Cloud integration
Oracle Cloud
Connect Oracle Cloud Infrastructure (OCI) with a cross-tenancy IAM policy. You admit OptCloud's published group by tenancy OCID — no API signing key or private key ever leaves your tenancy.
Cross-tenancy IAM policy (no keys shared)
Read-only
After first cost report / API sync (often same day)
How OptCloud connects with Oracle Cloud
OptCloud operates a single hub tenancy with a published Group and Tenancy OCID (the OCI equivalent of an AWS account ID / role ARN). OCI's cross-tenancy IAM policies let you grant that group specific read permissions directly in your own tenancy — usage reports and compartment metadata — by referencing our exact Tenancy OCID. You never create an IAM user, generate an API signing key, or hand us a private key; the trust is expressed entirely as an IAM policy statement you control and can revoke at any time.
Required permissions (read-only)
- admit group OptCloudConnector of tenancy OptCloudHub to read usage-reports in tenancy
- admit group OptCloudConnector of tenancy OptCloudHub to inspect compartments in tenancy
- admit group OptCloudConnector of tenancy OptCloudHub to read instance-family in tenancy (optional, for rightsizing inventory)
No permission to launch, terminate, or resize instances is required, and OptCloud never asks for an API signing key or private key from your tenancy. Access is entirely via the admit policy statements you write, referencing our published Tenancy OCID.
Usage Reports vs. Cost Analysis API — what you see, and when
Cost Analysis API calls return aggregated totals almost immediately once your policy is active. OCI's detailed Usage Reports (delivered to an Oracle-managed Object Storage location) provide resource- and tag-level line items but can take several hours to reflect same-day usage. Until the first usage report is available, Rightsizing and Idle Resources will show partial data.
Connecting multiple compartments or a full tenancy
A single cross-tenancy policy at the root compartment gives OptCloud visibility into every compartment in your tenancy. If you prefer tighter scoping, you can write the admit statements against a specific compartment OCID instead of the whole tenancy — OptCloud will only see cost and inventory for that compartment and its children.
Create a connection
- 1
Start an OCI connection in OptCloud
Go to Cloud Accounts → Add account → Oracle Cloud. OptCloud shows our published Tenancy OCID and Group OCID, plus the exact policy statements to add.
- 2
Add the cross-tenancy policy in your tenancy
In Identity & Security → Policies, create a policy in the root (or a specific) compartment that defines our tenancy and group, then admits it to read usage-reports and inspect compartments — using the statements OptCloud provided.
- 3
Enable Usage Reports (if not already on)
OCI generates usage reports automatically once cost tracking is active for your tenancy — no bucket or export setup required on your side.
- 4
Confirm in OptCloud
Enter your Tenancy OCID and, optionally, the compartment OCID(s) to scope. OptCloud validates it can read usage reports using the policy you just created — no key is entered anywhere in this flow.
- 5
Validate compartments and services
Confirm Cost Explorer shows OCI spend by compartment and service.
Backfilling historical usage data
OCI's Cost Analysis API typically exposes historical totals for a rolling window (commonly the last several months) as soon as your policy is active — no manual backfill request is needed. Resource-level detail from Usage Reports is generally only available from when cost tracking was first enabled on your tenancy going forward.
Data collected
- Cost and usage by compartment, service, and tags/freeform tags
- Optional compute/block storage inventory metadata
What you get in OptCloud
- OCI in the same multi-cloud views as AWS, Azure, and GCP
- Compartment-level allocation
- Budgets and anomaly alerts on OCI spend
Filterable dimensions
Once connected, you can filter and group cost data in Cost Explorer and Reports by:
- Compartment — compartment name and OCID
- Category — compute, storage, network, database, other (OptCloud's normalized category)
- Service — e.g. Compute, Block Volume, Autonomous Database
- Region — e.g. us-ashburn-1, eu-frankfurt-1
- Tag / Freeform tag — any OCI defined or freeform tag key and value
- Cost type — usage, tax, credit, commitment amortization
Updating or revoking your connection
Because access is granted via an IAM policy referencing our published Tenancy OCID rather than a key you issued, there's no signing key to rotate on your side. If OptCloud needs an additional permission later, we'll give you the exact statement to add — existing sync keeps working while you do. To revoke access at any time, delete or edit the admit policy in your tenancy; access stops immediately.
Troubleshooting
OptCloud can't read usage reports
Confirm the admit policy was created in the correct compartment (root, unless you scoped it), references our exact Tenancy OCID and Group OCID, and includes the 'read usage-reports' verb. Policy propagation can take a minute or two.
Do I need to create a user or API key?
No. OCI's cross-tenancy policies let OptCloud act using our own hub identity once your tenancy admits our group — nothing is created or shared on your side.
Related integrations
Ready to connect Oracle Cloud?
Open the dashboard to add the account, or book a walkthrough with our team.