# Manage connections

A connection is made once for the organization. It then feeds cost into every workspace it is associated with. This page covers what happens after the first connection is saved; each provider page covers how to connect it.

## Before you start

- Open **Integrations** in the sidebar, or **Settings**, then **Integrations**. The page is **Connected Providers & Apps**, with a **Manage** tab for existing connections and a **Connect** tab for new ones.
- Connecting, updating and removing connections needs the Owner or Integration Owner organization role. Editors can sync. See [Access model](/concepts/access-model).

## Read a connection's status

**Manage** lists every connection with its **Status** and **Last Sync**:

| Status | Meaning |
|---|---|
| Pending | Saved, not collected yet |
| Connecting | The first contact with the provider is in progress |
| Active | Collecting normally |
| Syncing | A collection is running now |
| Error | The last attempt failed; open the connection to see why |
| Disabled | Not collecting |

Open a connection to see its **Integration status**. **Run checks** tests two things, **Authentication** and **Cost data access**, and each shows Passed, Failed or Not run. The overall state is Healthy, Degraded, Error or Not checked.

On AWS and Azure, the **Accounts** or **Subscriptions** card lists what the connection reaches:

- **Collecting**: collected by this connection.
- **Covered**: its cost arrives through another account's collection, such as an AWS member account billed to the management account.
- **Unavailable**: reachable but not collectable, for example an Azure subscription where the connection holds no cost role. The reason is shown.

## Choose which workspaces see the cost

A connection's cost appears only in the workspaces it is associated with. There are two places to set that:

1. From the connection: the **Workspace access** card has an **Associate with** switch for each workspace.
2. From a workspace: **Settings**, then **Workspace Providers**, lists the connections the current workspace uses. **Add Provider** associates another connected one; **Remove Provider** takes one away. The cost data from that provider is then no longer available in that workspace; other workspaces keep it.

Adding and removing a workspace's providers needs the Owner or Editor team role on that workspace with Can edit access.

## Sync now

Costfluent collects on its own schedule several times a day. To collect immediately, use the sync button on a connection's row, labelled "Sync" and the connection's name. "Sync started" confirms the request. An explicit sync runs even when a workspace has [automatic syncing](/syncing) turned off.

## Update credentials

When a key, secret or role changes on the provider side, open the connection and select **Update credentials**. Then **Run checks** to confirm the new credentials work.

## Remove a connection

Open the connection and select **Remove integration**. The confirmation says: "All associated cost data will be removed." Reports, budgets and alerts stay, but no longer show that connection's cost. To stop one workspace seeing a connection without deleting its data, remove it from that workspace under **Workspace Providers** instead.

## Related

- [Automatic syncing](/syncing)
- [How Costfluent works](/concepts/how-costfluent-works)
- [AWS](/connect/aws), [Azure](/connect/azure), [Google Cloud](/connect/gcp), [Kubernetes](/connect/kubernetes)
