Multi-tenancy and access
Many organizations. One deployment.
Tenancy is enforced where it counts: on the server, in every query. Built for outsourced SOCs from the first design note.
Organizations
Onboarding a customer is creating an organization.
Per-organization everything
Ingest keys, installer bundles, SLA policy, notification routing, automation ceiling, report branding and portal access.
Scoped analysts
Grant an analyst some organizations or all of them. Resources outside the grant stay invisible.
Organization switcher
Alerts, logs, hosts and cases filter to the selected scope from the top bar.
Roles
Four roles, server-enforced.
| Role | Can |
|---|---|
| Admin | Everything, including users, organizations, integrations and system settings. |
| Lead | Work and manage the queue, cases, detections and playbooks for granted organizations. |
| Analyst | Work alerts, cases, logs and response for granted organizations. |
| Viewer | Read-only access to granted organizations. |
Accountability
Every action has a name on it.
- Actions from the console, playbooks and the endpoint fleet land in one audit trail, kept for a year.
- Notes, rules and reports record their author; published copies strip analyst provenance.
- Single sign-on through Fluence Account (OIDC). Roles and grants come from the console account.
- Sessions expire and re-authenticate on a schedule you can see in the console.
See XenXDR on your own telemetry.
A 30-minute walkthrough on fictional data, then a pilot in your environment. No slides, no pressure.