Skip to content

Creating & Scheduling Audits

Audits start from a template. Most MSPs run the same handful — you can tune the baseline and response after creating one.

Audit Templates

Pick a template from the New audit dialog (or from the first-run "Start watching your clients" screen). The available templates are:

TemplateWhat it checksWorks with
Patch complianceDevices with operating-system patches that are approved or pending but not installedNinjaOne, ConnectWise RMM, Syncro, Datto RMM
MFA coverageLicensed users and admin-role holders without a registered second factorMicrosoft 365, Google Workspace, CIPP
Offline devicesDevices that haven't checked in to the RMM for a set number of days (default 30)NinjaOne, Datto RMM, ConnectWise RMM

MFA coverage is provider-agnostic — it combines every connected identity provider for each company. Unlicensed shared, resource, and service mailboxes are out of scope; block interactive sign-in on those instead.

A template you can't use yet appears grayed out with the reason (for example, "Connect NinjaOne, Datto RMM or ConnectWise RMM to use this"). Connect a supporting integration to enable it.

Create an Audit

  1. From the Audits list, click New audit.
  2. Choose a template card.
  3. If more than one supporting RMM is connected (for device templates), pick which one is authoritative from the target chooser. Identity templates like MFA coverage need no choice.
  4. The audit is created — but it starts Inactive and won't run until you activate it.

Activate

Going live is an explicit step. On the audit's detail page:

  • The header shows an Active / Inactive chip.
  • Click Activate to start running the audit on its schedule.
  • Use Pause to stop it running, and Run now to trigger a pass immediately.

Schedule

Each audit runs one pass across all companies in scope on its schedule. Edit the cadence inline on the Detection tab:

  • Hourly, Daily, Weekly, Monthly, or Every N days.
  • The default is Monthly.

Scope

An audit is either:

  • Global — it applies to every in-scope company (shown with a globe icon), or
  • Single company — scoped to one company.

Use Add company to bring more companies into scope. Within an audit you can Disable for this company or Enable for this company from a company's Manage drill-in.

Run a Pass on Demand

You don't have to wait for the schedule:

  • Run now (in the header) queues a pass for the whole audit. Findings update as the pass completes.
  • Re-scan (on a company's card in the Findings tab) re-runs the pass for just that one company.

Test Before You Commit

To preview what an audit would find without creating anything, use Run test pass (a dry run) on the Detection tab. It reports how many findings it would emit across the companies scanned and shows a sample — but creates no findings, tickets, or runbook runs. This is a good way to sanity-check a template against your clients before activating.

Next Steps