specification: FinOps Framework specificationVersion: '1.0' schema: https://www.finops.org/framework/ provider: Topaz providerId: topaz created: '2026-07-11' modified: '2026-07-11' reconciled: false tags: - Access Control - Authorization - Fine-Grained Authorization - Open Source - FinOps - Cost Management - FOCUS description: >- FinOps view of Topaz spend. Topaz is open source (Apache-2.0) and free to self-host - in that model there is no vendor invoice, and cost is the compute, memory, and storage for running the authorizer (often as a sidecar) plus the embedded directory. Because the authorizer runs local to your applications, the dominant cost drivers are replica count and directory size rather than per-decision charges. The optional Aserto hosted control plane (a separate commercial product built on Topaz) is where any subscription/usage spend lives: central policy and directory management, decision logs, and real-time sync to deployed authorizers. Aserto per-unit rates are not reconciled here. notes: >- For self-hosted Topaz, model cost as owned infrastructure (containers running ghcr.io/aserto-dev/topaz) with no license fee. If you adopt Aserto, treat its control-plane subscription as a separate vendor charge and verify rates on the Aserto pricing page. sources: - https://www.topaz.sh/ - https://github.com/aserto-dev/topaz - https://www.aserto.com/pricing - https://focus.finops.org/focus-specification/v1-3/ alignedWith: framework: FinOps Foundation Framework frameworkUrl: https://www.finops.org/framework/ dataSpec: FOCUS dataSpecVersion: '1.3' dataSpecUrl: https://focus.finops.org/focus-specification/v1-3/ publisherName: Aserto serviceCategory: Identity and Access Management billingModel: pricingCategory: Open Source billingFrequency: Monthly billingCurrency: USD chargeCategories: - Usage - Purchase focusColumns: ServiceName: Topaz ServiceCategory: Identity and Access Management ProviderName: Aserto PublisherName: Aserto InvoiceIssuerName: Aserto BillingCurrency: USD ChargeCategory: Usage PricingCategory: Open Source meters: - name: self_hosted_compute description: Infrastructure cost of running the self-hosted Topaz authorizer (no vendor invoice). unit: hours aggregation: sum dimensions: - deployment - replica - name: directory_storage description: Storage backing the embedded Zanzibar-style directory (objects and relations). unit: bytes aggregation: max dimensions: - deployment - name: aserto_subscription description: Optional Aserto hosted control-plane subscription (separate commercial product). unit: months aggregation: sum dimensions: - tenant principles: - name: Visibility description: Track the compute and storage of your Topaz authorizer replicas and directory; on Aserto, track the control-plane subscription separately. - name: Allocation description: Tag Topaz deployments per application/team so authorization infrastructure maps to internal cost centers. - name: Optimization description: Right-size replicas for decision volume, keep the directory scoped to needed objects/relations, and self-host to avoid vendor per-decision fees when volume is high. - name: Accountability description: Assign owners per authorizer deployment; review monthly infrastructure cost against decision volume, and any Aserto subscription against its usage. maintainers: - FN: Kin Lane email: kin@apievangelist.com