Katabarwa Labs
← All Azure apps

Governance & hygiene · Policy Exemption Tracker

Track Azure Policy exemptions so none lapses or lingers unnoticed

Exemptions with an expiry lapse silently and break deployments. Exemptions without one become permanent gaps. One daily report covers both.

Deploys as a managed application in your own subscription. No vendor backend, no data egress. Flat monthly fee, billed by Microsoft.

The gap

Someone grants an exemption to unblock a release, sets ninety days, and moves on. Ninety days later a deployment fails and nobody connects the two. The exemptions with no date are worse: they are security waivers with no owner and no end.

What it does
The daily card: expired, expiring, and permanent exemptions.
The daily card: expired, expiring, and permanent exemptions.
Per-exemption detail with the policy, scope, and date.
Per-exemption detail with the policy, scope, and date.
Threshold settings.
Threshold settings.
Honest about its limits
How it runs, and what it needs

A serverless function on a schedule, with a system-assigned managed identity, deployed into your subscription by the Azure Marketplace. Roles are granted by you after deployment with the one-line script in the package, so nothing runs until you say so. Every role it asks for, and why:

Reader list policy exemptions and their expiry dates

Alerts go to the Teams webhook you configure. Nothing is sent anywhere else.

FAQ

Does any data leave my subscription?

No. The function runs in your subscription and writes only to your configured alert destination. Katabarwa Labs operates no backend and receives nothing.

How is it billed?

A flat monthly fee on your Azure bill through the Marketplace, plus the small consumption cost of the function itself. No per-resource or per-user pricing.

How do I remove it?

Delete the managed application from the Azure portal. Its resource group and identity go with it, and any role you granted can be removed the same way.

Where do I get support?

support@llmgraph.ai, or the support page.

Deploy Policy Exemption Tracker in your subscription.

Exemptions with an expiry lapse silently and break deployments. Exemptions without one become permanent gaps. One daily report covers both.

Deploy from the Azure Marketplace