Onam Security

Access & Entitlement

One login, one console

Onam FinOps runs at /finops inside the same console as the rest of the platform, behind the same session. You switch to it from the product switcher — no second login, no separate credential.

Entitlement

FinOps is a per-organisation add-on, granted individually. It is not part of any Onam Security plan tier, so upgrading a security plan does not turn it on.

  • Organisations without the grant do not see the FinOps link.
  • The API gateway enforces the same grant server-side on every FinOps request. Hiding the link is a user-experience choice; the gateway is the boundary.
"I'm on Enterprise, why can't I see FinOps?" Because it is not a tier feature. Ask your platform administrator to grant the add-on for your organisation, or talk to us.

Can I buy FinOps on its own?

Yes. It stands alone and does not require Onam Security. If you do run more than one product they share the same console and the same discovery, so your cloud accounts are connected once.

Permissions

FinOps reads billing data. It holds no write access to your cloud accounts and changes nothing in them — including when a savings recommendation is accepted, which records a decision and nothing more.