← Help & Docs

Vendor Complaints & On-site Visits

Two Ops pages that feed the vendor record - and one of them writes to the Risk Register on your behalf. Last updated 2026-09-06

What these two pages are

Vendor Complaints and Vendor Visits sit next to each other in the TATER Ops sidebar and both hang off a vendor record. They answer two different questions about the same supplier:

Both are org-scoped and both appear in the vendor's context alongside contracts, security ratings and questionnaires. Neither replaces the vendor questionnaire; a questionnaire is what the vendor tells you, a visit is what you saw.

Logging a complaint

Open Vendor Complaints from the Ops sidebar and create a record against the vendor. A complaint carries the vendor, a title, the substance of what happened, and a status you move as it is worked.

The value of the log is cumulative rather than individual. One late delivery is an anecdote; eleven of them over a contract term is a negotiating position, and it is the kind of thing nobody can reconstruct from memory at renewal time. If your organisation reviews suppliers annually, this is the page that makes that review evidence-based.

Complaints are read by Auditor and above and written by Admin and above, in line with the rest of the vendor module.

Recording an on-site visit

Open Vendor Visits and create a review against the vendor. A review has a title, the vendor it concerns, a status, and a list of findings you append as you go.

Each finding carries a severity, one of:

A finding submitted with a severity outside that set is stored as Medium rather than rejected, so a typo downgrades a finding instead of losing it. If a finding matters, check the severity that was actually saved.

Completing a visit writes to the Risk Register

This is the behaviour worth knowing before you click the button, because it creates records outside the page you are on.

When you mark a review complete, TATER walks its findings and promotes some of them into the Risk Register as new risks. A finding is promoted when all three of these hold:

That third condition is what makes completing a review twice safe: a finding already promoted carries the id of the risk it produced and is skipped. Re-completing a review does not duplicate its risks.

What the created risk looks like

Each promoted finding becomes a risk titled [Onsite <review title>] <finding title>, so it is recognisable in a register that also holds risks from other sources. Its description records that it was promoted from an on-site review of that vendor, and carries the finding's own description and recommendation underneath.

The risk opens with a score already set, derived from the finding's severity:

Status is Open and treatment is Mitigate. The category is the finding's own category if it has one, and Vendor Risk if it does not.

Those numbers are a starting position, not a verdict. They exist so a promoted finding lands with a defensible score instead of a blank one; re-score it in the Risk Register if your own scale says something different.

What is not promoted

Medium, Low and Informational findings stay on the review and create nothing. So do findings you have already closed. If you want a Medium finding tracked as a risk, raise it in the Risk Register yourself - completing the review will not do it for you, and nothing will tell you it declined.

Who can do what

Because completing a review creates risks, the person completing it is effectively writing to the Risk Register. That is deliberate, and it is why completion sits behind Admin rather than Auditor.

Through the AI Analyst

Both surfaces are reachable through the MCP tools, so you can ask the AI Analyst about them in plain language:

The last one is worth reading twice. Completing a review through the Analyst has exactly the same effect as clicking the button, risks and all.