What these two pages are
Vendor Complaints and Vendor Visits sit next to each other in the TATER Ops sidebar and both hang off a vendor record. They answer two different questions about the same supplier:
- Vendor Complaints - something went wrong and somebody wants it on the record. A missed SLA, a botched delivery, a support experience that wasted a day.
- Vendor Visits - a scheduled on-site review of that supplier, with findings, that closes out into your risk register.
Both are org-scoped and both appear in the vendor's context alongside contracts, security ratings and questionnaires. Neither replaces the vendor questionnaire; a questionnaire is what the vendor tells you, a visit is what you saw.
Logging a complaint
Open Vendor Complaints from the Ops sidebar and create a record against the vendor. A complaint carries the vendor, a title, the substance of what happened, and a status you move as it is worked.
The value of the log is cumulative rather than individual. One late delivery is an anecdote; eleven of them over a contract term is a negotiating position, and it is the kind of thing nobody can reconstruct from memory at renewal time. If your organisation reviews suppliers annually, this is the page that makes that review evidence-based.
Complaints are read by Auditor and above and written by Admin and above, in line with the rest of the vendor module.
Recording an on-site visit
Open Vendor Visits and create a review against the vendor. A review has a title, the vendor it concerns, a status, and a list of findings you append as you go.
Each finding carries a severity, one of:
CriticalHighMediumLowInformational
A finding submitted with a severity outside that set is stored as Medium rather than rejected, so a typo downgrades a finding instead of losing it. If a finding matters, check the severity that was actually saved.
Completing a visit writes to the Risk Register
This is the behaviour worth knowing before you click the button, because it creates records outside the page you are on.
When you mark a review complete, TATER walks its findings and promotes some of them into the Risk Register as new risks. A finding is promoted when all three of these hold:
- its severity is
CriticalorHigh; - its status is
OpenorDiscussed; and - it is not already linked to a risk from an earlier completion.
That third condition is what makes completing a review twice safe: a finding already promoted carries the id of the risk it produced and is skipped. Re-completing a review does not duplicate its risks.
What the created risk looks like
Each promoted finding becomes a risk titled [Onsite <review title>] <finding title>, so it is recognisable in a register that also holds risks from other sources. Its description records that it was promoted from an on-site review of that vendor, and carries the finding's own description and recommendation underneath.
The risk opens with a score already set, derived from the finding's severity:
- Critical - likelihood
4, impact5, risk score20 - High - likelihood
3, impact4, risk score12
Status is Open and treatment is Mitigate. The category is the finding's own category if it has one, and Vendor Risk if it does not.
Those numbers are a starting position, not a verdict. They exist so a promoted finding lands with a defensible score instead of a blank one; re-score it in the Risk Register if your own scale says something different.
What is not promoted
Medium, Low and Informational findings stay on the review and create nothing. So do findings you have already closed. If you want a Medium finding tracked as a risk, raise it in the Risk Register yourself - completing the review will not do it for you, and nothing will tell you it declined.
Who can do what
- Auditor and above can read complaints and reviews.
- Admin and above can create and edit them, append findings, and complete a review.
- Deleting a review is an Admin action and is a soft delete - the record leaves the list without leaving the database.
Because completing a review creates risks, the person completing it is effectively writing to the Risk Register. That is deliberate, and it is why completion sits behind Admin rather than Auditor.
Through the AI Analyst
Both surfaces are reachable through the MCP tools, so you can ask the AI Analyst about them in plain language:
list_vendor_complaints- complaints, filterable by vendorlist_vendor_onsite_reviews- reviews and their findingscomplete_vendor_onsite_review- completes a review, including the promotion described above
The last one is worth reading twice. Completing a review through the Analyst has exactly the same effect as clicking the button, risks and all.
Related
- Vendor External Posture, Contracts & Lifecycle - the vendor record these two pages hang off
- Risk Register - where promoted findings land
- TATER Ops overview - where these pages sit in the console