Your AWS dashboards show what happened. Not what to do about it.
Connect a read-only role and get findings a human can act on — the tier that cannot scale, the commitment about to lapse, the money going nowhere. What is wrong, why it matters, exactly how to fix it, and what the fix costs. Not a wall of graphs to interpret at 3am.
For the people who get paged — and the people who see the bill. No credit card, real findings in minutes.
Not another wall of graphs
Three things every AWS estate is quietly losing: money it cannot see, capacity that cannot scale, and alerts nobody trusts. Here is what each looks like.
It refuses to guess
Every figure states its pricing basis, and anything it cannot justify is reported as unpriced rather than counted as zero. A memory-optimised instance at 5% CPU looks like an easy win and is not one — shrinking a cache tier to save money is how a cost review becomes an outage. So we surface it and refuse to put a number on it.
ecs-capacity-provider-inert
ECS asks the Auto Scaling Group for more instances, but an ASG with Min == Max has none to grant. The decision is made and silently discarded — more dangerous than no autoscaling, because every dashboard reports the tier as protected.
Raise Max above Min so scaling has headroom. If the ceiling is deliberate — a per-instance licence, a downstream connection limit — document it and alarm on saturation instead.
Written by someone who got paged
That finding is real. It described an image-processing tier where every dashboard showed autoscaling enabled and the tier still fell over, because the group beneath it had no room to grow. Neither resource looked wrong alone — only the join between them did.
Every rule encodes a failure that actually happened. Not one came from a benchmark. Every one ends with an action and its price.
It will tell you when it can't see
Most monitoring treats missing data as a failure in your infrastructure. When the collector itself stops, that produces a page for every watch at once, at 1am, about services that are perfectly healthy.
TellHound checks its own pipeline first. If our data is stale, alerting pauses and says so in one message — because a monitor that cries wolf about its own outage is worse than one that stays quiet.
or keys to hand over
nothing we can change
to first finding
no card required
Everything here exists because something broke
Not a checklist. A record of what actually goes wrong.
Findings, not metrics
What is wrong, why it matters, the exact remediation, and what acting costs — including when the answer is "nothing".
Cost that survives scrutiny
Ranked monthly savings with the pricing basis stated, and an explicit refusal to price what it cannot justify.
Commitment expiry
Reserved Instances and Savings Plans stop on a fixed date with no console banner. We warn at 60 days, escalate inside 14.
Honest alerting
Flap guards, cooldowns, guaranteed recovery notices — and a pause when our own collection goes stale.
Security posture
World-open groups, public databases, unencrypted storage, missing flow logs. A failed sweep is reported, never silently passed.
Explained health
One score per account with the arithmetic shown, so you can argue with it. Unassessed accounts are never graded.
You already have cost tools. This is the other half.
AWS answers cost questions well and owns the billing data — we are not going to beat it there, and we do not try. What none of it answers is whether the thing you are paying for still works.
A request crosses services. Each console shows one.
A CDN, a load balancer, a target group and an instance are four separate screens, all green. The failure lives in the gap between them — a cache with no floor that the origin can switch off with a single header, a health check so shallow that a broken box passes it. Nothing reading one service at a time can see it.
Some of this appears on no dashboard at all.
An instance that fell out of its Auto Scaling group keeps billing while losing health replacement and launch-template updates. The group reports a healthy count that excludes it. EC2 shows a running box like any other. Neither console reports the state, which is exactly why it survives for months.
A checklist grades your config. This reports your reality.
Catalogue scanners flag settings against a best-practice list. These rules read what your resources are actually doing: managed scaling switched on above a group pinned so it cannot act, a matcher keeping a failing target in rotation, a commitment lapsing on a date with no banner anywhere.
Every account on one screen.
Findings across all your AWS accounts, ranked together. If you run infrastructure for clients, that is the difference between a service you can sell and a browser tab per customer.
It tells you when it does not know.
A permission we lack, a metric switched off, a field the API did not return — reported as unassessed, never quietly counted as clean. An empty report is the easiest thing in the world to produce and the most expensive thing to trust.
Built from outages, not from a spec.
Every rule traces to something that actually broke on a production estate, and carries the caveat learned when it did — including the ones that say do not act on this yet, and here is what to check first.
Every region, not only the ones you list.
The regions you remember to configure are the regions you are already watching. We check every enabled region for the things that bill while doing nothing: idle addresses, unattached disks, encryption keys in a region holding nothing else. We found one on our own account — $1 a month, in a region nobody had opened in months.
We tell you what watching you costs — with a number.
Polling runs inside your account, so CloudWatch bills you rather than us. For most accounts that is about a dollar a month: measured, a 28-resource estate costs $1.12 and a 571-resource one $43.69. We show the figure for your account next to the setting that changes it, and default to fifteen minutes because five costs three times as much and finds nothing extra.
None of these fail loudly. They sit in an account for months looking fine, and you meet them during an incident, in a bill, or in a customer's email — whichever arrives first.
Connected in three steps
Create a read-only role
One CloudFormation template, published in full so you can read every permission before you run it. Scoped to an ExternalId unique to you.
We read, we never write
TellHound holds no AWS keys and cannot accept them. It assumes your role for 15 minutes at a time and has no permission to change anything.
Get findings, not homework
Inventory, health score, ranked cost opportunities, and the findings that matter — each with a remediation you can hand to whoever owns it.
See what your account is hiding
14 days, one AWS account, no card. If it finds nothing worth fixing, that is worth knowing too.
Start free trial