Answers to what we are asked most about FinOps Pilot: what it does, what permissions it needs, where your data lives and how it is purchased. If what you are looking for is not here, write to us at support@xenix.es.
13 frequently asked questions
- What does FinOps Pilot do?
- What do I need to get started?
- What permissions do you ask for on my Azure?
- Where is my data stored, and what exactly do you keep?
- How often is cost data refreshed?
- Why don't the totals match my invoice?
- Can I manage several Azure tenants?
- What happens if I exceed my plan's spend limit?
- How is it billed, and who bills me?
- Can I try it before paying?
- How do I cancel, and what happens to my data?
- How do I revoke your access to my Azure?
- What support do I get?
1. What does FinOps Pilot do?
It reads your Azure cost and turns it into decisions. It answers the four questions of a cost review: what did we spend, what changed, what will the month close at and what do we do about it.
It breaks spend down by subscription, service, resource group and resource, calculates month-on-month variance and an end-of-month projection, detects anomalies automatically, and lets you allocate cost by client or business unit. The FinOps action plan keeps each initiative with an owner, a target and a date.
2. What do I need to get started?
Two clicks in your own Azure portal, and nothing to install:
- An admin consent, which creates the FinOps Pilot identity inside your own Entra ID directory.
- An ARM template that delegates read-only access through Azure Lighthouse. It is deployed once per subscription: you pick which one in the portal itself, and repeat the step for each one you want to include.
There is no agent to install, no infrastructure of yours to maintain and no setup call.
If you have many subscriptions, there is a second template that delegates an entire management group in one go, including subscriptions you create later. Both are in the π Access panel of your environment.
The management-group template asks for more permissions than the per-subscription one: you must be Owner of the management group. If you are not, the per-subscription template gets you just as far β you simply repeat it once per subscription.
3. What permissions do you ask for on my Azure?
Two roles, both read-only:
- Cost Management Reader β to read cost and billing data.
- Reader β to read resource metadata, so cost can be named and grouped.
FinOps Pilot cannot create, modify or delete any resource: that is not a limitation of our code, it is what the delegated roles allow. And no credential is shared: the delegation is Azure Lighthouse, so there is no secret to hand over, rotate or safeguard.
4. Where is my data stored, and what exactly do you keep?
We store cost aggregates: amount per day, per subscription, service, resource group and resource, plus your environment and user records. Nothing from inside your resources β no application data, no database contents, no machine contents.
That information is processed and stored in a XENIX Solutions Azure subscription, in Azure SQL Database, within the European Union. In other words: your cost data does pass through our platform β that is what makes it possible to keep our own history instead of querying Azure on every screen β but it never leaves Microsoft Azure.
5. How often is cost data refreshed?
Ingestion runs every 6 hours. It is not real time, and that is a deliberate decision: Azure Cost Management limits how many queries it accepts per hour against a given scope, and querying it on every screen load would make the application fail precisely when most people are using it.
In exchange, every screen is served from stored history and responds instantly. Bear in mind too that Azure takes time to consolidate the current day's cost: today's and yesterday's figures are refined over the following hours, in Cost Management and here alike.
6. Why don't the totals match my invoice?
Almost always one of these two, and neither is a fault:
The charge type filter. "Azure usage only" excludes Marketplace purchases and SaaS; "All" includes them. Comparing "Azure usage only" against an invoice total will never reconcile.
The scope. If the environment is configured against a billing account, you see everything invoiced, including charges that belong to no subscription β centrally purchased reservations, support plans, account-level Marketplace purchases. If it is configured against delegated subscriptions, those charges do not appear.
The application states which scope it is using underneath the title. If the totals still do not reconcile after checking both, get in touch.
7. Can I manage several Azure tenants?
Yes, with a Pro plan. They are built for partners and for groups that answer for the cost of more than one organisation: every tenant appears in the same console, isolated at the data layer, each with its own users, environments and allocation rules.
Standard plans cover the subscriptions of a single tenant, yours. If you try to add a second environment on a Standard plan, the application will tell you, and you can change plan from your own subscription in the Azure portal.
8. What happens if I exceed my plan's spend limit?
Your service is not cut off. Taking your cost visibility away because your cloud grew would be the opposite of what you need at that moment.
Spend is measured as the average of the last three closed months, so that a one-off spike β a migration, a month of testing β does not change your plan. If you stay above the limit, we will get in touch to move you to the tier that fits.
9. How is it billed, and who bills me?
FinOps Pilot is purchased through Microsoft Marketplace, from your own Azure portal. Microsoft does the billing, and the charge appears on your Azure invoice alongside the rest of your consumption β no new vendor to onboard, no separate contract to negotiate.
If your organisation has an Azure consumption commitment (MACC), the purchase may count towards that commitment.
10. Can I try it before paying?
Some plans include a free trial, and its length also depends on the plan. The offer listing states, before you confirm the purchase, whether the plan you chose has a trial and for how many days.
When it ends, the subscription automatically converts to a paid one unless you cancel first or turn off auto-renewal, exactly like any other Marketplace offer.
11. How do I cancel, and what happens to my data?
You cancel from the SaaS resource in your own Azure portal, without calling us and with no minimum term. We are notified automatically and the environment stops being processed.
On cancellation we stop ingesting new data. If you want us to delete what we already hold, write to support@xenix.es and we will.
12. How do I revoke your access to my Azure?
From your own portal, without going through us and at any time: Service providers in Azure Lighthouse, and remove the delegation. That is the point of the architecture β you grant the access and you remove it.
From that moment we cannot read anything from your environment. Data already ingested remains on the platform until you ask us to delete it.
13. What support do I get?
Email support at support@xenix.es, in English and Spanish.
So the first reply is not a request for information, please include: the environment identifier, the approximate time with its time zone, the literal error message β not a summary β and which charge filter and period you had selected.