What
What changed?
Review snapshots, diffs, timelines, deleted resources, and drift across the selected Azure window.
See what changed in Azure, why cost or risk moved, and who owns the next step.
Lineage brings Azure history, cost, identity, security findings, recommendations, reports, and Atlas AI into one review view, then turns findings into assigned work or a review pack.

Monitoring tells you what is happening now. Lineage connects history, identity, cost movement, and ownership so teams can move from signal to decision without building a report by hand.
What
Review snapshots, diffs, timelines, deleted resources, and drift across the selected Azure window.
Who
Connect activity, identity, RBAC, service principal, and automation context where source data is available.
How much
Put cost movement beside the resources, owners, and changes that shaped the review period.
What next
Route ownership, prepare a report note, or review an approved action path when the account has it enabled.
Lineage keeps Azure teams from jumping between cost charts, activity logs, security findings, recommendations, tickets, and screenshots. It keeps the review window intact, connects related changes, routes follow-up to owners, builds recurring reviews, and supports approved AI-assisted operations where enabled.
Operating loop
One path from Azure activity to the owner, review pack, and approved operating action.
Collect Azure resource, cost, activity, identity, recommendation, and risk signals.
Keep snapshots, timelines, diffs, and deleted-resource history for the selected review window.
Connect change history to cost movement, identity context, activity, risk, and ownership.
Route findings through Action Center with owners, status, comments, and decisions.
Build reports, exports, schedules, and recurring review packs from the same source context.
Use Atlas AI, Azure Write, and Deployment Mode only inside approved action paths where enabled.
Time Machine is the historical memory. The full Lineage workspace connects change intelligence, cost movement, identity and risk, assigned work, reports, Atlas AI, and administrable trust controls.
See what changed, when it changed, who acted, and what downstream signals moved.
Explain Azure cost movement through change, ownership, allocation, commitments, budgets, forecasts, and license material.
Review security, compliance, identity, permissions, failed operations, and recommendations with operational context.
Convert findings into assigned, prioritized work and recurring stakeholder review packs.
Use Atlas AI for investigation and drafted next steps; keep write-class actions in approved control paths.
Manage roles, SSO, API keys, sessions, tenants, audit, sync freshness, health, mail, licenses, and backups.
Move through the same product surfaces a cloud review uses: operate the estate, investigate change, explain cost, manage risk, route work, administer access, and use Atlas AI where approved.
Dashboard gives platform, finance, security, and leadership teams a common starting point for posture, freshness, cost, risk, and assigned work.

Lineage separates investigation from write-class operations. Atlas AI can help analyze source context and draft next steps. Where enabled, Azure Write and Deployment Mode route action through customer identity, product permissions, approval, policy checks, execution records, and verification.
Ask operational questions across Lineage history, cost, risk, activity, and Action Center context, then prepare summaries and follow-up material for review.
Where enabled, route approved write-class operations through customer identity, Azure RBAC, product permissions, approval, policy checks, execution records, and audit.
Where enabled, organize infrastructure change through intent, preflight, plan, what-if, approval, apply, verification, and run records.

Lineage is not a replacement for Microsoft-native tools, FinOps platforms, CNAPPs, ITSM systems, observability platforms, or IaC pipelines. It adds a review workspace that connects their signals to Azure history, assigned work, reports, and approved action.
| Existing tool category | Keep using it for | Lineage adds |
|---|---|---|
| Azure Portal, Cost Management, Advisor, Defender for Cloud, Entra | Native control plane, security posture, recommendations, identity administration, and billing or cost views. | AI summaries tied to tenant history, costs, risks, owners, recommendations, decisions, and reports. |
| FinOps platforms | Broad financial management, allocation, unit economics, billing operations, and finance workflows. | Azure change and ownership context for why cost moved, plus AHUB and license decision support. |
| CNAPP and security platforms | Cloud security posture, exposure management, vulnerability programs, policy, and security operations. | Azure operational history, identity and activity context, Action Center ownership, and report-ready risk notes. |
| ServiceNow, Jira, Azure DevOps | Enterprise ticketing, approvals, service management, change records, and systems of record. | Azure-specific investigation context, suggested follow-up work, retained decisions, and review packs. |
| Terraform, Bicep, GitOps, deployment systems | Source-controlled infrastructure change, plan and apply automation, policy pipelines, and deployment operations. | Actual Azure-state history, review context, approval-bound artifacts, exact apply, and verification where enabled. |
| AI assistants and copilots | General natural-language help, product-specific assistance, summaries, and embedded workflows. | Lineage-grounded tenant context, historical memory, Action Center ownership, and controlled action paths where enabled. |
Native control plane, security posture, recommendations, identity administration, and billing or cost views.
AI summaries tied to tenant history, costs, risks, owners, recommendations, decisions, and reports.
Broad financial management, allocation, unit economics, billing operations, and finance workflows.
Azure change and ownership context for why cost moved, plus AHUB and license decision support.
Cloud security posture, exposure management, vulnerability programs, policy, and security operations.
Azure operational history, identity and activity context, Action Center ownership, and report-ready risk notes.
Enterprise ticketing, approvals, service management, change records, and systems of record.
Azure-specific investigation context, suggested follow-up work, retained decisions, and review packs.
Source-controlled infrastructure change, plan and apply automation, policy pipelines, and deployment operations.
Actual Azure-state history, review context, approval-bound artifacts, exact apply, and verification where enabled.
General natural-language help, product-specific assistance, summaries, and embedded workflows.
Lineage-grounded tenant context, historical memory, Action Center ownership, and controlled action paths where enabled.
Lineage is built around tenant-aware boundaries, role-gated administration, sync observability, reports, audit surfaces, and account-specific security review. Evaluation teams can review the delivery model, permissions, sync health, and administrative controls before rollout.
Tenant-aware application and data-access boundaries
Role, group, permission, SSO, and API key administration
Active session and audit visibility
Sync status, history, scheduler health, configuration, and progress
Report scheduling and delivery controls where configured
System health, mail, license, backup, and restore administration
Account-specific security and data-handling review
Deployment architecture review for network, data, and model-routing scope
Choose a tenant, subscription, customer, or workload. Confirm sources, sync status, access, and the evaluation question. Then run the investigation, produce a source-backed summary, and review administration and advanced capability scope.
Bring a recent incident window or change review.
Bring a subscription, service, or resource group with spend movement.
Bring a set of risks, identities, failed operations, or permissions.
Bring a recurring review or stakeholder reporting need.
Scope Atlas AI, Azure Write, or Deployment Mode only where approved.
Action Center turns findings into assigned, prioritized work. Reports turn the same source context into executive reviews, audit packages, cost reviews, security and identity reviews, MSP QBRs, and recurring service packs where configured.

We will review how Lineage connects source context, explains the decision, routes ownership, and produces a reviewable summary, ticket, or report while keeping advanced actions governed where enabled.