Getting started
How your data flows
A read-only, pull-based path from your Azure estate to your dashboards — nothing writes back.
Infralign reads your estate once a night through a read-only service principal, shapes the raw data through a warehouse, and surfaces it as dashboards, reports, a chatbot, and recommendations. Figure 1 is that path end to end; the table under it names each column.
What figure 1 shows
Section titled “What figure 1 shows”| Part of the diagram | What it is |
|---|---|
| Left column | The nightly pull at 02:30 (CET). One read-only service principal, holding two roles per subscription, reads five gated sources. Every source, endpoint, and role is in the data sources reference. |
| Centre column | The pipeline. What is read lands as bronze parquet, then is shaped into a gold warehouse. Dashboards, reports, chatbot, and recommendations all build from gold. |
| Right column | Outputs and the approval gate. Your team approves or rejects each recommendation, and no change is prepared without that step. |
| Dashed lane | The optional FOCUS export for very large estates, joining bronze instead of the daily Cost Details API. Not part of the default path — see FOCUS exports and storage setup. |
No arrow points back: the flow cannot create, modify, or delete a resource, tag, or export. Remove the two role assignments and it stops the same moment.
Where your data lands
Section titled “Where your data lands”The nightly pull copies your billing and resource metadata into Infralign’s warehouse in Microsoft Azure, Italy North (EU). Each tenant gets its own isolated databases; data is encrypted in transit with TLS and at rest on Azure-managed storage. Metadata only — never credentials, never data inside your resources. Security and data handling covers hosting, isolation, retention, and deletion.
Next: Dashboards — the four persona boards the gold warehouse feeds.