The first day
Establishes the tenant, applies the baseline policy inherited from the service package, and begins ingestion from the sources the client already runs.
ClearSkies iISOC for MSSPs
Everything a provider buys is measured in daily ingestion volume, and every client it serves occupies a tenant inside one deployment. A tenant is licensed on a bundle, and the bundle sets the daily volume and the entitlements that come with it. Two bundles are sold per tenant, Lite and Pro, and a provider that prefers to buy capacity once and allocate it takes the Ultimate volume pool instead.
A provider picks the one that matches how it buys. Under MSSP Ultimate the provider buys a daily ingestion volume up front and distributes it across its client tenants, moving volume between them as clients are signed or churn, so unused capacity is reallocated rather than repurchased. Under Pay-As-You-Grow the provider buys one tenant license at a time, Lite or Pro, sized to the client in front of it. Both routes carry the same platform, the same operator console and the same add-on catalog; what differs is when the capacity is bought and who holds the headroom.
| MSSP Ultimate | Pay-As-You-Grow: Lite and Pro | |
|---|---|---|
| What is bought | A daily ingestion volume, held as a pool | One tenant license at a time, on the Lite or Pro bundle |
| Volume | Bulk volume and extended in volume increments | 5 or 10 GB per day on Lite, 20, 30 or 40 GB per day on Pro |
| How capacity moves | Allocated and reallocated across tenants from the console, without a repurchase | Fixed to the tenant it was bought for. A tenant that outgrows Lite moves to Pro or Ultimate |
| Suited to | A practice with a book to serve and a growth plan, optimizing unit cost through volume | A practice scaling on actual client acquisition, and pilots |
| Commercial profile | Lower cost per gigabyte, predictable capacity planning, headroom held by the provider | Minimal initial commitment, cost that starts when the client does |
| Prerequisite | iISOC Platform Central Management Console, billed once a year | iISOC Platform Central Management Console, billed once a year |
The iISOC Platform Central Management Console is included with the first purchase and billed once a year, whatever the number of tenants that follow. It is the console from which volume, bundles, tiers and add-ons are assigned, so a second tenant costs a bundle and no new infrastructure.
Licensing is measured in daily ingestion volume rather than in endpoints or seats, and a provider either holds that volume as a pool it distributes across clients or buys it one tenant at a time, so efficiency gained through automation is retained by the provider instead of being surrendered as a discount.
| Native add-on | Exposure domain | Licensed by |
|---|---|---|
| Attack Surface Monitoring | External exposure | In-scope sub-domains monitored under the authorized root domains |
| DNS Shield | Resolution layer | DNS queries analyzed per day |
| Identity Threat Protection | Identity plane | Protected identities, human and service |
| Active Defense | Active response | Protected environment or scope |
| Endpoint Threat Monitoring and Response | Endpoint | Monitored endpoints |
| AI-SecOps Autonomous Analyst | Alert and incident triage | Number of intelligent analysts |
Onboarding is templated per environment type rather than built per client.
The first day
Establishes the tenant, applies the baseline policy inherited from the service package, and begins ingestion from the sources the client already runs.
The first week
Completes connector coverage, tunes the baseline against observed traffic, and produces the initial exposure picture from Attack Surface Monitoring.
The first month
Delivers the first full reporting cycle, the initial coverage and gap view against MITRE ATT&CK, and the tuning backlog that sets the next cycle.
The client supplies administrative access to the sources in scope, an escalation contact tree, and the response authority matrix that governs what may be actioned without approval.
The license covers ingestion and analytics for one infrastructure, not multi-tenant delivery. A provider still supplies the tenancy model, the cross-client operations, the correlation across non-Microsoft sources, and the branding layer, and still pays for ingestion above the entitlement. The comparison to run is fully loaded cost per tenant at the volume the provider actually carries, not license cost at zero.
It does, and it will continue to. The question is what it is worth in three years: efficiency gains accrue to the supplier, the client relationship is shared, and the capability is not proprietary at exit. The three-routes comparison on the overview states this without arguing that every provider should switch.
Separation is enforced at the data layer, no tenant holds or infers the data of another, and hosting region is configurable per deployment. The subprocessor terms and the assurance reports are the artifacts to review.
Volume is bought in bands rather than metered without a ceiling, so a busy month meets a known band instead of an open invoice. The console reports ingestion per tenant, so a client that grows is repriced on evidence at renewal. Normalization and filtering happen at collection, so low-value telemetry is dropped before it counts against the band. Under MSSP Ultimate, capacity released by one client is reallocated to another rather than repurchased.
That is the normal case and it is not an obstacle. Endpoint telemetry from the vendor the client already runs is ingested and correlated, and response actions are executed through it where the vendor exposes them. Endpoint Threat Monitoring and Response is licensed only where a client has no incumbent or is replacing one.
To evaluate ClearSkies MSSP, request a partner workshop, a sandbox tenant and a quotation against the intended client base from the ClearSkies partner team.
We use cookies and process personal data for the following purposes: Functional, Analytics & Marketing. See the full list of cookies or read our privacy policy.
Please choose the services and third-party applications we may use. See the full list of cookies or read our privacy policy.