Customers & access
Every customer is a separate tenant. Provider access must be explicit.
The access model
| Term | Meaning |
|---|---|
| Organization | An enterprise or service provider and its staff |
| Customer / tenant | One customer’s isolation boundary |
| Site / business unit | A grouping within a customer |
| Delegated grant | Permission for particular resources and operations |
An MSSP console should show Customers, then Sites or Business Units. Provider organization membership alone must not grant access to customer evidence.
Available today
The Query API maps each existing console owner to one customer. Keys carry that customer and explicit API scopes. Database policies and scoped access functions constrain API data access. Explicit inaccessible target IDs reject the entire job. Findings and audit records are customer-scoped.
Planned granular permissions
One person will be able to receive separate grants for several customers and their sites. Permissions stay paired with resource scope: analyst at Site A plus viewer at Site B must remain read-only at Site B.
The same checks must cover the console, API, MCP, exports and previously saved results. Revoking access must also remove derived authority. Cross-customer correlation and indicator sharing are not enabled by a provider relationship.