Evaluate Infralign
Customer effort and onboarding checklist
The people, access, and decisions to plan for — connecting takes under an hour, dashboards land the next morning, and the audit working session is in week one.
The free tier and audit are designed for a lean team, but they are not zero-effort. Infralign performs the data shaping, expert review, and audit. Your organisation supplies access, operating context, and decisions.
People to involve
Section titled “People to involve”| Role | What they do | Time needed |
|---|---|---|
| Azure technical owner | Defines subscription scope, creates the service principal and role assignments, explains workload constraints, and owns production decisions. On a lean team this may be the only person needed. | Under an hour to connect, plus the working session |
| Finance or FinOps contact | Reconciles billed cost, explains discounts and commitments, and agrees how savings will be measured. | The working session and the readout |
| Identity or security approver | Reviews the data flow, approves the two Azure roles and any dashboard sign-in consent, and confirms the security position. | A few minutes for consent, plus their own review |
| Executive sponsor (optional) | Resolves priority or ownership questions at the audit readout. | The readout |
One person may cover several roles.
Before you connect
Section titled “Before you connect”- Identify the Azure technical owner and the subscriptions to include.
- Review the free offer and security and data flow.
- Review the two effective Azure role definitions, including the unused
Microsoft.Support/*permission bundled in Cost Management Reader, or agree a narrower custom role. - Assess whether names, tags, allocation labels, or Activity Log fields in scope hold personal, confidential, or regulated values.
- Note any retention, deletion, subprocessor, or data-processing terms your security team needs confirmed.
Connecting (under an hour)
Section titled “Connecting (under an hour)”- Create an Entra app registration in your tenant.
- Grant Cost Management Reader and Reader per subscription — nothing broader.
- Transfer the credential through your agreed secure process.
- Run the validation runbook.
- Test role and credential revocation, and record who can trigger it.
- If dashboard sign-in is enabled, complete its separate admin consent and user list.
Step-by-step instructions are in connect Azure.
The morning after
Section titled “The morning after”- Check the first dashboards — they populate within 24 hours of access being verified (see your first day).
- Reconcile the billed-cost baseline with finance.
- Note material events, shared-cost rules, and data gaps to raise in the audit session.
Week one — the audit
Section titled “Week one — the audit”- Attend the audit working session with the people who own the largest cost lines, so findings get owners on the spot.
- Review each priority finding as accept, reject, or investigate.
- Attend the audit readout.
If you proceed to fixes
Section titled “If you proceed to fixes”- Select which accepted findings receive change planning under an engagement.
- Review dependencies, risk, validation, and rollback expectations.
- Merge chosen changes through your own engineering process, and record release dates.
- Review the measured result once enough Azure billing data has landed — typically weeks three to four.
The visibility tier stays free whether or not you proceed. There is no deadline to decide.
Next: Get your free audit — or start the technical setup at connect Azure.