M ManySignal

Guide · ManySignal

Launching an MDR Practice: MSSP Guide

Launching an MDR practice as an MSSP is less about the platform and more about the operating model. This guide covers the practical decisions — pricing, coverage model, tenant isolation, SOC-2 posture — that separate MSSPs whose ManySignal-powered practice grows profitably from those who take a year to reach their first client.

HR Hannah Roth — VP Product, ManySignal
14 min read Published Aug 3, 2026 Download PDF
01

Choose your pricing model before you write the SOW

The three viable MDR pricing models are: per-endpoint, per-log-volume, or per-outcome. Each maps to a different client-acquisition motion. Per-endpoint sells to security-conscious CIOs; per-log-volume aligns with data-heavy enterprises; per-outcome (verdicts triaged, incidents contained) matches ManySignal's economics best but requires trust.

Whatever you pick, price the shared-service coverage separately from environment-specific detection engineering. Shared costs (24/7 monitoring, ManySignal subscription passthrough) are predictable; custom detections are project-priced.

02

Tenant isolation for MSSP practices

ManySignal's multi-tenant model gives each client its own tenant with independent data, detections, RBAC, autonomy grants, and kill switch. The MSSP operator has a top-level MSSP console that switches contexts across tenants with full audit of who viewed what.

Never share detections between tenants by default. Publish shared content from a signed ruleset library that tenants opt into — this preserves per-client customisation and prevents cross-client leakage.

03

Coverage model and shift design

24/7 coverage does not mean 24/7 analysts. The ManySignal triage agent works every alert to a verdict autonomously; humans handle escalations. A viable US-only MSSP shift is one primary analyst 8am-8pm plus on-call for P1 pages after hours. Global MSSPs run three follow-the-sun 8-hour rotations.

Define P1/P2/P3 SLAs in the MSA. Standard: P1 acknowledged in 5 min, contained in 15; P2 acked in 15, contained in 1h; P3 acked in 1h, contained in 8h. ManySignal's response agent handles containment inside the SLA; the human confirms.

04

SOC 2 for the practice

Prospective enterprise clients will demand your SOC 2 report before your first proof-of-value. Achieve Type I in the first 90 days of practice launch; Type II within 12 months. ManySignal's own SOC 2 + ISO 27001 substantiates the platform layer — you're on the hook for the operator layer.

The relevant Trust Services Criteria for an MDR practice are CC6 (logical access), CC7 (system operations), and CC8 (change management). Map each to the operational controls in your runbook so the auditor doesn't have to invent evidence.

  • Formal access review quarterly for all analyst logins
  • Change management for detection promotions (git PR + review)
  • Shift handover procedure documented + audit-logged
  • Client SLA breach report generated monthly from case data
05

Client onboarding: 30 days to production

Standard onboarding: week 1 connectors + tenant provisioning, week 2 baseline learning, week 3 shadow-mode with weekly report, week 4 production cutover with named-analyst introduction. Communicate this timeline in every SOW so clients don't expect same-day.

The first monthly executive report — auto-generated by the report agent from case data — is the single highest-value client artefact. It shows verdicts rendered, incidents contained, coverage growth, and MTTR. Send it on the same date every month, unchanged in format.

Key takeaways

  • Price the outcome, not the seat.
  • Tenant isolation is per-client at every layer; shared content is opt-in via signed library.
  • 24/7 coverage is agent-first + human-on-call — not a 24/7 human rota.
  • Get SOC 2 Type I in 90 days, Type II in 12 months.
  • Standard onboarding is 30 days. The monthly executive report is the highest-value client artefact.

Further reading

Frequently asked questions

What is Launching an MDR Practice: MSSP Guide in an agentic SOC?

Launching an MDR Practice: MSSP Guide is part of ManySignal's agentic SOC and MDR platform, where AI agents detect, triage, investigate, and respond to threats with human-governed autonomy.

How does ManySignal handle launching an mdr practice: mssp guide?

ManySignal grounds launching an mdr practice: mssp guide in a temporal entity graph and behavioural baselines, so every verdict is backed by auditable evidence rather than opaque scores.

Can ManySignal replace my SOAR or MDR for launching an mdr practice: mssp guide?

Yes. ManySignal combines detection, triage, investigation, response, and reporting in one platform, and can operate as your MDR or augment an existing SOC team.

How is autonomy governed?

Through an autonomy ladder: recommend-only, approve-gated, and autonomous modes per action class, with dry-run previews, blast-radius limits, and a one-click tenant kill switch.

How fast is time to value?

Declarative connectors and shipped detections typically produce AI agent verdicts on live alerts within days, not quarters — no parsing projects or playbook-building phase.

Is ManySignal available as a managed service?

Yes. Consume ManySignal as MDR with 24/7 coverage and monthly reporting, run it as your in-house agentic SOC, or use it as the platform behind your own MDR practice.

How does ManySignal license the platform?

Pricing scales with protected assets and autonomy tier, not per-GB ingestion or per-alert volume. Starter, Growth, and Enterprise plans are available; MDR providers receive volume discounts for multi-tenant deployments.

Where does our data reside?

By default in AWS us-east-1. Enterprise tenants can pin data to specific AWS regions, deploy self-hosted on their own Kubernetes cluster, or use customer-managed encryption keys (CMK) to retain cryptographic control.

What does the evidence trail contain?

Each verdict stores the full question set, per-question agent answers, confidence weights, source event references, entity graph snapshots, and operator attestation — preserved immutably for the retention period chosen at contract time.

How does ManySignal handle a false-positive alert?

The triage agent auto-closes findings it assesses as false positives with a documented rationale — which rule fired, why the evidence fails to support escalation, and the entity baseline that informed the decision. Auto-closure rates typically reach 85–95% within 90 days as baselines mature.

Continue reading

See the agentic SOC in action

Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.