A single table per program, reviewed weekly. Lives in the team wiki or as a shared query over work items tagged risk / dependency; this page is the format.
Exposure = likelihood × impact. ≥ 9 goes into the weekly stakeholder update; ≥ 12 needs a decision owner above the team.
Responses: avoid (change the plan), mitigate (reduce likelihood or impact), transfer (another team or vendor owns it), accept (record who accepted it and until when).
Dependency statuses: Requested → Confirmed (date agreed) → Delivered, or At risk (confirmed date missed or unconfirmed within 5 business days of request).
SignalR Free tier quota (20 000 msg/day) → exhausted during a large incident → live updates stop
2
3
6
mitigate
Client refetch fallback in place; Bicep param for S1 tested; trigger: > 15 000 msg/day
M. Roman
2026-10-09
Open
R-015
2026-09-29
API key shared by Functions and alert sources → rotated on one side only → escalations and alert ingestion fail
3
3
9
mitigate
Rotation runbook updates the deployment secret (Container Apps secret, Function app setting, Action Group URL) and the Alertmanager file together; alert on 401s from Functions
A. Ribeiro
2026-10-06
Open
R-016
2026-09-29
Serverless SQL auto-pause → first request after idle takes seconds → availability test flaps at night
3
1
3
accept
Accepted by EO until traffic justifies provisioned tier; review quarterly
D. Okafor
2026-12-15
Accepted
ID
Raised
We need
From
Needed by
Confirmed
Impact if late
Status
Work item
D-007
2026-09-29
Contributor on Action Groups in production subscription