a scattering of typos, carrying $37,400 a month between them.

The bill split by whether a tag can reach it, which fixes the ceiling

ClassMonthlyShareWhat closes it
Tagged, and the tag reaches the cost report$222,48054.0%Done, minus the owner join
Taggable and untagged$91,46422.2%A tagging standard, which is the only class it fits
Tagged, but the type never passes it to billing$28,0166.8%A parent grouping tag; enforcement cannot touch it
Structurally untaggable$70,04017.0%Five shared-cost rules with a basis each
Ceiling if tagging is the only mechanism83.0%
Ceiling once the shared-cost rules exist98.7%
Target written in the draft policy95.0%

The target sat 12 points above what tagging could ever reach, so the programme was unwinnable before a single resource was tagged. With the rules written it has 3.7 points of room.

The untagged list, joined against what created each resource

Provisioning pathResourcesTaggedUntagged spendEnforcement that reaches it
Terraform, with provider default tags7,18097%$3,120Pipeline validation
CloudFormation and CDK1,98888%$8,942Pipeline validation
Console, by a person1,06247%$31,102Preventive policy at the platform
Created by another resource1,6124%$48,300Only a scheduled sweep or parent propagation

1,547 of the 2,605 untagged resources, 59 percent, were created by another resource. Volumes attached by a node group, snapshots taken by a database, interfaces created by a load balancer. The drafted plan of a deny policy plus a pipeline check could not have reached any of them, and would have moved the best-tagged population from 97 percent to 98.

What the five months of policy review cost

Fixable spend arriving unallocated each month$91,464
Months the draft sat in review5
Line items that can never be re-cut by a tag$457,320
A three-month rollout at a linear ramp adds$137,196

The 40 largest untagged resources carried $61,300, which is 67 percent of the fixable gap and 1.5 percent of the untagged count. That list was cleared in one afternoon, and it started recovering the following billing period.

What is in the pack

01

Allocation Ceiling

The four-class split of the bill, with the tagging-only ceiling and the with-rules ceiling itemised beneath it.

02

Tag Coverage by Service

Resource coverage, spend coverage and allocated coverage per service, with the creation path behind each gap.

03

Untagged Spend Register

The fixable list ranked by monthly cost rather than resource count, with what created each row and who fixes it.

04

Owner Map

Every distinct tag value joined to a real team, with aliases kept so historic reports still reconcile.

05

Shared Cost Rules

One row per pool a tag can never reach, with its basis, why that basis holds and the alternative rejected.

06

Tagging Standard

One page: four or five keys, closed value lists, and an explicit answer for resources created by other resources.

07

Enforcement Approach

The four layers sequenced by recovered dollars, each carrying the monthly amount it is expected to reach.

08

Untagged Spend Alert

A weekly pass reporting new unallocated run rate by creation path, because coverage is a level and leaks are rates.

How it works

  1. 1

    Open it in River, or download it

    Edit with AI opens the pack as a private Space with the agent ready to measure. Download hands you five Word documents and five CSV sheets, with no account needed.

  2. 2

    Send the bill and the audit log

    A month of cost and usage at line-item granularity, the resource inventory with current tags, and the team list. The audit log is the one people forget.

  3. 3

    Get three coverage numbers and a ceiling

    River measures resources, spend, and spend resolving to a real team, then puts every dollar in one of four classes and computes what tagging can reach.

  4. 4

    Aim enforcement at the population that has the problem

    The untagged list gets joined against what created each resource, which usually shows the drafted controls pointed at the best-tagged part of the estate.

Frequently asked questions

Is this template free?

Yes, and the download needs no account, card or email. Edit with AI is the optional half and the one that does the arithmetic: it measures coverage three ways, computes the ceiling and ranks the gap by monthly cost. The rest of the template library works the same way.

What format are the downloaded files?

Five documents as .docx and five sheets as .csv, in one zip. Word, Pages, Google Docs, Excel, Numbers and Sheets open them with nothing to convert. The sheets arrive carrying the worked veterinary-software example, so the arithmetic is visible before you replace it.

We already know our coverage percentage. What does this add?

Probably the resource-count number, which is the highest of the three and the one a console gives away. At Cranmore it read 78 percent while 54 percent of the bill carried a tag and 44.9 percent reached a team that existed. The gaps between those three are three different problems.

Why compute a ceiling instead of aiming for full allocation?

Because part of a cloud bill has no resource to tag, so full allocation by tagging is arithmetically unavailable. Naming the bound early turns an unwinnable target into two workstreams with different owners, and it stops a year being spent improving the number that was already fine.

Does this replace our tag enforcement tooling?

No, it tells you which layer to build first. Enforcement is four mechanisms reaching four populations, and the pack ranks them by recovered dollars from your own creation-path split. The infrastructure side of that lives in an infrastructure code review.

How urgent is this really?

AWS is explicit that cost allocation tags are not applied to resources created before the tags, so a tag added today does not re-cut last quarter's bill. Cranmore's five months of policy review left $457,320 of line items permanently unattributable. That figure is what got the standard approved.

Where does this stop and cost reduction start?

Here you find out whose spend it is. Deciding whether the amount is defensible is a cloud cost analysis, and sizing the headroom before a growth event is a capacity plan. Allocation comes first, because the other two need an owner to argue with.

Find the ceiling before the target

Edit with AI