Skip to main content

Review Checklists: Best-Practice Coverage

Overview

Review Checklists in Spotto scan selected Azure subscriptions for best-practice coverage and surface the gaps that matter. They combine automated checks with effort estimates, clear business context, and manual verification so you can run consistent reviews across teams and environments.

Why use this? (Jobs, pains, gains)

Jobs to be done

  • When I need a WAF or landing-zone review, I want a repeatable checklist that shows coverage across subscriptions, so I can report on readiness and risk.
  • When I see an open item, I want to know the likely effort and why it matters, so I can prioritize work.
  • When checks cannot be automated, I want a place to document manual verification, so the review is still auditable.

Common pains

  • Reviews get trapped in spreadsheets and never stay consistent across subscriptions.
  • Best-practice guidance is scattered across docs, and context is missing when you need it.
  • Manual checks are hard to track and easy to lose.

What you gain

  • A single review flow that aggregates findings across subscriptions.
  • Status, severity, and coverage charts that show progress at a glance.
  • Effort estimates and rationale so review items come with context, not just a label.

Turn the evidence into a decision

After selecting a checklist, select the labelled briefcase Business Value button beside Notes. The brief combines live open/unverified, fulfilled, high-priority, and non-compliant results with a priority body of work.

Live results are not replaced by AI. Generate tailors only the narrative and saves it for that checklist and exact subscription scope, so another checklist retains its own brief. Clear removes only that checklist's saved narrative and immediately restores its standard Business Value content without deleting Customer Context or changing live results. Regenerate when evidence changes. Above 100 subscriptions, the curated live brief remains available without tailoring.

Current position and priority work

Resolve high-severity open or unverified findings that affect foundational controls or multiple services. Classify the remaining items as remediation, accepted trade-off, or deferred work and sequence them against the delivery roadmap.

Business outcomes

A review makes architecture trade-offs explicit before more workloads depend on them. WAF reviews test workload decisions across the five pillars, while Landing Zone reviews validate the identity, networking, policy, security, and operations foundation used by the wider estate.

Cost of delay

Unreviewed foundations can lead to inconsistent controls, slower delivery, audit gaps, hidden resilience problems, and retrofit work that is more expensive and disruptive later. Not every failed item warrants remediation; some are legitimate, documented trade-offs.

Decision required

Agree which findings will be remediated, accepted, or deferred, with an owner and target date for every priority group.

Validate with stakeholders

When you can manage Company Notes, select any question in the portal to retain the answer in the relevant Customer Context note.

  • Which business outcome, audit, migration, or growth event prompted the review?
  • Which findings represent accepted design trade-offs or compensating controls?
  • Who can accept residual risk and fund the agreed improvements?

Key capabilities

Where to find it

In the Spotto Portal, open your company and navigate to Generate -> Generate -> Review Checklists.

Choose a checklist and subscriptions

Pick a checklist from the catalog and select one or more subscriptions. Spotto runs the review per subscription and aggregates results into a single view.

Run scans and track coverage

Use Scan All to queue checks for the selected subscriptions. The summary shows per-subscription status and the last run time, so you can see coverage and progress without guesswork.

Review items and statuses

Results are aggregated by checklist item and can be searched, filtered by Category and Status, and sorted by fields like Pillar, Service, or Severity.

Status values include:

  • Open
  • Unverified
  • Fulfilled
  • Not required
  • Not Applicable
  • Error

Effort and business context

Each item can include an effort estimate (hours) and a short explanation of what drives that effort. In business view, Spotto surfaces plain-language summaries to make stakeholder reviews less painful.

Manual verification and comments

Some checks require human validation. For those items, the detail view flags manual verification and lets you update status and comments across the selected subscriptions.

Resource lists and export

Item details list compliant and non-compliant resources, with search and direct links to resource details. You can also export results to CSV or Word for audit trails, customer review, or follow-up work.

When available, each item links to supporting documentation or training modules so reviewers can jump straight to guidance.

Common starting points include:

  • Well-Architected Framework (WAF)
  • Azure Landing Zone
  • Cost Optimization
  • AKS
  • API Management
  • Front Door

The full catalog includes additional platform and workload-specific checklists.

Technical reference

ComponentDetails
InputsChecklist catalog, Spotto review scans per subscription, and resource metadata for compliant/non-compliant items.
OutputsAggregated checklist results, coverage charts by status and severity, per-item details with resource lists, and CSV or Word export.
DefaultsItems without a result are shown as Unverified until a scan or manual update is recorded.

How it differs from cloud-native reviews

Cloud-native assessments often live in separate portals or spreadsheets. Spotto keeps the review in one place and adds:

  • Cross-subscription coverage and rollups.
  • Effort estimates and rationale to support prioritization.
  • Manual verification and comments as first-class data, not a footnote.

How it works (high level)

  • You select a checklist and subscriptions.
  • Spotto queues a scan per subscription and stores a review document for each.
  • Results are aggregated by checklist item so you see a single checklist view.
  • Detail pages show context, effort, status, and linked resources, with manual updates when needed.

Limitations (honest, boring, useful)

  • Not real-time: results appear after a scan completes and data syncs.
  • Single cloud account per scan: subscriptions must belong to the same cloud account to run a scan.
  • Some items are manual: not every best practice can be automated, and those items require verification.

Troubleshooting

Scan button is disabled

What you're seeing: Scan All is disabled. Likely causes:

  • No checklist selected.
  • No subscriptions selected.
  • Selected subscriptions belong to multiple cloud accounts.
  • Your role lacks scan permissions. How to fix:
  1. Select a checklist from the catalog.
  2. Select subscriptions from a single cloud account.
  3. Ensure your assigned role includes review checklist scan permission.

No results yet

What you're seeing: The page shows an empty state or pending scan banner. Likely causes:

  • A scan has not been run yet.
  • The scan is still processing. How to fix:
  1. Run Scan All and wait a few minutes.
  2. Check the per-subscription status summary to confirm progress.
  3. Refresh the page after the scan completes.

Manual verification required

What you're seeing: A checklist item says manual verification is required. Likely causes:

  • No automated check exists for that item. How to fix:
  1. Verify the item manually.
  2. Update status and comments in the detail view.
Optimize Your Azure Environment

Looking to enhance your cloud setup for cost efficiency, performance, reliability, or security?

Talk to a cloud specialist. Email us or schedule a 30-minute consultation and let's optimize your cloud environment together.

Book a Free Consultation