tatersecurity.com Open App

TATER Documentation

Welcome to the TATER documentation. Find guides, references, and tutorials for managing compliance across your Microsoft 365 tenants and endpoint environments.

5,000+
Compliance Controls
19
Frameworks
1,446+
Remediation Scripts
13
GRC Modules

Compliance

Security & Devices

Fleet Management

Track your entire device fleet with compliance scoring, MDE integration, and drill-down analytics.

Security Operations

Identity security, automated remediation, incident playbooks, and Azure resource scanning.

Implementation Guides

Curated step-by-step rollouts for Conditional Access, MFA, DMARC, BitLocker, PIM, and other common security initiatives. Per-org progress tracking with verification + rollback at every step.

TATER Tips

50+ short, action-oriented tips covering every TATER capability — each one deep-links to the page it describes. Login popup with per-user opt-out, MCP-accessible for AI walkthroughs.

Power BI Integration

Connect Power BI Desktop, Excel, or Fabric to TATER's flat data endpoint (controls, scans, risks, overrides, vendors, audits, training, BCP/DR, policies, changes). Scheduled refresh-friendly.

Power Automate Integration

Custom connector for Power Automate flows — query compliance data, create risk acceptances, trigger scans, and react to scan.completed webhook events.

MCP Feedback

How TATER MCP casually solicits feedback during a session, auto-files ADO Issues on negative sentiment, and exposes a SuperAdmin review page tracking every submission.

TATERpedia

Wikipedia-style platform-shared wiki for generic process knowledge — troubleshooting playbooks, diagnostic decision trees, remediation methodology. Searchable, contributable by any Auditor+.

Evidence Agent

Autonomously collect compliance evidence by navigating Microsoft admin portals and running PowerShell controls — driven by AI, running on your local TATER agent.

Agent Deployment

Install the TATER agent on endpoints via MSI. Deploy silently with Intune, SCCM, or Group Policy.

Agent Network Requirements

FQDN bypass list and per-vendor SSE/SASE config (Microsoft GSA, Zscaler, Netskope, Umbrella, Prisma Access). Required for accurate speed tests and Evidence Agent connectivity.

GRC Modules

Risk Register & Heat Map

Central risk register with 5x5 heat map, quantitative ALE scoring, treatment plans, and risk-to-control linkage.

Exception & Waiver Management

Structured exception requests with multi-level approval chains, automatic expiry, and compensating controls.

Audit Management

Plan audits, track findings, collect evidence from control owners, and maintain an audit calendar.

Business Continuity & DR

BCP/DR plans with BIA, RTO/RPO tracking, and test exercise management for audit compliance.

Data Classification & Privacy

Data asset inventory, flow mapping, privacy impact assessments, and retention policy management.

Security Awareness Training

Training campaigns, completion tracking, phishing simulation results, and audit-ready evidence reports.

Control Testing Automation

Scheduled test plans, reusable procedures, historical results with trend analysis, and gap detection.

Vendor Risk Management

Vendor inventory, risk tiering, assessment tracking, and continuous monitoring.

Access Reviews

Periodic access review campaigns with approve/revoke decisions and audit trail.

GRC Calendar

Unified timeline of all GRC obligations: access reviews, control tests, exceptions, BCP/DR tests, training deadlines, and vendor assessments.

Regulatory Change Management

Track framework updates and regulatory changes, assess their impact on your controls, and manage the transition to compliance with new requirements.

Change Control

Structured approval workflow for High and Critical impact control changes. Low/Medium auto-approved; scan-detected changes auto-generate requests.

Custom Control Frameworks

Build custom frameworks with drag-and-drop domains, import/export via JSON for MSP distribution, and cross-map to standard frameworks.

Collaboration

Platform Customization

Integrations

Audit & Activity

People & Organizations

Azure Setup

Sales & Positioning

Platform Features

M365 Auditing: Exchange, Teams, SharePoint, Defender compliance
OS Scanning: Windows 11, Server 2019/2022/2025 CIS benchmarks
Endpoint Security: MDE vulnerabilities, CISA KEV, EPSS scores
Multi-Framework: NIST 800-53, ISO 27001, SOC 2, PCI-DSS, HIPAA
Risk Scoring: Weighted risk prioritization with SLA tracking
Drift Alerts: Real-time compliance regression detection
Remediation: One-click automated remediation via Azure Automation
Policy Templates: 11 pre-built security policy templates
Fleet Tracking: Device compliance across your entire estate
MITRE ATT&CK: Adversary technique coverage mapping
Smart Discovery: Auto-discover software with version tracking
Executive Reports: PDF/CSV reports for board and auditors
Risk Register: Heat map, ALE scoring, treatment plans
Audit Management: Plan, findings, evidence collection
BCP/DR: Plans, BIA, RTO/RPO, test tracking
Data Classification: Inventory, flow mapping, PIAs
Training Tracking: Campaigns, completion, phishing sims
Control Testing: Scheduled tests, procedures, gap detection
Custom Frameworks: Builder, import/export, cross-mapping
Exception Mgmt: Approval chains, expiry, compensating controls
Regulatory Change: Impact assessment, deadlines, transitions
GRC Calendar: Unified obligation timeline with deadline alerts
Licensing: Plan types and user/admin seat limits per org
Access Reviews: CSV import and manual user population
Compliance Roadmap: Multi-phase remediation planning with Phase 0 Discovery and cascading durations
MSP Portal: Multi-tenant management with tiered client access and white-labeling
Change Control: Approval workflows for High/Critical impact changes
Widget Dashboard: 16 drag-and-drop widgets with start page option
Community: XP levels, achievements, leaderboards, challenges
Auditor Portal: Read-only evidence packages with time-limited access
Vendor Management: Vendor inventory, risk tiering, questionnaires
AI Analyst: Agentic AI assistant for compliance workflows (12-iteration tool loop)
MCP Integration: 61 tools for Claude Desktop and claude.ai
Evidence Agent: Autonomous browser-based evidence collection
Favorites: Star any page for quick topbar access

System Requirements

Requirement Details
Web Browser Chrome, Edge, Firefox, or Safari 11+ with JavaScript enabled
PowerShell 5.1 or newer for scan script execution
M365 Admin Security Admin, Compliance Admin, or Global Admin role for cloud audits
Local Admin Administrator privileges on target machines for OS scans
Network HTTPS access to Microsoft Graph API (port 443) for cloud scans

Quick Start

Sign in to TATER

Navigate to app.tatersecurity.com and authenticate with your Microsoft Entra ID credentials.

Configure your organization

Go to Settings to configure company name, logo, accent colors, and tenant credentials.

Run your first scan

Execute a cloud or OS scan using the provided PowerShell scripts, or trigger a server-side scan from the dashboard.

Review compliance posture

View the dashboard for compliance scores, control status, and risk metrics across all frameworks.

Take action

Create overrides for accepted risks, assign controls to team members, trigger automated remediation, and generate reports.