Organised by what you see, not by how it works underneath: look for your symptom. If it is not here, write to us at support@xenix.es.
9 common situations
- I can't sign in, or I sign in and see nothing
- Problems authorising the application
- The numbers don't add up
- Understanding the ingestion panel
- "Azure Cost Management is saturated"
- Subscriptions or breakdowns are missing
- Users and permissions
- Things that look like bugs and aren't
- When to contact us, and with what
I can't sign in, or I sign in and see nothing
"Nothing to show yet"
You signed in correctly, but your account has no environment assigned. It is not a password problem, nor an Azure permissions problem.
- If you have just purchased: onboarding is not finished. Use the link you received on purchase, or open your SaaS resource in the Azure portal and click "Open SaaS Account on publisher's site".
- If someone in your organisation gave you access: ask them to assign you at least one environment from Manage users. It is the step most often forgotten.
They added me and I still see nothing
The user exists but was saved with no environments ticked. Whoever administers must edit you and tick at least one. In the user list, anyone in that state shows ⚠ no environments.
An environment is greyed out with "· not delegated"
The environment exists, but access to cost data has not been granted yet. Without it there is nothing to query. In Manage tenants, the 🔗 Access button on that row has the link and the instructions; once done, ⟳ Check reports how many subscriptions are visible.
Problems authorising the application
"Need admin approval"
Your account is a guest in that directory. Azure does not allow a guest user to authorise applications on behalf of the organisation, even with the global administrator role. Microsoft's message does not explain this, which is why it looks like a permissions problem when it is not.
It must be done by an administrator with a native account in that directory, not a guest. Global Administrator is not required: Cloud Application Administrator or Application Administrator is enough, and both are far narrower and easier to ask for.
I look for "XENIX FinOps Pilot API" to grant permissions and it isn't there
The application does not exist in that directory yet: the authorisation step is what creates it. Complete step 1 of the 🔗 Access panel first, then go back to Cost Management → Access control.
"AADSTS650052"
An application is being authorised that depends on another one not yet present in the directory. Use the link in the 🔗 Access panel, which authorises the right one, and discard any older link you had saved.
"Invalid or already used link"
The onboarding link is single-use and is consumed on completion. It is not an error: your onboarding finished correctly. Go straight into the application.
The numbers don't add up
Before assuming something is broken, check these three things in this order. Most discrepancies are explained by one of them.
1. Are you comparing the same filter?
The Charge type dropdown changes the result entirely:
| Filter | What it includes |
|---|---|
| Azure usage only | Azure service consumption. Does not include Marketplace purchases or SaaS |
| All (incl. purchases and SaaS) | Everything that appears on the invoice |
| Without Marketplace purchases | Consumption plus adjustments and credits |
| Marketplace only | Marketplace purchases only |
Comparing "Azure usage only" against an invoice total will never reconcile, and that is not an error.
2. Is it the same scope?
What is queried depends on how the environment is configured, and it is stated underneath the title:
- Billing account — everything billed to the account, across all its profiles. This is the one that reconciles with the invoice.
- Billing profile — that profile only. Useful when each profile is a different company in the group; you will see less than the account holds, by design.
- Delegated subscriptions — only those delegated. Does not include charges that belong to no subscription: centrally purchased reservations, support plans and account-level Marketplace purchases.
3. Has ingestion finished?
Data is stored; it is not queried from Azure on every screen. If you have just changed something or granted access, it may not be there yet. Check it in Manage tenants → 🕑 Ingestions.
Understanding the ingestion panel
Manage tenants → 🕑 Ingestions shows the most recent runs:
| Status | What it means | What to do |
|---|---|---|
| ✓ completed | Everything up to date | Nothing |
| ⚠ partial · N with no data | N breakdowns came back empty because of Azure's rate limits | Press ⟳ Refresh again; each pass leaves fewer gaps |
| running | In progress | Wait. You can keep using the application |
| ⚠ failed | It could not start | Read the message; if it persists, contact support |
Hover over partial to see which breakdowns are missing.
How long it takes. The first time, tens of minutes: Azure limits how many cost queries it accepts per hour, and ingestion waits on purpose between them. Later runs take minutes, because only the current and previous month are requested.
⟳ Refresh versus 🗑 Delete and rebuild
- ⟳ Refresh — keeps the history and requests only what is missing. This is what you want almost always.
- 🗑 Delete and rebuild — deletes everything stored and starts over. Only if you suspect the history is wrong. It leaves the panel empty while it rebuilds.
"Azure Cost Management is saturated"
Azure limits how many cost queries it accepts per hour, and the limit is especially tight when querying a whole billing account. The message includes the time at which you can retry.
It is not a fault of the product nor of your permissions.
- Wait the time indicated. Retrying in a loop makes it worse: every attempt consumes quota.
- If an ingestion is running, this is normal — it is using the same quota. Wait for it to finish.
- Close any tabs you are not using: every open screen queries too.
Subscriptions or breakdowns are missing
I see fewer subscriptions than I have
Almost always, the per-subscription breakdown for that charge filter has not been ingested yet.
- Try Charge type → All. If they all appear there, it is an ingestion matter.
- 🕑 Ingestions: if the last run came back partial, press ⟳ Refresh.
- If subscriptions are still missing with Lighthouse, they may not all have been delegated: delegation is per subscription. With many of them, the 🔗 Access panel offers a link that delegates a whole management group at once. That route requires you to be Owner of the management group; if you are not, stay with the per-subscription template.
Resource groups won't load
Same case: that particular breakdown has no data yet. 🕑 Ingestions confirms it.
A panel says "Only data since…"
That is correct and deliberate. Breakdowns are not all ingested at once — ingestion rotates them so as not to hit Azure's limits — so one can hold less history than the rest of the screen. What exists is served and labelled, instead of showing nothing.
The "Daily" chart has no detail for older months
Also expected. Older history is ingested at monthly resolution — the only way to bring it in without hitting the limits — and daily detail is kept for the last two months, which is where it is used. Older months are gradually filled in by later cycles.
Users and permissions
I can't add a colleague
You need the owner role. If you made the purchase, you have it; if someone else gave you access, ask them to raise your role or to add the user themselves.
It won't let me save a user without ticking environments
That is on purpose: a user with no environments signs in and sees nothing. If the environment does not exist yet, create it first in Manage tenants.
I can't see a user I know exists
As an owner you only see people who share one of your environments, and never XENIX staff. If the user has no environment assigned, they do not appear: add them again with the same email and tick an environment.
Things that look like bugs and aren't
| What you see | Why |
|---|---|
| €0 in a newly added environment | It may be correct: that subscription has no spend. Check in 🕑 Ingestions that ingestion finished |
| The browser says "Not secure" | Browser cache from an earlier visit. Open it in a private window; if the padlock is there, it is local |
| A button that isn't there | Old version cached. Reload with Ctrl+Shift+R |
| Amounts go up when you widen the scope | Correct: you are seeing more. If they go down, let us know |
| "Refresh data" changes nothing | That button refreshes the screen, it does not fetch new data from Azure. For that, use ⟳ Refresh in Manage tenants |
| After authorising, the screen says "Authorisation granted" and nothing else | Correct. That authorisation only grants identity; access to cost data is the next step |
When to contact us, and with what
Write to support@xenix.es if:
- The total goes down when you widen the scope.
- 🕑 Ingestions comes back partial with the same number of gaps three times in a row.
- A message mentions an internal error code.
- The amounts do not reconcile after ruling out the three points in "The numbers don't add up".
Always include, or the first reply will be a request for it:
- The environment identifier (the Id column in Manage tenants).
- The approximate time, with its time zone.
- A screenshot of 🕑 Ingestions.
- The literal error message, not a summary.
- Which charge filter and period you had selected.