Scope priority can select a broader management group when narrower identifiers are available
Source references: 2The scope-resolution table ranks Management Group—the broadest organizational scope—ahead of Resource Group and Subscription, potentially expanding cost and resource queries.
The agent could read and summarize billing and resource metadata from unrelated subscriptions or groups, placing additional sensitive business data in responses and local reports.
This is an active scope-selection rule: when several identifiers are present, it ranks the management group—explicitly described as the broadest organizational scope—ahead of resource group and subscription. A query could therefore cover more subscriptions and organizational data than the user expected. The user can require the resolved scope to be shown and confirmed before management-group queries.
## Scope Resolution PriorityWhen multiple scope identifiers are available in context, use the following priority order (highest first):| Priority | Scope | Notes ||----------|-------|-------|| 1 | Management Group | Broadest organizational scope. || 2 | Resource Group | Narrowest resource scope. || 3 | Subscription | Default scope for most queries. || 4 | Billing Profile + Invoice Section | MCA billing hierarchy. |Show 1 other places
## Step 1: Determine ScopeIdentify the Azure scope for the cost query from the Scope Reference table in the main [SKILL.md](../SKILL.md#scope-reference-shared-across-all-workflows).