tatersecurity.com Open App

Dashboard Guide

A comprehensive walkthrough of all dashboard features, from the main compliance view to team management, risk scoring, GRC status, and policy generation.

COMPLIANCE
● 85% passing   ● 8% failing   ● 4% manual   ○ 146 not scanned
4,306
Total Controls
12 scan(s)
3,670
Passing
85% compliant
327
Failing
Needs remediation
163
Manual Review
Needs verification
146
Not Scanned
No scan data yet
2
Overridden
2 risk · 0 overrides
ATTENTION: 163 controls in Manual Review awaiting evidence 1 override expiring within 30 days 12 controls failing > 30 days
RISK ANALYSIS
812
TOTAL RISK SCORE
4
CRITICAL RISKS
2.1
AVG RISK SCORE
REMEDIATION SLA
288
WITHIN SLA
31
SLA WARNING
8
SLA BREACH
Illustrative layout of the current dashboard. Predicted Pass / Predicted Fail cards also appear when “Predict the Unknown” is enabled.
What you see depends on your role

This guide is written for OrgAdmin and Auditor users. Viewer-role users see the same dashboard but with limited drill-down rights (no ability to acknowledge alerts, approve overrides, or edit settings). MSP and SuperAdmin users see additional widgets covering multi-org rollup and platform telemetry. Most-restricted views still surface the KPIs, trend chart, and readiness gauges. If a specific control or feature mentioned here isn't visible in your dashboard, your org admin may have hidden it via the Features & Groups settings.

Main Dashboard

The main dashboard provides at-a-glance compliance visibility with key performance indicators, trend analysis, and recent activity. It is the default landing page after sign-in and can be accessed at any time from the sidebar.

Key Performance Indicators

Located at the top of the dashboard, KPI cards display real-time compliance metrics. Each card is clickable and deep-links to the Controls page pre-filtered to that status:

  • Total Controls: Every security control in scope across your compliance zones - the full catalog (CIS Benchmarks, CISA SCuBA, DISA STIGs, and any custom frameworks), not just the controls a scan happened to cover. The sub-label shows how many scans are loaded.
  • Passing: Controls confirmed compliant in the latest scan (plus any verified via a manual-verification override). The sub-label is the headline % compliant = Passing ÷ Total Controls.
  • Failing: Controls that did not meet their benchmark requirement - active gaps needing remediation or a risk-acceptance decision.
  • Manual Review: Controls that can't be evaluated automatically (policy, process, access-review, and judgment-based checks) and need a human to verify with evidence.
  • Not Scanned: Controls in your catalog with no scan data yet - a coverage gap, not a pass or fail. The compliance posture of these controls is unknown until you run a scan or mark them N/A from Compliance Zones. (This card appears only when there are unscanned controls.)
  • Not Applicable (unlicensed): Controls that check an M365 feature your tenant isn't licensed for (e.g., Defender for Cloud Apps, E5 advanced auditing). TATER reads the tenant's provisioned service plans (subscribedSkus / ServicePlans) and automatically flips these license-gated controls to ⊘ N/A with a reason, excluding them from the compliance % - so an inapplicable control never drags your score or sends you chasing a setting you can't reach. A real Pass/Fail result is never overwritten, and if service-plan data is unavailable nothing is flipped.
  • Overridden: Controls with an active risk acceptance or formal override. The sub-label breaks this into "N risk · M overrides" and flags any expiring within 30 days.
  • Predicted Pass / Predicted Fail: Shown only when Predict the Unknown is enabled (Settings → Features). These estimate whether each Manual-Review control's default OS/tenant setting meets the benchmark, surfacing likely-compliant vs likely-non-compliant controls before a scan confirms them.
Why "% compliant" counts the whole catalog

TATER is catalog-first: the denominator for compliance is every control in scope, including Not Scanned ones. A low percentage with a large Not Scanned count usually means a coverage gap (a scan isn't running or isn't landing), not that your environment is failing - run or fix the relevant scan, or mark out-of-scope controls N/A, to get an accurate posture.

Tip

Click any KPI card to filter the controls view to show only controls in that status. For example, clicking "Failed" will navigate to the controls page filtered to only failing controls.

Compliance Bar

The compliance bar is a horizontal stacked bar chart beneath the KPIs showing the proportion of each status category. It provides a quick visual indicator of overall health:

  • Green: Passing controls (includes manually-verified overrides)
  • Red: Failing controls
  • Amber: Manual review required (includes risk-accepted overrides)
  • Teal / Pink: Predicted Pass / Predicted Fail (only when "Predict the Unknown" is enabled)
  • Gray: Not Scanned - controls with no scan data yet

A "○ N not scanned" count appears beside the bar so coverage gaps are always visible alongside the pass/fail/manual split.

Connector Health Banner

When a service connector hasn't been established, every control that depends on it silently falls back to Manual - which can bury dozens of unscannable controls without an obvious cause. The dashboard now rolls these up into one actionable banner per missing connector, for example:

  • "Teams connector not established → 25 controls unscannable"
  • "Intune connector not established → 12 controls unscannable"

Each banner includes a one-click Connect action that takes you straight to the connector setup, so you can restore scan coverage without diagnosing the Manual pile-up by hand. Banners apply to any scan-source connector (Teams, Intune, Fabric, SharePoint, and others) and disappear once the connector is established.

Historical Trend Chart

The trend chart plots compliance data from scan history combined with current resolved totals:

  • Each data point represents a scan, plotted chronologically along the X-axis
  • The latest data point includes resolved totals, accounting for overrides and current scan results
  • Historical points show raw Pass/Fail/Manual counts as they were at scan time
  • Hover over any data point to see exact counts and date
  • Click a scan point to drill into that specific scan's detailed results
  • Multiple scan types (Cloud, Endpoint) are plotted on the same timeline
How the trend line works

The trend chart uses historical scan data for past points and current resolved totals for the latest point. This means the most recent point reflects overrides and manual adjustments, while historical points show the raw scan results at the time they were recorded.

Priority Distribution Chart

The priority distribution chart breaks down findings by severity level, helping you prioritize remediation efforts:

PriorityDescriptionSLA Default
CriticalRequire immediate attention; active exploitation risk24 hours
HighShould be addressed in the near term7 days
MediumPlan for remediation in the current cycle30 days
LowLonger-term improvement targets90 days

Primary Application Highlighting

Applications marked as "Primary" in Compliance Zones settings receive special dashboard treatment:

  • Sorted to the top of the application compliance list with a star badge
  • Displayed with an accent-colored left border for visibility
  • Prioritized in reports and executive summaries
  • Shown first in the compliance bar breakdown
Tip

Set the primary flag in Settings > Compliance Zones by checking the "Primary Application" checkbox on any zone.

Risk Analysis

Risk Score KPIs

The dashboard includes weighted risk scoring to prioritize remediation efforts:

  • Total Risk Score: Aggregate weighted risk across all failing controls
  • Critical Risks: Count of failing controls with risk score above the critical threshold
  • Average Risk: Mean risk score across all evaluated controls
  • Risk Trend: Arrow indicator showing risk direction compared to previous scan

SLA Summary

SLA monitoring tracks remediation timelines for failing controls:

SLA StatusDescription
Within SLA (green)Remediation on track within the defined deadline
Warning (yellow)Approaching SLA deadline, typically within 48 hours
Breach (red)Exceeded remediation deadline, escalation triggered

Default SLA deadlines by severity: Critical = 24 hours, High = 7 days, Medium = 30 days, Low = 90 days.

Customization

SLA deadlines can be configured per organization in Organization Settings. Override individual control SLAs when business context requires different timelines.

Live Readiness Gauges (per framework)

Below the KPI row, the dashboard displays readiness gauges for your top 4 active frameworks. Each gauge is a weighted compliance score that estimates how prepared you are for an audit on that framework - not just the raw pass rate, but a criticality-aware rollup.

Scoring rubric

Each control's contribution is weighted by status, then multiplied by a criticality factor:

  • Status weights: Pass = 1.0 · Verified (manual verification override) = 1.0 · Risk Accepted = 0.9 · Manual Review = 0.5 · Fail = 0 · Not Scanned = 0
  • Exempt / Not Applicable = neutral (out of scope): a control covered by an approved, non-expired Exception is removed from the readiness denominator entirely rather than earning partial credit. Marking a genuinely inapplicable control Not Applicable (e.g. a DISA STIG on a commercial firm, or a Linux benchmark with no Linux estate) therefore does not drag the gauge below 100% — it simply stops counting, the same as descoping it via a Compliance Zone. (Risk Accepted stays 0.9 because the control still applies; it is a failing control whose risk you have formally accepted.)
  • Criticality multipliers: Critical / High = 1.0 · Medium = 0.75 · Low = 0.5

Color thresholds

ScoreColorGrade line
≥ 95%Green (pass)Audit-ready
≥ 85%CyanClose to audit-ready
≥ 70%Amber (manual)Material gaps to close
≥ 50%OrangeSignificant remediation needed
< 50%Red (fail)Not audit-ready

Click any gauge card to jump to the standard detail page for that framework, which lists the specific gaps contributing to the score.

Needs Attention Strip

Just below the KPI row, the Needs Attention strip surfaces items requiring action right now:

  • Risk Acceptances expiring within 30 days - click to jump to the Risk Acceptances page
  • Exceptions pending review - click to Exceptions
  • Controls in Manual Review - click to Controls v2
  • Persistent failing controls - failing for >30 days with no risk acceptance / exception

The strip is hidden when no items need attention. Each card is clickable and pre-filters the destination page.

MITRE ATT&CK Coverage

The dashboard displays MITRE ATT&CK coverage showing which adversary techniques your controls defend against:

  • Technique badges: Controls mapped to MITRE techniques display tactic and technique IDs (e.g., T1078 Valid Accounts, T1110 Brute Force)
  • Coverage percentage: Percentage of mapped techniques with at least one passing control
  • Gap identification: Techniques with no passing controls are highlighted in red, indicating defensive gaps
  • Tactic groups: Techniques are grouped by MITRE tactic (Initial Access, Persistence, Privilege Escalation, etc.)

Compliance Drift Alerts

Drift alerts notify you when controls change status between scan cycles. When a previously passing control regresses to Fail, a drift alert is generated.

Drift Alert Banner

When drift is detected, a banner appears at the top of the dashboard showing:

  • Drift count: Number of controls that changed from Pass to Fail since last scan
  • Affected frameworks: Which frameworks are impacted by the regression
  • Quick action: Click the banner to jump to the list of drifted controls for immediate review
Warning

Drift alerts indicate that previously passing controls are now failing. This may be caused by configuration changes, policy updates, or environmental changes. Investigate drift alerts promptly to prevent compliance gaps from widening.

GRC Status Widget

The GRC status widget provides a consolidated view of all Governance, Risk, and Compliance modules in a single dashboard panel:

  • Open Risks: Count of unresolved risks in the Risk Register with severity breakdown
  • Pending Exceptions: Exception/waiver requests awaiting approval
  • Upcoming Audits: Next scheduled audit engagements and their dates
  • Training Compliance: Percentage of staff who have completed required training
  • Control Test Results: Recent test pass/fail rates
  • BCP/DR Status: Days since last BCP/DR test exercise

Click any item in the GRC status widget to navigate directly to the relevant module for detailed management.

Tasks Widget

The tasks widget surfaces tasks from TATER Ops - the unified task system that backs the TATER app suite. (Previously TATER Security had its own separate task system; that has been consolidated into Ops so there is exactly one place tasks live.) Click any task to open its detail modal directly in Ops, or click the widget header to navigate to ops.tatersecurity.com → Tasks for full management.

The widget shows your assigned tasks and upcoming deadlines:

  • My Tasks: Tasks assigned to you across all modules (controls, audits, remediations)
  • Overdue: Tasks that have passed their due date, highlighted in red
  • Due Soon: Tasks due within the next 7 days
  • Quick Actions: Mark tasks as complete or snooze directly from the widget

Feedback Widget

The feedback widget provides access to the UserVoice-style feedback system directly from the dashboard:

  • Submit Ideas: Propose new features or improvements
  • Vote: Upvote or downvote existing suggestions from other users
  • Status Tracking: See which ideas are Under Review, Planned, or Completed
  • Comment: Add context or use cases to existing feedback items

Controls Page

Search by ID, title, description…
Status: All ▾ Framework: CIS ▾ Severity: All ▾ Domain: All ▾
CONTROL IDTITLEAPPLICATIONRISKSTATUS
ENT-MFA-001Require MFA for all usersEntra ID2.0Pass
EXO-004Block external auto-forwarding ▾Exchange8.5Fail
Remediation: Set the outbound spam policy AutoForwardingMode to Off.
Scan history: Fail · Fail · Pass  |  Frameworks: CIS 6.2.1 · SOC 2 CC6.7 · NIST SC-7  |  MITRE T1114
Risk 8.5 · SLA breach in 2d   ⚡ Remediate Assign 💬 2 comments
SPO-007Restrict external sharingSharePoint5.0Manual
Illustrative layout of the current Controls page.

The Controls page displays all compliance controls with advanced filtering, sorting, grouping, and detail expansion.

Filtering & Sorting

  • Status filter: Show Passing, Failing, Manual Review, Not Scanned, or Overridden
  • Framework filter: Filter by CIS, NIST, ISO 27001, SOC 2, PCI-DSS, HIPAA, etc.
  • Severity filter: Critical, High, Medium, Low
  • Text search: Search by control ID, title, or description
  • Framework Category: Toggle between "All / Compliance / Vulnerability" views
  • Domain filter: Filter by control domain (Identity, Data Protection, Network Security, etc.)

Control Detail Expansion

Click any control row to expand its detail panel showing:

  • Full description and CIS remediation guidance
  • Status details explaining why the control passed or failed
  • Scan history showing status trend across previous scans
  • Framework mappings and cross-references to NIST, ISO, SOC 2, etc.
  • Assigned owner and current override status
  • MITRE ATT&CK technique badges
  • Risk score and SLA deadline with countdown
  • Remediate button (if automated remediation is available for the control)
  • Comments thread for team discussion

Risk Acceptances Page

RISK ACCEPTANCES & OVERRIDES
+ New Override
CONTROL IDTYPESTATUSJUSTIFICATIONAPPROVED BYEXPIRES
EXO-004Risk AcceptedAcceptedLegacy LOB app needs SMTP AUTH; IP allow-list compensatingj.barberin 174d
SPO-007Risk AcceptedAcceptedExternal sharing required for client collaborationd.reynholmin 320d
ENT-009Manual VerifyVerified → PassConfirmed via tenant screenshot; evidence attachedr.trennemanexpired
Manual-verification overrides resolve to Pass; risk acceptances resolve to Accepted. Expiring/expired records are flagged on the dashboard.

Create formal risk acceptance records for failing controls with time-bound exemptions and business justification.

Creating an Override

Create a new override

Click "New Override" and select the control to override from the dropdown or search by control ID.

Choose override type

Select "Risk Acceptance" (permanent until revoked) or "Temporary Exemption" (requires an expiration date).

Document justification

Enter the business justification explaining why the risk is accepted and assign an owner responsible for monitoring the exception.

Save and track

The override is tracked in the register with automatic expiration warnings 14 days before the due date. Overridden controls show "Override" status instead of "Fail" on the dashboard and reports.

People & Assignments

Manage team members and assign controls for accountability:

  • Add person: Register team members by name and email, or search Entra ID directory
  • Assign controls: Allocate failing controls to team members for remediation ownership
  • Bulk assign: Use the bulk assignment feature to assign multiple controls at once
  • Entra ID search: Search your organization's Entra ID directory to find and add users
  • Workload view: See how many controls each person owns and their completion rate
  • Due dates: Set remediation deadlines per assignment with SLA tracking

Policy Template Library

POLICY LIBRARY
📋 From Template + New Policy
TEMPLATES
Information Security
InfoSec · ●●●
Acceptable Use
HR · ●●○
Incident Response
Security · ●●●
Vulnerability Mgmt
Security · ●●○
YOUR POLICIES
Information Security Policy v3Published
Incident Response Plan v2Review
Data Retention Policy v1Draft
Generate from a template with {{variable}} fill-in, then export to PDF or publish to the public Policy Library.

Generate security policy documents from pre-built templates with variable substitution.

Available Templates

TATER includes 21 pre-built policy templates covering common compliance requirements:

  • Information Security Policy
  • Acceptable Use Policy
  • Incident Response Policy
  • Access Control Policy
  • Data Protection and Privacy Policy
  • Vendor Management Policy
  • Business Continuity Policy
  • Change Management Policy
  • Network Security Policy
  • Physical Security Policy
  • Vulnerability Management Policy
  • Password & Authentication Policy
  • Encryption & Cryptography Policy
  • Asset Management Policy
  • Privileged Access Management (PAM) Policy
  • Cloud Security Policy
  • Mobile Device & BYOD Policy
  • Email Security Policy
  • Backup & Recovery Policy
  • Secure Software Development Lifecycle (SDLC) Policy
  • Artificial Intelligence (AI) & Generative AI Usage Policy

Generating a Policy

  1. Navigate to the Policies page from the sidebar
  2. Click From Template to open the template browser
  3. Browse or search templates by category, difficulty, or framework mapping
  4. Select a template and fill in the variable form (organization name, CISO, dates, etc.)
  5. Preview the generated Markdown document in the preview panel
  6. Save as a draft or export to PDF with organization branding (cover page, table of contents, back page)
Variable caching

Common values like organization name and CISO are cached across templates, so you only need to enter them once. The cache persists for the duration of your session.

Trust Center

R
Reynholm Industries
Trust Center
FRAMEWORK COMPLIANCE
94%
CIS Microsoft 365
91%
SOC 2 (TSC)
82%
CISA SCuBA
88%
NIST CSF
SECURITY PRACTICES
✓ MFA enforced ✓ Encryption at rest ✓ SSO / SCIM ✓ Annual pen test
SUB-PROCESSORS & DOCUMENTS
Microsoft Azure · Cloudflare · Stripe
🔒 SOC 2 Type II report (NDA-gated)
Ask a security question… Ask
Public, shareable posture page. Live framework scores, security practices, sub-processor registry, NDA-gated documents, and self-serve Q&A.

The Trust Center is a public-facing compliance posture dashboard showing framework compliance percentages, certifications, and security practices. Share it with customers and partners to demonstrate your security commitment.

  • Framework scores: Compliance percentage for each active framework
  • Certifications: Display earned certifications and audit dates
  • Security practices: Summary of implemented security controls and practices
  • Embeddable widget: Generate a compliance widget to embed on your website
  • Use the left sidebar to move between pages; sections collapse for easier navigation
  • Breadcrumbs at the top show your current location in the app
  • Dark/light mode toggle in the header adapts to your preferred viewing mode
  • Responsive layout adapts to tablet and mobile viewports
  • Use the organization switcher in the header to manage multiple organizations
  • Keyboard shortcut Ctrl+K opens the global search across all pages