Security and Privacy
How Adovance handles your data.
Read-only access
Adovance connects with read-only Microsoft Graph permissions. It never writes to, or changes anything in, your tenant.
| Permission | Purpose |
|---|---|
Reports.Read.All |
Copilot usage reports |
User.Read.All |
User directory (department, manager, role) |
Organization.Read.All |
Subscribed SKUs (purchased seats per plan) |
User.Read, openid, profile |
Sign-in |
Tenant isolation
- Every tenant’s data is strictly isolated. Access is scoped by your verified session on every query - never from anything a browser sends.
- You only ever see your own organization’s data.
- Enterprise customers can optionally run on a dedicated database for physical separation.
Sign-in
- Sign-in always uses a real Microsoft account (Microsoft Entra ID). There is no separate password and no bypass.
- MFA and conditional access policies from your organization apply as normal.
Support access (impersonation)
To reproduce a customer-reported issue, an Adovance super admin can be granted a limited, audited session that views your dashboard exactly as you see it. This access:
- Always requires the super admin to be authenticated as themselves first.
- Never carries super-admin privileges into the session.
- Is recorded in an audit log.
What we never do
- ❌ Write to your tenant
- ❌ Train AI models on your data
- ❌ Share your data with other tenants
- ❌ Change org-wide settings on your behalf