Every source is tied to the tenant composition it feeds, its evidence basis and its honest fallback.
Data sources
Where every number on these workspaces comes from, when it was last refreshed, whether it is measured or an estimate, and what stands in its place when it is absent.
2 of the 2 measured money feeds are not connected, so the dollars they would have measured are shown as a labelled estimate everywhere they appear — the figure is never missing, the word on it changes. counted
Every source, and what stands in its place when it is absent
The last column is the one to read if you are deciding whether to trust this product: it says what happens to each number when its source is not there.
No filter applied Showing every source these workspaces read.Change
No filter applied Showing every source these workspaces read.
Scroll sideways for the remaining columns.
| Source | What it feeds | Role & basis | Its own freshness | Consent, and what stands there without it |
|---|---|---|---|---|
| Microsoft Graph — Copilot usage reports
Microsoft 365
src/store.ts · getSponsorStats |
How many seats show qualifying Copilot activity, how many do not, and the activation percentage every workspace leads with.
Fields: stats, activationPct, idleSpendMo |
read counted
Answering |
reading updated |
Reports.Read.All
If absent: The reading carries `usagePending`, and every activation figure says the count is unread rather than showing a zero. A zero here would be indistinguishable from an organisation nobody is using Copilot in.
Turns on: An administrator grants Reports.Read.All in Entra. |
| Microsoft Graph — licence truth
Microsoft 365
src/graph/licensing.ts · getLicenseTruth |
Seats bought versus seats assigned, per SKU, and the seats already inside a renewal grace window. The denominator under every cost-per-seat figure in the product.
Fields: license, licenseEconomics |
read counted
Answering |
counted at |
Organization.Read.All
If absent: The read returns null and the licence figures are withheld entirely — they are never inferred from usage, because a seat nobody used is not the same object as a seat nobody bought.
Turns on: An administrator grants Organization.Read.All in Entra. |
| Microsoft Graph — directory departments
Microsoft 365
src/repos/dept.ts · getDeptDist |
Which department each person belongs to, so the programme can be reported by team. Aggregate only — no per-person row is ever built from it.
Fields: depts, deptRows |
read counted
Answering |
— no stamp of its own |
User.Read.All
If absent: Every department view says so and falls back to the organisation total. No department is invented and no person is placed in one by guesswork.
Turns on: An administrator grants User.Read.All in Entra. |
| Microsoft Graph — seat map and department utilisation
Microsoft 365
src/repos/dept.ts · getSeatmap / getDeptUtil |
Which teams hold the seats and which of those seats are working — the whole Users & teams workspace and the department table on the money pages.
Fields: seatRows, seatSlices, seatRowsWithheld, deptUtil, sliceLabels |
read counted
Answering |
crawled at |
User.Read.All and Organization.Read.All
If absent: The team tables are withheld. Where they are present, any team below the disclosure floor of five people is folded into a withheld count that is DISCLOSED rather than dropped silently.
Turns on: Both permissions granted in Entra. The crawl then runs on a schedule and is cached for thirty days. |
| Microsoft 365 Message Center and the public roadmap feed
Microsoft 365
src/radar/msgcenter.ts · getTenantRadar / src/radar/roadmap.ts · getRadar |
The Copilot rollout radar. Two feeds join one table and every row is stamped with which of the two it came from.
Fields: radar |
read counted
Answering |
feed updated |
ServiceMessage.Read.All for the tenant's own notices; nothing for the public feed
If absent: The radar shows the PUBLIC feed only, and labels every row public. A public roadmap item is never allowed to wear the tenant's own Message Center authority.
Turns on: An administrator grants ServiceMessage.Read.All. The public feed needs no consent and is always there. |
| Microsoft Graph — sign-in audit logs
Microsoft 365
src/graph/shadowai.ts · getShadowAiSignal |
How many people signed into a third-party AI application with a work identity — the unsanctioned-AI reading on Security & risk.
Fields: shadowAi |
read counted
Answering |
signal at |
AuditLog.Read.All and Directory.Read.All
If absent: The signal reads NOT MEASURED, never zero. A zero would be the most reassuring lie in the product: it is indistinguishable from a read nobody granted.
Turns on: An administrator grants both permissions in Entra. Neither is in the required set, so this is dark by default. |
| Microsoft Graph — agent registry (beta)
Microsoft 365
src/enterprise/agentinventory.ts · getAgentInventory |
The tenant's own catalogue of declarative agents on the AI agents workspace.
Fields: agentInventory |
read counted
Answering |
— no stamp of its own |
CopilotPackages.Read.All, plus the platform feature switch
If absent: The catalogue section states that the read is dark and names the consent. It never falls back to the curated demonstration catalogue for a real organisation.
Turns on: An administrator grants CopilotPackages.Read.All and the inventory read is enabled for the deployment. |
| Azure Cost Management — reconciled export
Microsoft Azure
src/repos/cmusage.ts · latestCmUsage |
The actual dollars for Cowork and credit consumption, per month, from the customer's own billing export. This is the source that upgrades the money pages from an envelope estimate to a measured figure.
Fields: cmUsage, creditPct, creditBasis, spendTrend |
read measured
Not connected |
— no stamp of its own |
A read-only blob SAS supplied by the customer, validated to be incapable of writing before it is stored
If absent: Every Cowork and credit dollar is shown as a labelled ESTIMATE envelope, with the estimate chip on it, in every place it appears. The number does not go missing; the word on it changes.
Turns on: Connect a read-only Cost Management export SAS on the Settings page. |
| Month-grained product and department history
Aristo
src/ux/demoseed.ts · demoProductMonths / demoDeptMonths — the sample organisation only |
Spend broken down by product month by month, and the seat position per team month by month. They are what the analytics stack is drawn from and what fills the department table's change and trend columns.
Fields: productTrend, deptTrend |
read estimate
Answering |
— no stamp of its own |
None — nothing is read from your tenant for these, because nothing yet produces them
If absent: The analytics page draws no stacked product trend and leaves the per-team change and trend columns out of the department table entirely, rather than drawing a flat line at zero. It states in words that a per-department monthly record is the one upstream change that fills both.
Turns on: Nothing turns this on today. It needs an upstream change: a month-grained record of the paid-SKU inventory, and a per-department seat record kept per refresh instead of overwritten. Until then the sample organisation carries a labelled-estimate series so the instruments can be seen working, and no real organisation is given one. |
| Copilot credits report
Microsoft 365 admin center
src/repos/policycredits.ts · latestPolicyCredits |
Credit consumption per billing policy — the run rates behind the spend lights and the credit share of the money trend.
Fields: spendLights, spendTrend |
read measured
Not connected |
— no stamp of its own |
None — an administrator exports the report and pastes it in
If absent: The spend lights fall back to the estimate envelope and say so on each light. No light is shown green on an estimate it cannot stand behind.
Turns on: Export the credits report from the Microsoft 365 admin center and paste it on the Settings page. |
| This organisation's own settings
Aristo
src/store.ts · getTenantConfig |
The seat cost every return figure is multiplied by, the monthly Cowork cap, and the enforcement mode beside it.
Fields: seatCost, coworkBudgetUsd, budgetEnforce |
read provided
Answering |
— no stamp of its own |
nothing external
If absent: The seat cost falls back to a labelled ASSUMPTION and carries that word wherever it is used. An assumed seat cost is never allowed to wear the measured chip.
Turns on: A leader sets them on the Settings page. Until a real seat cost is provided the product uses a labelled assumption and marks every figure derived from it. |
| Aristo's own run history
Aristo
src/repos/ffrun.ts · listFFRuns |
Every month-over-month comparison in the product: what changed, which direction, and the run number this reading belongs to. Since 2026-08-21 each run also records the seven chargeback quantities the KPI strips report — paid seats, idle seats, department rows, averageable departments, charged-back headcount, charged seats and the seat price they were costed at — so those cards can draw a movement instead of naming a missing figure. The sample-organisation flag is read here too, because a movement drawn from seeded fixtures says on the card that it is one.
Fields: history, prev, runNumber, demo |
read counted
Answering |
previous run |
nothing external
If absent: Comparisons are withheld and the pages say there is no prior run yet. A delta against nothing is not rendered as flat. A run recorded before a given figure began to be persisted says so specifically — it is a different fact from having no earlier run at all, and it is not reconstructed backwards.
Turns on: It fills itself. The first run has nothing to compare against and every comparison says "first run" rather than showing a change of zero. |
| Move plans and their completion
Aristo
src/repos/plans.ts · listPlans |
Which recommended moves this organisation has taken up, and how many have been completed.
Fields: plans |
read counted
Answering |
— no stamp of its own |
nothing external
If absent: The plans section is an empty state with a way to start, never a zero dressed as a result.
Turns on: A leader starts a move from a recommendation. Nothing is written by viewing one. |
| The forged-agent register
Aristo
src/repos/agentpkg.ts · countAgentPkgs / listAgentPkgs |
How many agents this organisation has built, who made each one, and the capability scope each maker attested to.
Fields: agentsBuilt |
read counted
Answering |
— no stamp of its own |
nothing external
If absent: An empty register renders as an empty state with the reason. A count of the PEOPLE who built them is floored at five and withheld below it.
Turns on: Somebody builds an agent. The register starts empty on purpose and says so. |
| The skill shelf
Aristo
src/repos/skillpkg.ts · skillShelfStats |
How many skills are published for this organisation and how many times they have been taken.
Fields: skillsOnShelf, skillDownloads |
read counted
Answering |
— no stamp of its own |
nothing external
If absent: The shelf renders as empty with a way to publish, never as a zero result.
Turns on: A skill is published to the shelf. |
| Business licence inventory
Microsoft 365
src/graph/licensing.ts · getAllLicenseInventory |
Every licence the organisation holds beyond Copilot, so the chargeback view can show what else is being paid for.
Fields: bli |
read counted
Answering |
— no stamp of its own |
Organization.Read.All
If absent: The inventory shows an em-dash and the exact permission that would fill it.
Turns on: Granted with the licence truth read. It is only called once that read has already proved consent, so an unconsented tenant never pays for a guaranteed refusal. |
| The tenant registry
Aristo
src/repos/tenant-registry.ts · getTenantRec |
The organisation's name, as it appears at the top of every page and on every report.
Fields: org |
read provided
Answering |
— no stamp of its own |
nothing external
If absent: Pages address "your organisation" rather than inventing a name.
Turns on: It is set when the organisation is registered. |
| The composition instant
Aristo
src/index.ts · composeFFView |
The "as of" stamp in the top bar and on every figure that has no fresher stamp of its own.
Fields: generatedAt |
read counted
Answering |
composed at |
nothing external
If absent: It is never absent — which is exactly why it must be read carefully. It records when ARISTO COMPOSED this view, not when any underlying system collected its data. The composition is cached for forty-five seconds, and the documents beneath it can be hours or days older. Where a source carries its own stamp, that stamp is what the row above shows.
Turns on: Every page load composes it. |
| The Frontier score engine
Aristo
src/enterprise/frontier.ts · buildFrontierScore |
The estate score and its band, computed from the pillars above it. Each pillar carries its own provenance — measured, or self-reported — and the score states what it was computed over.
Fields: frontier, trajectory |
computed
Answering |
— no stamp of its own |
Inherits the consent of whichever pillars are available
If absent: A pillar with no reading is DROPPED and the remaining weights are re-normalised over what is available. It is never scored zero — a zero would read as a failing grade for a permission nobody granted.
Turns on: It computes from whatever pillars can be read. Granting a missing read adds a pillar rather than changing one. |
| The readiness engine
Aristo
src/enterprise/readiness.ts · assessReadiness |
Who is credit-ready, the suggested capped funding, and the tier a leader is asked to act on.
Fields: readiness |
computed
Answering |
— no stamp of its own |
Inherits the usage and licence reads
If absent: The readiness tier is withheld rather than defaulted to the lowest one.
Turns on: It computes once the usage and cohort reads answer. |
| The strategy engine
Aristo
src/enterprise/strategy.ts · buildStrategy |
The narrative sentence at the top of the product and the ranked moves under it, each with the counted figure that justifies it.
Fields: moves, narrative |
computed
Answering |
— no stamp of its own |
Inherits every read the move it recommends is based on
If absent: No move is recommended, and the page says so rather than offering a generic suggestion.
Turns on: It computes from the readings above. A move with no counted figure behind it is not raised. |
| The licence economics engine
Aristo
src/licenseeconomics.ts · computeLicenseEconomics |
Idle seats, idle spend, and the cost-per-working-seat figure the chargeback pages are built on.
Fields: licenseEconomics |
computed
Answering |
— no stamp of its own |
Inherits the licence truth and usage reads
If absent: Every derived dollar is withheld. Where the seat cost underneath it is an assumption rather than a provided figure, the result carries `seatCostAssumed` and the assumption chip travels with it.
Turns on: It computes once licence truth answers. |
| The spend-light engine
Aristo
src/spendlights.ts · buildSpendLights / orgSpendNumerator |
The budget traffic lights, and the month-by-month spend trend under them. Each light carries the basis of the number it was computed from, and each month of the trend is drawn solid when measured and hatched when estimated.
Fields: spendLights, spendLightsWithheldK, spendTrend |
computed
Answering |
— no stamp of its own |
Inherits the export or the credits report; falls back to the estimate envelope
If absent: A light with no number it can stand behind is not shown green — it is shown as not ready, with the reason. Any cohort below the disclosure floor of five is withheld and the withheld count is disclosed.
Turns on: Connect the reconciled export for measured dollars. The lights work without it and say estimate. |
| The spend projection
Aristo
src/enterprise/forecast.ts · projectSpend |
Where this month's spend is heading, on the analytics workspace.
Fields: spendProjection |
projection
Answering |
— no stamp of its own |
Inherits the money feeds it extrapolates from
If absent: The projection is withheld and the page says how much history is still needed.
Turns on: It needs enough history. Below that it returns "needs more history" rather than a line through two points. |
| The score trajectory
Aristo
src/enterprise/frontier.ts · projectScoreTrajectory |
The "on pace to cross into the next band" sentence, where there is enough history to support one.
Fields: trajectory |
projection
Answering |
— no stamp of its own |
Inherits the score
If absent: The sentence is simply not written. It is withdrawn the moment the trend stops supporting it rather than being restated with a smaller number.
Turns on: Three runs and a band crossing within ninety days. Anything less returns nothing. |
| The live grant state
Microsoft Entra
src/setup.ts · diagnoseTenant |
Every permission table in the product: what this tenant has actually consented to, decoded from the roles claim in its own app token.
Read at the page that needs it, not through the composed view. |
read counted
Not checked here |
— no stamp of its own |
Admin consent in Entra
If absent: The whole table is withheld and the page says the state could not be decoded. It is never rendered as "nothing granted", which is what the underlying call returns on failure and is a different claim entirely.
Turns on: It reads whatever is granted. It is decoded per request and is never cached into a page. |
| The insight store
Aristo
src/repos/insightobj.ts · materialiseInsights |
The lifecycle of every finding this product has raised — its status, its owner, and every change made to it.
Read at the page that needs it, not through the composed view. |
read counted
Not checked here |
— no stamp of its own |
nothing external
If absent: Findings render without their lifecycle rather than disappearing.
Turns on: A finding raised by the engines is materialised the first time it is seen, idempotently. |
| The report registry and its schedules
Aristo
src/repos/reportreg.ts · listReportDocs / src/repos/reportsched.ts |
Every generated report and its frozen figures, plus the schedules that generate them. Each stored report carries its own per-figure freshness and a digest of the figures it froze.
Read at the page that needs it, not through the composed view. |
read counted
Not checked here |
— no stamp of its own |
nothing external
If absent: The library is an empty state with a way to generate the first one.
Turns on: Generate a report, or schedule one, on the Reports workspace. |
| The operations audit register
Aristo
src/repos/audit.ts · listAudit |
The auditability page: every act that changed money, licences, governance or configuration, with the role that carried it out.
Read at the page that needs it, not through the composed view. |
read counted
Not checked here |
— no stamp of its own |
nothing external
If absent: The trail says it could not be read rather than showing an empty history, which would suggest nothing had ever happened.
Turns on: It is written by the acts themselves. Nothing is written by reading a page. |
How to read source roles
A read is something Aristo asked a system for. A computed figure is produced by an engine over those reads. A projection describes an unfinished period and is always labelled as such.
The field map
The mechanical contract behind this page: every value these workspaces read, and the source it is claimed from.
Every workspace reads the same composed view. This mechanically tested crosswalk names the source behind each field.
Show all 43 fields and their sources
Scroll sideways for the remaining columns.
| Field | Fed by |
|---|---|
activationPct | Microsoft Graph — Copilot usage reports |
agentInventory | Microsoft Graph — agent registry (beta) |
agentsBuilt | The forged-agent register |
bli | Business licence inventory |
budgetEnforce | This organisation's own settings |
cmUsage | Azure Cost Management — reconciled export |
coworkBudgetUsd | This organisation's own settings |
creditBasis | Azure Cost Management — reconciled export |
creditPct | Azure Cost Management — reconciled export |
demo | Aristo's own run history |
deptRows | Microsoft Graph — directory departments |
deptTrend | Month-grained product and department history |
deptUtil | Microsoft Graph — seat map and department utilisation |
depts | Microsoft Graph — directory departments |
frontier | The Frontier score engine |
generatedAt | The composition instant |
history | Aristo's own run history |
idleSpendMo | Microsoft Graph — Copilot usage reports |
license | Microsoft Graph — licence truth |
licenseEconomics | Microsoft Graph — licence truth; The licence economics engine |
moves | The strategy engine |
narrative | The strategy engine |
org | The tenant registry |
plans | Move plans and their completion |
prev | Aristo's own run history |
productTrend | Month-grained product and department history |
radar | Microsoft 365 Message Center and the public roadmap feed |
readiness | The readiness engine |
runNumber | Aristo's own run history |
seatCost | This organisation's own settings |
seatRows | Microsoft Graph — seat map and department utilisation |
seatRowsWithheld | Microsoft Graph — seat map and department utilisation |
seatSlices | Microsoft Graph — seat map and department utilisation |
shadowAi | Microsoft Graph — sign-in audit logs |
skillDownloads | The skill shelf |
skillsOnShelf | The skill shelf |
sliceLabels | Microsoft Graph — seat map and department utilisation |
spendLights | Copilot credits report; The spend-light engine |
spendLightsWithheldK | The spend-light engine |
spendProjection | The spend projection |
spendTrend | Azure Cost Management — reconciled export; Copilot credits report; The spend-light engine |
stats | Microsoft Graph — Copilot usage reports |
trajectory | The Frontier score engine; The score trajectory |
What this page does not claim
The design system asks that every result carry seven things. Aristo carries five of them, and here is the honest account of the other two.
Every figure carries its source, period, freshness, basis and shared definition. Open the exceptions only when you need the methodology detail.
Read methodology limits and exceptions
Carried on every figure: the source it came from; the period it covers, where the source is periodic; when it was last refreshed, using the stamp the data itself carries; whether it is measured, counted, attested, provided, an estimate, an assumption or a projection; and the definition, through the shared metric vocabulary that means a word never changes meaning between two screens.
Not carried: a confidence interval on most figures. Aristo publishes one only where it has actually computed one — the never-nudged holdout comparison bills on the lower bound of a ninety-five per cent interval, and says so. Attaching a confidence figure to a counted seat total would be decoration: the count is either right or the read failed, and there is no distribution to describe. Where a figure is genuinely uncertain the product's answer is the basis word and the withheld state, not a percentage nobody computed.
Not carried: a single methodology paragraph per figure. The methodology is on the workspace where the figure appears — beneath the chart it was drawn from, in the evidence line under the number, and in the "view the data behind this chart" panel that shows the rows. Restating it here would create a second description of the same method, and two descriptions of one method eventually disagree. This page names the source; the workspace explains the arithmetic.
And one caveat that belongs at the top rather than the bottom. The "as of" stamp in the shell is the moment Aristo composed the view, and the composition is cached for forty-five seconds. It is not a statement about when Microsoft collected anything. Where a source carries its own stamp — an export's ingest time, a crawl's fetch time, a feed's update time — that stamp is in the table above and it is the one to believe.