Appearance
Creating & Scheduling Audits
Audits start from a template. Most MSPs run the same handful — you can tune the baseline and response after creating one.
Audit Templates
Pick a template from the New audit dialog (or from the first-run "Start watching your clients" screen). The available templates are:
| Template | What it checks | Works with |
|---|---|---|
| Patch compliance | Devices with operating-system patches that are approved or pending but not installed | NinjaOne, ConnectWise RMM, Syncro, Datto RMM |
| MFA coverage | Licensed users and admin-role holders without a registered second factor | Microsoft 365, Google Workspace, CIPP |
| Offline devices | Devices that haven't checked in to the RMM for a set number of days (default 30) | NinjaOne, Datto RMM, ConnectWise RMM |
MFA coverage is provider-agnostic — it combines every connected identity provider for each company. Unlicensed shared, resource, and service mailboxes are out of scope; block interactive sign-in on those instead.
A template you can't use yet appears grayed out with the reason (for example, "Connect NinjaOne, Datto RMM or ConnectWise RMM to use this"). Connect a supporting integration to enable it.
Create an Audit
- From the Audits list, click New audit.
- Choose a template card.
- If more than one supporting RMM is connected (for device templates), pick which one is authoritative from the target chooser. Identity templates like MFA coverage need no choice.
- The audit is created — but it starts Inactive and won't run until you activate it.
Activate
Going live is an explicit step. On the audit's detail page:
- The header shows an Active / Inactive chip.
- Click Activate to start running the audit on its schedule.
- Use Pause to stop it running, and Run now to trigger a pass immediately.
Schedule
Each audit runs one pass across all companies in scope on its schedule. Edit the cadence inline on the Detection tab:
- Hourly, Daily, Weekly, Monthly, or Every N days.
- The default is Monthly.
Scope
An audit is either:
- Global — it applies to every in-scope company (shown with a globe icon), or
- Single company — scoped to one company.
Use Add company to bring more companies into scope. Within an audit you can Disable for this company or Enable for this company from a company's Manage drill-in.
Run a Pass on Demand
You don't have to wait for the schedule:
- Run now (in the header) queues a pass for the whole audit. Findings update as the pass completes.
- Re-scan (on a company's card in the Findings tab) re-runs the pass for just that one company.
Test Before You Commit
To preview what an audit would find without creating anything, use Run test pass (a dry run) on the Detection tab. It reports how many findings it would emit across the companies scanned and shows a sample — but creates no findings, tickets, or runbook runs. This is a good way to sanity-check a template against your clients before activating.
Next Steps
- Configuring Responses — decide what happens when a finding opens.
- Findings & the Risk Ledger — work the findings an audit produces.