Management Dashboard
Platform-wide health: organizations, users, agent fleet status, and recent activity.
Org Health · Cross-product snapshot
Recent Activity (last 50 audit events)
Organizations
All tenant organizations with role mapping and member counts.
Users
Registered platform users, global roles, and tenant memberships. SuperAdmin only.
Subscriptions
Per-org billing, license limits, suspend/activate. SuperAdmin only.
MSP Licensing
MSP partner relationships and seat-license tracking.
Clients
MSP partner client roster - relationships, tier, contract dates, and engagement details. Use Licensing for seat-level allocation.
Compliance Calendar
Upcoming GRC events for the active organization — every category the live feed serves: audits, access reviews and control tests, risk / exception / credential / contract expirations, BCP/DR tests, training, policy and governance reviews, vendor assessments, POA&M and project milestones, roadmap phases, tasks, Ops tickets, on-call shifts and scheduled scans.
TATER Tips
Bite-sized tips covering every TATER capability. The login popup on Ops, Manage, and My TATER pulls a random one of these on every session.
Setup Wizard
Environment setup for the active organization. Steps are auto-detected from live state wherever possible; steps TATER cannot observe can be attested by an admin. Prefer provisioning done for you? The downloadable Setup Wizard configures these features end to end.
All Reports
Cross-product reporting hub. Compliance, operational, telemetry, and admin reports - surfaced together so SuperAdmins and MSPs can pull a full-picture view without app-hopping. Each report opens in the product that owns the underlying data.
via-channel attribution (web / MCP / Copilot / agent / cron / ADO webhook).Activity Log
Cross-product audit trail with the via attribution channel.
Usage Analytics
Per-org engagement metrics across both products.
MCP Feedback
All MCP feedback submissions, auto-filed ADO links.
Access Control
Assign granular permission bundles to scope a member to specific modules (TATER Ops, Security, Audit, …). A member with no bundles keeps their role's default access — nothing changes until you assign one. SuperAdmins are always unrestricted. (ADO #766)
Meeting Vocabulary
Custom terms that bias the local TATER meeting recorder's transcription, so proper nouns come out right — company and client names, staff surnames, vendors, product names, hostname prefixes. Whisper mishears these badly (Bletzer → “Blitzer”, Nasuni → “Nissooning”), and a wrong name turns an assignable action item into a vague one. (ADO #1759)
One term per line (or comma-separated). These override the shipped defaults on any spelling collision. Kept lean — the recorder only attends to a couple hundred terms, so list what actually gets said in meetings.
These are added automatically — no editing needed. The recorder merges them with your custom terms and the shipped defaults on every recording. Add a vendor, person, or device and it shows up here next time.
MCP Tool Policies
Control which AI/MCP tools are available to users in this organization. Restrict by role, by custom group, or globally. Changes take effect on the next MCP call. This policy governs TATER's hosted MCP endpoint (/api/mcp) — the claude.ai connector and anything else that connects through it. The separately installed tater-mcp stdio server is not governed here: its tools call the REST API directly, so its reach is set by its API key's role instead. (ADO #1679)
Toggle tools off for everyone in the org. SuperAdmin still bypasses for break-glass access. Disabled tools return a polite error to MCP callers explaining the policy.
QA Checklist
Platform-wide testable surfaces across all five TATER apps + the Go agent. Sign off when you've verified an area; sign-offs reset when an SA touches the item to record a change. Listed authority is the minimum role required to access that surface.
Multi-Screen Viewer
Live screenshots from devices with capture enabled. Refresh manually or every 60s.
Application Monitoring
Automated detector signals - OneDrive sync health, CISA KEV exposure, and your templated agent monitors - kept as a continuously-updated state, not a ticket stream. Acknowledge, suppress, or promote a finding to an Ops task when you actually want help-desk lifecycle.
Vulnerabilities
Per-device installed software inventory correlated with the CISA Known Exploited Vulnerabilities (KEV) catalog.
Patch Management
OS + third-party patches available on each endpoint. Agents collect on a 6-hour cadence. Deploy via winget / brew / apt / dnf using the existing AgentCommands pipeline.
🩹 Patch Policies · auto-approve & auto-deploy patches by severity
A policy auto-approves patches at or above a severity threshold (optionally filtered by category) and — when auto-deploy is on — the daily scheduler queues upgrades to matching devices. Use report-only first to preview impact.
📜 Deployment History · latest 200 · manual + scheduler-queued
Every queued patch deployment with its agent-reported outcome. Failed rows expand to show the agent's stdout/stderr.
Software Deployment
Curated catalog of installable packages (winget / MSI / brew / pkg / deb / rpm) plus a deployment history of every push.
Catalog
Recent deployments
BitLocker / FileVault / LUKS Keys
Disk encryption recovery key escrow. Passwords are AES-256-GCM encrypted at rest; every reveal is audit-logged with the requesting SuperAdmin's identity.
Endpoint Policies
USB / removable media control · App allowlisting (AppLocker / Gatekeeper / AppArmor) · JIT admin elevation · Power management · Browser policies · DNS filtering. Compose a policy once, apply to N devices.
Release Notes
Consolidated change log for all five TATER apps + the agent. Bump TATER_PLATFORM_VERSION in _app_version.js and add an entry to _release_notes.js on every release.
Automated Remediations
Admin-defined diagnose+remediate scripts the agent exposes to end users via the tray menu. When a remediation fails, the agent auto-opens an Ops task so IT can pick it up. Configured per-organization.
Endpoint Profiles
ScriptLogic-style desktop authority. A profile is an ordered set of script elements the TATER Agent applies to matching devices on a trigger (logon, startup, unlock, interval, on-demand), gated by composable targeting. Authored here; the agent re-evaluates targeting locally and enforces.
Service Catalog
Predefined request types (forms + routing + approval flags) end users submit from My TATER → Self-Service Requests and TATER Ops. Submissions become Ops tasks bound to the item's fulfillment profile. Configured per-organization.
Status Page Subscribers
Visitors who subscribed an email on your public service-status page to receive incident & maintenance updates. These are personal data — view, remove (GDPR right-to-erasure), and export the list here. The status page itself (enable, title, public link) is configured in TATER Ops → Service Management → Status Page.
Subscribers
Email Signatures
Define the org's official email-signature templates. Staff open the generator in My TATER → Email Signature, review pre-filled values (from Entra + their People record), toggle the optional elements you approve per template, and copy a rendered HTML signature into Outlook / Gmail / Apple Mail. The company logo is embedded as base64 so it renders on paste.
Automations
When something happens (e.g. a CSAT response) and a condition holds (e.g. score ≤ 2), automatically run an action — create a follow-up ticket, notify someone, call a webhook, or start a full workflow. Shared engine; CSAT is the first event source.
Policies
Browse and edit security policies inline (no app switch). Same data as TATER Security → Policy Library.
Configuration Documentation
Browse and edit configuration docs inline. Same data as TATER Security → Documentation.
TATERpedia
Browse the shared cross-org platform wiki. Pages can be edited from here; the full authoring experience lives in TATER Security.
Branded Documents
Generate polished, co-branded Word deliverables built from this org's ACTUAL configuration — categories, priorities, teams, and Service Catalog items — so handouts match the real workflow. Each generation also saves a markdown rendition to Business Documentation.
Feedback
Tell us what's working in TATER Manage and what isn't. Negative feedback auto-files an Issue in our backlog.
Connections & Integrations
Third-party connectors used by both TATER Security and TATER Ops. Configured once here, consumed by both products.
SSO & SCIM Provisioning
Connect your identity provider (Okta, Microsoft Entra, OneLogin, JumpCloud…) so users are provisioned and deprovisioned automatically. When HR offboards someone in the IdP, their TATER access is removed — the access-review loop closes itself. SCIM provisioning is independent of how users sign in.
Configure your IdP
In your IdP's SCIM/provisioning settings, use:
| SCIM base URL | — |
| Unique identifier | userName (email) |
| Authentication | OAuth Bearer Token — paste the token generated above |
| Supported | Create + Update + Deactivate (push). Deactivation removes the user's TATER access for this org. |
SCIM provisioning (above) and OIDC login (below) are independent — you can enable either or both. Setup guide.
OIDC Single Sign-On (login)
Let users log in through your identity provider (Microsoft Entra, Okta, Google Workspace, OneLogin, Ping, Auth0…) via OpenID Connect. Disabled until you enable it — existing Microsoft / email sign-in is unaffected.
Register this redirect URI in your IdP
| Redirect / callback URI | — |
| Grant type | Authorization Code + PKCE |
| Scopes | openid email profile |
| Direct login link | — |
Users click Sign in with SSO on the login screen and enter their work email (matched against the allowed domains above), or use the direct login link. Full setup guide →
API Keys
Generate API keys for the TATER Compliance Agent and external integrations. Keys are SHA-256 hashed in storage and shown once at creation - copy immediately. Revoked keys stop working instantly. This is the single home for API key management; the sister apps no longer expose their own surfaces.
Azure DevOps Sync
When enabled, TATER Ops tasks created or updated for the active organization are mirrored to ADO as work items, with bidirectional links. SuperAdmin only.
ADO Task Sync Configuration
Task Notifications
Route every new Ops task to Microsoft Teams (Incoming Webhook) and/or email. Useful when the agent auto-opens tickets from a failed Self-Service Fix and your help-desk team needs to see them immediately.
Task Notification Configuration
📬 Daily Technician Digest
Every morning each technician gets one email: their own open/pending tasks (SLA-breached first) plus the unassigned tasks sitting in the queue — so email-intake tickets stop going unnoticed. Recipients are derived automatically from task assignees + Ops team members.
Ops Event Webhooks
Fire a signed JSON event to an endpoint you control the moment a TATER Ops task changes state, so an external automation can pick it up immediately — the machine-facing counterpart to Task Notifications, which is for people (email/Teams).
Approvals
One approval engine behind every "needs a decision" flow — travel, license rentals, change requests, exceptions, and more. Define reusable approval groups (e.g. "IT Security Approvers", optionally backed by an Entra group), with a decision mode (any / all / quorum / percentage), reminders, and escalation. Everyone's pending decisions surface in My TATER → My Approvals.
Power Automate Flow Monitor
Connect TATER to your Power Automate tenant so it can watch cloud flows for ones that get turned off, suspended, or start failing. Register an app in your Microsoft tenant with Power Platform access — see the setup guide. The client secret is encrypted at rest. The live flow list + per-environment muting is in TATER Ops → Flow Monitor.
File Storage
Every file TATER stores — ticket and email attachments, RFI documents, audit evidence, generated reports, and exports — lives in TATER's managed blob storage by default. Point all of it at an Azure Storage account your organization owns and maintains instead — TATER's size + file-type limits still apply, but the data lives in your account. The connection string is encrypted at rest and never shown again after saving. See the setup guide.
Power Platform Inventory
Every Power Platform asset captured for audit — environments, solutions, canvas & model-driven apps, and custom connectors — each with its maker/admin-portal deep link. Reuses the Power Automate connection (no second setup). Click an asset to document it and link it to controls/audits as evidence. Cloud flows have their own richer inventory in Ops → Flow Monitor.
License Rentals
Define rentable Microsoft licenses (Visio, Project, …) mapped to an Entra licensing group or a manual fulfiller. Users self-request in My TATER → My Licenses; IT approves in Ops → License Approvals. Granted and removed automatically on schedule, with email notifications.
Travel Exemptions
Define travel-exemption policies — each maps to an Entra group that you've excluded from the Conditional Access policies blocking foreign sign-ins. Users request a trip in My TATER → My Travel; managers approve there, IT/security in Ops → Travel Approvals. The user is added to the group around departure and removed on return.
Email-to-Ticket
Route inbound emails from one or more shared mailboxes into TATER Ops tasks via Microsoft Graph. Set up the shared Entra app registration once at the top, then add each department's mailbox below as its own integration. See the setup guide for the PowerShell provisioning walkthrough.
Microsoft Graph App Registration
Setup-TATEREmailIntake.ps1 once per org (no repo access needed), then paste the values here.Mailbox Integrations
Trusted External Senders
Optional · default OFF. Fully trust a vendor/service sender across BOTH Exchange Online surfaces at once — the positive-trust transport rule (banner + SCL -1) AND the ExternalInOutlook allow list that drops the native [External] tag. TATER generates one idempotent script with guardrails (tenant-confirm, DMARC pre-check, read-modify-write dedupe) so you never half-trust a sender or clobber existing entries.
Meeting Bot Configuration
Per-organization configuration for the TATER Meeting Bot - enable/disable, purpose, consent text, and the sensitivity blocklist. Edits propagate to the running bot within ~60 seconds (cache TTL).
/api/bot/config-by-entra-tenant/<tenantId> on each meeting join. SuperAdmin-only edits here flow to the bot without a Container App restart.
Devices
The canonical Devices / fleet home. Live TATER agent telemetry - heartbeats, version, platform, online/offline status. Restart agents and run remote commands from here. (TATER Ops and TATER Security show read-only fleet views; full management lives here.)
remoteControlEnabled: true in its config. All session lifecycle events are audit-logged for AU-2 / AU-12. Phase 2 (shipped v2.4.0) adds PE-3 end-user consent prompts, mouse/keyboard input injection, bidirectional clipboard, multi-monitor selection, and AU-14 session recording - each capability individually toggleable per session, off by default.
Agent Deployment
Download MSI / Linux package / macOS binary, copy install commands, manage Intune Win32 packaging.
Current agent version
Agent Versions
Per-platform binary metadata: version, SHA256, release date.