Organizations

The tenancy unit: what is set per organization, and how scoping works.

What an organization is

An organization is a tenant: typically one legal entity you protect. Every event, alert, case, host, ingest key and report belongs to exactly one organization. A single-company deployment has one; a provider has one per customer.

Per-organization settings

Settings › Organizations › the organization holds:

SettingEffect
SLA policyTargets per severity, coverage window and time zone, approach threshold. See SLA.
Notification routingExtra operator recipients, customer recipients, muted kinds, customer quiet hours.
Automation ceilingThe most consequential action a playbook may take automatically. See Modes and ceilings.
PortalWhether the customer portal is enabled, the logo, note and support contact it shows.
ContactsNamed customer contacts for reports and escalation.
Ingest keys, installer bundles, fleet groupsManaged from their own pages, always scoped to the organization.

An organization with no settings saved runs on the deployment defaults.

Scoping

Analysts are granted some organizations or all of them. Every query in the console is scoped to the analyst's grants; a resource outside the grant answers as if it did not exist. The organization switcher in the top bar narrows the view further to one organization or shows all granted ones.

Creating and retiring

Create an organization with a name and identifier. Retiring an organization disables its ingest keys and portal, keeps its data for the retention period, and removes it from analysts' scope.