Onboard a Client Tenant
Use this guide each time you add a new client tenant to an existing AI SOC for MSSP deployment. The central tenant is already live; you copy central values, install client packages, configure sync in the new client, and validate propagation.
For first-time MSSP deployment (install all three solution layers and configure both tenants), use Getting Started for MSSPGetting Started for MSSP instead of this guide.
Before You Start
- Central tenant deployment is already active and operational.
- You have admin access to the new client tenant and the central tenant.
- You have approved naming conventions for Client_Name values so central case and reporting views do not fragment.
- You have a Swimlane PAT for the client AI SOC Tenant Configuration asset (Private_Token), and an admin PrivateToken for AI SOC MSSP Central Sync. These are different tokens.
- After you install AI SOC MSSP Client Extension, disable Enrich TIA Record (Create) flow in the client AI SOC Main playbook. Do not disable the playbook itself. See Disable Enrich TIA Record in AI SOC Main in Configure AI SOC for MSSPConfigure AI SOC for MSSP.
Gather Values From the Central Tenant
You do not reconfigure the central tenant during client onboarding. Copy values from the existing central deployment:
- Copy the Ingest Record from Client webhook URL, username, and password from the central tenant (documented under Configure the Central Tenant in Configure AI SOC for MSSPConfigure AI SOC for MSSP). This webhook is required for Case Management and reporting sync.
- Confirm the sensor is enabled.
- Copy the central Threat Intelligence Artifact Cache application identifier for the new client AI SOC MSSP Client Configuration Central_TIAC_App_ID field (procedure Find the Central TI Cache Application ID in Configure AI SOC for MSSPConfigure AI SOC for MSSP).
Prepare the New Client Tenant
- Create or verify the new client tenant.
- Confirm tenant users, roles, and access controls are configured.
- Confirm base AI SOC dependencies are available for this tenant.
Install Client-Side Solution Layers
- Install AI SOC Core Solution (26.2.0 or later) in the new client tenant.
- Install AI SOC MSSP Client Extension in the same client tenant.
When the installer prompts to overwrite the Get Application Fields Schema component, accept that overwrite. Do not skip or deselect this component. See Accept Get Application Fields Schema overwrite in Getting Started for MSSPGetting Started for MSSP.
- Verify installation succeeded and MSSP assets are present (AI SOC MSSP Client Configuration, AI SOC MSSP Central Sync, AI SOC MSSP Reporting).
- Include TIA Central Sync Fields on the client Threat Intelligence application (Support β Threat Intelligence Metadata). See Include TIA Central Sync Fields in Configure AI SOC for MSSPConfigure AI SOC for MSSP.
- Disable the Enrich TIA Record (Create) flow in the Core playbook AI SOC Main. See Disable Enrich TIA Record in AI SOC Main in Configure AI SOC for MSSPConfigure AI SOC for MSSP.
Configure the New Client Tenant
In the new client tenant only, complete the client sections in Configure AI SOC for MSSPConfigure AI SOC for MSSP:
- Configure the Client Tenant (AI SOC Tenant Configuration PAT, include TIA Central Sync Fields, disable Enrich TIA Record (Create) flow in AI SOC Main, and confirm MSSP reporting).
- Configure MSSP Client Sync Assets using the central values you gathered.
Confirm Client_Name in AI SOC MSSP Client Configuration matches how you filter records in central Central Case Management and Central SOC Reporting.
Validate Client Onboarding
- Create or ingest a test record in the new client tenant.
- Confirm the record appears in central Central Case Management with the correct Client_Name.
- Confirm related TIAC records appear or update in central Threat Intelligence Artifact Cache.
- Verify updates continue after additional status or field changes in the client tenant.
- After the reporting job runs, confirm a reporting aggregate for this Client_Name appears in Central SOC Reporting.
If validation fails, see Validate and Troubleshoot MSSP SyncValidate and Troubleshoot MSSP Sync.
Common Onboarding Issues
Issue | Likely Cause | Action |
|---|---|---|
Hero AI or core playbooks fail in client | Incomplete AI SOC Tenant Configuration (including Private_Token) | Complete Configure the Client Tenant in Configure AI SOC for MSSPConfigure AI SOC for MSSP |
New client records do not appear in central | Client endpoint or tenant identifier mismatch | Recheck Configure MSSP Client Sync Assets in Configure AI SOC for MSSPConfigure AI SOC for MSSP |
Sync fails with authentication errors | Webhook credentials do not match | Align client sync asset and central Ingest Record from Client webhook in Configure AI SOC for MSSPConfigure AI SOC for MSSP |
TI cache does not update | Missing or incorrect Central_TIAC_App_ID or PrivateToken, or TIA Central Sync Fields not included | Recheck Find the Central TI Cache Application ID, PrivateToken, and Include TIA Central Sync Fields in Configure AI SOC for MSSPConfigure AI SOC for MSSP |
Client still enriches TIA when central TIAC already has the observable | Enrich TIA Record (Create) flow is still enabled in AI SOC Main | Complete Disable Enrich TIA Record in AI SOC Main in Configure AI SOC for MSSPConfigure AI SOC for MSSP |
Central reporting is empty for the new client | Reporting playbooks not running, or Client_Name mismatch | Confirm AI SOC MSSP - Reporting / SOC Reporting Sync and Client_Name |
Central API calls fail from the client tenant | Invalid PrivateToken or incorrect Central_Tenant_ID | Recheck AI SOC MSSP Central Sync PrivateToken and AI SOC MSSP Client Configuration |