Fix vendors

Work through vendor gaps from a single menu with live counts. Pick a gap, answer one question, and confirm one previewed batch before anything changes.

PluginAreaAccess
drata-grc-skillsThird-Party & Vendor RiskWrite

Purpose

  • Offers one flat menu: key information missing, review overdue, on hold, no renewal schedule.
  • Previews every change as a batch and waits for your confirmation.
  • Onboards vendors, imports a CSV, records a decision, or archives on request.

Access: This skill can change your Drata data: create / update / delete vendor. Every change is previewed and confirmed before it is applied.

MCP tools used

MCP toolLevelOAuth scope
Get CompanyReadread:company
List VendorsReadread:vendor
Get VendorReadread:vendor
Create VendorWritecreate:vendor
Update VendorWriteupdate:vendor
Delete VendorWritedelete:vendor
List Vendor Security ReviewsoptionalReadread:vendor-security-review
This skill uses every scope above that is not marked optional; without them it fails partway through. The one marked optional (read:vendor-security-review) is not required — the skill degrades cleanly without it. What any tool returns is bounded by your Drata role as well as the scope — see MCP Server setup.

Run it

Copy
Copied
/plugin marketplace add drata/drata-claude-plugin
/plugin install drata-grc-skills@drata

Then run the skill by name:

Copy
Copied
/drata-grc-skills:drata-vendor-resolve-gaps

Or ask for it in your own words:

  • "fix my vendors"
  • "assign vendor owners"
  • "record the Acme Corp decision"

Before you start

  • Connect the Drata MCP server. See MCP Server setup.
  • Your MCP OAuth configuration must grant the scopes behind the tools listed above.

Related skills

  • Vendors needing review — Seven checks across your current vendors, grouped by what the fix is, with a decision memo available for any single vendor.