---
title: Security and data isolation
canonical: "https://cloudmonitor.ai/docs/reference/security-and-data-isolation/"
description: "Where your cost data lives, how it is kept separate from other customers, and what CloudMonitor can and cannot see."
---

The short version: **your data lives in a dedicated workspace of its own and is never mixed with
another customer's.**

This page is the non-technical explanation. If your security team wants the architecture, ask us —
there's a deeper document written for exactly that conversation.

## Your own workspace

CloudMonitor is built on **Microsoft Fabric**, Microsoft's enterprise data platform. Inside it, every
customer gets a separate, dedicated workspace.

The analogy that fits: a building where each tenant has their own locked suite. Same trusted
building, entirely separate spaces. Your cost data sits in your suite. Another customer's sits in
theirs. There is no shared table that both of you read from with a filter in between — the separation
is structural rather than a rule applied at query time.

## What CloudMonitor reads

CloudMonitor reads the standard cost and usage data your cloud provider already produces — the same
exports you can generate yourself from the Azure portal. Cost records, pricing, reservations.

**There is no personal data in it.** These datasets contain resource identifiers, meters, quantities,
prices, dates and your own resource tags. Not names, not email addresses.

The one thing that is personal is the list of people you invite to CloudMonitor, which exists so they
can sign in and so an audit trail can record who changed what.

## If you connect Microsoft 365

That's a separate, explicit decision, and it's opt-in.

Connecting it requires a Global Administrator to approve a consent screen at Microsoft, and the
permissions granted are **read-only**. CloudMonitor never writes to your Microsoft 365 tenant and
never stores a credential for it. The consent dialog lists every permission and why it's needed
before you approve anything — it's worth reading rather than clicking past.

See [how to connect Microsoft 365](/docs/how-to/how-to-connect-microsoft-365/).

## Who can see what, inside your organization

Two layers, both yours to control:

- **Signing in** is controlled by your own Microsoft identity. CloudMonitor doesn't hold passwords.
- **Seeing costs** is controlled by cost group membership. Someone added to CloudMonitor sees only
  the cost groups they belong to, plus the catch-all Unallocated group.

Admins in your organization see everything. See
[Roles and access](/docs/reference/roles-and-permissions/) for the full matrix.

When someone leaves, archive them rather than deleting them: it removes every access immediately
while keeping the audit trail of what they did intact.

## The audit trail

Budget changes, membership changes, triage decisions and comments are recorded against the cost group
they affect, with who and when. It's on the **Audit trail** tab of any cost group.

This is the reason archiving beats deleting, and the reason dismissing an anomaly asks for a reason
rather than accepting a shrug.

## Questions worth asking us

We'd rather answer these than have you assume:

- Where is our data physically stored?
- Who at CloudMonitor can access it, and under what circumstances?
- What happens to it if we stop being a customer?
- Do you hold current certifications?

**Help & support** in the app reaches the team, and
[status.cloudmonitor.ai](https://status.cloudmonitor.ai/) publishes service health independently of
the product.
