RightSpend
Commitment-free EC2 optimization, and exactly what it can touch.
RightSpend raises the Effective Savings Rate of your EC2 compute by managing Convertible Reserved Instances hourly. It reads across your Organization and writes only to Reserved Instances, only in accounts you designate.
How RightSpend works
3-year Savings Plan rates, without the commitment.
RightSpend dynamically optimizes Convertible Reserved Instances (cRIs) to reach discounts equivalent to 3-year all-upfront Compute Savings Plans, without the commitment or the upfront cash.
Read-only monitoring
Continuously monitors EC2 usage, Savings Plans and Reserved Instances across every account in your AWS Organization.
Dynamic cRI optimization
Purchases, modifies and exchanges Convertible Reserved Instances hourly to match actual compute usage. No forecasting required.
Zero commitment
If your usage falls, commitments scale down with it. No overcommitment risk, no unused reservations, no upfront payment.
What RightSpend does not do. It never has write access to EC2 instances or any AWS resource other than Reserved Instances and Convertible Reserved Instances in designated cRI accounts. It does not move accounts between organizations, buy or sell RIs on the marketplace, or require changes to your existing Savings Plans.
IAM permissions
Three roles, each deployed only where it is needed.
Each follows least privilege. For how they fit together, see the RightSpend architecture diagram and the hourly optimisation loop.
Role 1 · Every member account in your Organization
CloudFix-RightSpend-ReadOnly-Role
ec2:DescribeInstancespoint-in-time running instance countec2:DescribeCapacityReservations / ec2:GetCapacityReservationUsageec2:DescribeHostsdedicated host monitoringec2:DescribeReservedInstancesexisting RI inventoryec2:DescribeRegionssavingsplans:DescribeSavingsPlans
Describe and List actions only. No write access to any resource.
Role 2 · Your AWS management (payer) account only
CloudFix-RightSpend-ReadOnly-Master-Role
organizations:ListAccounts / organizations:ListRootsenumerate the Organization’s accountsce:GetCostAndUsageaggregate billing datace:GetReservationCoverage / ce:GetReservationUtilizationce:GetSavingsPlansCoverage / ce:GetSavingsPlansUtilizationce:GetSavingsPlansPurchaseRecommendationcloudformation:CreateStackInstances / cloudformation:ListStackSetOperationsauto-deploy the ReadOnly role to member accounts, limited to CloudFix-RightSpend stacks
Role 3 · Only the designated account(s) that hold Convertible Reserved Instances
CloudFix-RightSpend-Write-Role
ec2:DescribeReservedInstancesec2:AcceptReservedInstancesExchangeQuoteec2:GetReservedInstancesExchangeQuoteec2:PurchaseReservedInstancesOfferingec2:ModifyReservedInstancesec2:DescribeReservedInstancesOfferingsec2:DescribeReservedInstancesModificationsec2:DescribeReservedInstancesListingsorganizations:DescribeOrganization
Limited to cRI operations. It cannot touch EC2 instances, S3 buckets, VPCs, databases or any other resource: it can only purchase, modify and exchange Convertible Reserved Instances.
CloudFormation templates
Review the templates before deployment.
Every role is deployed by CloudFormation. Ask us for the full template URLs for your onboarding.
| Template | Deploys to | Location |
|---|---|---|
| ReadOnly Master | Management account | s3.amazonaws.com/.../ReadOnly-Master.yaml |
| ReadOnly Member | All member accounts | s3.amazonaws.com/.../ReadOnly.yaml |
| Write role | cRI accounts only | s3.amazonaws.com/.../Write.yaml |
| Master (no auto-deploy) | Management account | s3.amazonaws.com/.../ReadOnly-Master-NoCreateInstances.yaml |
Onboarding
Four steps to live optimization.
Enable hourly granularity
In your management account, enable hourly Cost Explorer data under Billing and Cost Management, Cost Management Preferences.
Install read permissions
Deploy the ReadOnly Master stack in your management account. It deploys the ReadOnly role to every member account through StackSets.
Invite the cRI account
Invite the RightSpend cRI account from your management account. CloudFix accepts the invitation and deploys the Write role.
Dry run (optional)
Preview the commitment allocation the algorithm produces before you activate live optimization.
Account transfer
When you take over your own cRI accounts.
You send an invitation
From your management account, to the cRI account being transferred.
CloudFix completes it
Accepts the invitation, checks tax settings (removing a TRN not inherited from the payer) and deploys the RightSpend Write role.
You update the root email (optional)
Billing and impact
You pay from the savings, through AWS.
AWS Marketplace
RightSpend is a SaaS subscription in AWS Marketplace. You subscribe through AWS and charges appear on your AWS bill. EDP-eligible.
Share of net new savings
If RightSpend doesn't save you money, you don't pay. Typical subscription rates are 18–25% of realized savings.
Negligible API impact
RightSpend calls
ec2.DescribeInstancesabout once an hour per account. Against the 10 requests per second limit that is 0.0028% of the rate limit.
Questions about RightSpend security or onboarding?
Ask the team, or read the RightSpend documentation on the support portal.