Org Health · Cross-product snapshot

Loading…

Recent Activity (last 50 audit events)

Loading…
Loading…
Loading…
Loading…
Loading…
Loading…
Loading…
Loading…
Loading…
TATER Insights
The reporting product: full report catalog, custom report builder, XLSX/PDF export, scheduled email delivery, MSP cross-org rollups.
Open Insights →
Compliance reports
Executive summary, detailed, framework-specific. Generated server-side or rendered client-side. SOC2 / CIS / SCuBA / FedRAMP / custom frameworks.
Open in Security →
Audit snapshots
Point-in-time compliance snapshots. Used for evidence packets, auditor portals, and historical comparison.
Open in Security →
Ops & ticketing reports
Task volume, SLA aging, top assignees, by-category, by-team. Operational KPIs for service-management leadership.
Open in Ops →
Network speed test
Per-device download / upload / latency from the TATER agent fleet. ISP-vs-SLA validation, SSE bypass diagnostics.
Open in Ops →
Activity log
Cross-product audit trail with via-channel attribution (web / MCP / Copilot / agent / cron / ADO webhook).
Open →
Usage analytics (SA)
Page-view stats, feature engagement, MCP tool call distribution. SuperAdmin only.
Open →
Power BI / Power Automate
Direct data endpoint + custom connector. Build your own dashboards in Power BI, Power Automate, or any tool that speaks OAuth.
Configure →
Loading…
Loading…
Loading…

One term per line (or comma-separated). These override the shipped defaults on any spelling collision. Kept lean — the recorder only attends to a couple hundred terms, so list what actually gets said in meetings.

Auto-seeded from your TATER data

These are added automatically — no editing needed. The recorder merges them with your custom terms and the shipped defaults on every recording. Add a vendor, person, or device and it shows up here next time.

Loading…

Toggle tools off for everyone in the org. SuperAdmin still bypasses for break-glass access. Disabled tools return a polite error to MCP callers explaining the policy.

Loading tool manifest…
Total items
-
Current
-
Stale
-
Never
-
Loading…
Loading…
Loading...
Loading…

🩹 Patch Policies · auto-approve & auto-deploy patches by severity

A policy auto-approves patches at or above a severity threshold (optionally filtered by category) and — when auto-deploy is on — the daily scheduler queues upgrades to matching devices. Use report-only first to preview impact.

Loading…
Loading…

📜 Deployment History · latest 200 · manual + scheduler-queued

Every queued patch deployment with its agent-reported outcome. Failed rows expand to show the agent's stdout/stderr.

Loading…

Catalog

Loading…

Recent deployments

Loading…
Loading…
Loading…
Loading…
Loading…
Loading…

Subscribers

Loading…
Loading…
Loading…
Loading policies…
Loading documentation…
Loading wiki pages…
Loading templates…
Loading…
Loading…

Configure your IdP

In your IdP's SCIM/provisioning settings, use:

SCIM base URL
Unique identifieruserName (email)
AuthenticationOAuth Bearer Token — paste the token generated above
SupportedCreate + Update + Deactivate (push). Deactivation removes the user's TATER access for this org.

SCIM provisioning (above) and OIDC login (below) are independent — you can enable either or both. Setup guide.

OIDC Single Sign-On (login)

Let users log in through your identity provider (Microsoft Entra, Okta, Google Workspace, OneLogin, Ping, Auth0…) via OpenID Connect. Disabled until you enable it — existing Microsoft / email sign-in is unaffected.

Loading…

Register this redirect URI in your IdP

Redirect / callback URI
Grant typeAuthorization Code + PKCE
Scopesopenid email profile
Direct login link

Users click Sign in with SSO on the login screen and enter their work email (matched against the allowed domains above), or use the direct login link. Full setup guide →

Loading…

ADO Task Sync Configuration

Loading current config…

Task Notification Configuration

Loading current config…

📬 Daily Technician Digest

Every morning each technician gets one email: their own open/pending tasks (SLA-breached first) plus the unassigned tasks sitting in the queue — so email-intake tickets stop going unnoticed. Recipients are derived automatically from task assignees + Ops team members.

Loading…
Loading…
Loading…
Loading…
Loading…
Loading…
Loading…
Loading…

Microsoft Graph App Registration

One app reg services every mailbox integration below. Run Setup-TATEREmailIntake.ps1 once per org (no repo access needed), then paste the values here.
Loading…

Mailbox Integrations

Loading integrations…

Trusted External Senders

Optional · default OFF. Fully trust a vendor/service sender across BOTH Exchange Online surfaces at once — the positive-trust transport rule (banner + SCL -1) AND the ExternalInOutlook allow list that drops the native [External] tag. TATER generates one idempotent script with guardrails (tenant-confirm, DMARC pre-check, read-modify-write dedupe) so you never half-trust a sender or clobber existing entries.

Loading…
Run the generated script in an Exchange Online PowerShell session as an Exchange Admin. Idempotent & safe to re-run.
🤖 The bot's runtime fetches config from /api/bot/config-by-entra-tenant/<tenantId> on each meeting join. SuperAdmin-only edits here flow to the bot without a Container App restart.
Loading…
🖥 Interactive Remote Control - Org Policy
NIST 800-53 AC-17 master switch. Off by default per CM-7 least-functionality. When enabled, admins can start WebRTC sessions to any device that has remoteControlEnabled: true in its config. All session lifecycle events are audit-logged for AU-2 / AU-12. Phase 2 (shipped v2.4.0) adds PE-3 end-user consent prompts, mouse/keyboard input injection, bidirectional clipboard, multi-monitor selection, and AU-14 session recording - each capability individually toggleable per session, off by default.
Loading device fleet…

Current agent version

Loading…
Loading…