Between 30 and 55 percent of spend could not be allocated to anyone, because labels were optional rather than enforced at resource creation
Allocation is a policy problem wearing a tooling costume. The billing export is only as good as the label that was or was not applied.
Prepared by Redress Compliance · August 19, 2026 · Google Cloud FinOps engagements. 20 to 30 engagements led, 2024 to 2025.
Executive summary
Attribution gap: 30 to 55 percent of spend was unallocable because labels were optional rather than enforced through the resource hierarchy.
Folder sprawl: flat project structures hid 10 to 20 percent of cost that a folder hierarchy would have surfaced without any new tooling.
Late commitment: committed use discounts were under applied by 15 to 30 percent, and budgets were set after the fact rather than before the spend.
Four pillars carry every cost line: business unit, application, environment, cost center. Lock the label keys before any production deployment, not after.
Which four pillars carry the allocation?
Business unit, application, environment and cost center. Each maps to a label key, each key has a controlled vocabulary, and each vocabulary lives in one source of truth.
| Pillar | Label key | Source of truth | Cardinality |
|---|---|---|---|
| Business unit | bu | Finance master data | 10 to 50 |
| Application | app | Service catalog or CMDB | 100 to 1,000 |
| Environment | env | Controlled vocabulary | 4 to 6 |
| Cost center | cc | ERP cost center register | 50 to 200 |
Lock the keys before the first production deployment
Hold the controlled vocabulary in the infrastructure repository and reject any resource creation that does not carry the four labels. The lock is a policy at the organization level, not a convention in a wiki.
Project is isolation, not allocation
The project boundary is where access and blast radius live. Treating it as the allocation unit is what produces an invoice nobody can read, and it is the most common starting error.
What does a labelling policy that holds look like?
It lives in the deployment code rather than in a standard. Manual labelling drifts inside thirty days, so every resource creation path has to inherit the policy.
Six rules that survive an enterprise estate
- The four pillar labels are mandatory, with no resource creation without them.
- The controlled vocabulary is single source: one repository, one review.
- Labels apply at the lowest resource, not just at the project.
- Lowercase only, hyphen separated, because the keys are case sensitive.
- Folder labels propagate down, with explicit overrides.
- Drift detection runs daily against the billing export.
Drift is the default state
The policy fights drift with detection rather than with hope. Unlabelled spend lands in a daily exception report, and the label documentation sets out the mechanics.
The Google Cloud negotiation leverage framework
Where the leverage sits across commitments, rates and the renewal, and the buyer side moves that reach it.
Get the brief →What 20 to 30 Google Cloud engagements showed
Across roughly 20 to 30 Google Cloud FinOps engagements Fredrik Filipsson led between 2024 and 2025, unattributable spend was the biggest blocker. Three patterns recur.
- Attribution gap: 30 to 55 percent of spend was unallocable because labels were optional, not enforced through the resource hierarchy.
- Folder sprawl: flat project structures hid 10 to 20 percent of cost a folder hierarchy would have surfaced.
- Late commitment: committed use discounts were under applied by 15 to 30 percent, and budgets were set after the fact.
Clean labelling changed the economics. Nothing in the recovery required a rate concession, because the money was already being spent by somebody unnamed.
- Commitments sized from your actual consumption curve rather than last year's footprint
- Right sizing for databases, storage and compute schedules with dollar figures
- A ranked savings queue your team can work through
How does folder structure drive clean allocation?
The folder hierarchy is the structural counterpart to the labelling policy. It carries policy, access and budget at each level, described in the resource hierarchy documentation.
Four patterns, and one that aligns everything
- Business unit first: business unit, function, application.
- Environment first: production or non production, business unit, application.
- Function first: function, business unit, application.
- Hybrid: business unit, environment, application.
Why the hybrid pattern wins
Business unit owns the access grant at the top, environment carries the policy in the middle, and application owns the resources at the leaf. The chargeback query is short, the grant scope is predictable, and the application folder is the operational unit.
Watch the briefing · 4:16Negotiating Google 11: Run Google Between RenewalsThe gap between the paper rate and the ledger rate, the monthly rhythm, and the evidence file that keeps the next deal warm.
What does the maturity path actually require?
Three years with measurable gates. It moves the organization from invoice mystery to engineering ownership of cloud cost, and it cannot be shortcut with a dashboard.
Year one is coverage, not savings
Tagging coverage above 90 percent, the label policy live, and drift detection running. Nothing downstream is trustworthy until that gate is passed.
Commitments come after the data, not before
Committed use discounts were under applied by 15 to 30 percent precisely because they were sized against a consumption picture nobody could read. The commitment mechanics sit in the commitment negotiation tactics, and the budget controls belong in place before the spend rather than after it.
Where the common advice on cost allocation is wrong
The common advice is to buy a cost tool and let it attribute the spend. We disagree.
A tool cannot label what was never labelled
The billing export is authoritative and it is also downstream of the label. When 30 to 55 percent of spend arrives unlabelled, every dashboard built on it inherits the same gap and presents it confidently.
The buyer side move is to enforce the four labels at creation, mirror the organization in the folder hierarchy, and only then size the commitments. The Google Cloud practice runs the coverage measurement before any commitment conversation.
How that measurement is used at the table, rather than in a dashboard, runs through the twelve part Google negotiation series.
What the engagements measured, 2024 to 2025
Two cuts of the engagement file, both about attribution rather than rate.
Where labels were optional rather than enforced, leaving the largest lines on the bill with no named owner at all.
Recoverable by mirroring the organization in the folder hierarchy, with no additional tooling and no vendor conversation.
Neither figure needs a discount to recover. Both need a policy that runs at resource creation rather than at month end.
Your first five moves
- Lock the four label keys and their controlled vocabulary in the deployment code, because manual labelling drifts inside thirty days.
- Reject any resource creation that does not carry all four labels, which is what closes the 30 to 55 percent attribution gap at source.
- Mirror the organization in the folder hierarchy, since flat project structures hid 10 to 20 percent of cost that needed no tooling to surface.
- Run drift detection daily against the billing export, so unlabelled spend lands in an exception report rather than in a quarterly surprise.
- Size the commitments only after coverage passes 90 percent. The Google Cloud practice and the spend health check run that measurement first.
Frequently asked questions
How much spend goes unallocated?
Between 30 and 55 percent in the reviewed estates. Labels were optional rather than enforced through the resource hierarchy, so the largest lines had no named owner.
What are the four allocation pillars?
Business unit, application, environment and cost center. Each maps to a label key with a controlled vocabulary held in a single source of truth.
Is the project the allocation unit?
No. The project is the unit of isolation, where access and blast radius live. Treating it as the allocation unit is the most common starting error.
Why does manual labelling fail?
Because drift is the default state and manual labelling drifts inside thirty days. The policy has to live in the deployment code so every creation path inherits it.
What does folder structure recover?
Between 10 and 20 percent of cost that flat project structures hid. It needs no new tooling, only a hierarchy that mirrors the organization.
Which folder pattern is best?
Business unit at level one, environment at level two, application at level three. Access scope stays predictable and the chargeback query stays short.
Why were commitments under applied?
By 15 to 30 percent, because they were sized against a consumption picture nobody could read. Coverage has to come before the commitment conversation.
Can a cost tool fix attribution?
No. The billing export is authoritative and downstream of the label, so a dashboard built on unlabelled spend inherits the same gap and presents it confidently.
What is the year one gate?
Tagging coverage above 90 percent with the label policy live and drift detection running. Nothing downstream is trustworthy until that gate is passed.
Does any of this need a vendor concession?
No. The money is already being spent by somebody unnamed, so the recovery comes from policy at resource creation rather than from a rate negotiation.