Getting started
leancosts is a hosted product. There is nothing to install: you work entirely in the web app at app.leancosts.com. This page gets you from sign-in to real cost data.
Regulated customers (banks, insurers, and teams with data-sovereignty requirements) can run leancosts on-premise or in their own private cloud, entirely inside their environment. It’s an enterprise/contract option and is sales-led: talk to us to set it up.
leancosts is read-only by construction: connecting a cloud account grants read access only. The product never creates, changes, or deletes a resource in your cloud: every recommendation is handed to you as a guided CLI kit you review and run yourself.
1. Sign in
Section titled “1. Sign in”Open app.leancosts.com. You have four ways in, and three of them need no email at all:
-
Passkey: the fastest, and it needs no email. Sign in instantly with Face ID, Touch ID, or Windows Hello (or a hardware security key). Once you’re in for the first time, accept the Set up a passkey prompt: after that, signing in is one tap and works even if email is unavailable.
-
Magic link: enter your work email and leancosts sends you a one-time sign-in link. Click it and you’re in. The email also shows the full URL under “Or paste this URL into your browser”: copy that line as-is if clicking doesn’t work (for example, when the link opens in the wrong browser profile).
-
Password: choose Use a password instead on the sign-in screen. You set your password from Settings → Sign-in methods once you’re in; it needs at least 12 characters. Useful on a locked-down desktop where passkeys aren’t available. There is no reset email: if you forget it, sign in with a passkey or ask your workspace admin for a sign-in link, then set a new one.
-
Single sign-on (SSO): if your organization has SSO configured, use the SSO button to sign in through your own identity provider.
-
Two-factor authentication: turn it on under Settings → Sign-in methods: scan a QR code with any authenticator app (Google or Microsoft Authenticator, 1Password, Authy) and keep the ten backup codes it shows once. After a magic link or a password, leancosts then asks for the 6-digit code. Passkeys and SSO already count as two factors, so they never ask. Sensitive changes (roles, members, single sign-on, workspace security) ask you to confirm it’s you again after ten minutes: with your passkey if you have one, or a code. A passkey must check your fingerprint, face or PIN to count. Your workspace admin can require two-factor for everyone (Admin → Team → Sign-in), and can reset it for you if you lose your phone and your backup codes; that reset also removes your passkeys, so you set them up again after signing in.
-
Invited by a colleague? Open the invitation link from your email; it signs you in and adds you to their organization automatically.
-
Switching organizations? If you belong to more than one, use the organization switcher in the top bar.
2. Land on Opportunities
Section titled “2. Land on Opportunities”After sign-in you land on Opportunities: your team’s daily decision surface and the home of leancosts. It is the shared, dated record of what to do next: open optimization findings, cost anomalies worth a look, and the savings already in flight, all on one audit trail.
Two things sit beside it in the Start group of the sidebar:
- Copilot: ask about your costs in plain English and get an answer with an audit trace. It cites its sources; it does not guess.
- The Search button (or Ctrl/⌘ + K) opens the
command palette to jump to any page, or to find a resource by name and open its
detail drawer without hunting for a list that mentions it. Type at least two
characters of the name. It also decodes the jargon: type an acronym such as
CUD,AHBorDTUand the definition comes back with an example from your own estate.
3. Connect your cloud
Section titled “3. Connect your cloud”When you are ready for real numbers, connect a read-only cloud account:
- Go to Admin → Connections, click Add connection, and pick your cloud (Microsoft Azure, Amazon Web Services, or Google Cloud).
- Follow the connector wizard. The first healthy connection kicks off zero-config auto-discovery: subscriptions/accounts, resources, tags, and 13 months of cost history land within minutes.
The full step-by-step lives in Connect a cloud account.
4. How the app is organized
Section titled “4. How the app is organized”The sidebar follows the FinOps lifecycle. Non-technical roles see plain-language group names (shown in parentheses):
| Group | Plain name | What lives here |
|---|---|---|
| Start | — | Opportunities, Copilot |
| Inform & Plan | Where your money goes | Costs, Variance, Allocation, Commitments |
| Optimize | Save money | Hunters (the savings finder) |
| Operate | Take action | Change Requests, Savings (realized-savings ledger) |
| Govern | Set up & control | Tagging, Admin, Global Admin |
Some settings-grade rows are hidden from a new tenant’s sidebar by default. Click Show advanced at the bottom of the sidebar to reveal them: nothing is locked, and every page is also reachable from the command palette.
Where to go next
Section titled “Where to go next”Task-oriented walkthroughs:
- Connect a cloud account: ingest a real Azure / AWS / GCP estate, read-only.
- Act on a cost finding: turn a hunter finding into an executed, audited saving.
- Set up tag governance: define a taxonomy that drives allocation, coverage, and cost insights.
- Configure alerts & digests: get notified when cost behaviour changes.
- Set up single sign-on (OIDC): let your team sign in through your own Keycloak / OIDC identity provider.
- Use the API with a token: call the HTTP API from a script or CI job.
Stuck on any of these? Use Contact support in the app (top bar) to reach the team directly.