Skip to content

Architecture and data flow fabric

CloudMonitor runs on Microsoft Fabric. By default we deploy CloudMonitor into a Fabric workspace on capacity you own, in your own Microsoft Fabric tenant. CloudMonitor-hosted stays available if you would rather we ran that capacity. In both arrangements, Azure Cost Management writes your raw FOCUS export to a storage account you own, and CloudMonitor reads those source files with scoped, least-privilege access.

At onboarding you choose whose Fabric capacity your reports run on. The default is yours: we deploy the modeled cost tables, the semantic model and the CloudMonitor app into a Fabric workspace in your own tenant, and your people open them with the accounts they already sign in with. Choose CloudMonitor-hosted and we run that workspace on our own capacity, with your people invited into our tenant as guests. Ingest and cleansing run in CloudMonitor’s tenancy in both arrangements.

We create a lakehouse in the workspace you nominate to hold your finished cost tables, deploy the semantic model on top of them, and publish the CloudMonitor app there. Your data team can write their own reports against that same model, in a workspace they already reach.

You supply the Fabric capacity, switch on three developer settings in your Fabric tenant, and grant the CloudMonitor application admin access to that one workspace. Configure Fabric Access covers what your Fabric administrator does.

Your own capacity’s region is yours to set and does not have to match the region your cost processing runs in. We recommend matching them, so the modeled cost tables are not written across regions.

How your Azure cost data reaches a CloudMonitor workspace in your own tenant Your Azure Cost Management writes a scheduled FOCUS export into a storage account in a resource group you own, inside your own Azure tenancy. CloudMonitor's shared processing engine, in our tenancy and in the Azure and Microsoft Fabric region you choose during onboarding, reads that export through a OneLake shortcut and cleanses it, holding the raw and cleansed data in a workspace we operate. It then writes the finished, modeled cost tables across the tenancy boundary into a Microsoft Fabric workspace on your own capacity. That workspace holds the modeled data, the semantic model, the CloudMonitor app and Ask Finn, so your people sign in with their own accounts in your own tenant rather than as guests in ours. CloudMonitor keeps a scoped admin role on that one workspace to deploy the solution, update it, support it, and check your license. YOUR AZURE TENANCY Azure Cost Management scheduled FOCUS export CLOUDMONITOR RESOURCE GROUP Storage account ADLS Gen2 · exports landing zone raw FOCUS export remains here Scoped service principal least-privilege roles OneLake shortcut least-privilege access OUR AZURE TENANCY CloudMonitor · in the region you choose Shared processing engine pipelines & notebooks · holds no cost data YOUR DATA, IN A WORKSPACE WE RUN Raw as exported Cleansed typed & deduplicated cleansing and enrichment run here modeled cost tables written into your lakehouse deploy · update · support · license YOUR AZURE TENANCY Your Fabric workspace · your capacity Modeled cost data Delta tables in your OneLake your data lives here Semantic model Direct Lake your team can build on it too CloudMonitor app reports, governance & settings your people sign in here Workspace access CloudMonitor app as Admin on this one workspace Ask Finn · role-gated agent licensed organization admins · verified support · Support mode your people sign in with their own accounts — no guest access to our tenant YOUR PEOPLE IT / FinOps team monitor & optimize Business unit owners cost accountability Licensed org admins Ask Finn investigations
In your own Fabric tenant. Azure Cost Management writes the raw FOCUS export to your storage account. CloudMonitor reads it through a OneLake shortcut and cleanses it in our tenancy, then writes the modeled cost tables into a Fabric workspace on your own capacity — where the semantic model, the CloudMonitor app and Ask Finn run, and your people sign in with their own accounts.

The same lakehouse, semantic model and CloudMonitor app go into a workspace we run on Fabric capacity in our own tenancy. Your people reach the reports we publish to them there.

We size and pay for that capacity, and what it costs is inside your license price. Each of your users is invited into our tenant as a B2B guest, and the workspace permissions that govern sharing sit with us.

Your side of the setup is the Azure cost export and the least-privilege roles that let CloudMonitor read it, the same as in your own Fabric tenant.

How your Azure cost data reaches CloudMonitor Your Azure Cost Management writes a scheduled FOCUS export into a storage account in a resource group you own, inside your own Azure tenancy. CloudMonitor's managed SaaS on Microsoft Fabric processes that cost data in our tenancy, in the Azure and Microsoft Fabric region you choose during onboarding, using scoped, least-privilege access, then serves the CloudMonitor apps and Ask Finn. The apps use the governed cost model for role-based reports. Ask Finn uses organization-wide governed cost data and is limited to active, licensed organization administrators and verified support staff using Support mode. YOUR AZURE TENANCY Azure Cost Management scheduled FOCUS export CLOUDMONITOR RESOURCE GROUP Storage account ADLS Gen2 · hierarchical namespace exports landing zone raw FOCUS export remains here Scoped service principal least-privilege roles Scoped connection least-privilege access OUR AZURE TENANCY CloudMonitor · in the region you choose Microsoft Fabric dedicated customer environment processes your cost data CloudMonitor apps reports, governance & recommendations Ask Finn · role-gated agent licensed organization admins verified support · Support mode YOUR PEOPLE IT / FinOps team monitor & optimize Business unit owners cost accountability Licensed org admins Ask Finn investigations
CloudMonitor-hosted. Azure Cost Management writes the raw FOCUS export to your storage account. CloudMonitor processes the cost data in our Microsoft Fabric tenancy using scoped, least-privilege access. The CloudMonitor apps and Ask Finn read the same governed cost model, each through its own role gate.

The flow has three parts: your tenancy produces the data, our Fabric engine reads and transforms it, and your people consume the reports. Steps 1 to 3 are the same in both arrangements; step 4 is where they differ.

  1. Azure Cost Management writes a scheduled export. You set up one Azure Cost Management export that writes your cost and usage data — in the open FOCUS 1.2-preview format, as Parquet — into a storage account in your tenancy.
  2. The export lands in a storage account you own. It sits in a dedicated resource group, in an ADLS Gen2 storage account with hierarchical namespace enabled. This account exists solely to receive the exports.
  3. CloudMonitor connects to the export through a OneLake shortcut. Our Fabric pipeline uses a Microsoft Fabric OneLake shortcut as the source connection to your storage account.
  4. Fabric transforms the source files, and the modeled data comes to rest. Our pipelines clean and enrich the export into your modeled cost tables, in CloudMonitor’s own Fabric tenancy. In your own Fabric tenant, we write those tables into a lakehouse in your workspace and deploy the semantic model and the CloudMonitor app there on top of them. Under CloudMonitor-hosted, they stay in the workspace we run for you inside our tenancy.
  5. Your people consume the reports. Your IT and FinOps team, business unit owners, and executives get the views they each need — from day-to-day optimization to board-level spend visibility.

Azure Cost Management writes your raw FOCUS export to a storage account you own, and it stays there. CloudMonitor reads it through a OneLake shortcut and does the ingest, cleansing and modeling in our own Fabric tenancy, in the Azure and Microsoft Fabric region you choose during onboarding. That much is the same in both arrangements. Where the finished data comes to rest is what your choice settles: in your own Fabric tenant we write the modeled cost tables into a lakehouse in your workspace, on your capacity, and deploy the semantic model and the CloudMonitor app there on top of them. Under CloudMonitor-hosted, those stay in the workspace we run for you inside our tenancy.

CloudMonitor’s ingest, cleansing and modeling run in the Azure and Microsoft Fabric region you choose during onboarding, in a dedicated environment we deploy for you there rather than in a single home region of ours. That holds in both arrangements, so choosing CloudMonitor-hosted does not move your cost processing to another region. Our shared management plane is separate and runs in Australia East.

The CloudMonitor app is a Microsoft Fabric App item, and Fabric Apps are still in preview and not offered in every region. We confirm which regions are available with you at onboarding.

Your license price is set by your annual Azure Consumption Revenue. In your own Fabric tenant, the capacity your reports, semantic model and CloudMonitor app run on sits on your own Fabric bill. Under CloudMonitor-hosted we run that capacity for you. CloudMonitor’s ingest, cleansing and modeling run on Fabric capacity in our own tenancy in both arrangements.

You can revoke our access at any time by removing the role assignments.

CloudMonitor connects through a multi-tenant service principal you authorize. Most access is read-only. The one management-role exception is limited to the dedicated cost-export storage account:

  • Reader on the subscriptions or management groups you choose, so it can see service metadata and costs — but not change resources or read the data inside your services.
  • Read-only billing access (or a cost-data role at the subscription scope) so it can read your cost and usage records.
  • Storage Account Contributor on the one export storage account only — Azure requires this so the scheduled export can write your cost files there. It gives no access to your other resources.

The full step-by-step is in the access guide.

Live chat didn’t load

This browser blocked our chat widget, so the support button can’t open. A privacy shield or content blocker is the usual cause.

  1. Click the Brave Shields icon (the lion) beside the address bar.
  2. Turn Shields off for cloudmonitor.ai.
  3. Reload this page. The chat icon returns bottom right.
  1. Open your content blocker or privacy extension.
  2. Allow cloudmonitor.ai.
  3. Reload this page. The chat icon returns bottom right.

Rather leave the blocker on? Send us a message or search the help desk.