Newsroom
    Act
    4 min read

    Act on a recommendation where you find it

    Spotto can now apply a supported fix directly from the recommendation that surfaced it, least-privilege, reversible where it can be, and always with the operator in control.

    Finding the work is hard, it takes real time and skill to know what's worth doing across a client's cloud, and surfacing it is the part Spotto already makes easier. But finding it is only half the job.

    The friction that's left is the doing: an engineer needs the time to act on the things that matter, instead of leaving the tool, repeating the same Azure Portal steps for every affected resource, and hoping the change is as reversible as everyone assumed. So recommendations pile up, stuck on a final step that always stayed manual.

    Now Spotto can take that step in place. Right on the recommendation, an Implement option lets you review what it affects, choose the scope, and apply it under narrowly scoped permissions, or schedule it for a later one-time run, with the decision context kept on the recommendation. The routine work, handled where you found it, with the operator in control of every change, not handed to autopilot.


    Who it's for

    • Engineers apply a supported fix from the recommendation itself, instead of rebuilding the same Azure Portal steps for every affected resource.
    • Service delivery leads clear the backlog of small, well-defined fixes that pile up because the last step always stayed manual.
    • Security-conscious teams get a least-privilege permission model and a recorded reason for every change, so write access stays narrow and reviewable.
    • Anyone accountable for what's running in a client's production sees the risk, pre-checks, and rollback position before confirming, and can schedule the change for a maintenance window.

    How Spotto Actions work

    When a recommendation supports an action, an Implement button appears alongside the usual workflow options, only where there's a supported action behind it, not on every recommendation. Selecting it opens a guided request:

    • Review the recommendation, the affected resources, the risk level, and the pre-checks.
    • Choose the scope: one resource, a selected set, or all affected resources.
    • Add an optional reason, so the decision is clear later.
    • Confirm, then complete the post-validation steps Spotto lays out.

    The same flow can schedule the change for a later one-time run instead of applying it immediately.


    Built for safe change

    Acting from inside Spotto isn't about speed for its own sake, it's a smaller, repeatable change, with the impact clear before anyone touches production.

    • Least-privilege permissions. Each action declares exactly which write or delete permission it needs, so you can build a custom Azure role scoped to only the changes you've enabled. Read-only access still powers everything else; write access is requested only where you want Spotto to make a change.
    • Pre-checks and validation. Actions carry pre-checks, ownership, maintenance window, workload dependency, monitoring readiness, and post-validation steps, because a successful API call isn't always a good production outcome.
    • Rollback, stated honestly. Some actions include automated rollback. Others don't, because the underlying cloud operation can't be undone, and Spotto tells you which is which before you confirm, not after. Deletes are deliberately narrow, targeting only resources that pass orphaned, empty, unattached, or unassigned checks.
    • Staged rollout. Apply an action to one low-risk resource, validate it, then roll the same change across the rest once the pattern's proven.

    The Azure recommendations you can act on today

    The supported set covers the recurring, well-defined fixes an MSP meets across client estates:

    • Security tightening, set a minimum TLS 1.2 on App Service and storage accounts, enable secure transfer on storage, disable a Redis non-SSL port, disable blob anonymous access, and disable basic auth or FTP deployment on App Service. Several are reversible.
    • Cleanup of orphaned and unused resources, delete unattached network interfaces, unassigned network security groups, empty resource groups, orphaned application gateways, Bastion hosts, Front Door profiles, unused load balancers, and idle Synapse workspaces. These are deletes with manual recovery, so each one acts only after its checks pass and you confirm.
    • Configuration fixes, enable Always On, enable HTTP/2, or switch an App Service worker process to 64-bit.

    The supported list grows as new actions clear their safety and validation rules. And when a recommendation has no action yet, you're not left guessing, Spotto gives you a step-by-step playbook to fix it yourself: what to change, where, and how to confirm it worked. Every recommendation has a path to done.


    One step in a bigger motion: cloud operations meets revenue intelligence

    Acting in place is the routine end of acting on what Spotto finds, and the newest layer on a platform that already turns findings into scoped Statements of Work, tracked PSA tickets, and client-ready reports. Together, that's how an MSP acts across its whole book at a scale it couldn't reach by hand. And the set of actions Spotto can take in place keeps growing.

    Every fix leaves the client's environment genuinely better, safer, more reliable, better optimized. The bigger work goes further still: the projects a client actually needs, that you can scope, price, and deliver.


    Get started

    Remediation actions and scheduling are available now for supported recommendation types on managed Azure estates. Open a recommendation with an action available and you'll see the Implement option, start with one low-risk resource, watch it apply with the pre-checks and rollback position shown up front, then roll the same fix across the rest.

    See what's sitting in the estates you already manage, and start clearing it. Your Spotto contact can help set up the least-privilege role so write access stays scoped to exactly the changes you choose to enable.

    See it on your own estates

    Connect one tenant read-only and see what Spotto surfaces across the clients you already manage.