App Logo
IT ops

Drata MCP: failing tests, exclusions and users from Claude or ChatGPT (2026)

Prompt template

In Drata, list every monitoring test that is failing, group the findings by owner, and tell me which ones are out of scope so we can exclude them with a reason I approve.

Overview

Drata watches your stack all day and tells you what fails: a repository without branch protection, a laptop without disk encryption, a person who has not accepted a policy. Then someone has to open each test, read the findings, decide what is real and what is out of scope, and act. That is the part that waits.

Why it's hard

Failing tests are spread over many pages, each with its own list of resources. An exclusion needs the right resource, picked in the test's findings, and a reason good enough for an auditor. Checking whether a leaver is still a Drata user is another trip to the settings. None of it is hard, but all of it is manual, and it comes back every week.

How Reduck does it

Reduck is an MCP server whose Drata scripts run in your own Chrome, signed in as you. Your agent reads what you see in Drata and acts only when you ask. The Reduck team runs its own compliance in Drata with these scripts.

A typical weekly review, in one request:

  1. List failing tests returns every test that fails in production, with its failing resources or people.
  2. The agent groups them by owner and proposes what to fix and what is out of scope.
  3. You approve. Exclude a finding records each exclusion with the reason you agreed on.
  4. List platform users confirms that people who left are no longer in Drata.

What your agent does

  • List the monitoring tests that fail in production, with each finding and its severity
  • Group findings by owner and propose the next step
  • Exclude a resource from a test with the justification auditors read
  • List your Drata users with roles, date added and last login, or check one email
  • Read an employee's own compliance checks and policy acceptances

Who it's for

  • Startups going through SOC 2 or ISO 27001 with Drata
  • Founders and ops leads who own compliance without a GRC team
  • Anyone who wants a weekly Drata digest in their AI assistant

FAQ

List the monitoring tests that fail in production with each failing resource or person, exclude one resource from a test with a written justification, list the users of your Drata workspace, and read an employee's own compliance checks and policies.
No. Reduck works through the Drata web app, in your own Chrome, under your own login. Your agent sees and does what your Drata role allows.
Only when you ask for an exclusion. The other scripts only read. An exclusion changes the test result and keeps the reason you gave, which Drata shows auditors; you can undo it from the test's Exclusions tab.
List platform users takes an optional email and tells you whether that person is still listed in Drata, so you can confirm a leaver is gone. To remove the person from your other tools, see the user access review page.
Yes. Reduck connects to Claude, ChatGPT, Claude Code, Codex and any other MCP client. You ask in plain words, and the agent chains the scripts it needs.
No. Reduck is an independent tool. Its scripts use the Drata web app the way you do, one action at a time and only when asked, under your own login.

Similar use cases

GitHub Slack Notion

User access review

Run your quarterly user access review with Claude, ChatGPT or any MCP client. Your agent exports users and roles from GitHub, Slack, Notion, Vercel and the rest of your stack, flags who should not be there, and removes leavers with proof.

IT ops
Notion Vercel GitHub

Audit team access

Pull every member and role across your stack, then offboard someone with proof nobody else moved.

IT ops

Start building not clicking