At the moment we create a per-namespace Cost Monitor role and use it in the corresponding per-namespace service account, but due to the logic of removing role, where they linger as "deleted" for a while, we get a lot of noise in the list of service accounts and roles. Consider making that role per-project, similarly to the PostgreSQL instance.