CloudOps assurance
What should you ask before a read-only cloud assessment?
Ask for the exact permissions, the resources in scope, the information collected, who can access it and how to revoke access. Read-only describes a permission boundary; you still need to understand what the assessor can see.
Get the permission list before giving consent
Ask the assessor to name every role or permission they need and explain the purpose of each one. Put the agreed scope in writing: which tenant, subscriptions, resource groups or services are included? Who approves access, and when does the review end?
As one example, Azure's built-in Reader role allows control-plane reads and does not include data-plane actions in its role definition. That distinction matters when discussing visibility. It does not describe every other permission an assessment might request. Source 1.
Agree what happens to the information
Ask for a straightforward description of the information collected and where it goes. Identify which findings appear in the report, whether exports are retained, which people can access them and what happens when the engagement ends.
For an MSP engagement, settle the reporting relationship early. The client and service provider should understand who receives the report and who owns the next conversation. Keep that agreement alongside the access approval.
Keep assessment and changes as separate approvals
Write down whether the engagement only reviews configuration or also includes implementation. When an assessor recommends a change, ask for the supporting evidence, the affected service, the expected benefit and the operational risk.
A useful action record includes an owner, an approval, a planned window and a way to check the result. Access used for investigation should be reviewed again if the scope moves into implementation.
What should a useful assessment report contain?
Look for a clear scope, the date of the evidence, findings linked to that evidence and a prioritised set of actions. Each recommendation should explain why it matters and what would need checking before anyone acts.
Ask the author to distinguish observations, estimates and assumptions. If a cost estimate depends on contract terms they have not seen, that limitation belongs next to the estimate. If a configuration was outside scope, the report should say so.
How do you close the access loop?
Before starting, agree how your administrator can remove the assessor's access and who will verify that it has ended. After the review, retain the approval record, the final report and the agreed follow-up actions under your organisation's information-handling process.
For Optimizer365's stated approach to access and findings, read the security page and assessment scope. Confirm the exact permission request for your environment before granting it.
Sources and scope
This guide combines provider documentation with a suggested review process. It is general operational guidance; confirm your own environment and agreement before making changes.
Sources checked on 1 October 2026. Suggest a correction.