Run the paperwork agencies require — RMF system records, a POA&M that populates itself from your findings, and a generated System Security Plan — on the same continuous M365 and endpoint scans that already drive your posture. Commercial, GCC, GCC High, and DoD tenants supported.
Federal authorization normally means re-typing your posture into documents that are stale the moment they’re saved. TATER builds the RMF record, the POA&M, and the SSP from the live control results it already holds — so the paperwork tracks the environment instead of a point-in-time snapshot.
Stand up a system authorization record with its boundary, categorization, and control baseline, and track it through the RMF lifecycle — the anchor every other federal artifact hangs off.
Failing controls flow straight into the Plan of Action & Milestones — weakness, source, and remediation seeded from the finding — so the POA&M is a living view of open gaps, not a document someone re-keys before each review.
Draft a System Security Plan that pulls control implementation status from live results, route it through review and approval, and keep it in sync with posture — instead of a Word file that drifts out of date the week after it’s signed.
DISA STIG controls are evaluated alongside CIS and CISA SCuBA against your M365 and endpoint configuration, so STIG findings sit in the same posture and the same POA&M as everything else.
A profile toggle sets scope: a commercial org marks DISA STIG and other federal-only controls ⊘ Not Applicable so they don’t drag its score, while a federal or DoD-contractor tenant keeps them fully in scope. One platform, both postures.
Commercial, GCC, GCC High, and DoD tenants are all supported — scans target the correct sovereign Graph environment, and remediation guidance is written for the cloud the tenant actually runs in.
The pipeline runs the RMF flow on top of the posture the platform already produces.
Create the RMF system record, set its boundary and baseline, and select the applicable control set.
Auto-populate the POA&M from failing controls and draft the SSP from live implementation status.
Work milestones to closure, keep the artifacts synced to posture, and route the SSP through approval toward ATO.
The POA&M has to reflect every open weakness before the assessor arrives, and it’s always behind.
Failing controls auto-populate the POA&M with source and remediation attached, so it mirrors real posture on the day of the assessment instead of last quarter’s.
Same tenant, but the contract requires DISA STIG scope that a commercial baseline would ignore.
The federal profile keeps STIG controls fully in scope and in the POA&M, while a sister commercial org marks them N/A — no separate tool, no double posture.
The environment is GCC High and generic tooling keeps pointing at commercial endpoints.
Scans hit the correct sovereign Graph environment and remediation guidance is written for GCC High, so the SSP and evidence describe the cloud the system truly runs in.
The POA&M guide covers creating an RMF system record, auto-populating the POA&M, generating the SSP, and setting the commercial-vs-federal profile.
See the RMF record, auto-populated POA&M, and generated SSP on your own tenant in a live walkthrough.