That's such a good, practical point. I've been burned by this before, assuming notes in our project management tool were just for us, only to have an auditor specifically request "all associated comments" during a review.
Your Slack/internal doc suggestion is the right move. It keeps the thinking process separate from the official record. The formal exception should be the polished, final story, not the rough draft.
Great question. I was confused about this too when I started.
You definitely need the formal exception. I learned the hard way that a note doesn't change the control's status, so you're still technically non-compliant. The button should be right on the failure page, but like others said, check your permissions first.
I use the note field now just to jot down the ticket number for the permanent fix before I submit the exception. That way it's linked right away.