AI SOC for MSSP
use this guide set to deploy, operate, and validate ai soc in a managed service provider (mssp) model with client tenants and a central tenant mssp mode overview ai soc for mssp is an optional solution designed for multi tenant architectures while the ai soc core serves as the foundational solution running within each client tenant, the ai soc for mssp augments it with specialized multi tenant capabilities the mssp client extension uses synchronization features to update the central tenant with case management records, threat intelligence artifact cache (tiac) records, and periodic soc reporting aggregates, creating a centralized single pane of glass view rather than replacing the client's local case management, it facilitates centralized visibility and introduces mssp specific workflows how ai soc for mssp works ai soc for mssp deployment uses three solution layers solution layer install tenant purpose ai soc core solution client tenant base ai soc applications, workflows, dashboards, and playbooks (26 2 0 or later) ai soc mssp client extension client tenant syncs case records, full tiac records, and reporting aggregates from client to central tenant ai soc mssp central solution central tenant receives client records and maintains central case, ti cache, and soc reporting views ai soc mssp client extension uses two paths to the central tenant case management records and soc reporting aggregates go over the central ingest record from client webhook threat intelligence artifact cache records are created or updated over the swimlane api using privatetoken what resides in the central tenant is the threat intelligence artifact cache (ti cache), central case management , and central soc reporting architecture of mssp mode tenant role primary responsibility typical data scope client tenant detect, triage, investigate, and resolve customer alerts single customer records and tenant local operations central tenant aggregate synchronized records across clients multi client oversight and centralized reporting views ai soc mssp data flow from client tenant to central tenant the ingest record from client webhook receives two kinds of records case management records and soc reporting records full threat intelligence artifact cache records use the swimlane api ( privatetoken ), not the webhook client teams continue work in the client tenant; central is a single pane of glass tenant roles client tenant receives and processes customer alerts using standard ai soc workflows runs triage and investigation in case management configures core ai soc tenant configuration (including private token ) from ai soc core solution configures ai soc mssp client configuration and ai soc mssp central sync so case records, reporting aggregates, and tiac records reach the central tenant ( central webhook url , client name , central tenant id , central tiac app id , webhook basic auth, and privatetoken ) includes tia central sync fields on the client threat intelligence application ( support tab, threat intelligence metadata ) so central tiac create and update can write required metadata fields disables the enrich tia record (create) flow in core playbook ai soc main so the client does not re enrich tia observables that already exist in central threat intelligence artifact cache runs case record monitoring so case management updates post to the central webhook this webhook path is required for case sync runs ai soc mssp reporting and soc reporting sync so periodic reporting aggregates post to the same central webhook this path is required for central soc reporting synchronizes new or re enriched threat intelligence (ti) data from the client tenant to the central tenant's threat intelligence artifact cache (tiac) as full tiac records (create or update) over the api central tenant aggregates data across client tenants for mssp oversight uses the ingest record from client webhook to receive case and report payloads (no separate central mssp configuration assets in current packages) the only required central configuration is webhook authentication; playbooks, workspaces, and applications install with the package provides centralized record visibility in central case management stores multi tenant ti cache data in threat intelligence artifact cache can mark ti cache records for client side re enrichment when enrichment must be refreshed provides central soc reporting and the central soc reporting workspace for cross client aggregates, plus usage statistics flow overview client tenant ingest and investigation workflows create or update records case record monitoring sends case management records to the central ingest record from client webhook soc reporting sync periodically sends reporting aggregates to the same webhook client ti automation creates or updates full threat intelligence artifact cache records in the central tenant over the api central catch records from client routes webhook payloads to upsert central case management record or upsert central report record mssp analysts use central applications and dashboards for cross client monitoring client teams continue remediation and case handling in their own tenant workflows choose your path if you need to use this guide configure client and central tenants (assets, webhook, sync) configure ai soc for mssp docid\ azfpz c qlu3elvszkllw perform first deployment and baseline validation getting started for mssp docid\ ivvy6gxajwc34xvmnnqc add an additional customer environment onboard a client tenant docid\ fgkw7if8vsr9 hchdexus work day to day in the central tenant use ai soc for mssp central docid\ gualyzlqa 7acfkpszhcq confirm data propagation and resolve sync failures validate and troubleshoot mssp sync docid\ qyesknwk rnsc1w1uax d related ai soc guides if you want to go to run first investigation workflows in a client tenant getting started docid\ p7qjquayekczhpxeppwcp configure base ai soc tenant assets (pat, ti, correlation) installing and configuring ai soc solution docid b7njxu5xnzyrjcngqg5j and configure custom assets docid\ qdckijlols 7dwzjgrbqk learn ai soc applications and dashboards ai soc applications docid\ uosuzrpsl6hfe9d6br5az and dashboards docid\ aayntc5rumve6m xru 0 review operational and troubleshooting guidance operations and guidance docid\ dsdgtaqeg95dseaf2iat and troubleshooting docid\ cknuxqv85k9lu0ocqv218