Skip to content

Reference

Ending the connection

Stopping collection takes two removals you run yourself, while deleting what has already landed is a request with terms attached.

Two things end at different times, and conflating them is the mistake worth avoiding. Revocation stops new data arriving, and you run it yourself. Deletion removes what has already arrived, and it is a request with terms attached.

Any one of these stops collection. You need no action from Infralign, and nothing has to be revoked on Infralign’s side, because the connection holds no write permission in your estate.

What you doEffect
Remove both role assignments from infralign-readerThe service principal authenticates, and every call returns AuthorizationFailed
Disable the service principalAuthentication itself stops
Delete the app registrationBoth of the above, permanently
Rotate the client secret without giving Infralign the new valueThe stored credential stops validating at its next use

New collection stops once Azure applies the RBAC change, or as soon as the credential can no longer authenticate. Removing a role assignment is the reversible option; deleting the registration is not.

Test revocation before you rely on it, and record who in your organisation can trigger it. Customer effort has that on the onboarding checklist for exactly this reason.

Do this before deletion, not after.

  • Chart-level CSV export is available from the BI view on any dashboard.
  • During an engagement, monthly report figures can be provided as a spreadsheet on request.
  • Reports already delivered to the Audits page are HTML, and forward without editing.

A self-serve export API is on the roadmap and does not exist today, so allow time for the manual route.

Write to [email protected]. The intended target is deletion of your tenant warehouse, raw copies, and backups within 30 days, confirmed to you in writing.

The operational runbook behind that target is not finalised. Get the 30 days written into your contract while you are still negotiating access; security and data handling states where the commitment currently stands.

What happens to the dashboards and reports

Section titled “What happens to the dashboards and reports”

Revoking access does not empty anything. The dashboards keep serving the data already in your warehouse, the freshness banner starts falling behind, and sources begin reading STALE as each one passes its expected window. Nothing new lands, so nothing new is written: no further monthly report, and the chatbot answers only from the history it already has.

All of it goes when the warehouse is deleted. Your account’s app access ends at the same point.

Approved change plans already delivered to your team stay with your team, in your own repositories, under your own controls. Nothing needs unwinding on Infralign’s side, because every write to your estate was made by your own pipeline in the first place. See the safety model.

Savings verification stops when the billing data stops, so a change awaiting its observation window is left unclassified rather than marked verified.