Write internal-audit-grade Test of Design (TOD) and Test of Operating Effectiveness (TOE) procedures for an organization's controls, covering audit objective, test steps, population and sampling, and evidence to obtain. Use when a user asks how to test a…
Produce a prioritized digest and audit CSV of every Vanta personnel task (policy acceptance, security training, background check, device monitoring, custom tasks) that is overdue or due within a horizon. Use when asked for the personnel report, personnel task…
Analyze a specific risk scenario to suggest mitigating controls from the customer's control library. Use when the user asks which controls cover or reduce a risk, asks for suggested controls for a risk scenario, or wants to map existing controls to a risk…
Evaluate active compliance frameworks, connected integrations, technical architecture, disclosed controls, and the existing risk register to find coverage gaps and recommend tailored risk scenarios. Trigger when a user asks to "recommend new risks based on my…
Translate failing Vanta tests into per-engineer remediation instructions covering what to fix, how to fix it, and by when — so the compliance owner never translates test-by-test. Trigger when the user asks: "turn failing tests into remediation instructions",…
Identify controls with no owner and recommend a new active owner for each from domain-level ownership patterns, delivering a flagged CSV of recommendations. Use when a user asks who should own an unowned control, wants orphaned or ownerless controls found,…
Groups new and SLA-breaching vulnerabilities into priority tiers by severity and SLA status, excludes active risk acceptances, strictly grounds data in command output without fabrication, and drafts remediation outreach grouped by asset owner. Trigger on "run…
Vanta CLI: Manage security and compliance data.