Multi-tenant SOC for MSPs: all your clients, one console
Deliver managed detection and response to every client with true data isolation, role-based permissions and individual reports, without duplicating deployments.
Why an MSP needs a multi-tenant SOC
A managed service provider serves dozens of clients with different infrastructures. Running one security console per client multiplies cost and response time; mixing their data in one console breaks confidentiality. Multi-tenancy solves both: a single deployment, data separated per organization.
CiberEm is designed from the ground up for MSPs and MSSPs: each organization has its own agents, alerts, cases and vulnerabilities, and the administrator switches clients from a selector without logging in again.
Isolation per organization
Tenant filtering is enforced on every database query, not only in the interface. An analyst in one organization cannot see alerts, observables or cases from another, and response actions only reach the assets of the corresponding client.
4-role RBAC and auditing
Role-based access control defines what each user can do inside their organization.
- Admin: manages all organizations and global configuration.
- Organization owner: manages their own tenant, users and policies.
- Analyst: investigates, manages cases and executes the responses their role allows.
- Viewer: read-only access to dashboards and reports.
- Every mutating action is logged with user, organization, entity, IP and metadata for audits.
Per-client reports
Each organization gets its own KPIs: open and critical alerts, MTTR, cases, active agents and vulnerabilities by CVSS and EPSS. Executive reports are generated per client and serve as the monthly deliverable of the service.
FAQ for MSPs
How is each client’s data isolated?
Every database query is filtered by organization. Alerts, cases, observables, agents and vulnerabilities belong to one tenant and are not visible from another.
Can I give my clients access?
Yes. You can create users with the organization owner, analyst or viewer role inside the client’s tenant, so they see only their own information.
Which roles exist?
Four: admin, organization owner, analyst and viewer. The permission matrix also distinguishes between reversible and disruptive response actions.
Is every action logged?
Yes. Every data-changing action lands in an audit log with user, organization, affected entity, IP and metadata, useful for compliance and forensic analysis.
How does it scale with more clients?
Adding a client means creating an organization and connecting its sources. The deployment stays the same; the organization selector lets the MSP team operate all tenants from one console.