M ManySignal

Multi-Tenancy & MSSP Console

Operate dozens of customers from one console

The ManySignal MSSP tier gives you a unified view of all customer tenants: active alerts across tenants, SLA health per customer, shared detection libraries with per-tenant override capability, and customer-specific audit trails that are invisible across tenant boundaries.

The MSSP tenant model

MSSP parent tenant

Houses shared detection libraries, shared workflow templates, shared Universal Action connectors, and the unified alert queue. MSSP engineers have read-only visibility into customer tenants with explicit customer opt-in.

Customer child tenants

Fully isolated: data, audit trails, encryption keys, and billing metrics are per-tenant. A customer's events never appear in another customer's search results, findings, or entity graph.

Shared library publishing

Detection rules, agent question sets, workflow templates, and context rules can be published from the parent tenant to any or all child tenants. Child tenants can inherit, extend, or override without forking the parent definition.

Per-tenant configuration

Each child tenant has its own autonomy ladder settings, SLA tiers, connector configurations, data retention policies, and guardrail rules. MSSP defaults provide a baseline; customers can adjust within MSSP-defined bounds.

Unified alert queue

The MSSP console shows all active P1 and P2 alerts across tenants in a single prioritized queue. Analysts can filter by customer, severity, or detection type and open cases without switching tenant contexts.

Customer-level reporting

Monthly SLA reports, coverage summaries, and case volume metrics are generated per customer. Reports are exportable as branded PDFs or delivered to customer stakeholders via a scheduled email.

Isolation is enforced, not configured

Tenant boundaries in ManySignal are enforced at the data layer, not at the application layer. Every query, every event lookup, and every API call carries a tenant ID that is verified at the storage layer. There is no "tenant=all" query that an application bug could accidentally run cross-tenant.

MSSP engineers with cross-tenant visibility access customer data through a scoped delegation model: a customer administrator grants a named MSSP account read access to their tenant for a defined period. The delegation is logged in the customer's audit trail and can be revoked at any time.

MSSP operations advantages

Onboard a new customer in hours

A new customer tenant is created via API: connector configuration, detection library inheritance, SLA tiers, and autonomy settings are all templated. The first live alert appears within hours of completing connector setup.

Cross-tenant threat correlation

The MSSP console can surface IOCs observed across multiple customer tenants without exposing customer identity. 'This IP appeared in 4 of your customers' alerts this week' is visible to MSSP analysts but not to individual customers.

Per-customer billing metrics

Event ingestion volume, storage consumption, and active rule counts are metered per tenant with daily granularity. Export to your billing system via webhook or API.

SLA dashboard by customer

SLA health per customer in a single view: green, amber, red per P1/P2/P3 tier. Drill through to the cases driving any amber or red status without tenant-switching.

White-label reporting

Customer-facing reports carry your branding, not ManySignal's. Logo, color scheme, and report header are configurable per MSSP tenant.

MSSP-specific role model

MSSP analyst, MSSP engineer, customer admin, and customer viewer are distinct roles with independent permission sets. Customers can grant read-only access to their own staff without MSSP involvement.

Multi-Tenancy — FAQ

Is there a limit on the number of child tenants?

No hard limit. MSSPs operating 200+ customer tenants are supported. The unified alert queue and reporting infrastructure are designed for high tenant counts with pagination and filtering.

Can a customer tenant be migrated to self-hosted?

Yes. A customer tenant can be migrated from the cloud-hosted deployment to a self-hosted environment within the customer's own infrastructure. Data migration tooling and a migration runbook are provided.

How is cross-tenant threat correlation handled without exposing customer data?

Correlation uses one-way hashes of observables (IP addresses, file hashes, domain names). The hash appears in the MSSP view as 'observed in N tenants' without revealing which tenants or the original observable value.

Can MSSP customers see each other's alert volumes?

No. Tenant isolation prevents any data from crossing tenant boundaries. Customer-to-customer visibility is architecturally impossible, not just access-controlled.

How does per-tenant autonomy configuration work for MSSPs?

Each child tenant has its own autonomy ladder settings — action class tiers, blast-radius limits, and kill switch — managed independently. The MSSP parent console can view and override tenant autonomy settings. Changes to a tenant's autonomy are logged in that tenant's immutable audit trail.

How does ManySignal generate per-client reports for MSSP billing and reporting?

Automated monthly reports are generated per tenant: alert volume, verdicts, SLA performance, response actions taken, and control-effectiveness summary. Reports are available in the MSSP console, exportable as PDF, and can be white-labelled with your MSSP branding.

What does the onboarding workflow look like for adding a new client tenant?

New tenants are provisioned in under 5 minutes via the MSSP API or console. A guided onboarding flow configures data source connectors, detection scope, autonomy settings, and SLA thresholds. The first agent verdicts on live alerts typically appear within 24 hours of connector setup.

Can individual tenants be given self-service access to their own ManySignal instance?

Yes. Child tenants can be granted a customer-level login that shows only their own data: alerts, cases, entity graph, and reports. Customer access levels are configurable — read-only view or analyst-level interaction — and can be revoked by the MSSP at any time.

How does ManySignal handle compliance and data residency for MSSP customers in different regions?

Each child tenant's data residency is configured independently. An MSSP serving customers in the EU and the US can pin EU tenants to eu-west infrastructure and US tenants to us-east — all managed from the same parent console without commingling data.

Run a tighter MSSP operation

Talk to the MSSP team about onboarding your customer base to the unified console.