Help & FAQ

Answers to common questions about AZClarity

Getting started

How does AZClarity connect to my Azure subscription?
AZClarity uses Microsoft Entra ID OAuth. You click "Sign in", authenticate with your Microsoft account, and AZClarity receives read-only access to your Azure subscriptions. No agent, no manual configuration, no write permissions.

What permissions does AZClarity request?
Reader-equivalent access via the Azure Resource Manager user_impersonation scope. This allows AZClarity to list your resources and read configuration metadata. It cannot create, modify, or delete anything in your environment.

How do I revoke access?
In the Azure portal, go to Microsoft Entra ID → Enterprise applications → AZClarity → Delete. This immediately invalidates all stored tokens. You can also disconnect a subscription from the Account page in AZClarity.

My subscription isn't showing up after sign-in.
You must have at least Reader role on the subscription. Service Principal accounts without proper role assignment won't show subscriptions. If you authenticated with a guest account, ensure it has been granted Reader access in the target tenant.

Scanning

How long does a scan take?
Under 60 seconds for most subscriptions. Large subscriptions with hundreds of resources may take slightly longer.

How often can I scan?
Up to 5 manual scans per subscription per day. Scheduled scans run automatically once daily at 07:00 UTC, and a full change-detection scan runs every Sunday at 06:00 UTC.

What does the coverage map show?
Azure service categories with a green dot for active services and grey for not deployed. Within each category, individual services are listed with resource counts and regions. Tap any service to expand it and see cloud equivalents and contextual notes.

What Azure services are covered?
Around 70 services across categories including Compute, Storage, Databases, Networking, Security & Identity, Messaging & Integration, DevOps, Data & AI, Management & Governance, and IoT. Coverage is based on Azure Resource Graph queries against the most common resource types.

Insights & AI

How many AI calls do I get?
10 per user per day. The counter resets at midnight UTC. The remaining count is shown on the Insights page.

Why can’t AZClarity see my reservations?
Azure reservations live at the tenant level with their own access control, separate from your subscription. To let AZClarity read them, assign yourself the Reservations Reader role in the Azure portal (Home → Reservations → Role assignment → Add). It’s read-only and applies immediately.

What does naming consistency measure?
It looks at your resource names across the estate and reports how consistently they follow a dominant naming style — a maturity signal that helps with searchability, automation, and cost allocation.

What counts as an orphaned resource, and is it safe to delete them?
We flag unattached managed disks, unassociated public IPs, orphaned network interfaces, unused network security groups, and empty App Service plans. Two caveats. First, “orphaned” is a heuristic, not proof — a resource can look unattached and still be needed, so always review before deleting. We deliberately exclude the known false positives (Azure Site Recovery replica disks, AKS persistent-volume disks, backup disks, disks with an active SAS token, and private-endpoint NICs), because telling you to delete those would be harmful. Second, not all of them cost money: NSGs and NICs are free, so we label those as clutter rather than cost. We don’t put a price on orphaned resources ourselves — for real figures, the Azure Advisor panel on the same page shows Microsoft’s own savings estimates.

How does AZClarity calculate the Advisor savings figure?
It doesn’t calculate anything — it reports Azure Advisor’s own estimates. During each scan we read your open Advisor cost recommendations and capture the savings figures Microsoft attaches to them. Two things we’re careful about: Azure publishes a monthly and an annual figure as separate values, so we show both rather than deriving one from the other; and the currency is whatever your billing account uses, so if Azure reports in US dollars that’s what you’ll see. We never convert between currencies. These are Microsoft’s estimates, not guaranteed savings.

How does the Service Retirement Radar work?
During each scan AZClarity reads the Azure service retirement advisories that apply to your subscription, then matches them against the services we detected you actually run. Retirements affecting a service you run are shown first — with the deadline and days remaining — on the Azure Update Monitor page. We also show retirements we couldn’t match, because Azure names impacted services with display strings that don’t always line up with our catalogue. Treat it as a guide, not a complete list. It is a snapshot from your last scan, not a live alerting system.

Does AZClarity see policies inherited from my management group?
Yes. AZClarity reports the policies that actually apply to a subscription — assigned directly, plus everything inherited from your management group hierarchy and tenant root. The Governance page breaks it down (e.g. “18 policies apply — 3 direct, 15 inherited”). If you govern hierarchically — the Cloud Adoption Framework recommendation — you get credit for it. The same applies to RBAC role assignments.

Do my staff need their own Azure access to use the MSP tier?
No. MSP admins and members sign in with an email one-time code — no Microsoft sign-in, and no Azure access of their own. AZClarity connects to each client tenant with its own read-only identity, so your SAs, LTAs, and Service Managers can assess client estates without holding Azure roles.

How do I connect a client tenant?
On the Client Tenants page, add the client and their Azure directory (tenant) ID. Then (1) send the client’s Azure admin the admin-consent link, and (2) ask someone with Owner or User Access Administrator to assign AZClarity the Reader role at subscription or management-group scope (a management-group assignment covers all subscriptions beneath it). Then click Verify connection.

Why does the client assign a Reader role — isn’t consent enough?
For Microsoft 365 (Graph), admin consent alone is enough. Azure (ARM) is different: reading subscriptions always requires an explicit Reader role assignment — there is no one-click tenant-wide grant. It is read-only and applies within a few minutes.

Can I compare subscriptions?
Yes — the Compare Subs page shows coverage, adoption, and Well-Architected scores for all your subscriptions side by side, with the best value in each row highlighted. Useful for prod vs non-prod, or MSPs comparing client estates. Needs at least two scanned subscriptions.

What is the Adoption Score?
A score from 0 to 100 showing how broadly and deeply your subscription uses Azure — distinct from the Well-Architected Score. It blends breadth (active service categories) and depth (services within them), tracked across scans so you can see adoption improving over time.

What does the Well-Architected Score mean?
A score out of 50 across the five Azure Well-Architected Framework pillars: Security (0–10), Reliability (0–10), Cost Optimisation (0–10), Operational Excellence (0–10), and Performance Efficiency (0–10). The score is deterministic — based on which services are deployed and which capabilities are in place — not generated by AI. It is shown per subscription, and if you have more than one subscription, an estate-wide average with a per-subscription breakdown table appears at the top of the WAF Score page. Higher is better, but context matters: what's appropriate for a startup differs from a regulated enterprise.

How accurate is the Security Posture page?
The Security Posture page shows your Microsoft Defender secure score and control adoption based on direct ARM API queries — it reflects the actual state of your subscription at scan time. AZClarity presents this as read-only visibility of where security capabilities are switched on. It is not a security audit, a compliance attestation, or a remediation tool — it does not change anything in your environment. Use your judgement; some findings may be intentional in your setup.

Can the AI see my resource names or data?
No. AZClarity strips resource names and all personal data before sending anything to Anthropic. The AI receives only aggregate service type counts, regions, and configuration metadata. It cannot see what's inside your storage accounts, databases, or VMs.

What are change events?
When a scan detects that a service has appeared or disappeared compared to the previous scan, a change event is recorded. Change events are shown on the Insights page and summarised by AI where significant.

Features

What is the Azure Updates monitor?
It pulls the official Azure release communications feed and filters it to only the services you actually have deployed, so you see relevant product changes and retirement notices without the noise. AI assesses how relevant each update is to your estate.

What is DR Readiness?
A visibility view of your resilience posture: backup coverage across your VMs, availability-zone distribution, and high-availability findings surfaced from Azure Advisor. It shows where your architecture has resilience gaps — it does not configure or change backups.

What is the Advisor Adoption Trend?
A bar chart on the Cost Optimisation page showing open Azure Advisor cost recommendations across your last 12 scans. A falling count suggests guidance is being acted on. We track open count only — we cannot distinguish resolved from removed recommendations, and we say so. Requires at least 2 scans.

What is the Estate Health Snapshot?
A point-in-time count of your Azure resources by availability state, as reported by the Azure Resource Health API. States are Available, Degraded, Unavailable, and Unknown. The percentage shown excludes Unknown resources from the denominator — Unknown means Azure has not yet assessed that resource type, not that something is wrong. This is a snapshot from the time of the query, not a live monitor or alerting system.

What is Cost Optimisation?
Your Well-Architected cost pillar score plus waste findings in £ GBP — orphaned disks, idle public IPs, oversized resources — sorted by estimated monthly waste, each with a recommendation. It also shows tagging and budget visibility that affect cost allocation.

What is the Estate Map?
An AI-generated network topology diagram of your Azure estate — VNets, subnets, NSG coverage, and VNet peering, with hub-spoke detection. It is generated exclusively from your own scan data using read-only access and can be downloaded as an SVG for reports. The AI is strictly instructed to use only the data provided; it cannot invent connections that don't exist.

What is What If chat?
An AI assistant you can ask questions about your Azure estate. Answers are grounded strictly in your own scan data — it will not invent resource names or configuration, will not discuss other tenants, and only answers Azure-related questions. Limited to 10 prompts per user per day (resets midnight UTC).

Is AZClarity a security or compliance tool?
No. AZClarity is a feature adoption and visibility tool. It shows you what Azure services you are and aren't using, how well-architected your estate is, and where you could get more value. Where it surfaces security or cost signals, it does so as read-only context — it is not an audit, does not certify compliance, and never modifies your Azure environment.

MSP team features

How do I invite team members?
Go to Team in the navigation. Create your organisation, then enter the email address of the colleague you want to invite. They must have an email address in the same domain as yours. They will receive an invite email with a link to connect their Microsoft account.

Can team members see each other's subscriptions?
No. Members can only see the subscriptions they have personally connected. Org admins and the org owner can see all subscriptions connected by any team member via the portfolio view.

What happens if I cancel my MSP subscription?
All team members lose access immediately when the subscription lapses. Their data is retained for 30 days in case you resubscribe.

Can I have more than 5 team members?
The default limit is 6 seats (owner + 5 members). Contact support@azclarity.com to discuss higher limits.

Landing zones and multi-subscription scanning

What is a landing zone?
A landing zone is the recommended Azure architecture for organisations of any size — multiple subscriptions organised under Management Groups, typically with separate subscriptions for connectivity (hub VNet, DNS, firewall), production workloads, development workloads, and management (Log Analytics, Defender for Cloud). Even a 10-person business should implement this pattern if they are serious about Azure governance.

How does AZClarity handle landing zones?
When you connect your Azure account, AZClarity discovers all your subscriptions and retrieves your Management Group hierarchy. On the dashboard, subscriptions are grouped by their Management Group — so "Platform", "Workload", and "Dev" appear as separate groups. You can select any combination of subscriptions to scan together as a single scope.

Why scan multiple subscriptions at once?
In a hub-spoke topology, resources are split across subscriptions by design. Your hub subscription contains the networking (VNet, firewall, ExpressRoute). Your management subscription contains Log Analytics and Defender for Cloud. Your production subscription contains the actual workloads. Scanning them in isolation gives a misleading picture — the production subscription scores low on governance because the Log Analytics workspace lives in the management subscription. Scanning them together gives an accurate estate-wide view.

How do I scan a landing zone?
On the dashboard, you will see your subscriptions grouped by Management Group. Check the boxes for the subscriptions you want to include — for a full landing zone scan, select all of them. Click "Scan X subscriptions". Results are aggregated into one coverage map showing the combined estate.

Do I need Management Groups set up?
No. If you do not use Management Groups, your subscriptions appear in a flat list and you can still select multiple for a combined scan. Management Groups just add grouping in the UI to make selection easier.

What permissions are needed for Management Group discovery?
Reader access at subscription level is sufficient for scanning. Management Group discovery additionally requires the Microsoft.Management/managementGroups/read permission, which is typically available to anyone with a role at MG level. If this permission is not available, AZClarity falls back gracefully to a flat subscription list.

Billing

How do I get started / is there a free trial?
There is no free trial. You sign in with your Microsoft work or school account and subscribe to either Pro (£39/month) or MSP (£129/month) via Stripe. Your account activates as soon as payment is confirmed. You can cancel any time and keep access until the end of the billing period.

How do I cancel?
Go to Account → Billing → Manage subscription. This opens the Stripe customer portal where you can cancel. Your access continues until the end of the current billing period.

Do you offer refunds?
We do not offer refunds for partial months. If you experience a service issue, contact support@azclarity.com and we will review on a case-by-case basis.

Can I switch between Pro and MSP?
Yes. Contact support@azclarity.com and we will arrange an upgrade or downgrade at your next billing date.

Privacy & security

Where is my data stored?
All data is stored in Cloudflare D1, Western Europe region (Amsterdam). Data does not leave the EU except for AI processing (infrastructure metadata only, no personal data).

Is AZClarity GDPR compliant?
Yes. AZClarity is operated by Stephen Bennett, ICO-registered under ZC173030. See our Privacy Policy for full details.

How do I request deletion of my data?
Email support@azclarity.com with the subject "Data deletion request". We will delete all your data within 30 days and confirm by email.

Security team information pack

If your security, procurement, or IT governance team needs to assess AZClarity before approving its use, this section covers the questions they are most likely to ask. You can also download a pre-formatted copy to share with them directly — it is a self-contained page they can read, print, or save as a PDF.

What does AZClarity access in our Azure subscription?
A single delegated, read-only Azure Resource Manager scope (user_impersonation), limited to what the signed-in user can already read. It reads resource configuration and inventory metadata — types, counts, regions, SKUs, tags, policy assignments, budgets, security posture settings, and Advisor recommendations. It does not access the contents of your resources: not your storage accounts, databases, key vaults, VMs, or any application data. It reads the shape of your estate, not what is in it.

Can AZClarity change anything in our environment?
No — it is architecturally incapable of it. It holds only a read-only scope and issues only read operations. For MSP client tenants it is granted Azure's built-in Reader role, which cannot perform write operations; that restriction is enforced by Azure itself, not by our code.

Where is our data stored?
Cloudflare D1 (managed SQLite) in the Western Europe (WEUR) region, with application logic on Cloudflare Workers. Cloudflare is ISO 27001 and SOC 2 Type II certified. There is no self-managed infrastructure.

How are credentials protected?
Azure OAuth tokens are encrypted at rest with AES-256-GCM and a unique IV per value. Personally identifiable fields are additionally encrypted under a per-tenant key derived via HKDF-SHA256, so compromising one customer's data does not expose another's. Tokens and secrets are never logged, never returned in API responses, and never appear in error messages. Email addresses are deliberately not encrypted, because they are the lookup key used for sign-in — that trade-off is stated openly in the pack.

How do users authenticate?
AZClarity never handles a password. Standard accounts sign in through Microsoft Entra ID OAuth, so your own MFA and Conditional Access policies apply before we see the user. MSP accounts sign in with a six-digit email one-time passcode — hashed at rest, 10-minute expiry, single-use, attempt-limited, rate-limited, and designed so it cannot be used to enumerate which accounts exist.

Who can see our data?
Every query is scoped to the organisation or user taken from the authenticated session — never from a URL or request parameter — so one customer cannot reach another's data. Administrative access is limited to a single account protected by an email allow-list plus a step-up second factor, with actions recorded in an audit log.

Which third parties process our data?
Cloudflare (hosting and database, WEUR), Anthropic (AI analysis — receives summarised estate metadata only, never credentials or resource contents; does not train on API inputs), Stripe (payments — we never see card details), and Brevo (transactional email). Nothing is sold or shared with advertisers.

Are you GDPR compliant, and are you penetration tested?
Yes to UK GDPR — ICO registration ZC173030, with a 72-hour breach notification commitment. On penetration testing we will not overstate our position: AZClarity has not undergone a formal third-party penetration test or SOC 2 audit, and we would rather say so plainly than imply a certification we do not hold. We do maintain a documented internal security audit, a mandatory secure-by-design review for every change, and automated checks in the deployment pipeline. The full position is set out in the downloadable pack.

If your security team has a question the pack does not cover, email security@azclarity.com and we will answer it directly.

Still need help?

Email support@azclarity.com. We aim to respond within one business day.