For MSPs running Azure for their clients
Find the AI spend nobody is watching.
Your clients are standing up Azure OpenAI, Foundry and Copilot Studio faster than anyone writes budgets for them. Guardian scans each client's Azure read-only, finds the model deployments with nothing between them and a runaway bill, and rolls every client into one report.
- Read-only, nothing in the tenant changes
- No agent installed at the client
-
Unbounded
client-a gpt-4.1, GlobalStandard
150,000 tokens a minute, nothing watching it
No budget and no alert rule over the account
ai-deployment-unbounded -
Unbounded
client-b Copilot Studio billing plan
Copilot Credits billing on 22 days
No budget, no alert, and no quota on the meter
ai-copilot-spend -
Moved
client-a text-embedding-3-large
Token use 2.4 times its own 14-day baseline
Measured per deployment, not per account
ai-spend-anomaly -
Idle
client-c gpt-4o, provisioned
No requests in 30 days, billing every hour
Provisioned throughput nobody calls
ai-idle-deployment
Every finding points at the snapshot it came from, so any figure can be checked.
The bill that doesn't show up until it does
A pay-per-token model deployment costs nothing while it idles, so it never comes up in a cost review. Then an agent loops, or someone points a batch job at it, and it costs whatever it runs to.
Azure has no spend cap on a model deployment. The rate limit throttles the minute, not the month. 250,000 tokens a minute, sustained, is a very large invoice with nothing in the way.
Copilot Credits are worse. The meter has no rate limit and no quota at all.
Today you find out when the client does. Guardian moves that to the monthly report.
Four questions, asked of every AI deployment
Per deployment, not per account, so a chat model and an embedding model on the same account can't hide each other.
| Check | Question | What it reports |
|---|---|---|
ai-deployment-unbounded |
Would anything stop it? | Every model deployment with no budget and no alert rule over its account, with the model, SKU and token ceiling. The same-day action list. |
ai-spend-anomaly |
Did its usage move? | Token use against that deployment's own 14-day baseline. |
ai-idle-deployment |
Does anyone call it? | Provisioned throughput that serves no requests bills every hour it sits there. Pay-per-token that idles is quota to reclaim. |
ai-copilot-spend |
What is Copilot costing through Azure? | Copilot Studio, Copilot Chat, SharePoint agents and Security Copilot billed to the subscription, per billing resource, and whether a budget or alert watches it. |
And the rest of the estate while it's there
The same scan checks cost and alerting hygiene across every subscription in the manifest.
- Orphaned disks and registries still billing with nothing attached or pulling from them
orphaned-disk - Spend that jumped against its own recent baseline
spend-anomaly - Spend with no budget over it
unbudgeted-spend - Spend no alert rule watches
unmonitored-spend - Untagged spend nobody can attribute to a team or project
untagged-spend - Alert rules that flap, or point at resources that no longer exist
flapping-alert-rule - Action groups with no receivers, so the alert fires and nobody hears it
receiverless-action-group - Subscriptions with no cost data, such as sponsorship credit, with an estimated burn
credit-burn-estimate
How it runs
From your laptop or a jump box. Nothing is installed in the client's tenant and nothing is re-platformed.
List your clients
One manifest file names each client and its subscriptions.
Sign in with Reader access
Reader plus Cost Management Reader on each subscription. Every call Guardian makes is on an explicit read-only allowlist.
Run one command
Each client scans into its own history. One client failing doesn't stop the rest.
Read the roll-up
Monitored spend, AI share and every unbounded deployment across clients, plus proposed fixes as scripts for a person to review.
clients:
- name: client-a
subscriptions:
- 00000000-0000-0000-0000-000000000000
- name: client-b
subscriptions:
- 11111111-1111-1111-1111-111111111111
# read-only: Reader + Cost Management Reader
az login
guardian-live scan-set --manifest clients.yaml --run-id 2026-10
What it doesn't do
- It never applies a change. Guardian proposes, and a person approves and acts.
- Per-seat Microsoft 365 Copilot licences bill through the M365 admin centre, not Azure, so Guardian can't see them.
- Azure can't say which user or agent drove a Copilot meter, so neither can Guardian.
- Clients in different Entra tenants need a separate sign-in each.
- It's early. Today it runs from your machine, not as a hosted service.
Try it on one client.
Pick the client whose AI usage you understand least. We run the scan together in about thirty minutes, you read what it finds, and you decide whether it belongs in your service catalogue.