Blackpoint Multi-Tenant Operations
SkillSecurityPartner-level Blackpoint Cyber (CompassOne) operations: the partner-tenant hierarchy, enumerating customer tenants, sweeping detections and vulnerabilities across all of them, spotting volume anomalies, and building per-tenant scorecards.
Use Blackpoint Multi-Tenant Operations in Claude, ChatGPT or Ahel Desktop
Free. Sign in, add Blackpoint Multi-Tenant Operations and connect your AI. About a minute.
Also: Claude Code · Cursor · Codex
Then ask your AI: use the Blackpoint Multi-Tenant Operations skill
Details
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
No other account needed.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
What this skill tells your AI
The instructions your AI receives, as published by wyre-ai/msp-claude-plugins in msp-claude-plugins/blackpoint/blackpoint/skills/multi-tenant-operations/SKILL.md and read by ahel’s review.
The CompassOne partner account sees every customer tenant. This skill covers the partner-level operating loop: enumerate tenants, sweep across them, and roll up into a portfolio view.
Anti-triggers
blackpoint_partners_*— the partners domain is a stub. Partner scope comes from the token itself;blackpoint_tenants_listis the only enumeration that works.- Investigating one detection — the drill-down flow is
blackpoint-incident-response; this skill is the sweep across tenants, not the deep dive within one. - A tenant portfolio in another product — M365 tenants are
cipp-tenantsorinforcer-tenant-management; Blumira client accounts areblumira-msp. A CompassOne tenant maps to none of them automatically.
The Partner-Tenant Model
Partner (the MSP)
└── Tenant (customer) ← blackpoint_tenants_list / _get
└── Asset
└── Detections / Vulnerabilities
Every partner-level operation starts the same way: enumerate tenants, then iterate. Never present partner output without tenant attribution on every row.
API Tools
| Tool | Purpose |
|---|---|
blackpoint_tenants_list | Enumerate customer tenants (filter by account, status, name search) |
blackpoint_tenants_get | Detail for one tenant |
blackpoint_detections_list | Detections — call once per tenant with tenant_id |
blackpoint_vulnerabilities_list | Vulnerabilities — call once per tenant |
blackpoint_vulnerabilities_external_list | External exposures per tenant |
blackpoint_vulnerabilities_darkweb_list | Dark-web exposures per tenant |
Common Workflows
Multi-tenant detection sweep
blackpoint_tenants_list— enumerate all customers.- For each tenant,
blackpoint_detections_listfiltered to a recent window andstatusin {new,investigating}. - Roll up: detections per tenant, severity distribution, top detection types.
- Flag tenants with abnormal volume — a tenant well above its apparent baseline is itself the signal.
Portfolio exposure rollup (QBR prep)
- Enumerate tenants.
- Per tenant, pull
blackpoint_vulnerabilities_list,blackpoint_vulnerabilities_external_list, andblackpoint_vulnerabilities_darkweb_list. - Build a per-tenant scorecard: fix-now vulnerability count, external-exposure count, dark-web count.
- Rank tenants by exposure so the MSP knows where to spend remediation effort.
Morning queue triage
- Enumerate tenants.
- Sweep
newdetections from the last 24h across all of them. - Rank by severity, then tenant impact, then recency.
- Produce a shift-ready priority list (see the
alert-response-coordinatoragent).
Edge Cases
- Tenant scoping (403) — a partner may not have access to every tenant returned; a 403 on drill-down means scoping, not a bad token.
- Pagination at scale —
blackpoint_tenants_listand per-tenant detection lists can both paginate; fully page before claiming a count is complete. - Read-only — partner-level work here is reporting and triage; state changes happen in the CompassOne portal.
Best Practices
- Always start with
blackpoint_tenants_list— never hard-code a tenant set. - For QBRs, combine detection and exposure rollups into one per-tenant scorecard.
Related Skills
- incident-response - Drilling into one tenant's detections
- vulnerability-management - Exposure data per tenant
- api-patterns - Auth, hierarchy, pagination
Signals
- GitHub stars
- 48
- Forks
- 26
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
blackpoint-multi-tenant-operations- Source
- github.com/wyre-ai/msp-claude-plugins
github.com/wyre-ai/msp-claude-plugins