Documentation

Scanning & findings

How scans run, how to work through what they find, and why nothing is ever changed on your behalf.

Running a scan

Press Run scan now on the dashboard card or in the tenant header. Editors and Admins can do this; Readers cannot. Three conditions apply:

  • The connection must be verified.
  • Your trial or plan must be active — when it lapses, scanning pauses while everything already scanned stays readable.
  • If a scan is already queued or running, pressing again joins the existing one rather than starting a second.

Scans run on our side, not in your tenant. Nothing is installed, and nothing runs on your machines.

Scheduling

Under Settings → Schedule on a tenant you set two independent cadences:

  • Deep scan — off, daily, weekly or monthly, at the day and hour you choose (UTC). This is the full analysis that produces findings and a report.
  • Cost refresh — daily, weekly or off. A light pass that updates spend figures only. Useful if you watch cost closely but do not need a fresh findings run every day.

You can also trigger a cost-only refresh by hand with ↻ Refresh cost on the Cost tab. It queues for the background worker rather than running instantly.

What is in scope

Scope follows your Reader assignment: TenantThrift scans exactly the subscriptions the role was granted on, and nothing else. Settings → Scan scope lists what it can currently see, with resource counts.

To widen or narrow it, change the role assignment in Azure and press re-verify on the same panel. The subscription list is rebuilt from what it can actually reach — there is no separate place where scope could drift out of sync with Azure.

Working through findings

The Findings tab lists everything the latest scan found. Search by name and filter by subscription, resource group, category or severity; page through 25, 50 or 100 at a time.

Each row opens a drawer with the reasoning, the estimated monthly saving, and the concrete way to act on it — often more than one, for example Azure's native auto-shutdown as an alternative to resizing.

Fix commands are hidden until you ask

Commands, deploy buttons and runbook links stay hidden behind a one-time Show fix commands click. That is deliberate: it marks the moment you take responsibility for running something in your own tenant. Once clicked, it stays revealed for your account.

TenantThrift never executes any of it. Its Azure access is Reader — it could not act even if it wanted to. Every command is yours to review and run.

Ignoring what you have decided to keep

Some waste is intentional: a warm standby, a licence-bound VM size, a deliberately idle disaster-recovery region. Press Ignore and give a reason — the reason is required, and it is the point. Six months later, the note explains itself.

Ignored findings drop out of the headline savings number and are hidden by default; use the show ignored toggle to review them, and Restore to bring one back. Ignores survive across scans and are recorded in the activity log with the reason attached. Editors and Admins can do this.

Reading the numbers

  • Savings potential — the sum of open, non-ignored findings, per month.
  • New since last scan — what appeared since the previous run. This is the number worth watching once the initial cleanup is done.
  • Eliminated since first scan — waste that has disappeared, accumulated over time. Your evidence that the effort paid off.
  • Pricing coverage — what share of findings was priced from actual billed cost rather than list-price estimates. Higher means the savings figure is better grounded.

Getting findings out

Every scan can be exported as CSV from the Findings tab or the scan history, and as a PDF report from the tenant header. Neither is role-restricted — any member, including Readers, can download them. See Reports & alerts.