Reader role only for Azure discovery
Discovery does not require Contributor or Owner access. That is the first security review boundary.
C4CI is designed for the security conversation buyers actually need: least-privilege Azure discovery, read-only-first scans, audit-aware product surfaces, and NIS2 / DORA evidence support without claiming certification.
Discovery does not require Contributor or Owner access. That is the first security review boundary.
Diagram generation, scans, and drift review do not mutate customer infrastructure.
Pro and Enterprise surfaces use tier gates and product copy aligned with backend entitlement rules.
Enterprise Infrastructure-as-Diagram remains a human-reviewed workflow, not an automatic mutation path.
C4CI supports NIS2 / DORA evidence support, but does not claim certification or replace legal governance.
No for discovery. Reader role is enough for the public quickstart and architecture scan path.
No by default. Reviewed write-path workflows remain separate and require explicit human approval.
No. C4CI provides architecture evidence support for reviews and audits; it does not replace legal, security, or compliance programs.