Control Center for MSSP + MSP teams

Operate a customer portfolio without flattening tenant boundaries.

Threat Foundry Control Center gives authorized service teams one governed operating layer for tenant lifecycle, work, SLAs, health, licensing, delivery, reporting, and accountable tenant handoff—while customer evidence and action authority stay in each tenant.

Portfolio visibilitySee work, SLA, health, capacity, delivery, and customer state across the authorized portfolio.
Tenant independenceKeep customer data, evidence, permissions, policies, provider access, and approvals isolated.
Accountable handoffEnter one customer workspace for one purpose with minimum permissions, expiry, revocation, and audit attached.

Managed operations

Run the queue as an operating system, not a spreadsheet.

Control Center synchronizes bounded work summaries from assigned tenants, keeps source state distinct from managed state, and gives managers and analysts one current view of workload, ownership, urgency, and the next accountable action.

WQ

Work Queue

Filter by customer, category, severity, operational priority, managed state, assignee, team, SLA, escalation, health, and Forge state.

SL

SLA + calendars

Apply versioned service objectives and business calendars, preserve historical misses, and distinguish warning, breach, waiting, and paused conditions.

AS

Assignment + claim

Keep manager assignment, analyst claim, source ownership, bulk review, notes, and managed-state history explicit and auditable.

ES

Escalation

Route accountable escalations and notifications without silently changing customer source severity, lifecycle, case, detection, or validation state.

Governed tenant entry

Review the purpose and permissions before crossing the tenant boundary.

A tenant handoff is a signed, short-lived, single-use grant to one customer and a closed permission set. The resulting managed session is purpose-bound, read-only, continuously revocable, and visibly separate from a customer identity.

  • Active provider membership and explicit tenant assignment are both required
  • Handoff review shows customer, work, purpose, permission set, expiry, and current authority
  • Managed sessions cannot mutate customer configuration, policy, detections, cases, triage, validation, tuning, or provider state
  • Exit, expiry, assignment change, revocation, or emergency-action change ends the authority
Control Center Governed Entry
Control Center Governed EntryA purpose-bound handoff into one authorized customer workspace with read-only permissions, expiry, revocation, and audit context.

Customer lifecycle + commercial control

Connect the service promise to the exact capability delivered.

Control Center keeps provider, tenant, environment, offering, entitlement, capacity, projection, compatibility, and acknowledgment state visible instead of scattering those decisions across contracts and deployment notes.

ON

Onboarding

Track organization, tenant, environment, plan, ownership, readiness, connector dependencies, and lifecycle through reviewed stages.

LC

Signed licensing

Import and activate immutable signed offerings, assign the whole compatible offering, and project a tenant-specific entitlement snapshot.

CP

Capacity

See allocated and available capacity, customer assignment, replacement, upgrade, downgrade, expiration, suspension, and revocation consequences.

CM

Compatibility

Negotiate supported schemas and capabilities, surface stale or incompatible projections, and keep feature state fail-closed when versions do not intersect.

Fleet health + reporting

See the service dependency before it becomes invisible toil.

Health incidents, tenant compatibility, queue freshness, worker state, due reports, delivery circuits, and operational trends stay connected to the exact provider and customer scope an operator is allowed to see.

  • Fleet health, tenant readiness, worker and queue state, incidents, acknowledgments, and recovery notes
  • Operational, service, SLA, workload, coverage, customer, and shift reporting views
  • Bounded report runs with explicit status, source revision, delivery outcome, and retry history
  • Customer-safe summaries remain distinct from internal provider notes and raw tenant evidence

Delivery operations

Make every destination, retry, and dead letter reviewable.

Provider teams can operate closed email, webhook, Jira, and ServiceNow delivery paths through reviewed endpoints, routes, recipients, templates, source revisions, idempotency, retry limits, and circuit state.

  • Secrets stay in deployment-managed references, never notes or rendered configuration values
  • Delivery accepted means the destination service accepted a bounded message—not that a human read or acted on it
  • Retries use current approved dependencies while immutable prior attempts remain visible
  • Dead-letter review supports governed retry or cancellation without editing the payload or history
Customer Delivery Operations
Customer Delivery OperationsReviewed customer report, exact destination, bounded message, delivery state, retry history, and accountable owner.

Identity + provider governance

Give each operator the authority their service role requires—and no more.

ID

Identity lifecycle

Support provider membership, invitations, local or OIDC identity, role mapping, MFA, sessions, immediate revocation, and reviewed recovery paths.

GV

Provider governance

Manage teams, assignments, service plans, policies, controlled branding, capacity, and independent approvals within one provider boundary.

BG

Emergency access

Require one tenant, minimum permissions, an incident reference, short duration, separate approval, MFA step-up, immediate exit, and customer transparency.

AU

Append-only audit

Preserve successful, failed, and denied actions with bounded safe context. Filter and export only the provider and tenant scope the reviewer is authorized to inspect.

Forge Managed Operations

Use tenant-owned analysis as advisory portfolio context.

Eligible operators can request one closed Forge analysis purpose from Work Queue. The tenant revalidates the request, retrieves its own authorized evidence, contacts its selected model route, and returns an evidence-free projection to Control Center.

  • See current, stale, queued, running, unavailable, blocked, or not-run state
  • Review recommended priority, evidence sufficiency, workflow, limitations, and deterministic restrictions separately
  • Open current tenant analysis only through a short-lived read-only handoff
  • No cross-tenant retrieval, raw evidence centralization, automatic queue mutation, proposal acceptance, deployment, or response
Explore the full Forge boundary

“Provider accountability should get stronger without turning the control plane into a cross-tenant evidence store.”

Threat Foundry operating standard

The boundary that matters

Coordinate broadly. Access narrowly.

Control Center does not grant blanket provider access, merge customer data, impersonate customer users, expose one tenant to another, or make customer-owned approval and deployment decisions. It shows the portfolio state needed to operate the service and creates a governed path to the exact tenant context when review is required.

Start with the workflow

Design a managed threat-operations model that customers can trust.

Bring your tenant model, roles, service levels, work categories, delivery destinations, access rules, and reporting commitments. We will map them to the Control Center operating boundary.