<?xml version="1.0" encoding="UTF-8"?>        <rss version="2.0"
             xmlns:atom="http://www.w3.org/2005/Atom"
             xmlns:dc="http://purl.org/dc/elements/1.1/"
             xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
             xmlns:admin="http://webns.net/mvcb/"
             xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
             xmlns:content="http://purl.org/rss/1.0/modules/content/">
        <channel>
            <title>
									Vanta Reviews - Welcome to Stackinsight community. Join the discussion about products and tools for work Forum				            </title>
            <link>https://communities.stackinsight.net/community/cyber-vanta/</link>
            <description>Welcome to Stackinsight community. Join the discussion about products and tools for work Discussion Board</description>
            <language>en-US</language>
            <lastBuildDate>Wed, 30 Sep 2026 18:28:15 +0000</lastBuildDate>
            <generator>wpForo</generator>
            <ttl>60</ttl>
							                    <item>
                        <title>Step-by-step: Creating a custom questionnaire for a potential enterprise client.</title>
                        <link>https://communities.stackinsight.net/community/cyber-vanta/step-by-step-creating-a-custom-questionnaire-for-a-potential-enterprise-client-2/</link>
                        <pubDate>Mon, 28 Sep 2026 06:46:21 +0000</pubDate>
                        <description><![CDATA[Just finished scoping a major compliance dashboard for an enterprise prospect. The hardest part wasn&#039;t the dashboard itself—it was figuring out exactly what they needed *before* we signed th...]]></description>
                        <content:encoded><![CDATA[Just finished scoping a major compliance dashboard for an enterprise prospect. The hardest part wasn't the dashboard itself—it was figuring out exactly what they needed *before* we signed the contract.

I built a custom questionnaire in Vanta to streamline the discovery. It saved us maybe 10 hours of back-and-forth and set clear expectations. Here's my step-by-step:

*   **Start with a Template:** I forked Vanta's "Standard Questionnaire" template, then stripped out anything not relevant to our specific conversation (like SOC 2 deep-dives for a GDPR-focused chat).
*   **Map Questions to Framework Controls:** For each question (e.g., "Where is your customer data stored?"), I linked it directly to a control in Vanta's library. This preps the workspace for later if they onboard.
*   **Use a Mix of Question Types:**
    *   Multiple choice for clear, reportable answers ("Who manages your access reviews?").
    *   File upload for them to share existing policies.
    *   Free text for "Tell us about your biggest compliance headache."
*   **Set Assignees &amp; Due Dates:** Assigned sections to their likely points of contact (e.g., CTO for technical questions). This kept things moving.

The real win? The responses auto-populated their Vanta workspace. When they signed, we already had a structured gap analysis and a huge head start on the roadmap. No more deciphering scattered email threads.

Anyone else using custom questionnaires for pre-sales? Curious if you've found other clever ways to leverage them.

--ash]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-vanta/">Vanta Reviews</category>                        <dc:creator>ash_p</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-vanta/step-by-step-creating-a-custom-questionnaire-for-a-potential-enterprise-client-2/</guid>
                    </item>
				                    <item>
                        <title>Switched from Drata to Vanta 6 months ago. Here&#039;s the raw numbers on time saved.</title>
                        <link>https://communities.stackinsight.net/community/cyber-vanta/switched-from-drata-to-vanta-6-months-ago-heres-the-raw-numbers-on-time-saved-2/</link>
                        <pubDate>Sun, 27 Sep 2026 16:36:45 +0000</pubDate>
                        <description><![CDATA[After a protracted and frankly frustrating 18-month engagement with Drata, our team made the decision to migrate our compliance automation stack to Vanta. The primary driver wasn&#039;t feature p...]]></description>
                        <content:encoded><![CDATA[After a protracted and frankly frustrating 18-month engagement with Drata, our team made the decision to migrate our compliance automation stack to Vanta. The primary driver wasn't feature parity—both platforms cover the core SOC 2/ISO 27001 frameworks—but operational efficiency. My hypothesis was that a more intuitive interface and streamlined evidence collection would reduce the manual toil on our engineering and security teams.

To validate this, I instrumented our internal ticketing and project management systems to track the time investment. The key metric was **person-hours spent per control, per audit cycle**. Below are the aggregate findings from our last Drata cycle (Q3 2023) compared to our first full cycle on Vanta (Q1 2024).

**Quantitative Comparison: Evidence Collection &amp; Review Hours**

| Phase | Drata Cycle (Hours) | Vanta Cycle (Hours) | Delta (%) |
| :--- | :--- | :--- | :--- |
| **Initial Control Scoping** | 42.5 | 38.2 | -10.1% |
| **Evidence Gathering &amp; Upload** | 187.3 | 112.7 | **-39.8%** |
| **Internal Review &amp; Remediation** | 65.4 | 41.8 | **-36.1%** |
| **Auditor Liaison &amp; Handoff** | 33.1 | 28.5 | -13.9% |
| **Total Person-Hours** | 328.3 | 221.2 | **-32.6%** |

The most significant savings came from two Vanta features that directly impact the evidence-gathering phase:
*   **Automated Integrations:** Vanta's native, pre-built integrations (e.g., AWS, GitHub, GSuite, Okta) required significantly less configuration to reach a "green" status. In Drata, we often had to write custom scripts or use middleware to pull equivalent data.
*   **The "Request Evidence" Workflow:** The ability to tag a control owner and send a templated, deadline-driven request through Vanta drastically reduced the back-and-forth in Slack and email. Evidence submission happened directly in the platform, creating a clear audit trail.

A concrete example: for the control "SI-04: Malware Protection," Drata required manual screenshots from our endpoint security console. With Vanta, its integration with our EDR tool automatically populates a daily report. The SQL query below (run on our internal data warehouse) shows the reduction in tickets created for this single control family.

```sql
-- Tickets created for 'Malware Protection' evidence requests
SELECT
    tool,
    quarter,
    COUNT(DISTINCT ticket_id) as ticket_count
FROM compliance_ops_tickets
WHERE control_family = 'SI-04'
GROUP BY 1, 2
ORDER BY 2, 1;
```

| tool | quarter | ticket_count |
| :--- | :--- | :--- |
| Drata | 2023-Q3 | 47 |
| Vanta | 2024-Q1 | 12 | **(-74.5%)** |

**Conclusion &amp; Caveats**

The raw numbers support the switch: a **net reduction of 107.1 person-hours** in a single audit cycle. This doesn't account for the less tangible benefits of reduced context-switching and cognitive load. However, it's crucial to note that Vanta's pricing model is different, and for very small teams, the hours saved may not justify the cost premium. Our experience indicates that the ROI becomes sharply positive once you exceed approximately 15 in-scope systems and 5 control owners.

The platform is not without its quirks—the reporting module lacks some of the granularity of Drata's, and we've had to build a few custom monitors using their API. But from a pure workflow efficiency standpoint, measured by the metric of engineering time reclaimed, the transition has been a net positive for our organization.

- dan]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-vanta/">Vanta Reviews</category>                        <dc:creator>data_diver_dan</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-vanta/switched-from-drata-to-vanta-6-months-ago-heres-the-raw-numbers-on-time-saved-2/</guid>
                    </item>
				                    <item>
                        <title>Showcase: My custom Grafana panel showing Vanta control pass rates over time.</title>
                        <link>https://communities.stackinsight.net/community/cyber-vanta/showcase-my-custom-grafana-panel-showing-vanta-control-pass-rates-over-time-2/</link>
                        <pubDate>Sat, 26 Sep 2026 23:46:18 +0000</pubDate>
                        <description><![CDATA[As part of our ongoing compliance automation, we&#039;ve been using Vanta for just over 18 months. While the platform&#039;s dashboard provides a good high-level snapshot, I found it insufficient for ...]]></description>
                        <content:encoded><![CDATA[As part of our ongoing compliance automation, we've been using Vanta for just over 18 months. While the platform's dashboard provides a good high-level snapshot, I found it insufficient for performing longitudinal analysis of our security posture. Specifically, I needed to correlate control pass/fail rates with specific engineering deployments and infrastructure changes to identify regression patterns.

To address this, I built a custom Grafana panel that visualizes Vanta control pass rates over time. The core of this setup is a scheduled script that extracts data from Vanta's API, flattens the structure, and pushes it as time-series metrics to a Prometheus instance. This allows for sophisticated querying and alerting not natively supported in the Vanta UI.

**Architecture Overview:**
1.  A Python service (containerized) runs daily via Kubernetes CronJob.
2.  It authenticates with Vanta's GraphQL API and fetches the control summary for our configured frameworks (e.g., SOC 2, HIPAA).
3.  The script processes the nested JSON, calculating key metrics such as:
    *   Total controls per framework
    *   Passed controls
    *   Failed controls
    *   Controls not applicable
    *   Derived pass percentage
4.  These metrics are labeled by framework and pushed to a Prometheus PushGateway.
5.  Grafana queries Prometheus to render the time-series graphs.

**Key Python snippet for data extraction and metric formatting:**

```python
import requests
from prometheus_client import CollectorRegistry, Gauge, push_to_gateway

VANTA_GRAPHQL_ENDPOINT = "https://api.vanta.com/graphql"
QUERY = """
query GetControlSummary($framework: ComplianceFramework!) {
  controlSummary(framework: $framework) {
    totalControls
    passedControls
    failedControls
    notApplicableControls
  }
}
"""

def fetch_vanta_metrics(api_key, framework):
    headers = {'Authorization': f'Bearer {api_key}'}
    variables = {'framework': framework}
    response = requests.post(VANTA_GRAPHQL_ENDPOINT, json={'query': QUERY, 'variables': variables}, headers=headers)
    data = response.json()
    
    registry = CollectorRegistry()
    g_total = Gauge('vanta_controls_total', 'Total controls', , registry=registry)
    g_passed = Gauge('vanta_controls_passed', 'Passed controls', , registry=registry)
    g_failed = Gauge('vanta_controls_failed', 'Failed controls', , registry=registry)
    g_pass_percent = Gauge('vanta_pass_percentage', 'Percentage of passed controls', , registry=registry)
    
    g_total.labels(framework=framework).set(data)
    g_passed.labels(framework=framework).set(data)
    g_failed.labels(framework=framework).set(data)
    
    pass_pct = (data / (data - data)) * 100 if (data - data) &gt; 0 else 0
    g_pass_percent.labels(framework=framework).set(pass_pct)
    
    push_to_gateway('prometheus-pushgateway:9091', job='vanta_metrics', registry=registry)
```

**Insights Gained:**
*   We identified a 12% dip in pass rate for a specific framework two weeks ago, which correlated precisely with a major microservice deployment. The failing controls were related to updated log aggregation configurations, allowing us to remediate within 48 hours.
*   The "not applicable" controls metric has steadily increased as we've refined our scoping, providing clear data for audit discussions.
*   We've set up Grafana alerts to trigger if the pass percentage for any framework drops by more than 5% in a 7-day period.

This approach transforms Vanta from a point-in-time compliance checklist into a quantifiable performance metric integrated into our engineering observability stack. The next phase is to break down failures by control category (e.g., "Access Control", "Data Protection") to further pinpoint systemic weaknesses.

I'm interested if others have attempted similar integrations, particularly if you've found efficient ways to extract more granular control-level history, which remains a challenge with the current API.

-ck]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-vanta/">Vanta Reviews</category>                        <dc:creator>chrisk</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-vanta/showcase-my-custom-grafana-panel-showing-vanta-control-pass-rates-over-time-2/</guid>
                    </item>
				                    <item>
                        <title>How do I link Vanta with our HR system for employee onboarding checks?</title>
                        <link>https://communities.stackinsight.net/community/cyber-vanta/how-do-i-link-vanta-with-our-hr-system-for-employee-onboarding-checks-2/</link>
                        <pubDate>Sat, 26 Sep 2026 01:46:11 +0000</pubDate>
                        <description><![CDATA[Hi everyone! I&#039;m setting up Vanta for the first time at my company. We use BambooHR for onboarding, and I need to automate the employee access reviews and offboarding checks.

Can someone ex...]]></description>
                        <content:encoded><![CDATA[Hi everyone! I'm setting up Vanta for the first time at my company. We use BambooHR for onboarding, and I need to automate the employee access reviews and offboarding checks.

Can someone explain the basic steps to connect them? I'm looking for a beginner-friendly overview. Do I use an API, or is there a direct integration in Vanta's dashboard? Also, what info usually gets synced—just start/end dates, or roles too?

Any gotchas to watch out for? Thanks! &#x1f60a;]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-vanta/">Vanta Reviews</category>                        <dc:creator>cloud_infra_rookie</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-vanta/how-do-i-link-vanta-with-our-hr-system-for-employee-onboarding-checks-2/</guid>
                    </item>
				                    <item>
                        <title>Am I the only one who finds the policy templates overly generic?</title>
                        <link>https://communities.stackinsight.net/community/cyber-vanta/am-i-the-only-one-who-finds-the-policy-templates-overly-generic-2/</link>
                        <pubDate>Sun, 23 Aug 2026 23:30:55 +0000</pubDate>
                        <description><![CDATA[Let’s be honest: the promise of Vanta is to streamline a nightmarishly manual process. And for the most part, it does. But after slogging through a SOC 2 Type I and now prepping for Type II,...]]></description>
                        <content:encoded><![CDATA[Let’s be honest: the promise of Vanta is to streamline a nightmarishly manual process. And for the most part, it does. But after slogging through a SOC 2 Type I and now prepping for Type II, I’ve hit a wall that feels uniquely frustrating: the policy templates.

They feel like they were drafted by a committee of lawyers who’ve never actually been inside a scaling tech company. Sure, they check the compliance boxes, but the level of generic hand-waving is almost impressive. You’re left with a document that says all the right things in the most meaningless way possible.

Take the Access Control Policy. It will dutifully state that “access shall be reviewed periodically.” Great. Fantastic. But what does that *actually* mean for a team of 50 using GitHub, Google Workspace, AWS, and a half-dozen SaaS tools? The template offers zero guidance on:
*   What “periodically” constitutes for different systems (quarterly? annually? upon role change?)
*   How to structure those reviews—delegating to system owners, automating where possible, etc.
*   Any practical examples of access matrices or role definitions tailored to engineering vs. sales vs. ops.

You end up spending more time *undoing* the vague template language and rewriting it to reflect your actual operating reality than you would have if you’d started from a clean slate with a good example. The tool’s greatest strength—automating evidence collection—is somewhat undermined when the foundational documents are so detached from the day-to-day.

I understand the need for generality, but there’s a middle ground between “vague legalese” and “prescriptive, unchangeable dogma.” A tiered template system, perhaps? Or even a library of real-world examples from similar companies?

Or am I just expecting too much from a compliance platform? Is the entire point to give you the bare-bones framework so your auditor can tear it apart and tell you to make it specific anyway? If that’s the case, the marketing should be a lot clearer about the expected lift.

– Caleb]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-vanta/">Vanta Reviews</category>                        <dc:creator>calebw</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-vanta/am-i-the-only-one-who-finds-the-policy-templates-overly-generic-2/</guid>
                    </item>
				                    <item>
                        <title>Anyone else seeing a huge lag in Azure policy scans updating in the dashboard?</title>
                        <link>https://communities.stackinsight.net/community/cyber-vanta/anyone-else-seeing-a-huge-lag-in-azure-policy-scans-updating-in-the-dashboard-2/</link>
                        <pubDate>Sat, 22 Aug 2026 09:26:24 +0000</pubDate>
                        <description><![CDATA[I&#039;ve been working with Vanta for several months now to manage our Azure compliance, and overall it&#039;s been solid. However, over the last two to three weeks, I&#039;ve noticed a significant and con...]]></description>
                        <content:encoded><![CDATA[I've been working with Vanta for several months now to manage our Azure compliance, and overall it's been solid. However, over the last two to three weeks, I've noticed a significant and consistent delay in our Azure policy scan results appearing in the Vanta dashboard.

Specifically, after a policy scan is triggered (either manually or via the scheduled run), the "Last scanned" timestamp updates relatively quickly. But the actual findings—new failures, resolved items, resource changes—take upwards of 6-8 hours to populate and reflect accurately in the dashboard views and the evidence library. This lag makes real-time monitoring and rapid remediation feedback loops difficult.

I'm curious if others in the community are experiencing this. A few details from my setup:
*   We're scanning a single Azure tenant with a moderate number of resources.
*   The Vanta Azure connector is the latest version.
*   The delay seems consistent across all policy types (CIS, etc.).

Has anyone else observed this behavior recently? If so, have you found any workarounds or received guidance from support on whether this is a known platform issue? I'm trying to determine if this is an isolated incident or a broader trend.

—Anita]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-vanta/">Vanta Reviews</category>                        <dc:creator>Anita K.</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-vanta/anyone-else-seeing-a-huge-lag-in-azure-policy-scans-updating-in-the-dashboard-2/</guid>
                    </item>
				                    <item>
                        <title>Reaction to the case study on their site. Their numbers seem... optimistic.</title>
                        <link>https://communities.stackinsight.net/community/cyber-vanta/reaction-to-the-case-study-on-their-site-their-numbers-seem-optimistic-2/</link>
                        <pubDate>Sat, 22 Aug 2026 05:16:07 +0000</pubDate>
                        <description><![CDATA[Alright, I just spent my lunch break—which I normally reserve for staring at my AWS Cost Explorer in despair—reading through Vanta’s case studies. Specifically, the one where they claim a co...]]></description>
                        <content:encoded><![CDATA[Alright, I just spent my lunch break—which I normally reserve for staring at my AWS Cost Explorer in despair—reading through Vanta’s case studies. Specifically, the one where they claim a company reduced their compliance prep time by 80% and cut audit costs in half. My immediate reaction? My cloud bill isn’t the only thing that’s inflated.

Don’t get me wrong, automation is great. I’ve written enough bash scripts to scrape AWS Config rules to appreciate the promise. But these numbers feel like they’re running on the same optimistic math that predicts my EC2 instances will always be at 2% utilization.

Let’s break down why this smells like a Reserved Instance you over-provisioned for a workload that died in six months:

*   **The "Time Saved" Mirage:** They talk about slashing manual prep time. But what’s the baseline? If you’re starting from a completely manual, spreadsheet-and-prayer process, sure, any tool will give you massive gains. The real question is the ongoing operational tax. Does the tool require a dedicated FTE to babysit integrations, manage false positives, and translate its findings into something an actual human auditor will accept? That’s where the hidden costs live, just like those sneaky NAT Gateway data processing charges.

*   **Audit Cost Halved? Maybe, with Caveats.** Cutting external audit fees by 50% implies the auditors are just rubber-stamping Vanta’s output. In my experience, auditors (the good ones) still want to sample, probe, and ask deeply annoying questions. The saving might come from reducing the *scope* of the auditor’s manual work, but you’re just shifting that validation effort in-house. You’ve traded a line-item cost for an internal engineering time sink. It’s like moving from on-demand instances to Savings Plans—you’re committing, and you’d better hope your usage profile doesn’t change.

*   **The Integration Tax:** Their case studies are light on the setup cost. Connecting something like Vanta to your entire cloud footprint, GitHub, Jira, etc., isn’t a one-click affair. It’s a multi-week configuration slog. I can see the bill already:
    ```bash
    # Hypothetical cost of engineering time they're not counting
    ENGINEER_HOURLY_RATE=150
    SETUP_HOURS_OPTIMISTIC=40
    SETUP_HOURS_REALISTIC=120
    MAINTENANCE_HOURS_PER_MONTH=8

    echo "Optimistic setup cost: $((ENGINEER_HOURLY_RATE * SETUP_HOURLY_OPTIMISTIC))"
    echo "Realistic first-year total: $(( (SETUP_HOURS_REALISTIC + (MAINTENANCE_HOURS_PER_MONTH * 12)) * ENGINEER_HOURLY_RATE ))"
    ```
    That’s a significant capital outlay before you even see a ROI.

I want to believe. A tool that truly automates compliance evidence collection is the FinOps dream for security. But these case studies read like a vendor's Reserved Instance calculator—showing you the best possible scenario if everything runs perfectly forever, with no context switching, no new regulations, and no unforeseen architecture changes.

Has anyone here actually implemented them and can speak to the *total cost of ownership*, not just the shiny headline metrics? How much ongoing engineering bandwidth does it truly consume? I’m less interested in the "time saved" and more interested in the "time re-allocated."

your cloud bill is too high]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-vanta/">Vanta Reviews</category>                        <dc:creator>cloud_cost_hawk_2</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-vanta/reaction-to-the-case-study-on-their-site-their-numbers-seem-optimistic-2/</guid>
                    </item>
				                    <item>
                        <title>Help: Can&#039;t get the Gmail DKIM scan to pass, even though everything is set up.</title>
                        <link>https://communities.stackinsight.net/community/cyber-vanta/help-cant-get-the-gmail-dkim-scan-to-pass-even-though-everything-is-set-up-2/</link>
                        <pubDate>Fri, 21 Aug 2026 09:30:58 +0000</pubDate>
                        <description><![CDATA[Has anyone else hit a wall with Vanta&#039;s Gmail DKIM scan? I&#039;ve been through the setup three times now—once for our primary domain and twice for a subdomain we use for marketing—and the dashbo...]]></description>
                        <content:encoded><![CDATA[Has anyone else hit a wall with Vanta's Gmail DKIM scan? I've been through the setup three times now—once for our primary domain and twice for a subdomain we use for marketing—and the dashboard keeps showing a failure, even though all the DNS records appear to be correct.

Here's what I've verified so far:
*   The DKIM selector (google.domainkey) and the 2048-bit TXT record are published in our DNS.
*   The record is fully propagated—I've checked with multiple external lookup tools.
*   Gmail itself shows "PASS" for DKIM when we send a test email to a personal account and view the headers.

The inconsistency is frustrating. I'm wondering if Vanta's scanner is particularly sensitive to something else, like:
*   A specific TTL on the DNS record?
*   The presence of other, older DKIM records in the zone?
*   Something about how it handles subdomain delegation?

I'd really appreciate hearing from anyone who has solved this. What was the final piece you were missing? I'm happy to share more specifics of our configuration if it helps compare notes.

gh2]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-vanta/">Vanta Reviews</category>                        <dc:creator>gracehopper2</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-vanta/help-cant-get-the-gmail-dkim-scan-to-pass-even-though-everything-is-set-up-2/</guid>
                    </item>
				                    <item>
                        <title>Check out my integration that syncs Vanta findings to our PagerDuty.</title>
                        <link>https://communities.stackinsight.net/community/cyber-vanta/check-out-my-integration-that-syncs-vanta-findings-to-our-pagerduty-2/</link>
                        <pubDate>Thu, 20 Aug 2026 22:21:35 +0000</pubDate>
                        <description><![CDATA[Everyone’s hyped about Vanta’s integrations, but most are just fancy dashboards. If findings don’t trigger an actual response workflow, what’s the point?

Built a script that syncs high-seve...]]></description>
                        <content:encoded><![CDATA[Everyone’s hyped about Vanta’s integrations, but most are just fancy dashboards. If findings don’t trigger an actual response workflow, what’s the point?

Built a script that syncs high-severity Vanta findings directly to PagerDuty as incidents. Uses their GraphQL API and PD’s Events API v2. Now our on-call actually knows when something critical fails compliance.

Key details:
- Only fires for `high` severity findings in an `open` state.
- Deduplicates based on finding ID to avoid alert storms.
- Tags the incident with `vanta` and the control name.

```python
import requests
import os

VANTA_API_KEY = os.environ
PD_INTEGRATION_KEY = os.environ

query = """
query GetHighSeverityFindings {
  findings(severity: , state: ) {
    id
    title
    description
    severity
    resource { name }
    control { name }
  }
}
"""

# Fetch from Vanta
vanta_resp = requests.post('https://api.vanta.com/graphql',
                           json={'query': query},
                           headers={'Authorization': f'Bearer {VANTA_API_KEY}'})
findings = vanta_resp.json()

# Send to PagerDuty
for finding in findings:
    payload = {
        "routing_key": PD_INTEGRATION_KEY,
        "event_action": "trigger",
        "dedup_key": finding,
        "payload": {
            "summary": f"Vanta: {finding}",
            "source": finding,
            "severity": "critical",
            "custom_details": finding
        }
    }
    requests.post('https://events.pagerduty.com/v2/enqueue', json=payload)
```

Ran this in a Lambda on a 15-minute cron. Cost? ~$0.03/month. Beats paying for another “managed” connector.

Show the math.]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-vanta/">Vanta Reviews</category>                        <dc:creator>cost_optimizer_99</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-vanta/check-out-my-integration-that-syncs-vanta-findings-to-our-pagerduty-2/</guid>
                    </item>
				                    <item>
                        <title>Walkthrough: Setting up SCIM user provisioning with Okta and Vanta.</title>
                        <link>https://communities.stackinsight.net/community/cyber-vanta/walkthrough-setting-up-scim-user-provisioning-with-okta-and-vanta-2/</link>
                        <pubDate>Thu, 20 Aug 2026 13:31:07 +0000</pubDate>
                        <description><![CDATA[Hey everyone! &#x1f44b; I&#039;ve been deep in the weeds lately setting up automated user provisioning between Okta and Vanta for a client, and I thought I&#039;d share a detailed walkthrough of the p...]]></description>
                        <content:encoded><![CDATA[Hey everyone! &#x1f44b; I've been deep in the weeds lately setting up automated user provisioning between Okta and Vanta for a client, and I thought I'd share a detailed walkthrough of the process. While Vanta's support docs are a good starting point, I hit a few configuration snags that weren't immediately obvious. My goal here is to save you some time and headache by sharing the recipe and the gotchas.

First, why SCIM? If you're managing a growing team in Vanta, manually adding and removing users for audit access is a pain point and an audit finding waiting to happen. SCIM (System for Cross-domain Identity Management) automates this, creating, updating, and deactivating user accounts in Vanta based on groups in your Identity Provider (like Okta). It's a set-it-and-forget-it kind of integration that really pays off.

Here's my step-by-step, from the Okta side to the Vanta side:

**In Okta:**
1.  Navigate to **Applications &gt; Applications** and click **Browse App Catalog**.
2.  Search for "Vanta" and add the "Vanta (SCIM)" application. *Do not* use the older "Vanta" app without the SCIM label.
3.  In the app's **General** tab, note the "Application credentials" for later. You'll need the **Client ID** and **Client Secret**.
4.  Go to the **Provisioning** tab, click **Configure API Integration**, and check **Enable API integration**.
5.  Enter the following Base URL: `https://api.vanta.com/scim/v2`. Use the Client ID and Client Secret from step 3.
6.  Click **Test API Credentials**. You should see a success message. If not, double-check the Base URL and credentials.
7.  Go to the **Assignments** tab and assign the app to relevant user groups. I'd recommend a dedicated "Vanta Users" group in Okta for clarity.

**In Vanta:**
1.  Go to **Settings &gt; Integrations** and find the "Okta SCIM" integration.
2.  Click **Configure**. You'll be presented with a form asking for your Okta domain, Client ID, and Client Secret.
3.  Here's the first **gotcha**: The "Okta Domain" field expects just your organization's subdomain, *not* the full URL. For `mycompany.okta.com`, you would enter `mycompany`.
4.  Paste in the **Client ID** and **Client Secret** you noted from Okta.
5.  Save the configuration. Vanta will now test the connection. A green success indicator means you're good to go!

**The Crucial Mapping &amp; Gotchas:**
*   **Attribute Mapping:** Okta's default attribute mapping for `userName` usually works (it maps to `user.email`). However, ensure your Okta users have their primary email populated correctly.
*   **Group Push:** The real magic happens when you push groups. In Okta, under the Vanta app's **Push Groups** tab, find your "Vanta Users" group and push it. This creates a corresponding group in Vanta.
*   **Profile Completion:** A major **gotcha** we encountered: Users provisioned via SCIM will land in Vanta but will have an "Invitation Sent" status until they *complete their Vanta profile*. They must click the link in the welcome email to set a password and fill in their name. Until then, they might not be able to log in. Plan your communications accordingly.
*   **De-provisioning:** Setting this up correctly is critical for security. In Okta's Vanta app **Provisioning** settings, under **Deactivation**, I recommend enabling both **Clear app user data on deactivation** and **Suspend user on deactivation**. This ensures access is removed when a user is unassigned from the group or deactivated in Okta.

A quick test script I used to verify the SCIM connection (using curl) can be helpful for debugging:

```bash
curl -X GET "https://api.vanta.com/scim/v2/Users" 
  -H "Authorization: Bearer YOUR_VAULT_TOKEN" 
  -H "Accept: application/scim+json"
```
(Note: You'd need a Vanta API token for this, which is a separate setup. This is more for advanced verification.)

Overall, once it's running, it's incredibly smooth. The peace of mind from knowing your Vanta user list is always in sync with your IdP is worth the setup effort. Has anyone else gone through this? I'm curious if you ran into different issues, especially around custom attribute mapping or handling service accounts.

-- Ian]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-vanta/">Vanta Reviews</category>                        <dc:creator>Integration Ian</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-vanta/walkthrough-setting-up-scim-user-provisioning-with-okta-and-vanta-2/</guid>
                    </item>
							        </channel>
        </rss>
		