Skip to content
Cloud8 Logo
  • PRODUCT
  • PRICING
  • SUPPORT
  • CONTACT US
  • LOGIN
  • PRODUCT
  • PRICING
  • SUPPORT
  • CONTACT US
  • LOGIN

Best Practices

  • How to integrate Slack into Best Practices
  • How to monitor memory and swap with SSM
  • AWS Bucket S3 Topic Notification
  • Best Practices: Password and Credential Monitoring
  • Best Practices: Custom Rule Notifications via AWS S3
  • Best Practices: Microsoft Teams Support

Charging

  • AWS account suspension: tips and what to do

Concepts

  • Security groups
  • Access key
  • Cloud server image or template
  • Snapshot
  • Additional disks
  • Cost model: pay per use
  • Cloud Control Panel – AWS, Azure, GCP, Huawei and Oracle
  • Cloud Computing
  • Comparison: Automation via Cloud8 vs “homemade” automation
  • FINOPS: Data Integration and Enhancement Flow (Infographic)
  • Difference between RI Applied vs RI in Cloud8 Panel

Credentials

  • Using Cloud8 with a custom AWS security credential
  • How to use IAM Role to integrate your security with Cloud8
  • Security credentials for public clouds
  • Connecting OCI Providers to Cloud8 – Full Tutorial
  • Credential for Huawei Cloud
  • Best Practices: Enabling user monitoring in Azure

First Steps

  • Connecting GCP Providers to Cloud8 – Full tutorial
  • How to manage more than one AWS account
  • Hot to enable cloud cost estimates monitoring
  • Creating a new Amazon AWS account
  • Connecting Azure Enterprise Agreement providers to Cloud8 – Full tutorial
  • Creating a New Account on Amazon Cloud (AWS)
  • Connecting OCI Providers to Cloud8 – Full Tutorial
  • Cloud8 Users and Profiles
  • Onboarding: getting started on Cloud8
  • Connecting AWS Providers to Cloud8 – Full Tutorial

MSP / Reseller

  • White label at no additional cost
  • MSP: Configuring costs
  • MSP: Configuring markup

Services

  • Using Cloud8 Insights
  • Audit logs
  • Managers on Cloud8 – Resource management on AWS, Azure and GCP
  • Cloud usage statistics
  • Alerts
  • Cloud cost control, alerts and reports
  • Cloud aggregator control panel
  • Using Automations in Cloud8
  • Automated backup of cloud servers
  • Multiple Users – Multiuser Panel
  • ECS / Fargate support on Workflow
  • Enabling Azure AD SSO in the Cloud8 Dashboard
  • Detailed Costs Report
  • Workflow: How to reset tasks periodically
  • Kubernetes Cost Support
  • How to install Metricbeat component on AKS
  • How to enable support for ECS / EKS shared costs
  • Add TAGs with CSV file
  • GCP Storage Integration
  • RDS reports with grouping by ID
  • Exporting data to AWS S3 (Bucket)
  • How to install Metricbeat component on GKE clusters
  • How to install Metricbeat component on EKS
  • How to install the Metricbeat component in OKE
  • FinOps: Cost Anomaly Reports and Charts
  • Enabling MFA in the Cloud8 Dashboard
  • FinOps: Reverse API
  • FinOps: Tag Sharing and Prorating
  • FinOps: Tag Sanitization, Compliance and MultiCloud
  • FinOps: Tagged / Untagged
  • FinOps: Reports, Alerts and Budgets
  • FinOps: Tags and Usage
  • FinOps: Tags / Labels / Resource Groups
  • Exporting data to Azure Storage Account
  • S3 Lambda Notification Processor (deploy via CLI)

Troubleshooting

  • I subscribed Amazon and I still can’t access Cloud8
  • How is the cloud cost estimate calculated?
  • I created a security group through the AWS console and it still doesn’t appear in Cloud8
  • I exported the cloud server usage report. What do the fields mean?
  • Using Cloud8 with a custom AWS security credential
  • Cloud8 and Amazon don’t monitor my cloud server’s memory?

Tutorials

  • How to access a Windows server in the Amazon AWS cloud
  • How to access a Linux server
  • How to create a cloud server
  • How to integrate Slack into Best Practices
  • How to configure scheduling for script execution in AWS
  • How to configure scheduling by Tags / Labels
  • Configure vault copy at AWS (cross account) with KMS
  • How to configure the Scheduler for script execution on OCI
  • Workflow: How to reset tasks periodically
  • How to install Metricbeat component on AKS
  • How to install Metricbeat component on GKE clusters
  • How to install Metricbeat component on EKS
  • How to install the Metricbeat component in OKE
  • FinOps: Cost Anomaly Reports and Charts
  • Group data in Pivot Table
  • FinOps: Tag Sanitization, Compliance and MultiCloud
  • S3 Lambda Notification Processor (deploy via CLI)
  • Best Practices: Microsoft Teams Support
View Categories
  • Home
  • Docs
  • Services

FinOps: Tagged / Untagged

8 min read

Proper cost allocation is essential for expense control, identifying business units, projects, teams, and accounts. A good cost allocation strategy uses tagging to maintain consistency in reports. However, native metadata management tools from providers have limitations, such as resource types that cannot be tagged.

Cloud8 has a synthetic tagging strategy directly in the tool that allows you to create a single tag that can be used across multiple providers (AWS, Azure, GCP, OCI), facilitating cost tracking and resource management in multi-cloud environments. Thus, it’s possible to have, for example, a “global synthetic tag” that unifies resource and cost control across different clouds, without depending on the native limitations of each provider.

Untagged – Tag Audit #

Through the Untagged functionality, the user is able to identify untagged resources, or measure the percentage of coverage of a given tag. In the left sidebar menu, click on FinOps – Reports and select Untagged.

FinOps: Tagged / Untagged

Identifying resources without any tagging. #

When accessing the feature, you can identify resources without any associated tags by clicking on the “Tags” field and selecting the value “Without tags”.

FinOps: Tagged / Untagged

Select the verification period, which can be the default monthly view value in the “Entire month” option or a period specified in hours by selecting the “Last” option and setting a value for “hours”, as shown in the image above. 

It is important to note that “Entire month” takes into account the months defined in “Periods,” which may or may not coincide with the time the function is executed.

FinOps: Tagged / Untagged

To run the verification, click Run and wait.

FinOps: Tagged / Untagged

The result will generate a graph showing the total number of untagged resources.

Identifying resources with a specific tag. #

It is also possible to check the adherence level of a specific tag within the user’s infrastructure. Instead of selecting the value “Without tags”, define a tag key to be checked, as in the example below. Configure the verification period and click Run.

FinOps: Tagged / Untagged

The example below illustrates important features of the functionality, such as:

Synthetic tagging and multi-cloud management : the returned result shows service categories in which there are resources without the selected tag. Note that the example demonstrates that the tool was able to identify tags in both OCI and Azure.

Historical overview of the tag : it is possible to check the tag’s adoption history over a one-year period. In the example provided, we can see that efforts were made to tag all resources between January 2025 and March 2025. It is also noticeable that in subsequent months the tag ceased to exist for all resources, which can be explained by the environment’s growth without a policy for tagging new resources. 

Cost allocation : the panel displays the total cost of untagged resources, demonstrating the financial impact of the lack of identification. In the case of the “application” tag, these are resources whose classification has not been assigned to any specific application, making it impossible to correctly associate the expense with a system, project, or business unit.

FinOps: Tagged / Untagged

Resource detail : the tool not only shows the category of untagged resources, but also identifies exactly what they are.

FinOps: Tagged / Untagged

Assign tags to Untagged #

Once the untagged resources have been identified, it’s possible to export a CSV file of the result. This functionality ensures not only that the user can aggregate this information as a BI dataset, but also generates a blank column in the file for the user to fill in with the missing tag value. To do this, click on Download CSV (fill up tags).

FinOps: Tagged / Untagged

Open the file and fill in the tag column with the tag values ​​for each identified resource.

FinOps: Tagged / Untagged

After filling in the information, click on “Import filled-up tags – BETA”. Before starting, it is important to select the provider. The Untagged functionality needs to be managed individually in each configured provider and will not work in Business Units. At the top of the screen, you can see the display provider.

Note : Although it is possible to list a tag using Business Units, importing tags is a task that needs to be performed provider by provider.

FinOps: Tagged / Untagged

On the displayed screen, it is recommended to select the option “Apply automatically in the upcoming months”. This function will prevent the need to manually enter tag values ​​for existing resources each time period. Therefore, the tag values ​​adopted in the completed file will be replicated in the same resources later.

FinOps: Tagged / Untagged

It is also possible to change the tags directly in the cloud provider by selecting the option “Modify tags directly on cloud components using API calls”. The remaining fields to be filled in are:

  • Analyzed period : the period from which the filled tags were extracted.
  • Filename : clicking Select allows you to select the filled-in file to be imported.
  • Start period : the period from which tags need to be filled with the correct values, allowing the current tag definition to be applied to previous periods.
  • End period : the last month in which the tags need to be adjusted. Generally, this is the period from which the populated tags were extracted. However, nothing prevents a scenario where a tag needs to be classified with one value until a certain month, and then adopt a different value in subsequent months.
  • Notify emails : the option to be notified when the tagging process is complete.

Finally, click Import.

Note: The ability to modify tags directly in cloud components using API calls is only available for Azure and AWS providers. 

If you want to perform tagging in Azure by selecting the option to call the API, the service principal needs to be a Contributor or you need to select RBAC for the ResourceManager/tagOperations API.

If you want to perform tagging on AWS by selecting the option to call the API, you will need to enable the following access credentials:

...
tag:*
ec2:CreateTags
ec2:DeleteTags
rds:AddTagsToResource
rds:RemoveTagsFromResource
elasticloadbalancing:RemoveTags
elasticloadbalancing:AddTags
route53:ChangeTags*
dynamodb:Tag*
dynamodb:Untag*
logs:Tag*
logs:Untag*
eks:Tag*
eks:Untag*
elasticache:RemoveTagsFromResource
elasticache:AddTagsToResource
s3:DeleteObjectTagging
s3:DeleteJobTagging
s3:PutBucketTagging
s3:DeleteStorageLensConfigurationTagging
s3:ReplicateTags
s3:PutStorageLensConfigurationTagging
s3:PutObjectVersionTagging
s3:PutObjectTagging
s3:PutJobTagging
s3:DeleteObjectVersionTagging
dms:RemoveTagsFromResource
dms:AddTagsToResource
...

Audit tags adjusted in Untagged #

It is possible to manage the history of tag changes made in the tool through the “Applied tags – BETA” option. This feature provides even more control over tag governance and allocation, allowing you to identify changes made by provider, resource, region, and tag value changed.

FinOps: Tagged / Untagged

Tagged – Control of adherence to a specific tag. #

Unlike the previous functionality, Tagged aims to present adherence data for a specific tag value. In the left sidebar menu, click on FinOps – Reports and select Tagged. The coverage chart generates the following information:

  • Tag OK : percentage of resources that have the selected tag.
  • No support : percentage of resources that do not support tagging.
  • No Tags : percentage of taggable resources that do not have the selected tag.

The feature also displays the total cost of resources that adopt the selected tag and the total number of resources. By clicking on “Download data in CSV format,” it is possible to extract a file with the list of resources that adopt the desired tag. This feature allows the user to import this data into their BI and reporting tools, in order to support tagging implementation projects.

FinOps: Tagged / Untagged

The visualization allows you to evaluate the main values ​​of assigned tags, as well as their cost.

FinOps: Tagged / Untagged

The generated file contains key information for identifying the resource, such as the provider name, the resource name, and its respective ID in the cloud.

FinOps: Tagged / Untagged

Using Tags in Cloud8 #

Tags have several functions within the Cloud8 tool, ranging from user permissions to cost identification for specific business units. The topics below will discuss the use of tags in more detail.

Roles for data visualization and resource management in the tool. #

Tags can be used when creating new Cloud8 access Roles, allowing you to limit the visibility of resources based on a specific tag.

FinOps: Tagged / Untagged

Pivot Table in FinOps – Reports #

Tags can be included as an evaluation field in a Pivot Table in order to identify the costs of a product or business unit configured in the tool.

FinOps: Tagged / Untagged

Budget Setup #

Currently there are 3 (three) Budget methods implemented in the Cloud8 tool: Organization – Invoice; Organization – Products; Organization – Tags.

Organization – Tags (Business) is the budget configuration that monitors the budget through metadata and its respective values, allowing for greater control of budgets at the business level.

FinOps: Tagged / Untagged

FinOps – Analytics #

It is possible to use the FinOps – Analytics feature based on tags to detail costs per tag, allowing for a thorough evaluation of cloud spending for specific resources.

FinOps: Tagged / Untagged

The Details Panel allows for a detailed identification of costs, making it possible to select the desired tags in the analysis, the resources that use them, and the detailed costs for operating their workload. 

FinOps: Tagged / Untagged

Conclusion #

Proper tag management is one of the cornerstones of FinOps. With the Tagged and Untagged functionalities , Cloud8 allows multicloud companies not only to have visibility into their costs, but also to standardize, correct, and automate resource governance, strengthening financial efficiency and accountability across business areas.

Content – ​​Tags / Labels / Resource Groups #

  • Purpose and Use Cases
  • Tags and usage
  • Reports / Alerts / Budgets
  • Cost Anomalies
  • View Tagged/Untagged Resources
  • Tag Sanitization, Compliance and MultiCloud
  • Tag Sharing and Value Allocation
  • Reverse API

You may want to check these Docs too: #

  • Using Cloud8 Insights
  • S3 Lambda Notification Processor (deploy via CLI)
  • Exporting data to Azure Storage Account
  • FinOps: Tags / Labels / Resource Groups
  • FinOps: Tags and Usage
Alerts, Anomalies, Costs, Costs Anomalies, Finance, Finops, Report, Tag, untagged
Did this Doc help you?

Share This Article:

  • Facebook
  • X
  • LinkedIn
  • Pinterest
Table of Contents
  • Untagged – Tag Audit
    • Identifying resources without any tagging.
    • Identifying resources with a specific tag.
    • Assign tags to Untagged
    • Audit tags adjusted in Untagged
  • Tagged – Control of adherence to a specific tag.
  • Using Tags in Cloud8
    • Roles for data visualization and resource management in the tool.
    • Pivot Table in FinOps – Reports
    • Budget Setup
    • FinOps – Analytics
  • Conclusion
  • Content – ​​Tags / Labels / Resource Groups
Cloud8 Logo
  • Terms of Use
  • About Us
  • FAQ / Support
  • Blog
  • Contact Us
  • Cookies (EU)
  • Terms of Use
  • About Us
  • FAQ / Support
  • Blog
  • Contact Us
  • Cookies (EU)
Globe-americas Facebook Twitter Linkedin Youtube

Disclaimer: AWS, images, and associated services are property of Amazon Web Services Inc. and its affiliates. Azure, images, and associated services are property of Microsoft Corporation. GCP, images, and associated services are property of Google Inc. Huawei, images, and associated services are property of Huawei Technologies Co Ltd. Oracle, images, and associated services are property of Oracle Corporation. Cloud8 Brasil em Português.

Manoel Netto Designer
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}