MSSP & Multi-Tenant Features
Manage multiple client organizations, branded reports, and delegated feeds with MSSP tier features.
The MSSP tier is built for managed security service providers who need to manage threat intelligence across multiple client organizations from a single account. It provides multi-tenant management, branded reporting, and org-scoped API access.
What the MSSP Tier Provides
- Create and manage multiple client organizations under one umbrella
- Per-org feeds, alert rules, and webhook configurations
- Branded PDF reports with client logos
- 1,200 API requests per minute with org-scoped endpoints
- Everything included in the Business tier, plus multi-tenant capabilities
Organization Management
Each of your clients gets their own organization in ThreatCluster.
- Create organizations -- From the admin portal, click New Organization and enter the client name and details.
- Invite members -- Add client contacts or your own analysts to each org. Assign roles: Viewer, Analyst, or Admin.
- Manage roles -- Org admins can manage their own members. As the MSSP account holder, you have full access across all orgs.
Organization-Level Features
Each organization operates as an independent workspace:
- Dedicated feeds -- Configure feeds scoped to the org's industry, keywords, or threat profile. Feed content stays isolated to that org.
- Alert rules -- Set up alert rules specific to each client's environment and threat landscape.
- Webhooks -- Route alerts to each client's SIEM, Slack, or ticketing system independently.
- Workflows -- Assign investigation workflows scoped to the org, so each client's activity stays separate.
Branded Reports
Generate professional PDF reports with your client's branding.
- Go to the organization's settings and upload the client's logo.
- When generating a report from the Reports page, select the organization.
- The report will include the client logo, org name, and scoped data -- only clusters and entities relevant to that org's feeds.
Reports can be generated on demand or scheduled for automatic delivery.
API Access for MSSP
MSSP accounts get elevated API access:
- Rate limit: 1,200 requests per minute (vs. 600 for Business)
- Org-scoped endpoints: Pass an
X-Org-Idheader to scope API calls to a specific client organization - Bulk operations: Export IOCs, pull reports, and query feeds across multiple orgs programmatically
See the API Reference for endpoint details and authentication.
Upgrading to MSSP Tier
To upgrade to the MSSP tier:
- Go to Settings > Subscription.
- Select the MSSP plan.
- Complete billing setup.
If you're currently on a Business plan, your existing configuration carries over. You can start creating client organizations immediately after upgrading.