GCP Integration FAQ
Answers to common questions regarding the architecture, security, and implementation of the OneLens Google Cloud Platform (GCP) integration.
What is the high-level architecture of this integration?
What GCP scopes do you support for onboarding?
How is authentication handled?
What specific permissions does OneLens require?
IAM Role
Scope
Assignee
Purpose
Which APIs need to be enabled?
Is there any cost for enabling all these APIs?
Can we automate this setup?
Why does OneLens need "Viewer" role for the External User?
What if we have a third-party billing partner (CSP) and do not have access to enable the BigQuery cost export?
Why must the BigQuery Dataset be in the "US (multiple regions)" location?
Why is "Table Expiry" disabled on the dataset?
I already have a billing export. Do I need to create a new one?
Why do you require BigQuery roles (Job User, Metadata Viewer) on the target projects?
What is the cost incurred for this setup?
Scenario 1: Same Region (our standard setup)
Component
$5K/month spend
$50K/month spend
$500K/month spend
$5M/month spend
Scenario 2: Different Region (common with existing billing project)
Component
$5K/month spend
$50K/month spend
$500K/month spend
$5M/month spend
Last updated

