Self-service catalogue
Eighteen services in nine categories, from sandboxes and VNets to RBAC, policy exemptions and cost reports, each with live policy checks.
Everything is self-service. Critical changes still go to the platform team.
One portal for Azure application teams and the platform team that keeps them safe: a self-service catalogue, a routing policy that applies safe changes at once and sends risky ones for approval, and an AI assistant.
Where it is today Pilot-ready (version 0.3)
Every Azure change becomes a ticket, so teams wait days for routine work, while the platform team cannot hand out access without losing control of production, network and cost.
Eighteen services in nine categories, from sandboxes and VNets to RBAC, policy exemptions and cost reports, each with live policy checks.
Every change is checked. Safe changes apply straight away; production, access, network and large cost changes wait for an admin.
Approval queue with an advisory AI risk summary, policy checks, what-if, cost, blast radius and a topology diff. Keyboard triage and bulk approval of low risk.
Ask mode answers from live data with sources and changes nothing. Do mode drafts a change, which then goes through the same routing rules. It refuses to show secrets.
Describe a workload in plain words and get a pre-approved architecture with a diagram, cost, Bicep, a GitHub workflow and what-if.
Choose a change. The simplified policy below follows the portal's rules: what is checked, how risky it is, and whether it applies at once or waits for the platform team.
$ storage account st-orders-prod: public network access → disabled
Security improvements apply at once, even in production.
Simulated walkthrough with sample data. Nothing here connects to a live system.
Tell us where you are. An engineer replies with a proposal, not a sales script.
All products