What an organization is
An organization is a tenant: typically one legal entity you protect. Every event, alert, case, host, ingest key and report belongs to exactly one organization. A single-company deployment has one; a provider has one per customer.
Per-organization settings
Settings › Organizations › the organization holds:
| Setting | Effect |
|---|---|
| SLA policy | Targets per severity, coverage window and time zone, approach threshold. See SLA. |
| Notification routing | Extra operator recipients, customer recipients, muted kinds, customer quiet hours. |
| Automation ceiling | The most consequential action a playbook may take automatically. See Modes and ceilings. |
| Portal | Whether the customer portal is enabled, the logo, note and support contact it shows. |
| Contacts | Named customer contacts for reports and escalation. |
| Ingest keys, installer bundles, fleet groups | Managed from their own pages, always scoped to the organization. |
An organization with no settings saved runs on the deployment defaults.
Scoping
Analysts are granted some organizations or all of them. Every query in the console is scoped to the analyst's grants; a resource outside the grant answers as if it did not exist. The organization switcher in the top bar narrows the view further to one organization or shows all granted ones.
Creating and retiring
Create an organization with a name and identifier. Retiring an organization disables its ingest keys and portal, keeps its data for the retention period, and removes it from analysts' scope.