Security and Privacy

How Adovance handles your data.

Read-only access

Adovance connects with read-only Microsoft Graph permissions. It never writes to, or changes anything in, your tenant.

Permission Purpose
Reports.Read.All Copilot usage reports
User.Read.All User directory (department, manager, role)
Organization.Read.All Subscribed SKUs (purchased seats per plan)
User.Read, openid, profile Sign-in

Tenant isolation

  • Every tenant’s data is strictly isolated. Access is scoped by your verified session on every query - never from anything a browser sends.
  • You only ever see your own organization’s data.
  • Enterprise customers can optionally run on a dedicated database for physical separation.

Sign-in

  • Sign-in always uses a real Microsoft account (Microsoft Entra ID). There is no separate password and no bypass.
  • MFA and conditional access policies from your organization apply as normal.

Support access (impersonation)

To reproduce a customer-reported issue, an Adovance super admin can be granted a limited, audited session that views your dashboard exactly as you see it. This access:

  • Always requires the super admin to be authenticated as themselves first.
  • Never carries super-admin privileges into the session.
  • Is recorded in an audit log.

What we never do

  • ❌ Write to your tenant
  • ❌ Train AI models on your data
  • ❌ Share your data with other tenants
  • ❌ Change org-wide settings on your behalf