federated_credential_subject mismatch: Venturi’s signing subject doesn’t match the module.
Cost Management returns empty
EA/CSP billing data can require a billing-account, billing-profile, invoice-section, or enrollment scope beyond subscription Reader. Confirm the applicable billing scope during onboarding.
Azure OpenAI usage missing
Inference is going through APIM or an Event Hub; flip the matching enable_* flag and terraform apply.
terraform apply fails on azuread_application
A human caller needs tenant application-registration rights; CI may need Microsoft Graph Application.ReadWrite.OwnedBy with admin consent. Role assignments separately require Owner or User Access Administrator on the subscription.
Re-check terraform apply; share the output with Venturi. GCP and Azure positive reads are confirmed during connector activation, not by the current local script.
A write probe succeeded
Security finding: the identity has more than read access
Stop. Do not hand outputs to Venturi; contact your onboarding rep immediately.
Missing/invalid Authorization: Bearer or X-API-Key.
422 Unprocessable Entity
Payload failed schema validation. Check the required fields (event_id, ingestion_layer, ingestion_timestamp, provider, requested_model) and that estimated_cost_usd is a string.
Event accepted (202) but not in dashboard
Allow ~30s; confirm you’re querying the same tenant/instance.