The thread that leads out of the labyrinth.
ari — reference-integrity tooling for Microsoft 365 tenants. Builds a provenance-carrying graph of every Entra ID and Intune object, so you know exactly what breaks before you delete it.
Microsoft Graph answers "what does this Conditional Access policy target", but never "what targets this group". Ariadna inverts the query: it collects every reachable object, extracts every reference, and answers — for any object — what references it, what breaks if it is deleted, and what is referenced by nothing at all.
Read only, fully local, no telemetry. Snapshots are immutable and tenant-namespaced.
Phase 1 of EPIC E1 (Collector) is in progress. See PLAN.md for the full plan, ISSUES.md for the bug tracker.
| Command | Purpose |
|---|---|
ari collect |
Collect a raw, immutable snapshot of the tenant |
ari version |
Print version |
More commands (impact, refs, orphans, dangling, diff) ship with later epics.
go build -o ari ./cmd/ari
export ARI_CLIENT_ID="<app-registration-client-id>"
export ARI_CLIENT_SECRET="<secret>"
export ARI_TENANT="<tenant-id-or-domain>"
./ari collectSnapshots land in ~/.ariadna/snapshots/<tenantId>/snapshots/<snapshotId>/ (override with --out or ARI_OUT). Credentials come from the environment only and never touch disk.
The app registration needs the read-only scopes listed in ari help (brief §9: Directory.Read.All, Group.Read.All, User.Read.All, Device.Read.All, Application.Read.All, Policy.Read.All, RoleManagement.Read.All, RoleManagement.Read.Directory, AdministrativeUnit.Read.All, EntitlementManagement.Read.All, and the DeviceManagement* read scopes).
cmd/ari/ CLI entrypoint
internal/config/ config, flags, env, credentials
fixtures/ recorded Graph responses for offline tests
tenants/ snapshot output (git-ignored, never committed)