tatersecurity.com Open App

TATER Documentation

TATER is one connected platform - six apps that share a single Microsoft Entra sign-in, a single data model, and a single AI layer. Pick the app you need below, or browse the guides by topic.

6
Connected Apps
4,000+
Compliance Controls
19
Frameworks
450+
AI / MCP Tools

The TATER Platform

Six apps, one platform. Each owns a distinct job and links to the others - shared identity, shared data, shared AI. Start with the app that matches what you're doing today.

For End Users

If you're an everyday user of TATER (not an admin), start here. These guides cover submitting requests, tracking what you've submitted, and using your personal dashboard.

Compliance

TATER Security — Compliance & Endpoints

The compliance and security core: scanning, fleet and endpoint management, remediation, hardening, evidence collection, and continuous monitoring. App overview →

Fleet Management

Track your entire device fleet with compliance scoring, MDE integration, and drill-down analytics.

Endpoint Management (UEM)

Live interactive shell, patch management, software deployment, BitLocker key escrow, USB / app-allow / JIT-admin / power / browser / DNS policies. Endpoint Central parity built on TATER agents.

Security Operations

Identity security, automated remediation, incident playbooks, and Azure resource scanning.

Interactive Remote Control

WebRTC remote-support sessions to managed endpoints. PE-3 end-user consent, mouse/keyboard input injection, multi-monitor selection, and AU-14 session recording with in-app playback. Full NIST 800-53 ATO mapping.

Implementation Guides

Curated step-by-step rollouts for Conditional Access, MFA, DMARC, BitLocker, PIM, and other common security initiatives. Per-org progress tracking with verification + rollback at every step.

TATER Tips

50+ short, action-oriented tips covering every TATER capability - each one deep-links to the page it describes. Login popup with per-user opt-out, MCP-accessible for AI walkthroughs.

API Reference

Canonical X-API-Key auth, error catalog, key scoping, and curl/PowerShell/Python snippets for MSP and partner automation against the TATER REST API.

Power BI Integration

Connect Power BI Desktop, Excel, or Fabric to TATER's flat data endpoint (controls, scans, risks, overrides, vendors, audits, training, BCP/DR, policies, changes). Scheduled refresh-friendly.

Power Automate Integration

Custom connector for Power Automate flows - query compliance data, create risk acceptances, trigger scans, and react to scan.completed webhook events.

MCP Feedback

How TATER MCP casually solicits feedback during a session, auto-files ADO Issues on negative sentiment, and exposes a SuperAdmin review page tracking every submission.

TATERpedia

Wikipedia-style platform-shared wiki for generic process knowledge - troubleshooting playbooks, diagnostic decision trees, remediation methodology. Searchable, contributable by any Auditor+.

Evidence Agent

Autonomously collect compliance evidence by navigating Microsoft admin portals and running PowerShell controls - driven by AI, running on your local TATER agent.

Agent Deployment

Install the TATER agent on endpoints via MSI. Deploy silently with Intune, SCCM, or Group Policy.

Agent Network Requirements

FQDN bypass list and per-vendor SSE/SASE config (Microsoft GSA, Zscaler, Netskope, Umbrella, Prisma Access). Required for accurate speed tests and Evidence Agent connectivity.

Application Monitoring

OneDrive health, CISA KEV exposure, and your own templated agent monitors (service, process, port, disk, cert, BitLocker, scheduled task, custom script) as one findings surface. Create monitors, toggle on/off, promote to Ops tasks.

Backup Monitoring

Receive SaaS-backup job health from Keepit, Rubrik, Cohesity and more via their SIEM/webhook push. Failed or missed backups become monitoring findings and auto-created Ops tasks, with a per-provider job dashboard and MCP access.

Power Automate Flow Monitor

Catch Power Automate cloud flows that get turned off, suspended, or start failing above a threshold. Hourly scan, auto-filed Ops ticket per problem flow (auto-closed on recovery), SIEM events, and a Flow Monitor page in TATER Ops.

Power Platform Inventory

A GRC audit inventory of every Power Platform asset — environments, solutions, canvas & model-driven apps, custom connectors, and Power BI workspaces/datasets/reports — each with its maker deep-link, linkable to controls as evidence, with a consolidated CSV audit export and a Power BI feed.

OneDrive Sync Health

Automatic OneDrive sync monitoring, admin alerting with auto-Ops-tasks, opt-in self-heal, and user notifications. 10 health checks with 2-cycle hysteresis to prevent cry-wolf alerts.

OneDrive Business1 Regression

Troubleshooting guide for the recurring failure where the OneDrive Business1 registry record exists but the UserFolder value is missing - diagnostic steps, root cause, and remediation.

TATER Tuning

Per device-group, per app, dial-based hardening. Set a 0-10 level for each group-by-app cell and the TATER Agent enforces it on every device in the group within 30 minutes.

TATER Tuning - M365 Tenant Setup

Extend TATER Tuning to M365 tenant-level columns - setup, required credentials, and how tenant tuning levels are applied alongside endpoint hardening dials.

Self-Service Fixes

Admin-defined diagnose + remediate scripts the agent exposes to end users via the system tray. Auto-opens an Ops task when a fix fails. Seeded with OneDrive Reset + Drive Mappings.

TATER Ops — IT Service Management

A full ITSM help desk on the same platform: tickets, service catalog, change / incident / release, approvals, RFIs, expenses, meetings, surveys, and automation. Lives at ops.tatersecurity.com. App overview →

TATER Ops (Sister App)

Help desk and task management on the same TATER ecosystem. Tasks linked to TATER controls, recurring templates, ADO sync, MCP-driven workflows. Lives at ops.tatersecurity.com.

Independence Management

Audit-practice independence: a client roster (format-agnostic CSV/Excel import), annual full-roster + monthly delta attestation cycles, per-employee sign-off even with no conflicts, and conflict forms linked to the employee and client. MCP tools + Insights reporting.

Staff Roster & Account Classification

One authoritative answer to "who counts as staff?" for every all-staff audience. Automatic classification of admin variants, service principals and outside parties; durable manual overrides for owner/family accounts no rule can detect; departure tombstones that preserve historical attestations; and Entra directory sync that refuses to depart anyone on an incomplete read.

Ops Customization Guide

Per-org settings: hierarchical categories (5 levels deep), custom priority labels, per-category statuses, teams, custom request fields. Searchable typeahead everywhere.

Ops Workflow Automation

Trigger-once coordinated task sets. Define templates with sequential steps, role placeholders, and dependencies - trigger once to spawn all tasks with automatic dependency unlocking.

Ops Approvals & Bulk Actions

Multi-step approval chains per category (Manager → Director → CFO). Bulk-edit mode for selecting many tasks at once and applying status, priority, reassign, close, or archive.

Ops Public Intake (Email + Portal)

Convert email to tickets via Power Automate forwarding, or share the hosted self-service portal URL with end users. Token-gated, multi-mailbox routing supported.

Ticket Auto-Triage & Routing

Score each ticket's content to auto-suggest category, priority, and the assignment-group queue — on inbound email, on demand (🧭 Triage), or via the triage_task MCP tool. Configurable keyword taxonomy.

ITIL 4 Field Coverage

Complete reference for the 46 industry-standard help-desk ticket fields TATER Ops captures - full parity with ITIL 4, ServiceNow ITSM, Jira Service Management, Zendesk, and Freshservice. Documents auto-fill behavior for SLA + lifecycle fields.

ITIL Process Profiles

Per-task profiles that drive field visibility, allowed status transitions, and SLA defaults from an industry standard (ITIL 4 Incident / Service Request / Problem, NIST SP 800-61 IR, or custom). Ships with 5 seeded starter profiles; JSON editor for full customization. Same pattern coming to Risks, Audits, Changes, and Vendors.

Ops Script Library

Reusable PowerShell / Bash scripts with fan-out execution against up to 500 target devices via the TATER Agent. Per-target stdout/stderr capture, aggregated job status, MCP-driven for agent-led remediation. CRUD, versioning, risk levels, and the device/cloud/hybrid execution-target taxonomy (ADO #498).

Scheduled Runbook Execution & Drift Monitoring

Recurring script execution (hourly / daily / weekly / monthly) against device fleets or M365 tenants. Drift detection compares consecutive runs. Action rules fire email or Tasker tasks on drift / failure. Cron checks every 5 min. ADO #497 + #498.

Scheduling & Recurrence

The shared recurrence engine behind anything in TATER that repeats on a cadence - hourly, daily, weekly, monthly, quarterly, or yearly. DST-safe recurrence math, a generic scheduled-jobs store with a handler registry, a 15-minute sweep, run-now, enable / disable, and MCP access.

Cloud Script Execution (M365 / Entra ID)

Run PowerShell maintenance, audit, and diagnostic scripts against your M365 tenant from TATER Ops. Per-org Azure Automation runbook with Graph / EXO / ARM auth contexts. Ships with 8 curated templates (user diagnostic, MFA audit, mailbox delegation, suspicious inbox rules, app permissions, stale guests, license utilization, SharePoint sharing). MCP-addressable. Foundation for the planned shared library + TATERpedia auto-seed.

Intune Deployment from TATER Ops

Create and assign Microsoft Intune Proactive Remediations and Platform Scripts directly via Graph from TATER Ops → Intune. What-If preview, Entra group targeting with a Targets column, change-control gating, and audit logging. 8 MCP tools mirror the GUI exactly for AI-driven deployment.

Reimbursements & Expenses

Submit reimbursements or log company-card spend with multi-line requests, per-line receipts, approval routing, and an AP queue. Reimbursable lines route to an approver then AP pays; company-card lines are logged for reconciliation. Submit from Ops or My TATER → My Expenses, with per-employee reporting in Insights and five MCP tools. Replaces fragile Form → Power Automate intake. ADO #759.

Meetings & Business Documentation

Meeting Records with attendees, agenda, transcripts, decisions, and linked-artifact roll-up. New Business Docs area for SOPs / process maps / role descriptions / vendor briefs. MCP-first: your external LLM does all extraction via 14 new MCP tools; TATER never runs server-side LLM calls. ADO #499 + #501 + #503.

Meeting Recorder

Record the meetings you don't host, right in the TATER agent. Captures system audio + mic and transcribes locally (no cloud, no audio upload), then logs a Meeting Record with an Outlook calendar match. Review & save before anything uploads; extraction happens in your own AI via MCP.

Document Reviews & Acknowledgements

Post one or more internal documents - employee manuals, HR policies, SOPs - for staff to review and acknowledge in a single sign-off. Target specific individuals, all staff in the org, or groups (departments / tags). Auditable trail (who, when, IP, attestation snapshot), completion roster with CSV export, reminder emails before expiry, a weekly pending-reviews digest, and a cross-org My Reviews queue in My TATER.

Reviews & Attestations Engine

The universal engine behind every "N people each sign / attest / decide / complete a checklist" flow - document acknowledgements, sign-offs, attestations. Per-person completion tracking, completion rules (all / quorum / any), reminder and escalation sweeps, a cross-org My Reviews inbox, and MCP access.

Surveys

Build custom surveys (single/multi choice, rating, NPS, scale, text) and distribute them two ways: assign to staff (individuals / all-org / groups, answered in My TATER → My Surveys) or attach to ticket categories so a CSAT survey is emailed automatically when a ticket closes. Aggregated results with NPS, respondent roster, anonymous mode, and a public response page for external requesters.

Approvals (Universal Approval Engine)

One approval engine behind every "needs a decision" flow — travel exemptions, license rentals, change requests, exceptions, and more. Reusable approval groups (optionally Entra-group-backed) with decision modes (any / all / quorum / percentage), multi-stage workflows, automatic reminders + escalation, and a unified My Approvals inbox in My TATER. MCP tools included.

Information Requests (RFI)

Formally request information — typed custom fields (text, select, date, file upload, …) and/or supporting documents — that staff fulfill in My TATER → My Requests or external parties fulfill via a secure tokenized link. Reusable templates, document collection, reminders, accept / request-changes review, an embeddable hook for onboarding/offboarding (new-hire & exit info), MCP tools, and an Insights completion/aging report.

Service Catalog Administration

Design pre-defined request types with form schemas, fulfillment routing, approval flags, owner teams, ETAs. 13 starter items shipped via seed-defaults. ServiceNow-parity catalog.

CMDB / Configuration Items

Proper Configuration Items with 16 types, 10 typed relationships (auto-maintained inverses), criticality-weighted impact analysis, auto-discovery from Devices / CloudAccounts / Vendors. The foundation for Service Portfolio + Major Incident + CAB conflict detection.

Major Incident Workflow

ITIL Major Incident on top of TaskerTask. Bridge URL, incident commander, subscribers with email broadcast, status update log, affected CI rollup from CMDB. Auto-creates Post-Incident Review task on resolve with 14-day due date + 8-item checklist.

Problem Management

ITIL Problem records: the root cause behind recurring or major incidents, with a documented workaround and links to the incidents and CMDB CIs involved. Publish as a Known Error and the workaround is offered automatically on matching tickets. Open → Investigating → Known Error → Resolved → Closed.

Service Portfolio

Business-facing service view on top of CMDB. Health rollup (healthy / degraded / major-outage / maintenance) combines member CI status with active Major Incidents. Executive-friendly dashboard.

CAB Workflow on Change Requests

ITIL Change Enablement with multi-approver voting, conflict detection (window-overlap / same-CI / same-control), change calendar. Standard / Normal / Emergency change types with auto-approval for Standard.

Release Management

Bundle change requests into coordinated deployments. Rollout + rollback step lists with owners and estimated time. Deployment log capped at 500 entries. Auto-stamped lifecycle timestamps.

Projects, Milestones & Sprints

Expand-in-place Project → Milestone → Task tree with live progress rollup. Milestones carry timeframes, team, priority, and deliverables; flag one as a Sprint with a goal and a staff capacity roster (allocated vs. available hours per person).

TATERpedia Ratings & Suggested Articles

Per-user 1-5 ratings on wiki pages with optional comments, view counts, context-aware article suggestions for tickets (title 4x / tags 3x / summary 2x / body 1x scoring).

TATER Manage — Administration & Fleet

Tenant administration, endpoint fleet, MSP and licensing, patching, and the controls that govern who can do what. Lives at manage.tatersecurity.com. App overview →

My TATER — Personal Dashboard

The personal landing page for every user: assigned tasks, mentions, favorites, approvals, reviews, requests, and community. Lives at my.tatersecurity.com. App overview →

TATER Insights — Reporting

Centralized, filterable, exportable reporting across the whole platform, with group-based access control. Lives at insights.tatersecurity.com. App overview →

TATER Vault — Secrets & Passwords

A zero-knowledge password and secrets manager: master-passphrase encryption, TOTP, group sharing, one-time send, and a restricted vault for sensitive operational inventories. Lives at vault.tatersecurity.com. App overview →

GRC Modules

🤖

AI Governance (ISO 42001 / NIST AI RMF / EU AI Act)

Inventory every AI system, classify it under the EU AI Act risk tiers, and track your ISO 42001 / NIST AI RMF / EU AI Act control posture. AI System Inventory, 22-control checklist, MCP tools, and an Insights report.

🛡️

SOC 2 Readiness (Trust Services Criteria)

See how SOC 2-ready you are without re-scanning. TATER crosswalks the Trust Services Criteria (CC1–CC9 + Availability / Confidentiality / Processing Integrity / Privacy) to the M365 checks it already evaluates and computes readiness per category and per criterion.

📋

Governance Meetings

Track the recurring oversight meetings SOC 2 / ISO 27001 expect — security threat review, management review, access review, CAB, vendor review, IR, BCP/DR, training, policy. Cadence tracking, overdue alerts, control-evidence mapping, and a full audit trail.

📑

TATER Audit — Auditor Workbench

For audit firms: manage client engagements, ingest a client's evidence files with Claude (MCP-first), map them to the SOC 2 Trust Services Criteria, track coverage and gaps, and record workpapers — with or without the client on TATER.

GRC Guide (All 14 Modules)

Comprehensive walkthrough of all GRC modules: Risk Register, Exceptions, Audits, BCP/DR, Data Classification, Training, Control Testing, Change Control, Vendor Management, Questionnaires, Regulatory Changes, Access Reviews, POAM, RMF Tracker. Auditor Portal with PBC workflow.

Collaboration (Comments, Mentions, Threads)

How comments, @mentions, audit-trail attribution, and notification routing work across every TATER entity. Used by tasks, controls, risks, audits, change requests, wiki pages, major incidents, and PBC requests.

Entity Templates

Curated built-in templates and reusable org patterns for risks, vendors, audits, BCP/DR plans, control tests, training, and POAMs. AI agents follow a Template-First Rule.

Entity Profiles

Per-standard templates - field rules plus a status workflow - that shape GRC records (risk, audit, change, vendor) to a recognised methodology. The generalization of ITIL Process Profiles to GRC, with seeded templates for NIST 800-37, ISO 27005, SOC 2, ISO 27001, ITIL 4, SIG, and VSA-Lite, plus MCP access.

Risk Register & Heat Map

Central risk register with 5x5 heat map, quantitative ALE scoring, treatment plans, and risk-to-control linkage.

Exception & Waiver Management

Structured exception requests with multi-level approval chains, automatic expiry, and compensating controls.

Audit Management

Plan audits, track findings, collect evidence from control owners, and maintain an audit calendar.

Business Continuity & DR

BCP/DR plans with BIA, RTO/RPO tracking, and test exercise management for audit compliance.

Data Classification & Privacy

Data asset inventory, flow mapping, privacy impact assessments, and retention policy management.

Security Awareness Training

Training campaigns, completion tracking, phishing simulation results, and audit-ready evidence reports.

Control Testing Automation

Scheduled test plans, reusable procedures, historical results with trend analysis, and gap detection.

Vendor Risk Management

Vendor inventory, risk tiering, assessment tracking, and continuous monitoring.

Vendor RFP Evaluations

Weighted-criteria vendor selection: define scoring criteria, invite candidate vendors, score across evaluators in a live matrix, and award the winner.

Vendor External Posture, Contracts & Lifecycle

Scan vendor domains for SPF / DMARC / TLS / HSTS, grade external security A-F, and feed the score into vendor risk. Nightly auto-sweep + MCP tools. Also covers the rest of the vendor lifecycle: complaints, on-site reviews, DocuSign envelopes, and contracts & renewals - recording a contract, the Contract Renewals expiry window, renewing, and terminating vs. deleting.

Questionnaire Gap Review & Trust Center Q&A

Answer only the gaps with knowledge-base suggestions, and let prospects self-serve security questions on your public Trust Center.

Access Reviews

Periodic access review campaigns with approve/revoke decisions and audit trail.

GRC Calendar

Unified timeline of all GRC obligations: access reviews, control tests, exceptions, BCP/DR tests, training deadlines, and vendor assessments.

Regulatory Change Management

Track framework updates and regulatory changes, assess their impact on your controls, and manage the transition to compliance with new requirements.

Change Control

Structured approval workflow for High and Critical impact control changes. Low/Medium auto-approved; scan-detected changes auto-generate requests.

Custom Control Frameworks

Build custom frameworks with drag-and-drop domains, import/export via JSON for MSP distribution, and cross-map to standard frameworks.

Federal / DoD ATO Pipeline

Collaboration

Task Tracking

Unified task view across all modules with assignments, due dates, and Kanban board.

Questionnaires

Build and distribute compliance questionnaires with AI-assisted response generation.

Feedback Board

UserVoice-style feedback system with voting, comments, and admin status tracking.

Task Notifications Setup

Route new-task alerts to staff email and a Microsoft Teams channel. Includes the Power Automate Workflow setup, the DLP block workaround, and the Adaptive Card format.

Notification Hub

Gives every TATER notification - approvals, reviews, RFIs, task updates, license and travel decisions - a per-user in-app feed and an org-wide delivery log, on top of email. Per-org channels (including a Teams webhook), a cross-org My Notifications feed, an Auditor-visible delivery log, per-item snooze, and MCP access.

Email-to-Ticket Setup

Turn a shared mailbox into a TATER Ops ticket queue via Microsoft Graph. Includes the PowerShell provisioning script, Application Access Policy security gate, full Manage config walkthrough, and end-to-end test.

File Storage (BYO)

Point ticket, emailed-in, RFI, and audit-evidence file attachments at an Azure Storage account your organization owns and maintains. TATER's size + file-type limits still apply; the connection string is encrypted and the data lives in your account.

Trusted External Senders

Allowlist trusted external senders in Exchange Online. TATER generates an idempotent PowerShell script that bypasses spam filtering, suppresses the External tag, and stamps a "verified by IT" banner - with a tenant-confirmation and DMARC-spoofability guardrail.

Policy Library

21 policy templates with variable engine, Markdown preview, and PDF export with branding.

Compliance Roadmap

Multi-phase remediation planning with Phase 0 Discovery, cascading phase durations, MSP billing columns, and generate-from-scan automation.

Community & Gamification

Leaderboards, achievement badges, compliance streaks, and community challenges that drive team engagement and reward security improvements.

Platform Customization

Integrations

AI Compliance Analyst

TATER's built-in conversational AI. Ask questions about your scan data, create risk acceptances, assign controls, document evidence, and trigger remediations - all from a chat interface.

Claude MCP Integration

Connect Claude Desktop or claude.ai directly to your TATER compliance data via the Model Context Protocol.

Microsoft 365 Copilot Integration

Install TATER as an M365 Copilot declarative agent - combine your tenant's Graph context with TATER's compliance posture, risk register, and living documentation.

MCP Tool Policies

Per-org, per-role, per-group control over which AI tools your agents can invoke. Block destructive tools globally, scope sensitive ones to specific groups, preview policy decisions before saving.

Zoho / ManageEngine Endpoint Central

Native Zoho OAuth 2.0 connector that pulls patch posture from ManageEngine Endpoint Central Cloud into TATER's Application Monitoring surface - setup, scopes, and sync behavior.

Government Cloud Compatibility

How TATER supports commercial, GCC, GCC High, and DoD tenants - per-control GCCH/DoD remediation guidance, sovereign-cloud scanning configuration, and the path to a private TATER Gov deployment.

Ticketing Integration

Create Jira or ServiceNow tickets directly from failing controls - individually or in bulk - so security findings flow into your team's existing workflow.

Ops Event Webhooks

Signed JSON webhook for machine consumers - fire task.created (and other lifecycle events) to your own automation the moment a ticket is submitted, with a loop guard, filters, and a delivery log.

Ops Event Webhooks - Developer Reference

Wire format and signature spec for webhook consumers - the event envelope schema, task.created payload fields, X-TATER-Signature HMAC-SHA256 verification, and delivery retry/dead-letter semantics.

Audit & Activity

People & Organizations

Azure Setup

Sales & Positioning

Platform Features

M365 Auditing: Exchange, Teams, SharePoint, Defender compliance
OS Scanning: Windows 11, Server 2019/2022/2025 CIS benchmarks
Endpoint Security: MDE vulnerabilities, CISA KEV, EPSS scores
Multi-Framework: NIST 800-53, ISO 27001, SOC 2, PCI-DSS, HIPAA
Risk Scoring: Weighted risk prioritization with SLA tracking
Drift Alerts: Real-time compliance regression detection
Remediation: One-click automated remediation via Azure Automation
Policy Templates: 21 pre-built security policy templates
Fleet Tracking: Device compliance across your entire estate
MITRE ATT&CK: Adversary technique coverage mapping
Smart Discovery: Auto-discover software with version tracking
Executive Reports: PDF/CSV reports for board and auditors
Risk Register: Heat map, ALE scoring, treatment plans
Audit Management: Plan, findings, evidence collection
BCP/DR: Plans, BIA, RTO/RPO, test tracking
Data Classification: Inventory, flow mapping, PIAs
Training Tracking: Campaigns, completion, phishing sims
Control Testing: Scheduled tests, procedures, gap detection
Custom Frameworks: Builder, import/export, cross-mapping
Exception Mgmt: Approval chains, expiry, compensating controls
Regulatory Change: Impact assessment, deadlines, transitions
GRC Calendar: Unified obligation timeline with deadline alerts
Licensing: Plan types and user/admin seat limits per org
Access Reviews: CSV import and manual user population
Compliance Roadmap: Multi-phase remediation planning with Phase 0 Discovery and cascading durations
MSP Portal: Multi-tenant management with tiered client access and white-labeling
Change Control: Approval workflows for High/Critical impact changes
Widget Dashboard: 16 drag-and-drop widgets with start page option
Community: XP levels, achievements, leaderboards, challenges
Auditor Portal: Read-only evidence packages with time-limited access
Vendor Management: Vendor inventory, risk tiering, questionnaires
AI Analyst: Agentic AI assistant for compliance workflows (12-iteration tool loop)
MCP Integration: 500+ tools for Claude Desktop and claude.ai
Evidence Agent: Autonomous browser-based evidence collection
Favorites: Star any page for quick topbar access

System Requirements

Requirement Details
Web Browser Chrome, Edge, Firefox, or Safari 11+ with JavaScript enabled
PowerShell 5.1 or newer for scan script execution
M365 Admin Security Admin, Compliance Admin, or Global Admin role for cloud audits
Local Admin Administrator privileges on target machines for OS scans
Network HTTPS access to Microsoft Graph API (port 443) for cloud scans

Quick Start

Sign in to TATER

Navigate to app.tatersecurity.com and authenticate with your Microsoft Entra ID credentials.

Configure your organization

Go to Settings to configure company name, logo, accent colors, and tenant credentials.

Run your first scan

Execute a cloud or OS scan using the provided PowerShell scripts, or trigger a server-side scan from the dashboard.

Review compliance posture

View the dashboard for compliance scores, control status, and risk metrics across all frameworks.

Take action

Create overrides for accepted risks, assign controls to team members, trigger automated remediation, and generate reports.