For MSPs running Azure for their clients

Find the AI spend nobody is watching.

Your clients are standing up Azure OpenAI, Foundry and Copilot Studio faster than anyone writes budgets for them. Guardian scans each client's Azure read-only, finds the model deployments with nothing between them and a runaway bill, and rolls every client into one report.

  • Read-only, nothing in the tenant changes
  • No agent installed at the client
Roll-up across clients Example findings
  1. client-a gpt-4.1, GlobalStandard

    150,000 tokens a minute, nothing watching it

    No budget and no alert rule over the account ai-deployment-unbounded

    Unbounded
  2. client-b Copilot Studio billing plan

    Copilot Credits billing on 22 days

    No budget, no alert, and no quota on the meter ai-copilot-spend

    Unbounded
  3. client-a text-embedding-3-large

    Token use 2.4 times its own 14-day baseline

    Measured per deployment, not per account ai-spend-anomaly

    Moved
  4. client-c gpt-4o, provisioned

    No requests in 30 days, billing every hour

    Provisioned throughput nobody calls ai-idle-deployment

    Idle

Every finding points at the snapshot it came from, so any figure can be checked.

The bill that doesn't show up until it does

A pay-per-token model deployment costs nothing while it idles, so it never comes up in a cost review. Then an agent loops, or someone points a batch job at it, and it costs whatever it runs to.

Azure has no spend cap on a model deployment. The rate limit throttles the minute, not the month. 250,000 tokens a minute, sustained, is a very large invoice with nothing in the way.

Copilot Credits are worse. The meter has no rate limit and no quota at all.

Today you find out when the client does. Guardian moves that to the monthly report.

Four questions, asked of every AI deployment

Per deployment, not per account, so a chat model and an embedding model on the same account can't hide each other.

CheckQuestionWhat it reports
ai-deployment-unbounded Would anything stop it? Every model deployment with no budget and no alert rule over its account, with the model, SKU and token ceiling. The same-day action list.
ai-spend-anomaly Did its usage move? Token use against that deployment's own 14-day baseline.
ai-idle-deployment Does anyone call it? Provisioned throughput that serves no requests bills every hour it sits there. Pay-per-token that idles is quota to reclaim.
ai-copilot-spend What is Copilot costing through Azure? Copilot Studio, Copilot Chat, SharePoint agents and Security Copilot billed to the subscription, per billing resource, and whether a budget or alert watches it.

And the rest of the estate while it's there

The same scan checks cost and alerting hygiene across every subscription in the manifest.

  • Orphaned disks and registries still billing with nothing attached or pulling from themorphaned-disk
  • Spend that jumped against its own recent baselinespend-anomaly
  • Spend with no budget over itunbudgeted-spend
  • Spend no alert rule watchesunmonitored-spend
  • Untagged spend nobody can attribute to a team or projectuntagged-spend
  • Alert rules that flap, or point at resources that no longer existflapping-alert-rule
  • Action groups with no receivers, so the alert fires and nobody hears itreceiverless-action-group
  • Subscriptions with no cost data, such as sponsorship credit, with an estimated burncredit-burn-estimate

How it runs

From your laptop or a jump box. Nothing is installed in the client's tenant and nothing is re-platformed.

  1. List your clients

    One manifest file names each client and its subscriptions.

  2. Sign in with Reader access

    Reader plus Cost Management Reader on each subscription. Every call Guardian makes is on an explicit read-only allowlist.

  3. Run one command

    Each client scans into its own history. One client failing doesn't stop the rest.

  4. Read the roll-up

    Monitored spend, AI share and every unbounded deployment across clients, plus proposed fixes as scripts for a person to review.

clients.yaml
clients:
  - name: client-a
    subscriptions:
      - 00000000-0000-0000-0000-000000000000
  - name: client-b
    subscriptions:
      - 11111111-1111-1111-1111-111111111111
Terminal
# read-only: Reader + Cost Management Reader
az login
guardian-live scan-set --manifest clients.yaml --run-id 2026-10

What it doesn't do

  • It never applies a change. Guardian proposes, and a person approves and acts.
  • Per-seat Microsoft 365 Copilot licences bill through the M365 admin centre, not Azure, so Guardian can't see them.
  • Azure can't say which user or agent drove a Copilot meter, so neither can Guardian.
  • Clients in different Entra tenants need a separate sign-in each.
  • It's early. Today it runs from your machine, not as a hosted service.

Try it on one client.

Pick the client whose AI usage you understand least. We run the scan together in about thirty minutes, you read what it finds, and you decide whether it belongs in your service catalogue.