A structured way to get in control
Scanning is the easy part. Praefic is built around what comes after it.

See. Every subscription is scanned across 19 areas, from network exposure and privileged access to cost and AI models. Every finding is stored with its history.
Decide. For each finding you can:
acknowledge it,
assign it to a person or a group,
accept the risk with an exception that has a reason and an expiry date,
or mark it for fixing.
Every decision carries over from one scan to the next.
Organize. Group the work into Initiatives, named remediation projects such as “Q4 network hardening” or “Clean up before the audit”. Each one has an owner, a scope and a burndown.
Verify. Fixed means fixed. When someone marks a finding as fixed, the next scan checks it. A finding that comes back is reopened, and Praefic shows who changed the resource.
Prove. Maturity levels, trend lines and a management report show progress in terms leadership understands.
Fixed findings are resolved automatically on the next scan.
Findings that come back are reopened and flagged.
Your acknowledgements, assignments and exceptions carry over from one scan to the next.
Praefic never writes to your environment. Not one setting is ever modified.
Initiatives: turn a list of problems into a plan
A backlog of four hundred findings isn’t a plan. An Initiative is: a named remediation project with a clear scope, owners and a finish line.

Scope it in a click. Filter findings by area, severity, subscription or resource group, select them, and add them to an Initiative. A finding can belong to more than one.
Assign ownership. Assign findings to people or to groups. Everyone gets an “assigned to me” view, and @-mentions in comment threads bring the right person in.
Separate claims from verification. Owners move work through Planned → In progress → Fix applied, or record Risk accepted. Praefic keeps that separate from what the scanner sees. “Fix applied” is the owner’s claim; “Resolved” means the next scan confirmed it.
Track progress honestly. Each Initiative shows how its findings break down by status and a burndown built from the actual finding history, including anything that came back after it was fixed.
Hand it to people outside Praefic. Generate a hand-off document as Markdown or self-contained HTML for a supplier, a partner or a product team that doesn’t use Praefic. It groups findings by issue, with why each one matters, how to fix it, a ready-to-run az command and the CIS/MCSB reference. A CSV or JSON export is available for ticket systems.
Initiatives are how a security review becomes a project with a deadline, rather than a report that ages in someone’s inbox.
Cost, next to the risks
Governance and cost are usually two tools and two teams. In Praefic they share the same resources, and the same findings.

Daily spend per resource. Praefic builds a daily cost history for every resource, explorable by subscription → resource group → resource, or by service and resource type at any level.
Spikes caught early. Praefic compares each resource with its own recent spend, not with the estate as a whole. A Key Vault going from a few dollars a day to thousands stands out even when it’s nowhere near your top-10 spenders.
Budgets that work. Praefic flags subscriptions with no budget, budgets with no alerts, expired budgets, budgets already exceeded and budgets forecast to exceed. It also shows which budget alerts actually fired.
Waste with a price on it. Orphaned disks, stopped VMs, unattached gateways and empty App Service plans are ranked by what they actually cost you over the last 30 days. Any finding on a billed resource shows its cost, so you can prioritize by money as well as severity.
AI spend by model. Track spend per AI model and deployment, alongside alerts for models approaching retirement.
Honest about gaps. Some Azure offers, like sponsorships, MSDN and trials, have no cost API. Praefic says so, instead of showing a cost of zero.
Who changed what, and why it keeps coming back
Praefic reads the Azure Activity Log for every connected subscription and keeps the history, so posture findings come with context.

Who changed this. Every finding shows the likely change that introduced it and whether anyone has touched the resource since.
Fixes that don’t stick. When a fixed finding keeps coming back, Praefic names the identity behind the pattern. That’s often a pipeline or script quietly putting the old setting back.
Privileged access, measured by actual use. Standing Owner and Contributor grants are marked active or dormant from what the identity actually did. Praefic also flags PIM roles that stay active long after the work is done, and eligible roles nobody ever activates.
People vs automation. See how much of your change volume comes from people clicking in the portal and how much comes from code. Deployments are reconstructed with success rates and durations.
Early warning signals. Repeated access denials for one account, integrations failing the same call for days, and operations colliding with each other.
One governed list, not five noisy ones
Findings from 19 areas of Azure land in one place. Where an Advisor recommendation repeats one of Praefic’s own checks on the same resource, it’s shown once, not twice. Tenants without Defender keep the Advisor finding, so nothing is lost.
Decisions that stick
You can acknowledge a finding, assign it to a person or group, mark it in progress or accept the risk. All of it carries over from one scan to the next. Praefic records the history, so you can see who decided what, and when.
Exceptions with an expiry date
Approve deviations in the app, or declare them as a tag on the Azure resource in the same pull request that creates it. Every exception carries a reason and an end date. When it lapses, the finding comes back by itself.
Remediation as a project, not a list
Initiatives group findings into owned projects with burndowns, verified fixes, and hand-off documents for suppliers who don’t use Praefic.
Reporting management can read
Maturity levels (Level 1, 2, 3), a health-score trend, and a management report as a PDF or an interactive web page. It covers top risks, how fast findings get fixed and CIS/MCSB coverage.
Security and cost in one view
Daily spend per resource, budget hygiene, cost spikes and priced waste, on the same resources as the security findings.
Read-only and agentless
There’s nothing to install and no write permissions. Praefic is a multi-tenant app you consent to once, with the Reader role on the subscriptions you choose.
Platform and cloud operations teams
Keep a growing estate clean: orphaned resources, missing backups, retiring runtimes and AI models, untagged spend.
Security teams
Get continuous visibility of network exposure, privileged access and Key Vault posture, without another agent to deploy or another list to reconcile.
Compliance-driven organizations
Exceptions with an owner and expiry date, a complete finding history, and reports mapped to CIS and the Microsoft cloud security benchmark. It’s the evidence an auditor asks for.
FinOps and cost owners
Daily spend per resource, budget coverage across every subscription, spikes caught early, and waste ranked by what it actually costs.
IT leadership
A health score, a maturity level and Initiatives with burndowns answer “are we in control, and are we getting there?” in one page.
Related articles

Explainer
From backlog to burndown: running a remediation project in Azure
A list of four hundred findings is not a plan. Here's how to turn a governance backlog into something a team can finish, and prove it's finished.
·
5 min read

Explainer
Level 1, 2, 3: building a governance baseline you can actually reach
Security benchmarks start you at hundreds of failures. A ladder of levels gives your team a target it can finish, and a trend line that proves progress.
·
5 min read

Explainer
Exceptions are part of governance, not a failure of it
Every real Azure estate has resources that break the rules on purpose. How you record those deviations decides whether your dashboard means anything.
·
5 min read

