Controls needing work

Two worklists over your not-ready controls — the ones with nothing mapped, and the ones whose manual evidence is out of date — plus any control missing an owner or a description.

PluginAreaAccess
drata-grc-skillsCompliance & Audit ReadinessRead-only

Purpose

  • Lists controls with no evidence, policy or monitor mapped.
  • Lists controls whose manual evidence is no longer current.
  • Flags in-scope controls with no owner or no description.

Access: This skill cannot change anything in Drata.

MCP tools used

MCP toolLevelOAuth scope
Get CompanyReadread:company
Search ControlsReadread:controls

This skill uses every scope listed above; without them it fails partway through. What any tool returns is bounded by your Drata role as well as the scope — see MCP Server setup.

Run it

Copy
Copied
/plugin marketplace add drata/drata-claude-plugin
/plugin install drata-grc-skills@drata

Then run the skill by name:

Copy
Copied
/drata-grc-skills:drata-control-identify-gaps

Or ask for it in your own words:

  • "which controls have nothing mapped"
  • "controls with no owner"

Before you start

  • Connect the Drata MCP server. See MCP Server setup.
  • Your MCP OAuth configuration must grant the scopes behind the tools listed above.

Related skills

  • Fix controls — Work through control gaps from a single menu with live counts.
  • Control readiness — How many of your controls are ready, and why the rest are not — in scope versus out, the ready share, and the not-ready ones broken down by cause.