Skip to content
Development
Skill

/tenant-compliance

ImmyBot tenants (client organizations) and fleet-wide reporting: the tenant and background-task tool surfaces, the per-tenant compliance scorecard and fleet task-queue audit procedures, and how to assemble a client QBR report from stats, compliance, software inventory, and

From plugin
msp-claude-plugins
46200 skills146 agents200 commands4 MCP
Install
$ npx -y skills add wyre-technology/msp-claude-plugins --skill tenant-compliance --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/tenant-compliance

Context preview

The summary Claude sees to decide when to auto-load this skill.

ImmyBot tenants (client organizations) and fleet-wide reporting: the tenant and background-task tool surfaces, the per-tenant compliance scorecard and fleet task-queue audit procedures, and how to assemble a client QBR report from stats, compliance, software inventory, and

SKILL.md

tenant-compliance.SKILL.md
name: "ImmyBot Tenant & Compliance Reporting"
description: >
  ImmyBot tenants (client organizations) and fleet-wide reporting: the tenant
  and background-task tool surfaces, the per-tenant compliance scorecard and
  fleet task-queue audit procedures, and how to assemble a client QBR report
  from stats, compliance, software inventory, and failed-task history.
when_to_use: >-
  When working with ImmyBot tenants (client organizations), reviewing per-tenant compliance
  dashboards, software inventory rollups, or auditing background task queues across the fleet. Use
  when: immybot tenant, immybot client organization, immybot compliance report, immybot tenant
  stats, immybot task queue, immybot failed tasks, or immybot fleet report.

ImmyBot Tenant & Compliance Reporting

Tenants are ImmyBot's client organizations. This skill covers tenant-level queries, compliance rollups, and the background-task queue that powers fleet-wide operational and QBR reporting.

Anti-triggers

  • **Regulatory or framework compliance** — "compliance" here means

installed software matches desired state, nothing more. CIS, NIST, and SOC 2 control mapping is `scalepad-controlmap`; Microsoft 365 security baselines are `cipp-standards`.

  • **A Microsoft 365 or Entra tenant** — an ImmyBot tenant is a client

organization inside this ImmyBot instance and is unrelated to an M365 tenant ID, even though ImmyBot authenticates via Entra. Use `cipp-tenants`.

  • **Fixing what the report shows** — this skill reports; remediation is

`immybot-software-deployment` and `immybot-maintenance-sessions`.

Tenant API Tools

| Tool | Purpose | |------|---------| | `immybot_tenants_list` | List tenants with name/status filters | | `immybot_tenants_get` | Full detail for one tenant by ID | | `immybot_tenants_search` | Search tenants by name | | `immybot_tenants_stats` | Statistics for a tenant | | `immybot_tenants_computers` | Computers belonging to a tenant | | `immybot_tenants_deployments` | Deployments scoped to a tenant | | `immybot_tenants_compliance` | Compliance dashboard data for a tenant | | `immybot_tenants_software_inventory` | Software inventory rollup for a tenant |

Task Queue API Tools

| Tool | Purpose | |------|---------| | `immybot_tasks_list` | Background tasks with computer/tenant/status/type filters | | `immybot_tasks_get` | Detail for one task | | `immybot_tasks_running` | All currently running tasks | | `immybot_tasks_queued` | Tasks waiting for execution | | `immybot_tasks_failed` | All failed tasks | | `immybot_tasks_for_computer` | Tasks for a specific computer | | `immybot_tasks_for_tenant` | Tasks for a specific tenant | | `immybot_tasks_by_type` | Tasks of a given type (SoftwareInstall, ScriptExecution, …) | | `immybot_tasks_queue_stats` | Task queue statistics | | `immybot_tasks_history` | Task execution history over a date range |

Per-Tenant Compliance Scorecard

1. `immybot_tenants_search` → resolve the tenant. 2. `immybot_tenants_get` and `immybot_tenants_stats` for the overview (computer count, status). 3. `immybot_tenants_compliance` for the compliance rollup — which deployments are met vs failing. 4. Drill into failing deployments with `immybot_deployments_compliance`. 5. `immybot_tenants_software_inventory` to confirm what is actually installed across the tenant.

Fleet Task-Queue Audit

1. `immybot_tasks_queue_stats` for the high-level picture. 2. `immybot_tasks_failed` — every failure across the fleet. 3. `immybot_tasks_running` and `immybot_tasks_queued` for current load and backlog. 4. For a problem client, `immybot_tasks_for_tenant` to scope the failures. 5. `immybot_tasks_history` over a date range for trend reporting.

Building a Client QBR Report

For each tenant, assemble:

  • Computer count and online ratio (`immybot_tenants_stats`,

`immybot_tenants_computers`).

  • Compliance percentage and failing deployments

(`immybot_tenants_compliance`).

  • Software inventory highlights — required software present,

outdated packages (`immybot_tenants_software_inventory`).

  • Recent failed tasks and how they were resolved

(`immybot_tasks_failed`, `immybot_tasks_history`).

Present per-tenant so the technician knows which client each finding belongs to.

Best Practices

  • Always scope task and compliance queries by tenant when reporting

to a specific client — unscoped results span the whole MSP.

  • Treat a low compliance percentage as a remediation backlog: route

failing deployments into a maintenance session.

  • Track failed-task trends over time, not just the current snapshot,

to catch recurring issues.

Related Skills

  • [software-deployment](../software-deployment/SKILL.md) — fix failing deployments
  • [maintenance-sessions](../maintenance-sessions/SKILL.md) — reconcile non-compliant tenants
  • [endpoint-management](../endpoint-management/SKILL.md) — drill into individual computers
Read more
Ships withmsp-claude-plugins

One command to supercharge Claude Code for MSP workflows. Then restart Claude Code. That's it. Documentation: mcp.wyre.ai

Get the whole plugin

Other skills on msp-claude-plugins.