Overview
-
Last Snapshot
-
Subscriptions
-
Snapshot Runs
All time
-
Audit Entries
Quick Actions
Trigger management operations for all configured tenants
Shared Network Traffic
Shared allocation rows · per customer breakdown
Traffic Volume per Customer (GB)
Shared Bandwidth Cost per Customer (€)
Inventory
Inventory Views
Choose an inventory domain to manage source-of-truth mapping and tag compliance.
Data Operations
Snapshot
Broad ingestion and baseline job. Use this when you want the full system snapshot path, not a scoped refresh or a stored-data rebuild.
Cost Ingestion Controls
Configure ingestion safety limits, retries, circuit breaker thresholds, and backfill policy.
Max Concurrent Requests
Requests Per Interval
Request Interval (ms)
Subscription Batch Size
Batch Delay (ms)
Max Retries Per Request
Backoff Base Delay (ms)
Max Retry Duration (ms)
Circuit Breaker Threshold
Circuit Cooldown (ms)
Default Ingestion Scope
Backfill Month Limit
Cost Ingestion Monitoring
Live request queue, circuit breaker status, run health, and partial data indicators.
Click Refresh Status to load ingestion telemetry.
Refresh Latest Source Data
Fetch the latest data from source systems. This may call Azure/source APIs. Use Rebuild below when you only need to recompute prepared views from stored Ledger data.
Refresh Scope
Cost Period
Data To Refresh
Attribution
Rebuild Prepared Views
Recompute prepared datasets from stored Ledger data and latest internal state only. This action must not call Azure Cost APIs or other source systems.
Rebuild Scope
Period
Prepared Datasets
Budget Summary uses the canonical shared-only refresh and does not trigger Financial Intelligence. Dashboard Summary rebuild is available only for the all scope. Customer and subscription rebuilds stay narrowly scoped.
Unified Attribution Cutover
Run a unified attribution snapshot for a period and compare it against the current showback engine before cutover.
Period
Traffic Evidence Ingestion
Ingest VNet flow logs and Azure Firewall logs from Log Analytics workspaces. Evidence is attached to attribution lines for confidence-backed allocation.
Period
Snapshot History
Click Load to fetch history.
Sealed Period Recovery
Correct and republish one Showback period through fixed validation gates. No machine key or operator endpoint is exposed to this page.
Recovery identity
The period is immutable after the workflow starts. A second active workflow for the same period is refused.
Loading authoritative period availability…
Select a period to inspect its accounting state.
Cost Exports
Cost Export Source
Configure Azure Cost Management export storage for the savings engine.
Tenant
Display name
Storage account name
Container name
Path prefix
Auth tenant ID
Auth mode
Client ID
Configured Sources
Test connectivity, run ingestion, and review the latest operational state.
Loading cost export sources...
Loading connectors...
Loading StreamOne mapping...
StreamOne Source Operations
Run V1 Azure Plan billing dry-runs and full imports using the stored ION settings. The connector mapping page above uses the same live structure and saved mappings.
Stored ION settings status: loading...
Testing
Cross-Tenant Connection
Validate app registration credentials and list accessible subscriptions. You can test all configured tenants or a single selected tenant.
Tenant To Test
Tenant Permission Diagnostics
Run the same permission diagnostics used in onboarding without creating a new customer first. Select a specific configured connection or test all.
Connection To Check
Loading cached diagnostics...
StreamOne Billing Import
Imports StreamOne ION V1 billing rows and attaches them to the StreamOne structure mappings. Structural mapping is managed separately from this import.
V1 Billing
Customer Links — JSON object mapping your internal customer key to the StreamOne customer_id (a number). Used as filter[customer_id] on /reports/billing/azureplan. Example: {"example-customer":"123456"}. Leave blank or use {} for none.
Entitlement Links — JSON object mapping your internal customer key to an array of StreamOne entitlement ids. Example: {"tpcm":["4ea77352-b0f1-4d04-dd79-12db67ad60e9"]}. Leave blank or use {} for none.
V3 Entitlement Metadata
Used for ION V3 entitlement metadata and V3 connection testing. V1 API key/secret is still used for billing.
Preview uses one StreamOne customer_id and does not write to the database. Import queues a background job for all StreamOne customers. Use ION API Key/API Secret from StreamOne Admin Portal, not your normal portal login password.
Loading saved ION settings...
Diagnostics Overview
Top-level operator summary across AI, page, data pipeline, scope consistency, performance, system, flow, and data quality diagnostics.
Diagnostics source: Loading overview diagnostics...
Operator Summary
What is healthy, what is degraded, what needs attention first, and where to drill next.
Loading diagnostics overview summary...
-
Healthy Domains
Waiting for diagnostics
Diagnostics Domains
Each domain shows state, key metrics, and direct navigation into the corresponding diagnostics page.
Loading diagnostics domain summaries...
Priority Attention
Prioritized by current diagnostics pressure from available evidence signals only.
Loading priority attention summary...
Page Diagnostics
Validate page wiring, route/panel alignment, permissions, runtime health, API behavior, cache architecture, prepared-data freshness, and scope/data-quality risks before deployment.
Telemetry source: Loading page diagnostics telemetry...
Operator Summary
Compact deployment-readiness view for page wiring, data freshness, and mismatch risk across the Ledger admin experience.
Loading page diagnostics summary...
-
Total Pages Checked
Waiting for inspection
Architecture Audit Controls
Source-grounded wiring checks, runtime/API observations, and prepared-data freshness mapped into a tighter operator triage view.
Surface
Search
Status
Category
Diagnostics Table
Fast triage table for which pages are healthy, where freshness/runtime need attention, and where mismatch risk may exist. Open a row for the deeper technical evidence.
Open this page to inspect current page wiring.
Flow Health
Synthetic journey coverage, persisted flow results, and direct operator actions for manual execution.
Synthetic flow health will appear here when diagnostics are loaded.
Performance Diagnostics
Operator visibility into page latency, API timing, cache-path behavior, and bottlenecks across the admin surfaces.
Diagnostics source: Loading performance diagnostics...
Operator Summary
Why is this page slow? This summary combines page load telemetry, API latency observations, and cache path usage into one triage view.
Loading performance diagnostics summary...
-
Average Load
Waiting for diagnostics
Page Performance
Average page load latency, fastest/slowest pages, and total pages analyzed from persisted telemetry.
Loading page performance diagnostics...
API Performance
Average API latency, slowest endpoint, API calls per page, and total API time per page.
Loading API performance diagnostics...
Cache Usage
Cache hit rate and request-path distribution across L1 memory, L2 prepared, and L3 live data sources.
Loading cache usage diagnostics...
Heavy Pages / Bottlenecks
Pages with highest load time, highest API count, and lowest cache usage to speed up bottleneck triage.
Loading heavy page diagnostics...
Production Performance Telemetry
Durable evidence from recovery, update, recalculation, and targeted-repair runs. Missing observations remain unavailable.
Loading production run telemetry...
Planner Estimate vs Actual
The planner estimate is compared with observed wall-clock runtime after execution; variance is actual minus estimated.
Loading planner telemetry...
Avoided Work
Historical totals for reuse-backed snapshot, Azure, archive, and storage work avoided by the observed plans.
Loading avoided-work telemetry...
Frontend Render Evidence
Showback summary and Full Investigation render observations captured by the existing browser diagnostics batch.
Loading frontend performance telemetry...
History and Trend
Average, P95, worst, best, and recent run history for the recorded production lifecycle.
Loading performance history...
Payload Inspector
Internal operator tool for inspecting the exact payload currently being served on key prepared-data-backed surfaces and validating whether scoped rebuilds actually applied.
Inspect Served Payload
Choose a surface, scope, and period. The inspector fetches the current API response, surfaces its prepared metadata, and shows a raw JSON view without changing any financial or attribution behavior.
Surface
Scope Type
Period
Dashboard rebuild is limited to the all scope. Inspection is available across all listed scopes.
Requested vs Served Scope
Useful context for seeing what was asked for, what was actually served, and whether the result came from prepared data.
Run an inspection to view scope and prepared metadata.
Key Field Inspection
For any returned row collection, especially showback customer rows, surface the fields most useful for validating classification and prepared-data structure.
Selected Row
No row selected yet.
Raw JSON Response
This is the response body returned by the selected API surface.
No payload loaded yet.
Showback Network Attribution Diagnostics
Operator-safe proof for shared network attribution across customers, shared subscriptions, VNets, subnets, and service categories. Load lightweight metadata on open, then run full diagnostics only when you need reconciliation evidence and timings.
Diagnostic Controls
Ledger checks prepared showback, traffic links, attribution runs, real customers, and customer-scoped results for the selected month. The first page load fetches metadata only so the view does not fail on startup warmup.
Period
Customer
Service Category
Source Subscription
Destination Subscription
Source VNet
Destination VNet
Source Subnet
Destination Subnet
Use the fields above only when you want to pin the investigation to one exact source or destination path. Otherwise Ledger auto-selects the strongest candidate for the chosen period/customer.
Discovered Targets
Auto-discovered network attribution candidates from current traffic links. Use a candidate to fill the filter controls before rerunning full diagnostics.
Loading discovered targets...
Discovered Periods
Periods where Ledger currently sees showback prepared data, evidence runs, attribution runs, or traffic links.
Loading discovered periods...
Discovered Customers
Live Ledger customer records only. `cust001` will not appear unless it exists in current product data.
Loading live customers...
Compact Evidence
Period, run, billing, matched links, selected target, customer attribution result, showback row count, reconciliation status, and timing breakdown.
Open the page to load metadata. Run diagnostics to load compact evidence and timings.
Data Pipeline Diagnostics
Operator visibility into whether the underlying billing and prepared datasets are complete, fresh, healthy, and reliable.
Diagnostics source: Loading pipeline diagnostics...
Operator Summary
Can I trust the data right now? This summary combines durable refresh history, prepared registry state, and ingestion control telemetry.
Loading data pipeline diagnostics summary...
-
Pipeline Trust
Waiting for diagnostics
Loading refresh health diagnostics...
Loading freshness diagnostics...
Loading completeness diagnostics...
Loading registry diagnostics...
Loading backlog diagnostics...
Month Coverage
Per-month trust matrix for the configured required coverage window. Uses real snapshot history, prepared metadata, stored month artifacts, and retention settings.
Loading month coverage controls...
Loading month coverage summary...
Loading month coverage table...
No month coverage action has been run yet.
Shadow Provider Diagnostics
Admin-only read model for diagnostics-only shadow provider dry-run visibility. In-process runtime state remains the source of truth.
Diagnostics source: Loading shadow provider diagnostics...
Runtime Provider Shadow Status
Read-only comparison diagnostics. The in-process runtime remains the source of truth.
Loading shadow provider diagnostics...
Loading shadow provider diagnostics...
Loading shadow provider diagnostics...
Bounded Mismatches
Diagnostics-only mismatch records, truncated by the backend contract.
Loading shadow provider diagnostics...
SQL DTU Telemetry
Read-only telemetry for core SQL and Ledger SQL during nightly source snapshot and prepared rebuild execution. SQL text is redacted/fingerprinted before persistence.
Diagnostics source: Loading SQL DTU telemetry...
Collector Status
The collector samples SQL DMVs only, writes durable artifacts to Blob Storage, and does not tune SQL or change production workload.
Loading SQL DTU collector status...
-
Samples
Waiting for telemetry
Loading SQL target telemetry...
Loading artifact details...
Cost Basis Reconciliation
Validation-only Azure cost basis reconciliation for Usage, Actual Cost, Amortized Cost, Reservation purchases, Savings Plan purchases, Marketplace, Refunds, Credits, Adjustments, and Azure Hybrid Benefit.
Diagnostics source: Loading Azure cost basis reconciliation...
Azure Cost Basis Validation
Current month is treated as Month-To-Date and previous months remain validation evidence only. This page does not change any production financial behavior.
Loading latest stored cost-basis snapshot...
Financial Reconciliation
Read-only prepared financial health and independent Azure-vs-Ledger reconciliation. Prepared datasets are never labelled as Azure evidence.
Diagnostics source: Loading financial reconciliation...
Financial Health and Reconciliation Diagnostics
This page is diagnostics-only. It reads prepared data and the latest stored Azure diagnostics snapshot; it does not queue deploys, backfills, refreshes, rebuilds, or live Azure scans.
Period
Cost Basis
Mode
Production-like reconciliation guard disabled.
Loading financial reconciliation...
Loading Financial Intelligence authoritative freshness...
Prepared Data Registry Diagnostics
Admin-only read model for prepared-data registry contract state, runtime mapping, and freshness diagnostics.
Diagnostics source: Loading prepared-data registry diagnostics…
Registry Summary
Static registry definitions overlaid with observed runtime diagnostics from the existing management route.
Loading prepared-data registry diagnostics…
Loading prepared-data registry diagnostics…
Dataset Diagnostics Table
Read-only per-dataset view with runtime freshness, observed period metadata, and consumer surface counts.
Loading prepared-data registry diagnostics…
Loading prepared-data registry diagnostics…
Loading prepared-data registry diagnostics…
No diagnostics history loaded.
No regression diagnostics loaded.
Engineering Capabilities
Authoritative inventory of completed Ledger capabilities, their dependencies, implementation evidence, and runtime health.
Capability Registry
Loading capability registry...
Select a capability to inspect implementation, dependencies, runtime health, and change history.
System Diagnostics
Operator visibility into platform and infrastructure health signals to quickly confirm whether system conditions are driving incidents.
Diagnostics source: Loading system diagnostics...
Operator Summary
Is the system/infrastructure the problem? This view combines real SQL, storage, runtime, config, scheduler, and dependency checks.
Loading system diagnostics summary...
-
Overall State
Waiting for diagnostics
Loading database diagnostics...
Loading storage diagnostics...
Loading runtime diagnostics...
Loading configuration diagnostics...
Loading job diagnostics...
Loading dependency diagnostics...

Business Rules

Read-only Ledger rule inventory and actual prepared-run lineage. This view never evaluates, edits, publishes, assigns, or simulates a rule.

Rule Library

Loading rule library…

Hard-coded Rule Tracker

Loading migration tracker…

Lineage Runs

Loading lineage runs…

Applied Rules

Loading actual applied-rule evidence…
Ledger Guardrails
Internal read-only diagnostics for current passive guardrail observations. This page stays aligned with the existing admin shell and does not change evaluator behavior.
Diagnostics source: Loading ledger guardrails...
Internal Passive Summary
Current evaluator output only. No enforcement, no customer-facing behavior, and no implied full-system coverage.
Loading ledger guardrails...
-
Ledger Guardrails
Waiting for diagnostics
Internal validation only
These diagnostics remain passive and partially covered by design. A visible pass reflects the current evaluator output only and should not be read as full-system certification.
Observed Rules
Rule IDs, status, coverage, and evaluator notes presented for quick internal review. Coverage remains partial by design.
Showing current internal guardrail observations.
Loading ledger guardrail observations...
AI Diagnostics
Operational visibility into AI execution health, serving mode, latency, cache freshness, and sanitized failure signals.
AI Runtime Status
Read-only operator view for the Ledger AI execution path. Prompts, raw payloads, and customer-facing identifiers stay hidden.
Range
Loading AI diagnostics...
-
AI Health
Usage
Requests, outcome split, and cache effectiveness.
Open this page to load AI usage telemetry.
Performance
Latency distribution and slowest recent execution characteristics.
Waiting for diagnostics.
Freshness & Cache
Cache age, TTL, and whether served AI output looks current enough for operators.
Waiting for diagnostics.
Recent Executions
Most recent AI execution attempts and cache serves in a compact operator-friendly timeline.
Waiting for diagnostics.
Errors & Recovery
Sanitized error surface showing whether there is an open failure state, what category it falls into, and whether fallback or cache recovery signals exist.
Waiting for diagnostics.
Prepared Data & Source
Execution-source chain, observed scope hash, and prepared-source coverage visible to diagnostics.
Waiting for diagnostics.
Prompt & Safety
Prompt/version references and platform safety posture without exposing hidden prompt contents.
Waiting for diagnostics.
Provider Config Snapshot
Current provider, deployment, auth mode, and guarded execution settings relevant to operators.
Waiting for diagnostics.
Workspaces
Evidence Workspaces
Select tenant first, then one or more subscriptions, then assign one or more Log Analytics workspace resource IDs to that selection.
Tenant
Subscriptions in selected tenant
Dropdown multi-select with checkboxes.
Workspace Resource ID(s)
Comma, semicolon, whitespace, or newline separated.
Loading workspace configs...
Data Source & History Policy
Policy Configuration
Configure source fetch depth separately from visible history. Current month stays MTD where relevant, and completed-month comparisons continue to use closed months only.
Configuration Boundary
This page is configuration-only. Fetch windows control ingestion depth from upstream systems. Retention controls how much historical data stays visible to users in dashboards and reporting domains.
Upstream Data Fetch
This controls how much data is retrieved from external sources.
Source Fetch Window Backfill Mode Throttling Status
Historical View Retention
This controls how much history is visible in dashboards and reports.
Default retention
Visibility Rule
Retention changes what users can view historically. It does not change what Ledger fetches from Azure Cost Management, StreamOne, or other upstream services.
Domain Retention Window
Customer Overrides
Apply per-customer retention overrides without changing the default policy for other tenants and accounts.
Customer selector
Override retention window
Affected domains
Customer Retention Affected Domains
Impact Preview
Preview expected operational pressure before the policy is saved.
-
Estimated Snapshot Duration
Waiting for policy inputs
-
Estimated SQL / Storage Impact
Waiting for policy inputs
-
Prepared Refresh Pressure
Waiting for policy inputs
MTD
Current Month Handling
Current month remains partial; completed-month comparisons stay honest.
Tagging Governance
Tagging Compliance
Validate required tags and allowed values using cached resource inventory in the selected scope.
Scope
Configure scope and click Run Check.
Helper
Configuration Reference
SettingEnvironment VariableDescription
Tenant B IDAZURE_TENANT_ID_BTenant where the data lives
Client IDAZURE_CLIENT_IDApp registration client ID (in Tenant B)
Client SecretAZURE_CLIENT_SECRETApp registration secret
StorageSTORAGE_CONNECTION_STRINGTable + Blob storage (Tenant A or B)
Allowed TenantALLOWED_TENANT_IDTenant A — restricts admin access
Snapshot ScheduleSNAPSHOT_SCHEDULECRON expression (default: 02:00 daily)
Azure Tenants
Configured Tenants
Loading...
Refund Policy / Billing Scope
Configure rolling 12-month reservation refund capacity once per tenant billing scope.
Loading refund policy...
User List
Ledger Access Truth
User List
Inspect Ledger-relevant users, how access resolves, and what security requirements apply right now. Use What If for read-only evaluation, then jump to the authoritative edit page when a change is needed.
Ledger-Relevant Users
Users are derived from effective RBAC resolution, direct assignment exceptions, and app-assigned group membership that can currently be resolved.
Loading user list…
What If
Run a read-only access and policy evaluation for a selected Ledger user.
Select a user to evaluate current access resolution and security requirements.
User Access Detail
Expanded per-user view of identity, source groups, resolved roles, scope inheritance, and policy outcome summary.
Select a user row to inspect effective access and operator guidance.
Identity Sources
Ledger Identity Operations
Tenant-Driven Identity Sources
Select one tenant to inspect the Ledger app registration, current app-assigned groups, and visible members. This page does not operate in an all-tenants inspection mode.
Tenant App Registrations
Per-tenant registration visibility for the Ledger auth / source-of-truth layer. Fields are read directly from the admin tenant store.
Tenant Admission & Assigned Groups
This page handles tenant allow-listing, app-assigned Entra groups, and source-of-truth group membership visibility. Business access rules belong on Access Assignments.
Select a tenant to inspect app registration and assigned groups.
Assigned App Groups
Current app-assigned Entra groups, with existing RBAC mappings and member visibility.
Loading assigned groups…
Group Members In Selected Tenant
Inspect source-of-truth group membership before mapping groups to Ledger roles.
Select a tenant and click Load Group Members.
Role Catalog
Ledger Role Definitions
Role Catalog
Define what Ledger roles grant, inspect their exact permission surface, and understand assignment impact without mixing in principal-to-role mapping.
Separation of concerns. Role Catalog defines what roles grant. Access Assignments decides which users and groups receive those roles within a scope.
Ledger Roles
Browse built-in and custom Ledger roles, then select one to inspect permissions, usage, and editing posture.
Role Detail
Operator-friendly view of identity, permissions, security sensitivity, and current usage.
Role Editor
Create, duplicate, or adjust custom roles. Built-in Ledger roles remain protected and duplicate-first.
Role Usage
Current assignment usage for the selected role in the loaded tenant scope, including direct vs group bindings and impacted scopes.
Access Assignments
Ledger Access Control
Access Assignments
Map principals to Ledger roles within an identity source and scope. Group assignments stay primary; direct users remain exception-based and legacy visibility stays preserved during the transition.
Role Catalog
Pick a role to inspect its real permission set and prefill the assignment form with the current scope context.
Assignment Builder
Save a user or group binding in the selected tenant and scope. Scope selections above prefill this builder but can still be adjusted before save.
Group Assignments
Real group-to-role mappings for the selected identity source and exact scope. Membership counts only appear when they can be resolved from the current tenant group load.
Loading group assignments…
Direct User Assignments
Exception-based user bindings that complement group-driven access. Identity details stay visible; expiry is omitted until the model carries real expiration data.
Loading direct assignments…
Effective Access Summary
Resolved effective access for the selected scope using direct assignments plus currently loaded group membership. Inherited global and platform rules are included where they really apply.
Loading effective access…
Legacy Direct Access Entries
Transition-safe visibility for the previous explicit user permission model. These entries remain preserved while RBAC assignments phase in.
Legacy entries stay visible so the transition remains backward-safe. Map stable cases into roles first; keep direct legacy edits for exceptions only.
Loading access control users...
Access Control App Registrations
Ledger Authentication Wiring
Access Control App Registrations
Inspect and manage the Ledger authentication app registration model, tenant service-principal wiring, app-assigned group readiness, and access-control validation health without mixing in customer reader registrations.
Access-control registrations only. Access-control app registrations are used for Ledger authentication, service principal identity wiring, and app-assigned group resolution. Customer reader applications for cost/data ingestion are managed separately.
Configured Registrations
Current Ledger authentication and access-control registrations by tenant. This list stays separate from customer data-reader onboarding registrations.
Loading access-control app registrations…
Readiness Summary
Selected registration validation checks for service-principal reachability, credentials, group readiness, and tenant binding health.
Select a registration to inspect readiness.
Registration Details
Operator-facing source of truth for which Ledger auth app is configured, which service principal is connected, and whether the registration is ready for app-assigned group based access control.
Select a registration to inspect details.
Add / Edit Registration
Configure a dedicated access-control registration reference for Ledger authentication and service-principal wiring. Secret material is never shown here.
Catalog
Catalog Workspace
Select a section on the left. Content loads here on the right.
Service Catalog
Existing Catalog Services
Review, edit, or remove reusable services that are available for assignment and platform automation.
Loading catalog...
Accounts Section
Existing Accounts
Review account profile defaults, environments, and counts. Use row actions to view or edit an account.
Loading...
Controlled July Network Successor
Load the proven failed predecessor, retained derived 10-source inventory, and duplicate/lease fencing before starting one linked successor.
Choose Load proven state to inspect the controlled recovery boundary.
Network V2 raw recovery
Start the single authenticated July raw-blob recovery path into immutable network-hourly-edge.v1 evidence.
Choose Load recovery boundary to inspect the approved inventory and writer fences.
Legacy July writer reconciliation
Prove the exact stale writer is fenced before any Engine 2 certification run.
Choose Load stale writer authority to inspect the exact operation and generation.
VNet/Subnet Ownership
Automatic inventory of VNets and subnets with customer resolution for ownership and shared-platform routing.
Tenant
Subscription
Customer
Role
Status
Tagged
Search RG/VNet/Subnet
Loading network inventory...
Subscription Ownership
Source of truth for subscription ownership, role, customer, environment, classification, and tag compliance.
Tenant
Subscription
Customer
Role
Classification
Tagged
Search
Loading subscription inventory...
Azure Account Governance
Subscriptions
Manage stored Azure subscription inventory, ownership mapping, business metadata, and contract controls in one admin surface.
Subscription Inventory
Rows are enriched with subscription settings and preserved customer ownership mapping.
Loading subscriptions...
Details & Settings
Business, commercial, ownership, and optimization contract fields.
Select a subscription to view or edit settings.
Commitment Inventory
Reservations
Maintain current Azure reservations from reservedInstances.csv, link them to subscriptions and customers, and track pricing enrichment status.
Reservation Inventory
CSV imports upsert by Reservation Id and enrich prices from Azure Retail Prices when SKU, region, and term match.
Loading reservations...
Details & Pricing
Link records to a subscription/customer and use manual pricing only when Azure Retail Prices is unavailable.
Select a reservation to view or edit it, or choose Add to create one.
Resource Group Ownership
Grouped source-of-truth view by resource group with expandable linked resources, ownership fields, and tag compliance.
Tenant
Subscription
Customer
Role
Classification
Tagged
Search
Loading resource inventory...

Demo Access

Manage one-time-visible access codes and the validated, immutable demo dataset.

Create access code

Issued access codes

Loading access codes…

Prepared demo dataset

Loading dataset metadata…

Audit history

Loading audit history…
Audit Log
Audit Log
Review admin actions, configuration changes, and maintenance events in a cleaner activity timeline.
From
To
Tenant
Actor
Action
Result
Loading...
Click Refresh to load entries.