Reference
Ending the connection
Stopping collection takes two removals you run yourself, while deleting what has already landed is a request with terms attached.
Two things end at different times, and conflating them is the mistake worth avoiding. Revocation stops new data arriving, and you run it yourself. Deletion removes what has already arrived, and it is a request with terms attached.
1. Revoke access
Section titled “1. Revoke access”Any one of these stops collection. You need no action from Infralign, and nothing has to be revoked on Infralign’s side, because the connection holds no write permission in your estate.
| What you do | Effect |
|---|---|
Remove both role assignments from infralign-reader | The service principal authenticates, and every call returns AuthorizationFailed |
| Disable the service principal | Authentication itself stops |
| Delete the app registration | Both of the above, permanently |
| Rotate the client secret without giving Infralign the new value | The stored credential stops validating at its next use |
New collection stops once Azure applies the RBAC change, or as soon as the credential can no longer authenticate. Removing a role assignment is the reversible option; deleting the registration is not.
Test revocation before you rely on it, and record who in your organisation can trigger it. Customer effort has that on the onboarding checklist for exactly this reason.
2. Take your numbers with you
Section titled “2. Take your numbers with you”Do this before deletion, not after.
- Chart-level CSV export is available from the BI view on any dashboard.
- During an engagement, monthly report figures can be provided as a spreadsheet on request.
- Reports already delivered to the Audits page are HTML, and forward without editing.
A self-serve export API is on the roadmap and does not exist today, so allow time for the manual route.
3. Request deletion
Section titled “3. Request deletion”Write to [email protected]. The intended target is deletion of your tenant warehouse, raw copies, and backups within 30 days, confirmed to you in writing.
The operational runbook behind that target is not finalised. Get the 30 days written into your contract while you are still negotiating access; security and data handling states where the commitment currently stands.
What happens to the dashboards and reports
Section titled “What happens to the dashboards and reports”Revoking access does not empty anything. The dashboards keep serving the data already in your warehouse, the freshness banner starts falling behind, and sources begin reading STALE as each one passes its expected window. Nothing new lands, so nothing new is written: no further monthly report, and the chatbot answers only from the history it already has.
All of it goes when the warehouse is deleted. Your account’s app access ends at the same point.
If you were mid-engagement
Section titled “If you were mid-engagement”Approved change plans already delivered to your team stay with your team, in your own repositories, under your own controls. Nothing needs unwinding on Infralign’s side, because every write to your estate was made by your own pipeline in the first place. See the safety model.
Savings verification stops when the billing data stops, so a change awaiting its observation window is left unclassified rather than marked verified.