Know your Azure footprint
before you walk into the room

AZClarity connects to your Azure tenant and gives you a coverage map across 10 service categories in under 60 seconds. Scan a single subscription or your full landing zone. See what is deployed, what you are paying for but not using, and which services Microsoft is retiring underneath you.

Read-only. No agents. No changes to your environment — ever.
Already a customer? Sign in with Microsoft.

What AZClarity actually tells you

What is deployed

A coverage map across 10 Azure service categories — compute, networking, storage, databases, security, identity, monitoring, integration, AI and DevOps. What you use, what you don't, and what you're missing.

What you're wasting

Orphaned resources: unattached managed disks, unassociated public IPs, idle App Service plans. Plus Azure Advisor's own cost recommendations — Microsoft's figures, not ours.

What is about to break

Service retirement warnings, matched against the services you have actually deployed — so you get the ones that affect you, not a firehose of everything Microsoft is deprecating.

How mature your estate is

Well-Architected Framework scoring across all five pillars, plus governance: tagging coverage, policy assignments (including those inherited from management groups), budgets and resource locks.

What we cannot see

If a permission or a licence stops us reading something, we say so — and tell you exactly how to enable it. We never guess, and we never report a gap in our visibility as a failing in your security.

Across every client

MSPs connect client Azure tenants and scan them all from one place. Each client is isolated; each grants read-only access explicitly and can revoke it at any time.

Who it's for — and who it isn't

AZClarity is not a FinOps platform for procurement teams. If your problem is forecasting, chargeback or reservation management, there are tools that do that better than we do, and we will happily say so. This is an instrument for the people who have to answer for the estate.

Managed service providers

Walk into a client review knowing their estate better than they do. Show them what they're paying for and not using — with Microsoft's own savings figures behind it. Fifteen clients in fifteen tenants, from one place.

IT consultancies

Scope an engagement in minutes instead of days. A coverage map on day one, not after a fortnight of discovery workshops.

Internal Azure teams

Answer “what have we actually got?” without trawling the portal subscription by subscription — and know what Microsoft is about to retire underneath you.

The common thread. Every one of these is someone who has to answer for the estate — to a client, to a board, or to whoever walks over and asks why the bill went up. The data has always been in Azure. What costs you is going and getting it, every single time somebody asks.

Most Azure tools answer a different question

The market is full of FinOps platforms. They are good at what they do. It is just not this.

A FinOps platform asks

“What does this cost, and how do I cut it?”

  • Forecasting and budgets
  • Chargeback and showback
  • Anomaly alerts on spend
  • Reservation and savings-plan management

If cost is your only problem, several of them are better at it than we are.

Simple pricing

No per-resource fees. No percentage of your cloud spend. No annual lock-in.

Pro

£39 / month

For internal Azure teams and consultants working in their own tenant.

  • Unlimited scans of your own Azure subscriptions
  • Coverage map across 10 service categories
  • Cost Optimisation — orphaned resources, Azure Advisor savings, and adoption trend showing whether open recommendations are being acted on
  • Azure Updates — retirement radar matched to what you actually run
  • Well-Architected maturity scoring, all five pillars
  • Governance — tagging, policy (incl. inherited), budgets, locks
  • Security Posture — Defender plans and secure score
  • DR Readiness & Resource Health — backup coverage, AZ distribution, and a real-time estate health snapshot (Available / Degraded / Unavailable)
  • Estate Map — see how your resources connect
  • What If — question your estate in plain English
  • Compare Subs — spot drift between subscriptions
  • QBR report — a client-ready estate summary
  • Scheduled daily scans + change detection

Before you connect. AZClarity requests a single read-only Azure scope. It reads configuration and inventory metadata — resource types, counts, regions, tags, policy assignments. It cannot read the contents of your resources: not your storage accounts, databases, key vaults or virtual machines. And it cannot change anything, because it holds no write permission at all. Revoke access from Entra ID at any time.

Questions you're probably about to ask

Why not just use the free native Microsoft tools?

Because the data is free, but assembling it is not. Azure Advisor, Resource Graph and the Service Retirement workbook are genuinely good, and most of what we read comes from the same APIs they do. We are not going to pretend otherwise. The question was never whether Azure has the information — it is what it costs you to go and get it, every time someone asks.

Concretely: Advisor scores your workloads, flags cost waste, and has a Service Retirement workbook. Resource Graph can query every subscription at once. Advisor also has Quick Fix, which can bulk-remediate certain recommendations from the portal — a genuine capability we do not have, though Microsoft notes it is only available for specific recommendation types.

To be clear about what AZClarity does: we score all five Well-Architected pillars, we find cost waste (orphaned resources, idle plans, unassociated IPs) and we surface Azure Advisor’s own savings figures alongside them. Those are not things you give up by using us — they are in the product. The question is not whether the data exists; it is who assembles it, across how many tenants, and whether they tell you when they could not see something.

One distinction worth being precise about, because it is the one people ask us to justify: Advisor’s retirement coverage is a curated list. Microsoft’s own documentation says the coverage “isn’t comprehensive” and that it “doesn’t have information about the Impacted Resources for a subset of recommendations.” AZClarity reads the raw Azure Service Health retirement feed and matches every advisory against the services you actually run — not a curated subset of them. That is the difference, and it is a real one.

Three things it will not do for you:

1. Assemble it. Those answers live in five different blades, a workbook you have to install from a gallery, and a KQL query you have to write. Knowing it is possible is not the same as having it on a screen in sixty seconds. AZClarity is the assembly, not the data.

2. Cross the tenant boundary. Resource Graph queries subscriptions you can see. If you are an MSP with fifteen clients in fifteen separate tenants, native tooling gives you fifteen portals and no consolidated view. That is the gap the Multi-Tenant plan exists to fill.

3. Tell you what it could not see. When a permission or a licence stops a check from running, native tools tend to show you a zero. We mark it not assessable and tell you how to fix it — because a gap in our visibility is not a finding about your security.

So the honest answer is: it depends what your time is worth. If you enjoy the portal and nobody is waiting on you, the native tools will get you there. If you are an internal team who needs to answer “what have we actually got, what are we wasting, and what is Microsoft about to break” this afternoon — or an MSP who has to answer it for fifteen clients in fifteen separate tenants — that is the hour you are buying back, every time you ask.

What makes AZClarity different from the other third-party tools?

The short version is above — most Azure tools are FinOps platforms, and we are not one. Two deliberate differences are worth spelling out, because both cut against us in some sales conversations:

We are read-only. We will never delete your unattached disk. That is a weaker product than one that auto-remediates — and a much easier one to get approved, because there is nothing to sign off. No change board, no “what if it breaks production”.

We say when we cannot see something. Most posture tools quietly turn “I was not allowed to read this” into a red cross on your dashboard. We think that is a lie, so we mark it not assessable and tell you exactly which role to grant. It makes our reports look less impressive. It also makes them true.

Can it change anything in my Azure environment?

No — it is architecturally incapable of it. AZClarity holds a single read-only Azure Resource Manager scope. For MSP client tenants it is granted Azure's built-in Reader role, which cannot perform write operations — that restriction is enforced by Azure itself, not by our code. There is no "are you sure?" button, because there is nothing to be sure about.

What can it actually see?

Resource configuration and inventory metadata: types, counts, regions, SKUs, tags, policy assignments, budgets, security posture, Advisor recommendations. It cannot read the contents of your resources — not your storage accounts, databases, key vaults, VMs, or any application data. It reads the shape of your estate, not what is in it.

What happens when it can't see something?

It says so. If a permission or a licence tier stops us reading a check, we mark it not assessable and tell you exactly how to enable it — we never score a gap in our visibility as a failing in your security. Most tools quietly turn "I couldn't read this" into a red cross. We think that's a lie, so we don't do it.

How long does a scan take?

The coverage map typically lands in 15–30 seconds. The deeper analysis — security posture, cost waste, retirements, maturity scoring, AI recommendations — runs straight after and usually completes inside a minute.

To be precise about what that number is: it is measured on small-to-mid subscriptions. A very large estate — hundreds of subscriptions, tens of thousands of resources — will take longer, and we would rather tell you that than quote a round number we cannot stand behind. The scan reads aggregated inventory rather than walking every resource, so it scales with the number of service types you use, not the number of resources you have.

Scans also run automatically each day, so change detection works without you doing anything.

How do I connect a client tenant as an MSP?

Two deliberate actions, by your client: an administrator grants consent to the AZClarity application, and someone with Owner or User Access Administrator assigns the built-in Reader role. That's a real friction point and we won't pretend otherwise — Azure has no one-click tenant-wide grant the way Microsoft 365 does. The upside: your client retains full control and can revoke access from the Azure portal at any time.

Are you SOC 2 certified? Have you been penetration tested?

No, and we won't pretend otherwise. AZClarity is an independently operated product. What we do have: OAuth tokens encrypted at rest with AES-256-GCM, per-tenant key derivation for personal data, parameterised queries throughout, a documented internal security audit, and infrastructure on Cloudflare (ISO 27001, SOC 2 Type II). If your security team needs the detail, there's a downloadable security pack that answers the questions they'll actually ask — including the uncomfortable ones.

Can I cancel?

Any time, from your account page. No annual contract, no minimum term, no percentage of your cloud spend. If you cancel mid-month you keep access until the period you've paid for ends.