SaaS Alerts MSP Security Monitoring
Unified security monitoring capability for Managed Service Providers using SaaS Alerts. Combines event detection, alert management, customer visibility, and user risk monitoring into a single workflow for MSP security operations teams.
What You Can Do
MCP Tools
list-security-events
List SaaS security events across monitored applications. Filter by event type (login.failure, data.exfiltration, impossible.travel, etc.), severity (low/medium/critical), application, and date range.
query-security-events
Execute a structured query against SaaS Alerts event indexes. Supports complex filtering on multiple event types, severities, applications, and customers simultaneously.
list-security-alerts
List security alerts triggered by anomalous behavior detection. Filter by severity and resolution status to prioritize incident response.
list-customers
List all MSP customer tenants being monitored. Returns customer IDs, names, monitored applications, user counts, and monitoring status.
list-monitored-users
List users monitored across customer tenants including activity summaries, risk scores, and alert counts. Use to identify high-risk users for investigation.