> For the complete documentation index, see [llms.txt](https://docs.powermonitor.com.br/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.powermonitor.com.br/en/perguntas-frequentes/duvidas-tecnicas/seguranca-e-privacidade.md).

# Data security and privacy

How Power Monitor protects access to your tenant, what data it stores, and how to revoke access.

This page describes how Power Monitor handles the data in your environment and which security measures are in place.

### Does Power Monitor access the data in my reports?

**No.** Power Monitor reads **technical metadata and operational status** (item names and IDs, model structure, refresh status, capacity consumption, permissions) through the official Microsoft APIs. It **does not copy or store the content** of your semantic models, reports, lakehouses, or warehouses.

There are three specific situations in which a query is executed, always with a technical result:

* **Capacity consumption:** Power Monitor queries the semantic model of the **Fabric Capacity Metrics** app in your tenant, which contains the capacity consumption telemetry (not business data).
* **Data Freshness** (optional): for each table you configure, Power Monitor queries only the **most recent value** of the chosen date/time column, to find out whether the data is delayed.
* **Performance Assessment** (on demand, by administrators): the model structure (tables, columns, sizes) is read to generate recommendations.

### How is access to my tenant performed?

* Through the **Power Monitor application (Service Principal) in your Microsoft Entra ID**, created in the automatic installation or provided by you in the manual installation. You control this application and can revoke it at any time.
* Some actions use the **delegated access of the administrator** who performs them (for example, granting additional permissions), always with the Microsoft consent window.
* The temporary permissions used by the wizard in the automatic installation are **removed at the end** of the installation.

### How are credentials protected?

The application's Client ID and Client Secret (and the AI provider keys, when configured) are stored **encrypted**: the data is encrypted with AES-256 and the key is protected by an RSA key kept in **Azure Key Vault**. The secret is never returned to the screen after it is saved.

### Can one company's data be seen by another?

No. Each tenant corresponds to an **isolated organization**. All records belong to an organization, and the organization is always determined by the authenticated account, never by a parameter sent by the browser. A resource from another organization is simply not found.

### Who in my company accesses Power Monitor?

* Sign-in is done **exclusively with Microsoft accounts** from your tenant (or its B2B guests). There are no Power Monitor-specific passwords.
* Only people who have been **registered in Users** by an administrator can sign in.
* Administrators can **restrict users to certain workspaces** and **block pages**. Write actions are exclusive to **Administrators**.

### What does Power Monitor store?

* **Inventory metadata:** workspaces, items, model structure, capacities, gateways, connections, permissions;
* **History:** refreshes, runs, consumption, costs, alerts, and incidents;
* Power BI/Fabric **activity events** (when collection is enabled), including user, operation, item, and the source IP, which is converted into country, state, and city for access analysis;
* Organization **settings**, Power Monitor users, and billing data.

### Is there a record of what users do in Power Monitor?

Yes. **Audit › Application Events** records sign-ins, pages accessed, and configuration changes (user, date/time, IP, previous and new values), with CSV/JSON export.

### What about Artificial Intelligence?

The AI features (AI Assistant, Performance Assessment suggestions, and explanations) only work after an administrator configures **the organization's own AI provider** in **Settings › AI** (Claude, OpenAI, Azure OpenAI, Gemini, or Microsoft Foundry, with the organization's API key). To respond, Power Monitor sends the provider **metadata and metrics**, such as names of items, tables, and columns, counts, consumption, and rule findings, never the content of the data. The structure of Power Query queries is only sent if an administrator explicitly enables that option. All AI usage is logged, with monthly limits per organization and per user.

### Where is the data hosted?

On Power Tuning infrastructure in **Microsoft Azure**. Power Tuning is a Brazilian company and a Microsoft partner.

### LGPD compliance

The personal data processed (such as users' email and login, and activity records) is used exclusively for the performance of the contract and handled in accordance with the **Brazilian General Data Protection Law (LGPD)**. At the end of the contract, the stored data is permanently deleted. See the [Privacy Policy](/en/useful-links/politica-de-privacidade.md).

### How do I revoke access?

You can revoke Power Monitor's access to your tenant at any time through the **Microsoft Entra ID portal**:

1. Go to [portal.azure.com](https://portal.azure.com).
2. Go to **Microsoft Entra ID › Enterprise applications**.
3. Find the Power Monitor application (in the automatic installation, **PowerMonitor-APP**).
4. Disable or delete the application. If you want, also delete the App Registration and the **PowerMonitor-Group** security group.

After revocation, Power Monitor can no longer collect data from your tenant.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://docs.powermonitor.com.br/en/perguntas-frequentes/duvidas-tecnicas/seguranca-e-privacidade.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `automate deployments from our CI pipeline` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
