Reports
Operational reporting - task volume, SLA aging, top assignees, by-category, by-team, and worklog / billable time. The full report catalog (custom builder, XLSX/PDF export, scheduled delivery) lives in TATER Insights.
Worklog & billable time
Aggregates logged time across all tasks — by technician, by client / billing code, and by month. Totals split billable vs non-billable.
Speed Test
Quick links to fleet network diagnostics. The full per-device download / upload / latency table lives in TATER Security › Scans (Speed Test filter); use it to validate ISP service against SLA and to spot split-tunnel / SSE bypass misconfiguration.
Endpoint Profiles
Observe and troubleshoot endpoint profiles - the ScriptLogic-style desktop authority that applies ordered elements at logon / startup / unlock / interval based on a targeting rule. This is the read-only operational console: per-device applied state, drift, and targeting evaluation. Authoring (create / edit / delete) lives in TATER Manage → Endpoint Profiles. Use the "Run now…" action on a profile to re-apply it on a specific device immediately (queues its compiled elements as agent commands).
Profiles
Read-only view of the endpoint profiles configured for this org. Authoring is in TATER Manage → Endpoint Profiles.
Per-device applied state
What each TATER agent last reported applying, per profile. Click a device to expand its per-profile applied element ids and timestamps - use this to spot drift between what a profile defines and what actually landed.
Troubleshoot targeting
Dry-run the targeting rules against a device by hostname to see which profiles would match it and why. Each profile expands to a per-condition trace (matched / not, with the reason). Server-resolvable conditions (OS, groups, hostname, time) are evaluated here; agent-only conditions (registry/file/service presence, machine type) are re-checked locally on the device before it applies.
Application Monitoring
Live detector signals from your TATER agents - OneDrive sync health, CISA KEV exposure, and your templated monitors - kept as a workable findings queue. Acknowledge, suppress, resolve, or promote a finding to an Ops task when it genuinely needs help-desk lifecycle. Auditor+ can view; Admin+ can work findings. Monitor definitions are created and turned on/off in TATER Manage → Endpoint Fleet → Application Monitoring.
Fleet
Read-only endpoint fleet view - live TATER agent telemetry. Heartbeats, version, platform, compliance posture, last logged-in user, and online status. Auditor+ can view; Admin+ can queue commands and restart agents. The canonical Devices home (full action set, deployment, versions, BitLocker) is TATER Manage → Devices.
Intune
Create and assign Microsoft Intune Proactive Remediations, Platform Scripts and macOS Shell Scripts directly from TATER, scoped to this org's tenant. Every apply is gated behind a What-If preview, an explicit target group, and an approved change request, and is fully audit-logged. Auditor+ can view posture; Admin+ can deploy.
Tasks
All operational tasks across the organization. Filter by status, category, or assignee. Which tasks are these?
My Tasks
Open ITSM Tasker tasks assigned to you. (For lightweight personal to-dos, see My TATER → My Tasks.)
Projects
Active workstreams (migrations, cutovers, IdP changes, network changes, Intune deployments). Break a project into Milestones, then link Tasker tasks to a milestone for automatic progress rollup.
Dashboard
Activity at a glance.
📈 Task volume (last 30 days)
🥧 Tasks by category
📊 Top assignees by load
⏳ Aging by priority
Org Health · Cross-product snapshot
Recent Activity
Service Catalog
Predefined request types with form schemas, approvals, owner teams, and ETA. Submissions become routed tickets bound to the right process profile. Backs My TATER Self-Service and the public portal.
Service Requests
Incoming self-service requests from My TATER and the public portal — software installs, JIT admin, access, and support. Approve or decline, or convert a request into a tracked Ops ticket.
CMDB
Configuration items with typed relationships, recursive impact (blast-radius) analysis, and auto-discovery from devices, cloud accounts, and vendors. Business-facing health rollups live on the Service Portfolio page.
Service Portfolio
Business-facing view of the services your CIs compose. A service is a CMDB CI of type business-service or service; its health rolls up from member-CI status combined with any active major incidents touching them. Create service CIs in the CMDB, then wire members here.
Major Incidents
Active major-incident bridge: incident commander, subscribers, affected CIs, and broadcast status updates. Declare a major incident from any task detail.
Problem Management
ITIL problem records: track the root cause behind recurring or major incidents, document a workaround, and publish Known Errors (the Known Error Database). Link problems to the incidents (tasks / major incidents) they explain and the configuration items they affect.
Change Advisory Board
CAB boards, the pending-change voting queue, and the change calendar. Standard changes auto-approve; Normal/Emergency go to board vote with conflict detection.
Release Management
Bundle change requests into releases with rollout/rollback step plans and a deployment log. Lifecycle: planned → approved → scheduled → in-progress → deployed / rolled-back.
On-Call
Who's on the hook right now. Rotations cycle through a list of members on a fixed cadence — the current on-call is computed from the anchor date, so there are no shifts to maintain by hand.
Status Page
A public, statuspage-style board for your customers. It surfaces your active Major Incidents and upcoming maintenance windows (from Release Management), and lets visitors subscribe for updates. Share the public link below.
License Approvals
Approve or deny user requests for time-boxed Microsoft license rentals, and see the active queue. Configure the rentable licenses in TATER Manage → License Rentals.
Travel Approvals
IT/security approval of Conditional Access travel exemptions, and the org-wide exemption queue. Manager approvals happen in the traveller's My TATER. Configure travel policies in TATER Manage → Travel Exemptions.
Task Catalog
Reusable task definitions (templates) for common requests (IT setup, document review, etc.). Pick one to pre-fill the create form — it produces a workflow-driven Tasker task on the Tasks page. Not the same as ad-hoc personal to-dos under My TATER.
Policies
Organizational policies - browse and edit inline. The richer policy editor (templates, sign-offs, PDF export) lives in TATER Security.
Documentation
Configuration documentation - what is configured, why, how. Living docs maintained by the team and AI Analyst.
Ops Settings
Customize categories, statuses, priorities, teams, and SLAs to match how your departments actually work. Changes take effect immediately for your organization.
📂 Categories · Add custom categories per department
Each category defines a service surface (IT helpdesk, HR onboarding, AP invoice review, etc.). Set an icon, color, default priority, and SLA targets. Categories appear as searchable typeahead options on every task form.
🧭 Auto-Triage · Categorize, prioritize & route tickets automatically
Score each ticket's title + body against keyword rules to suggest its category, priority, and the assignment-group queue that owns it. When enabled, inbound email tickets without a matching subject routing rule are auto-triaged on arrival. Technicians can also click 🧭 Triage on any ticket. Leave the taxonomy blank to use TATER's sensible built-in defaults.
🎯 Priorities · Custom labels per org
Replace built-in priorities with your own labels (e.g. P1/P2/P3 or Urgent/Standard/Backlog). Order matters - first is highest.
📐 Process Profiles · ITIL, NIST IR, Basic templates
Profiles control which fields appear on a new task, which status transitions are allowed, and SLA targets per priority. Seed the defaults (Basic, ITIL Incident, ITIL Service Request, ITIL Problem, NIST SP 800-61 IR) or build your own for industry-specific workflows (HIPAA Breach Response, FedRAMP IR, etc.). Same pattern will apply to Risks, Audits, and Change Requests in future releases.
📊 Default Status Lifecycle · Drives the status pills, filters + edit-modal select
Order matters - first is the starting state, the final entries should be your terminal states (Closed / Cancelled / Resolved etc.). The status pivot buttons on the task view, the dropdown on the edit modal, and the status filter on the Tasks list all come from this list. Profile-bound tasks still follow their profile lifecycle; per-category overrides below take precedence over this default. Avoid spaces - use camelCase like InProgress (rendered "In Progress" automatically).
📊 Per-Category Status Overrides · Optional, overrides the default lifecycle above
Leave blank to use the default lifecycle above. Override a category to match its specific workflow (HR: "Awaiting IT Setup", "Equipment Issued"; AP: "Awaiting CFO Sign-off"). Comma-separated.
👥 Teams · Group assignees for routing
Define teams (e.g. "IT Tier 1", "HR Business Partners", "AP Approvers"). Assign tasks to a team or to a specific person. Team members are comma-separated email addresses.
🧩 Custom Request Fields · Per-category form fields
Add custom fields per category (AP: invoice #, vendor, amount; IT: device, location). Fields appear in the create/edit task form whenever that category is selected.
🔄 Approval Chains · Default per-category approver list
Define a default approval sequence per category. New tasks in that category auto-attach the chain. Approvers act in order; rejection halts the chain.
📥 Ticket Intake Portal & Token
Generate an intake token to receive tasks from outside the app - wire up Power Automate forwarding, or share the public self-service portal URL with end users. For shared-mailbox email-to-ticket (Graph subscription, per-department routing), configure TATER Manage › Connections › Email-to-Ticket instead.
helpdesk@yourcompany.com) and a Power Automate flow that POSTs each new email as JSON to:
POST https://api.tatersecurity.com/api/tasker/intake?token=<TOKEN>&tenantId=<TID>&organizationId=<OID>
Content-Type: application/json
{ "title": "<subject>", "description": "<body>", "requesterEmail": "<from>",
"category": "IT", "priority": "Normal", "source": "email" }
See the email intake guide for the Power Automate template.
Troubleshooting Guides
Step-through playbooks for common help-desk issues across operating systems and applications. Pick a guide, follow the numbered steps, and create a linked task in one click.
TATER Tips
A growing library of bite-sized tips covering every TATER capability - including Ops-specific workflows. Each tip links to the page or doc it describes.
Vendor Complaints
Tickets reporting issues with vendors - data leaks, SLA breaches, support failures, compliance lapses, billing disputes. Lifecycle mirrors a help-desk ticket (Open → Investigating → Escalated → Resolved/Closed). Critical / High complaints should also have a linked Risk Register entry.
Vendor Visits
Scheduled on-site and virtual vendor assessments. Visits with Critical/High findings auto-promote to the Risk Register on completion. Click a row to open the visit detail in TATER Security.
Feedback
Tell us what's working, what isn't, and what you'd like to see in TATER Ops. Negative feedback auto-files an Issue in our backlog.
TATERpedia
Shared platform wiki - generic process knowledge across all TATER organizations. Contributed by humans and AI agents.
Workflows
Multi-step process templates - trigger once to spawn a coordinated set of assigned tasks.
Script Library
Reusable PowerShell / Bash scripts. Run on targeted devices via the TATER Agent.
Onboarding / Offboarding
Run a join or leave event. Onboarding creates the person record and optionally triggers a provisioning checklist. Offboarding marks the person departed, runs a deprovision checklist, opens an access review to certify access revocation, and queues a vault recovery + purge reminder. Admin only.
Recent lifecycle events
SLAs
Service-level agreements applied to tasks. Built-in templates included; clone to customize.
Templates & Schedules
Recurring task templates that auto-generate on a schedule. Cron runs daily at 06:00 UTC.
Reimbursements & Expenses
Submit out-of-pocket reimbursements or log company-card spend — multiple line items per request, each with a receipt. Reimbursable lines route to an approver, then AP marks them paid. Company-card lines are logged for reconciliation only. Replaces fragile Form → Power Automate intake; failures surface here, never silently.
Opportunities
Sales pipeline — deals by stage with value, probability, and owner. Records are created here or pushed by the TATER Meeting Bot: your own LLM (via MCP) extracts stage, decision-makers, blockers, and next steps from sales-call transcripts into these opportunities.
Org To-Dos
Org-scoped to-dos — lightweight work items management (Auditor+) assigns to any org member. Assignees see them in My TATER → My To-Dos → Org tasks and complete or decline there; editing and cancelling stay on this board. Completion is always assignee-only.
Meetings
Durable Meeting Records - attach raw transcripts, run external-LLM extraction via MCP, and roll up linked tasks, business docs, decisions, and risks per meeting.
get_meeting_transcript, then write artifacts back with create_business_doc, create_tasker_task, append_meeting_decision, etc.
Outlook Calendar
Upcoming meetings from your Outlook calendar. Click Capture on any meeting to create a TATER Meeting Record pre-filled from the event - then attach a transcript when the meeting concludes.
Calendars.Read consent. Granted just-in-time so it's not requested for users who never visit this page.
Meeting Templates
Per-type extraction profiles. When you create a Meeting Record and pick a template, it hydrates defaults: sensitivity, retention, extraction hints (surfaced to your LLM as prompt input), notification destinations, brief-lead time.
Business Documentation
SOPs, process maps, role descriptions, vendor briefs, client procedures, onboarding/offboarding docs, and other operational documentation. Distinct from policies (security), config docs (technical), implementation guides (compliance), playbooks (IR), and TATERpedia (cross-org wiki).
Document Reviews
Post a document — an employee manual, HR doc, SOP, or any operational document — for assigned staff to review and acknowledge. Assignees sign off from My TATER → My Reviews; track who has signed and who is outstanding here.
Surveys
Build a custom survey and either assign it to staff (they answer from My TATER → My Surveys) or attach it to ticket categories so a feedback survey (CSAT) goes out automatically when a matching ticket is closed.
Information Requests
Formally request information — typed custom fields and/or supporting documents — from staff or external parties. Internal fulfillers answer from My TATER → My Requests; external parties answer via a secure link. Track responses and accept or request changes here.
Flow Monitor
Watch your Power Automate cloud flows for ones that get turned off, suspended, or start failing above a threshold — so a silently-broken flow can't run unnoticed for days. Problem flows raise an auto-filed Ops ticket (de-duplicated per flow, auto-closed on recovery) and appear in the Application Monitoring queue. Re-scanned hourly.
Scheduled Runbook Execution
Run library scripts on a recurring schedule against device fleets or cloud tenants. Drift detection compares consecutive runs and fires email or Tasker tasks on change. Cron checks every 5 minutes.
Independence — Cycles & Reviews
Firm-wide independence attestation cycles (annual full-roster + monthly delta) and engagement-level independence assessments. Staff confirm independence against the client roster; conflicts are documented on a form.
Independence — Client Roster
The master list of clients staff attest independence against. Import from CSV or Excel in any layout — bare name lists, header-mapped tables, or month-grouped "new sales" sheets. Flag restricted entities.
My Independence Attestation
Your open attestation cycles. Review the client list (full roster annually, the delta monthly), document any conflicts, and sign off — even when you have none.
Independence — Configuration
Who attests, how often, the attestation statement, and the conflict types. Defaults match the common model: all employees review the full roster annually plus a monthly delta.