A budget alerts. It never caps spending on its own.
Billing is a separate object from the project, with its own IAM roles.
roles/billing.admin
Manages payment methods and project linking
roles/billing.user
Links a new project โ never sees payment details
A 100% budget alert fired correctly โ to a former employee's inbox nobody was reading โ while a runaway query hit 340% of budget. Point every alert at a Cloud Identity group, checked for freshness, never an individual address.
Capping spend requires custom automation on the budget's Pub/Sub trigger. Export now offers three formats: standard, detailed (with labels), and FOCUS (vendor-neutral, multi-cloud).