AI SOC for MSSP Release Notes
AI SOC for MSSP is a new AI SOC offering for managed security service providers that run AI SOC across multiple customer environments.
Each client tenant keeps full AI SOC workflows—ingestion, triage, investigation, and case handling. A central tenant receives synchronized cases, threat intelligence artifacts, and periodic SOC reporting aggregates so MSSP analysts can oversee every customer in one place.
The offering ships as two packages that work with AI SOC Core in each client tenant. AI SOC MSSP Client Extension runs in the client tenant. AI SOC MSSP Central Solution installs in the central tenant. Case Management records and SOC reporting aggregates sync over the central ingest webhook. Full Threat Intelligence Artifact Cache records sync over the Swimlane API.
Client teams continue day-to-day work in their own tenant. Central visibility complements local Case Management; it does not replace it.
Overall, AI SOC for MSSP helps MSSPs scale AI SOC with centralized visibility while keeping customer workflows isolated in each client tenant.
Requires AI SOC Core Solution (26.2.0 or later) in each client tenant.
For more information, see Getting Started for MSSPGetting Started for MSSP and Configure AI SOC for MSSPConfigure AI SOC for MSSP.
Central Oversight
Review Cases Across Clients
MSSP analysts can review synchronized cases from every client tenant in one central Case Management application.
Each central case includes the client name and a link back to the originating client tenant record. You can filter by customer and open the source case when investigation or response is needed in that tenant.
For more information, see Work With Central Case Management in Use AI SOC for MSSP CentralUse AI SOC for MSSP Central.
Compare Threat Intelligence Across Clients
The central tenant maintains a Threat Intelligence Artifact Cache of full artifact records synced from client tenants.
Use the cache to compare observables across customers, confirm enrichment state, and request client-side re-enrichment when central data is stale. This comparison assumes threat intelligence vendors are the same across client tenants.
For more information, see Work With Threat Intelligence Artifact Cache and Request Client-Side Re-Enrichment in Use AI SOC for MSSP CentralUse AI SOC for MSSP Central.
Report MTTD and MTTR Across Clients
The central SOC reporting workspace provides cross-client aggregates for Cases, MTTD, and MTTR. Case aggregates are further grouped by report criteria such as severity, verdict, MITRE techniques, signal source, owner, and cases closed by Hero AI. MTTD and MTTR are grouped by signal source.
Reporting uses New (past week) and Total (near-full history) spans. Dashboards default to a current-week filter, except trend lines. Client reporting playbooks generate aggregates in the client tenant and post them to the same central webhook used for case sync.
For field definitions and the Sunday filter workaround, see Work With Central SOC Reporting in Use AI SOC for MSSP CentralUse AI SOC for MSSP Central, and Known Limitations.
Action Required
Complete Client Setup After You Install the Client Extension
After you install AI SOC MSSP Client Extension, complete these client tenant steps so sync works as designed.
Include the TIA Central Sync Fields applet on the client Threat Intelligence application (Support tab, Threat Intelligence Metadata). Without it, central Threat Intelligence Artifact Cache create and update can fail when writing required metadata fields.
In the Core playbook AI SOC Main, disable the Enrich TIA Record (Create) flow only. Do not disable the playbook. This keeps the client from re-enriching observables that already exist in the central Threat Intelligence Artifact Cache.
Then configure the client AI SOC Tenant Configuration asset (client PAT) and the two MSSP sync assets: AI SOC MSSP Client Configuration and AI SOC MSSP Central Sync.
For procedures, see Accept Get Application Fields Schema overwrite and Install in the Required Order in Getting Started for MSSPGetting Started for MSSP; Include TIA Central Sync Fields and Disable Enrich TIA Record in AI SOC Main in Configure AI SOC for MSSPConfigure AI SOC for MSSP; and Onboard a Client TenantOnboard a Client Tenant when you add another client.
Known Limitations
The following behaviors are documented constraints for this release. See the linked user guide topics for workarounds and setup steps.
Central SOC Reporting Current-Week Filter on Sundays
Central SOC Reporting dashboards default to a Current week filter (except trend lines). That filter uses the viewer's local timezone. Reporting timestamps are stored in UTC at midnight (00:00:00) on the day the weekly job runs.
On Sundays, the Current week filter can return no results even when data exists. On Central SOC Reporting Workspace dashboards, change the Current week date filter to a custom range that includes the report timestamps, or check again after Sunday in your timezone. New is the last week of aggregates; Total is near-full history.
See Work With Central SOC Reporting in Use AI SOC for MSSP CentralUse AI SOC for MSSP Central.
Get Application Fields Schema Overwrite on Client Extension Install
When you install AI SOC MSSP Client Extension in a tenant that already has AI SOC Core Solution, the installer may prompt to overwrite the Get Application Fields Schema component. Accept that overwrite. Do not skip or deselect this component. AI SOC Core does not use this component for client workflows. A later Core package will remove it.
See Accept Get Application Fields Schema overwrite in Getting Started for MSSPGetting Started for MSSP.
TIAC Tracking-ID Gaps When Observable Is Unique
The observable field in Threat Intelligence Artifact Cache must remain unique. Do not remove that uniqueness constraint.
When observable is unique, Tracking-ID numbers may not be assigned sequentially. Some ID numbers may be skipped if the system encounters duplicate observable values during record creation. This does not indicate data loss; skipped IDs correspond to suppressed duplicate entries.
See Tracking-ID gaps when observable is unique in Use AI SOC for MSSP CentralUse AI SOC for MSSP Central.