Platform Features

Built for security teams who treat compliance as a means to an end. Every feature here is designed to improve your actual security posture; the audit score follows.

Explore

Capabilities at a glance

TATER is broad. Start here and drill into any area as deep as you want — each card opens a full write-up.

Compliance Automation

4,000+ controls in the TATER Control Framework, crosswalked to CIS, SCuBA, NIST, ISO, SOC 2, HIPAA & PCI — assessed every scan, not once a year.

Explore →

Security Operations

1,400+ one-click fixes, device hardening, and vulnerability scanning ranked by real-world exploitation.

Explore →

GRC Suite

Risk register, audits, exceptions, BCP/DR, vendor/TPRM, control testing, regulatory change — 18+ modules.

Explore →

Federal / ATO

The full federal authorization pipeline — plans, milestones, and security paperwork in the formats agencies require, with GCC / GCC High / DoD support.

Explore →

Agentic AI & MCP

AI Compliance Analyst, autonomous Evidence Agent, and a 500+ tool MCP server for Claude, Copilot & ChatGPT.

Explore →

TATER Ops (ITSM)

Help desk, ITIL & NIST 800-61 profiles, service catalog, CMDB, Change/CAB with a personal “Awaiting your CAB vote” queue, Planned tasks with activation dates, Release Management, Major Incident, Problem, on-call.

Explore →

Project Management

Projects → milestones → tasks, sprint mode, staff capacity, portfolio, workload, timeline & RAID log.

Explore →

Identity & Threat Defense

ITDR alerts & playbooks, non-human-identity inventory, access reviews, and automated user lifecycle.

Explore →

Access Reviews (UAR)

Decision-trail CSV export for auditors, “Keep & always re-review” decisions, orphaned-account detection that diffs Entra accounts against your employee roster, and end-state offboarding profiles per account type. Plus self-service access requests: employees request SharePoint sites, shared mailboxes, or custom resources from My TATER; approvals route through the same engine and fulfillment is tracked in Ops.

Explore →

Insights & Reporting

Live dashboards, scheduled email reports, custom report builder, XLSX/PDF export & a Power BI dataset.

Explore →

Endpoint & Fleet

One cross-platform agent, fleet management, TATER Tuning hardening dial, and Intune deployment from TATER — plus Endpoint Profiles: Desktop Authority-style drive mappings, printers, shortcuts, and a branded logon splash, targeted per user, group, or device.

Explore →

Continuous Monitoring

Always-on health beyond the scan window: OneDrive sync health, CISA KEV exposure, Purview DLP alerts, endpoint hardening drift, and backup job health (Keepit, Rubrik, Cohesity) raise monitoring findings that route to tickets and your SIEM — plus DMARC reporting and scan-source freshness SLAs.

Explore →

Multi-Cloud Posture

Onboard AWS, Azure, and GCP accounts for CSPM scanning, with CIS AWS Foundations v3.0 mapped alongside your M365 posture. (GCP findings view coming soon.)

Explore →

Team Engagement

My TATER personal dashboard, TATERpedia wiki, security training, surveys/CSAT, achievements & leaderboards.

Explore →

TATER Vault

Zero-knowledge team password manager — MFA codes, group sharing, breach detection & org key escrow.

Explore →

Administration & Data

Per-org feature flags & group permissions, keep files in storage you control, audit log, and a public Trust Center.

Explore →
Advisory & MSP

Built for advisory & MSP engagements

Run a least-privilege assessment on a client tenant, hand back a branded deliverable, and stand up a new tenant in minutes — without ever writing to the client’s environment.

Read-only audit mode Least-privilege

An org-level switch for advisory and consultant engagements. When enabled, all remediation is suppressed across the app and the API rejects every write — remediation triggers, Cloud-Ops script execution, and Intune deployments all return 403 — so a read-only engagement can never touch the client tenant or its devices.

  • Distinct least-privilege scan profile: every *.Read.* Graph scope, excluding the two write-capable roles (Sites.FullControl.All, Exchange.ManageAsApp)
  • Findings still show fix guidance — never an executable trigger — so auditors can report how to fix each finding
  • Clear read-only indicators: dashboard banner, remediation-page notice, and guidance-only Top Priorities copy

Guided Tenant Onboarding ~2 min

A wizard on Settings → Tenants generates a single self-contained Microsoft.Graph PowerShell script the client’s admin runs once. It creates a least-privilege app registration, grants admin consent via app-role assignments, mints a secret, and prints Tenant ID / Client ID / Secret to paste back — roughly two minutes versus the 20–30 minute manual flow.

  • Defaults to the read-only-audit permission profile (pure Graph, no Exchange step); a Full option adds write-capable roles
  • Cloud-tier aware — Commercial / GCC / GCC High / DoD map to the correct Connect-MgGraph environment
  • Paste-back reuses the encrypted-credential save and existing tenant list

Three leave-behind reports

Standalone, branded deliverables designed to hand a client after a read-only assessment — each exportable via Print/PDF and a dedicated CSV, no platform access required.

Client Audit Report

Leave-Behind. A branded document with an executive posture summary, findings grouped by severity with plain-language remediation guidance, and a framework crosswalk appendix mapping each finding to the standards it satisfies (highlighting NIST). Read-only by nature — remediation appears as guidance text, never a trigger — so it pairs with read-only audit mode.

Compromise Assessment

Current-State Baseline. Consolidates the account-takeover / BEC indicators TATER already collects — over-permissioned OAuth apps, standing privileged access, guest admins, stale app credentials, external sharing, and recorded ITDR identity threats — plus a manual BEC-indicator checklist for the higher-signal mailbox and audit-log checks.

Continuous Compliance Evidence

SOC 2. Reconstructs each control’s pass/fail state across every scan in an auditor-chosen window to prove controls held their state over a period, not just at a point in time. Flags every drift event with a timestamp, evidences the monitoring cadence, and attests exemption integrity (active risk acceptances with approver + expiry).

Deep dives

Every feature, its own page

Individual write-ups — what each one does, how it works, and where to set it up.

Automated RemediationFix failing controls in one click Risk RegisterScore, own, and close enterprise risk Endpoint SecurityKEV-prioritized vulnerability management Evidence AgentAudit evidence that collects itself Meeting RecorderRecord & transcribe meetings locally AI Compliance AnalystAn agent that knows your tenant MCP ServerRun compliance from Claude, Copilot, or ChatGPT Audit ManagementRun engagements on live data Policy LibraryGenerate policies from templates Change ControlLog, review, and approve changes Vendor Risk (TPRM)Assess and monitor third parties Access Reviews (UAR)Campaigns that actually finish Federal ATO & POA&MRMF records, SSP, and STIG coverage TATER Ops (ITSM)Incidents, changes, CAB, and releases Data ClassificationKnow what data you hold
Built for the real work

Built for the analyst who works nights before an audit

Audit prep shouldn't require an all-nighter. With continuous monitoring, evidence collection and control assessment never stop, so you're as audit-ready in March as you are the week the auditor arrives.

Contact Sales →

Ready to simplify compliance?

Get audit-ready in days, not months.

Try Interactive Demo → Launch TATER Contact Sales