Start with the least access needed to produce useful evidence
Revenue Opportunity Radar begins with scoped, read-only evidence collection where the connected system supports it. Agencies and customers choose the sources and resources in scope, and people review the results before they become customer-facing work.
Visibility for review—not standing production control
Read-Only First
Selected Scope
Human Review
Revocable Access
Access is explicit and source-specific
| Source | Starting Access | Scope Control |
|---|---|---|
| GitHub | GitHub App with Contents and Metadata read-only permissions | Selected repositories are the preferred installation mode |
| Microsoft Azure | Service principal using the Reader role | Monitor only the subscriptions or resource groups approved for the pilot |
| Google Cloud | Read-only service-account access | Connect only approved projects and monitored resources |
| Azure DevOps Pilot | Time-bounded personal access token with Code Read permission | Selected repositories in one connected organization |
Exact permissions vary by evidence source and enabled workflow. Pilot scope should document the requested permission, selected resources, approver, expiration or rotation plan, and revocation path before activation.
What Radar does
- Reads the evidence sources and resources explicitly configured for the customer
- Produces reports, findings, limitations, and opportunity candidates for review
- Preserves source context so reviewers can understand why a candidate exists
- Limits application access to the agency and customer scopes authorized for each user
What Radar does not do by default
- Modify source code, repositories, cloud resources, or production infrastructure
- Request blanket administrative access as the normal discovery model
- Send an agent finding directly to a customer without a human-controlled workflow
- Turn a security signal into proof of exploitation, compliance failure, or guaranteed work
Analysis processing and customer review
InfraSteady stores the connection metadata, selected resource scope, reports, findings, opportunities, and audit records needed to operate the configured workflow. Do not put passwords, tokens, private keys, or other secrets into free-text notes or instructions.
Some enabled workflows use third-party analysis or model tooling. For example, selected repository-analysis workflows use Cursor CLI inside dedicated task containers. The applicable providers, data handling, retention, hosting requirements, and deletion plan should be confirmed for the configured pilot before customer approval.
InfraSteady does not use this page to claim a certification, universal zero-retention policy, or data residency commitment. Those requirements should be handled through the customer security-review and contracting process for the deployment being considered.
Review security before connecting a client
Tell us which evidence sources are in scope and which customer security, processing, retention, or revocation requirements the pilot must satisfy.
