An allowlist, applied in the query
Sulcus asks Application Insights only for the fields it shows: record type, identifiers, timestamps, duration, outcome, error type, agent and tool names, and model name. Messages, replies, tool inputs and results, and who was talking aren’t requested, so they aren’t sent to Sulcus.
The client secret is stored, encrypted
Unlike the API keys of a hosted run, this connection needs a saved credential. Sulcus stores the client secret encrypted, tied to that one project, and never shows it again. The tenant, environment, Application Insights and client IDs are stored with the project and visible to workspace members.
Disconnecting
Disconnect in the project’s settings deletes the saved client secret and stops Sulcus reading the environment. Existing runs are kept. You can also revoke the secret or the Reader role in Microsoft at any time.