Skip to content
Aristo's read Grounded in page evidence

Connection state is separated into answering, genuinely off and not measured on this request.

Why it matters
An unavailable grant or configuration read cannot masquerade as a green connection or a reassuring zero.
Recommended action
Start with the genuinely off connections, then resolve every unchecked state before relying on the capability it feeds.

Integrations

Every system Aristo is connected to for this organisation, what it is authorised to read, and when it last answered.

The live grant state could not be decoded on this request, so 5 of the 10 connections below state nothing at all rather than guessing.

Every connection, and what a check actually returned

A green word means a check ran on this request and answered yes. Grey means it answered no, or that this build has no check to run — the row says which.

0 live5 not measured

Scroll sideways for the remaining columns.

Every system Aristo connects to for this organisation, what it feeds, the state a real check returned on this request, and the timestamp the data itself carries.
Connection What it feeds State
checked on this request
Last answered
Microsoft Graph — application permissions
Microsoft 365
Seat counts, licence truth, department grouping, the rollout radar — most counted figure in the product. Not measured
This is the illustrative organisation. It holds no consent of its own, so there is no live grant state to decode — in your own tenant every row here is read from your app token live, from a reading at most 30 seconds old.
no timestamp of its own
Azure Cost Management — reconciled export
Microsoft Azure
The Cowork and credit dollars on every money surface. Without it those dollars are a labelled ESTIMATE rather than a measured figure. Not connected
No export is connected, so Cowork and credit dollars are shown as a labelled estimate envelope everywhere they appear.
Turns on: Connect a read-only Cost Management export SAS on the Settings page. Aristo validates that it cannot write before it will store it.
no timestamp of its own
Azure Cost Management — intraday query
Microsoft Azure
The month-to-date "so far" reading. Display-only — it never replaces the reconciled export as the source of record. Not connected
No subscription is configured for the intraday query, so the month-to-date reading is not offered anywhere.
Turns on: Add the subscription id on the Settings page, then grant the Aristo service principal Cost Management Reader on it in Azure.
no timestamp of its own
Copilot credits report
Microsoft 365 admin center
Per-policy credit consumption behind the spend lights and the credit share of the money trend. Not connected
No credits report has been ingested, so per-policy credit consumption is not shown and the spend lights fall back to the estimate envelope.
Turns on: Export the credits report from the Microsoft 365 admin center and paste it on the Settings page.
no timestamp of its own
Microsoft 365 Message Center
Microsoft 365
The tenant's own Copilot rollout notices on the Roadmap workspace, told apart from the public roadmap on every row. Not measured
The grant state could not be decoded on this request, so this row states nothing about ServiceMessage.Read.All. This is the illustrative organisation. It holds no consent of its own, so there is no live grant state to decode — in your own tenant every row here is read from your app token live, from a reading at most 30 seconds old.
feed updated
Teams — the Aristo assistant
Microsoft Teams
Proactive nudges, the sponsor digest, and the in-chat answer. Nothing on these workspaces depends on it. Not measured
No Teams conversation was recorded for this organisation in the last 30 days. That is not the same as "not installed" — Aristo has no signal for whether the app is present in a tenant, so a quiet month and an absent app look identical here and neither is claimed.
no timestamp of its own
Knowledge corpus — your own documents
Aristo
Grounded answers about the organisation's own material. No workspace figure depends on it. Not connected
The corpus is dark. Nothing of the organisation's own material has been uploaded or indexed.
Turns on: Upload documents on the Settings page. They stay inside this tenant's own partition.
no timestamp of its own
Microsoft account team — expansion signal
Outbound email
One notification to a named Microsoft seller when consumption reaches 90% of the cap. Nothing else ever leaves. Not connected
No Microsoft contact is named and no opt-in has been given, so this organisation's consumption posture is never shared outside it.
Turns on: Name the contact and give the opt-in on the Settings page. Either one alone sends nothing.
no timestamp of its own
Commercial marketplace — SaaS fulfilment
Microsoft commercial marketplace
Subscription lifecycle events, if and when this organisation is transacted through the marketplace. Not measured
Aristo records no marketplace webhook state against an organisation. The webhook handler acknowledges every event it receives and its result is discarded at the call site — no heartbeat is written and no health component exists — so there is no last-event time, no success rate and no failure count to show. This row stays grey until a real signal is built; a green light here would be an invention.
no timestamp of its own
Microsoft Secure Score
Microsoft 365 security
The security pillar of the Frontier score. While it is absent the pillar is DROPPED and the remaining weights re-normalise — it is never scored zero, which would read as a failing grade for a read nobody granted. Not measured
The grant state could not be decoded on this request, so this row states nothing about SecurityEvents.Read.All. This is the illustrative organisation. It holds no consent of its own, so there is no live grant state to decode — in your own tenant every row here is read from your app token live, from a reading at most 30 seconds old.
no timestamp of its own
No connection is switched on by reading this page. Every consent above is granted once by an administrator in Entra and can be revoked there at any time; revoking one darkens the capability beside it and changes no number that was already counted.

Why some rows have no light at all

The rule this page is built on, stated plainly enough to be argued with.

Three states appear above and only one of them is a colour worth trusting. Connected means a check ran on this request and answered yes — a permission decoded out of this tenant's own token, a file with a real ingest stamp, a conversation that actually happened. Not connected means a check ran and answered no, which is a useful thing to be able to say. Not measured means this build has no check to run, and it is the state that most integrations pages quietly convert into a green tick.

Aristo refuses three specific conversions. A fleet-wide heartbeat is never rendered as one organisation's health, so the Teams row counts this organisation's own questions and admits that a quiet month and an uninstalled app look identical. A stored subscription id is never rendered as an authorisation, because the grant that makes the query work is made in Azure and only a query answering proves it. And a platform environment variable is never rendered as a marketplace connection, because it is a fact about the deployment rather than about this organisation.

This page has no filter bar and no empty state, and both absences are deliberate rather than unfinished. The list of connections is a property of the product, not of the organisation — every row exists for every tenant, and a tenant that has connected nothing sees the same ten rows all reading "not connected", which is the most useful thing this page can say to somebody who has just arrived. There is consequently nothing to filter and nothing that can be empty. What CAN fail is the reading, and that has its own state above: two reads that should have worked and did not are reported as a fault, never as an absence of connections.

The last column is held to the same rule. It shows the timestamp the data itself carries — the moment an export was ingested, the day a feed was refreshed — and where a connection carries none it says so. The instant this page was composed is not that timestamp, and printing it in that column would make a connection nobody has checked in six weeks look like it answered four seconds ago.