Inside a single organisation, cost allocation is mostly a discipline problem. Agree a tagging standard, enforce it at creation, and the reporting follows.
Across a portfolio of operating companies that must stay separate, several of those assumptions stop holding, and the ones that break are not obvious until you are some way in.
There is no single view to build on
The usual approach consolidates billing data into one place and slices it. When tenants are separate legal entities under different regulators, moving their billing data into a shared analysis environment may itself be the thing you are not allowed to do.
What worked was keeping the detailed data within each tenant boundary and lifting only aggregates upward. Group reporting saw totals and trends by tenant. Detail stayed where it belonged, and anyone who needed it worked inside that boundary.
Shared infrastructure is the hard case
Anything genuinely shared has to be split somehow, and every splitting rule is arguable. Split a shared registry by pull volume and a tenant with large images subsidises one that pulls constantly. Split evenly and a small tenant carries a large one.
There is no correct allocation for shared cost. There is only one that everybody has agreed to in advance.
The practical resolution was to minimise what is shared, and to write down the rule for whatever remained before anyone saw a number attributed to them. Agreeing a method after the first invoice is a negotiation. Agreeing it before is a policy.
The account boundary does most of the work
Where isolation was at account or project level, allocation was close to free: the billing boundary already matched the tenant boundary, and no tagging discipline was required to get an accurate number.
This is an underrated argument in the isolation decision. Teams weigh account separation on security and blast radius, then discover afterwards that it also removed an entire category of allocation work. Where tenants shared a cluster, we were reliant on labelling being right, and labelling is only ever as right as the last thing someone deployed in a hurry.
Showback before chargeback, always
Publishing numbers that teams have not seen before produces disputes about the numbers rather than about the spend. Every early conversation goes into whether the figure is correct instead of whether the cost is justified.
Running showback for a couple of cycles first gets the arguments out of the way while nothing is at stake. By the time anything is charged, the method has been challenged, corrected and accepted. Teams also start optimising during showback, before any money moves, purely because they can finally see what they are responsible for.
What to build first
Get to a per-tenant total that nobody disputes, even if the internal breakdown is still rough. A total that finance and each tenant both accept is worth more than a detailed model that one party rejects, because the total is what conversations about direction are based on.
Then improve the breakdown where the money is. Perfect allocation of a small line item is a poor use of the effort compared with a defensible split of the largest one.



