Configure
Console route · /workspace
Workspace
Tenant control plane for identity, directory, access, security posture, apps, devices, connectors, routing, notifications, billing, reporting, and audit. Closer to an admin workspace than a flat settings page. Several sections are still scaffold — labeled as such in the table below.
Who uses it
Tenant admins with workspace:manage. Day-to-day analysts typically never need this surface. Super Admins do not use Workspace for SOC configuration — they use Access Review. Prefer Workspace for people and access; use Admin for endpoint ingest and low-level company settings panels.
Sections and maturity
| Section | What you configure | Maturity |
|---|---|---|
| Overview | Readiness metrics and shortcuts into other sections | Live metrics where data exists |
| Organization | Display name, domain, region, retention, timezone, directory mode | Profile fields persist where API wired |
| People | Invite, roles, OU-style grouping, suspend/resend patterns | Membership API + evaluation directory |
| Groups & units | Groups with policy baselines and dynamic flags | Interactive; evaluation-friendly |
| Access control | Member grants/denials and RBAC matrix | Live |
| Security | SSO/directory mode, session, MFA, login controls, IP allowlist drafts | Scaffold UI . evaluation may save locally |
| Apps & services | Which console modules are enabled for the tenant | Scaffold toggles with notes (Hunt Ledger vs Automation roles called out) |
| Devices | Enrollment inventory summary and links to Integrations | Scaffold / inventory dependent |
| Integrations | Pause, resume, test, sync per connector | Live sync when not in evaluation |
| Data routing | Pipeline stages, dead-letter, replay inspectors | Mostly scaffold inspectors |
| Notifications | Channels, escalation, quiet hours entry points | Scaffold / ties to alert center |
| Billing & plan | Plan, seats, renewal, billing contact | Scaffold — no payment processor |
| Reporting | Scheduled digests (hunt ledger, incidents, access review, connector health) | Scaffold schedules |
| Audit & export | Administrative decision log export | Export available in evaluation and where API exists |
How to use Workspace without lying to yourself
Configure people and access first — those gates decide who can approve containment tomorrow. Pause connectors from Workspace when you need a controlled freeze. Treat Security, Billing, Reporting, and Data routing scaffold sections as previews of intent unless the UI and API both confirm persistence.
Apps & services toggles can note that Hunt Ledger and Automation serve different jobs; both can remain enabled. That note is product truth, not decoration.