Skip to content

Getting started

How your data flows

A read-only, pull-based path from your Azure estate to your dashboards — nothing writes back.

Infralign reads your estate once a night through a read-only service principal, shapes the raw data through a warehouse, and surfaces it as dashboards, reports, a chatbot, and recommendations. Figure 1 is that path end to end; the table under it names each column.

Infralign data flowMultiple customer Azure subscriptions — development, staging, production, and a hub subscription — are read through five read-only feeds (Cost Details API, Resource Graph, Advisor, Monitor metrics, and the Activity Log) by a single read-only service principal, pulled nightly into a bronze parquet layer and a gold warehouse, then surfaced as dashboards, reports, a chatbot, and recommendations, which your team approves. An optional FOCUS export container joins the bronze layer on a dashed appendix path.Your Azure estateWhat you seeDevsubscriptionStagingsubscriptionProdsubscriptionHubsubscriptionRead-only feedsCost Details APIResource GraphAdvisorMonitor metricsActivity Logread-only service principalCost Management Reader + ReaderNightly acquire · 02:30Bronze · parquetWarehouse · goldDashboardsReportsChatbotRecommendationsapprove / rejectYour team approvesFOCUS exportappendix · optional
Figure 1 — Every arrow points away from your estate: the flow is a nightly read-only pull, and no step writes back.
Part of the diagramWhat it is
Left columnThe nightly pull at 02:30 (CET). One read-only service principal, holding two roles per subscription, reads five gated sources. Every source, endpoint, and role is in the data sources reference.
Centre columnThe pipeline. What is read lands as bronze parquet, then is shaped into a gold warehouse. Dashboards, reports, chatbot, and recommendations all build from gold.
Right columnOutputs and the approval gate. Your team approves or rejects each recommendation, and no change is prepared without that step.
Dashed laneThe optional FOCUS export for very large estates, joining bronze instead of the daily Cost Details API. Not part of the default path — see FOCUS exports and storage setup.

No arrow points back: the flow cannot create, modify, or delete a resource, tag, or export. Remove the two role assignments and it stops the same moment.

The nightly pull copies your billing and resource metadata into Infralign’s warehouse in Microsoft Azure, Italy North (EU). Each tenant gets its own isolated databases; data is encrypted in transit with TLS and at rest on Azure-managed storage. Metadata only — never credentials, never data inside your resources. Security and data handling covers hosting, isolation, retention, and deletion.


Next: Dashboards — the four persona boards the gold warehouse feeds.