Configure AI SOC for MSSP
Use this guide to configure client and central tenants after you install the AI SOC for MSSP solution layers. For install order and first validation, see Getting Started for MSSPGetting Started for MSSP.
Choose Your Path
If you are configuring | Go to |
|---|---|
Core client tenant PAT asset | |
Client TIA applet for central TI sync | |
Disable Core TIA enrichment on the client | |
Central ingestion webhook | |
MSSP sync assets on a client tenant |
Credential and Asset Overview
Asset or credential | Tenant | Purpose |
|---|---|---|
AI SOC Tenant Configuration | Client | PAT-based Swimlane API access for Hero AI flows (from AI SOC Core Solution). Field: Private_Token. |
AI SOC MSSP Client Configuration | Client | Client_Name, Central_Webhook_URL, Central_Tenant_ID, and Central_TIAC_App_ID (from AI SOC MSSP Client Extension) |
AI SOC MSSP Central Sync | Client | Webhook basic auth for case and reporting sync, and PrivateToken for central TIAC API calls (from AI SOC MSSP Client Extension) |
Ingest Record from Client webhook | Central | Receives Case Management records and SOC reporting aggregates from client tenants. Required for case and reporting sync. |
AI SOC Tenant Configuration comes from AI SOC Core Solution. MSSP sync assets come from AI SOC MSSP Client Extension. Open each by its title under Orchestration β Assets.
PrivateToken on AI SOC MSSP Central Sync is an admin personal access token authorized for the central tenant. It is used to create and update full Threat Intelligence Artifact Cache records over the API. It is not used to post case or report payloads; those use the webhook and Authorization username and password. It is also not the same value as Private_Token on the client AI SOC Tenant Configuration asset.
Configure the Client Tenant
Complete these steps in each client tenant after AI SOC Core Solution and AI SOC MSSP Client Extension are installed.
AI SOC Tenant Configuration
- Open AI SOC Tenant Configuration under Orchestration β Assets.
- Configure:
- Base_URL: Client Swimlane host
- Account_Id: Swimlane account identifier
- Tenant_Id: Client tenant identifier
- Private_Token: Valid Swimlane PAT that belongs to an Orchestrator or Administrator in the client tenant
- Save and activate the asset when required.
For additional core asset detail, see Configure Custom AssetsConfigure Custom Assets.
Confirm client MSSP reporting
- Confirm the AI SOC MSSP Reporting application and AI SOC MSSP Reporting Workspace are installed with AI SOC MSSP Client Extension.
- Confirm AI SOC MSSP - Reporting and SOC Reporting Sync playbooks are present. Reporting sync uses the same central webhook as case sync; it is required for Central SOC Reporting.
- Open the reporting workspace once to verify default dashboards load for your RBAC role.
Include TIA Central Sync Fields
The AI SOC MSSP Client Extension includes the TIA Central Sync Fields applet. Add it to the client Threat Intelligence application so central TIAC create and update can write the required metadata fields. If this applet is missing, AI SOC MSSP - Central Sync can fail on Update_TIA_Record with key errors.
- In the client tenant, open Application Builder for the Threat Intelligence application.
- Select the Support layout tab.
- From Applet Display, add TIA Central Sync Fields to the Threat Intelligence Metadata section.
- Save the application.
Repeat this step in every client tenant after you install AI SOC MSSP Client Extension.
Disable Enrich TIA Record in AI SOC Main
In each client tenant, disable the Enrich TIA Record (Create) flow in the Core playbook AI SOC Main. If this flow stays enabled, the client tenant enriches TIA observables even when a matching record already exists in central Threat Intelligence Artifact Cache. That duplicate enrichment defeats the purpose of the central TI cache.
- In the client tenant, open Orchestration β Playbooks.
- Open AI SOC Main (from AI SOC Core Solution).
- Select the Enrich TIA Record action (Create).
- Disable the flow.
- Save the playbook.
Disable the Enrich TIA Record (Create) flow. Do not disable the AI SOC Main playbook. The AI SOC MSSP Client Extension checks central Threat Intelligence Artifact Cache first. Client enrichment is reserved for cache miss, stale data, or Requires Re-Enrichment, not for this Core create flow.
Repeat this step in every client tenant after you install AI SOC Core Solution and AI SOC MSSP Client Extension.
Configure the Central Tenant
Complete these steps in the central tenant after AI SOC MSSP Central Solution is installed.
Central Ingestion Webhook
This webhook is required. Client Case Record Monitoring and SOC Reporting Sync both post to it.
- Navigate to Orchestration β Playbooks.
- Open Catch Records from Client (the playbook that contains the Ingest Record from Client webhook sensor).
- Select the Ingest Record from Client sensor.
- Under authentication, set Username and Password for incoming client sync requests. The package may ship with a default username until you change it; use credentials you will copy to each client AI SOC MSSP Central Sync asset.
- Enable the sensor if it is disabled after install.
- Copy the webhook URL from the sensor configuration.
- Save the playbook.
- Record the webhook URL, username, and password in your onboarding worksheet for additional client tenants.
The central MSSP solution does not ship separate central configuration assets. After install, the only required central configuration is Ingest Record from Client webhook authentication. Playbooks, workspaces, and applications are present from the package; you do not configure them beyond enabling the webhook sensor and confirming they load.
After install, these central objects are available without further configuration:
- Playbooks: Catch Records from Client, Upsert Central Case Management Record, Upsert Central Report Record, Set Requires Re-Enrichment
- Workspaces: AI SOC MSSP Central, Central SOC Reporting Workspace, Usage Statistics Workspace
- Applications: Central Case Management, Threat Intelligence Artifact Cache, Central SOC Reporting, Usage Statistics
Configure MSSP Client Sync Assets
Complete these steps in each client tenant after the central ingestion webhook is configured.
- Open Assets under Orchestration.
- Configure AI_SOC_MSSP_Client_Configuration (AI SOC MSSP Client Configuration):
Field | What to enter |
|---|---|
Client_Name | Unique MSSP client or tenant display name. This value is stamped on central case and reporting records so you can filter by client. |
Central_Webhook_URL | URL of the central Ingest Record from Client webhook |
Central_Tenant_ID | Central tenant identifier |
Central_TIAC_App_ID | Central Threat Intelligence Artifact Cache application identifier |
- Configure AI_SOC_MSSP_Central_Sync (AI SOC MSSP Central Sync):
- Under Authorization, set Username and Password to match the central Ingest Record from Client webhook credentials.
- Set PrivateToken to a valid Swimlane admin personal access token for central API operations (TIAC create and update).
- Save and verify both MSSP assets are active.
Find the Central TI Cache Application ID
To find Central_TIAC_App_ID:
- In the central tenant, open Threat Intelligence Artifact Cache.
- Copy the application identifier from the application URL or application settings (format varies by environment).
- Enter that value in the client AI SOC MSSP Client Configuration asset.
You can also use the Swimlane API to retrieve the application identifier.
Configuration Checklist
Client Tenant
- AI SOC Tenant Configuration is configured (including Private_Token).
- TIA Central Sync Fields is included on the client Threat Intelligence application Support tab, under Threat Intelligence Metadata.
- Enrich TIA Record (Create) flow is disabled in the client AI SOC Main playbook.
- AI SOC MSSP Client Configuration and AI SOC MSSP Central Sync are active.
- Client_Name is set and matches how you identify the customer in central Central Case Management and Central SOC Reporting.
- Central_Webhook_URL, Central_Tenant_ID, and Central_TIAC_App_ID are complete.
Central Tenant
- Ingest Record from Client webhook is enabled with known credentials.
- Central Case Management, Threat Intelligence Artifact Cache, and Central SOC Reporting are accessible after install.
Next Steps
If you need to | Go to |
|---|---|
Install solution layers and run first validation | Getting Started for MSSPGetting Started for MSSP |
Add another customer tenant | Onboard a Client TenantOnboard a Client Tenant |
Work day to day in the central tenant | Use AI SOC for MSSP CentralUse AI SOC for MSSP Central |
Troubleshoot sync issues | Validate and Troubleshoot MSSP SyncValidate and Troubleshoot MSSP Sync |