MSSPs looking to automate more of the SOC without handing every decision to AI have a new set of controls to consider.
Stellar Cyber announced version 7.0 of its security operations platform on Oct. 5, adding AI-assisted case handling and multi-tenant automation for managed security service providers (MSSPs) running security operations centers (SOCs).
For providers juggling many customer environments, the release reaches both analyst workload and the repetitive administration that grows with every tenant.
Case queues become the control point for automated review
Administrators can enable Case Summary and Auto-Triage on selected case queues. Work routed into those queues can receive automated analysis before an analyst begins review.
Once a case enters an enabled queue, Auto-Triage investigates its associated alerts and assigns each alert a verdict: true positive, benign true positive, false positive, or inconclusive. Analysts can review the supporting evidence, ask follow-up questions through AI Assistance, and override individual alert verdicts. The platform then reevaluates the case verdict. Case Summary serves a different role by organizing evidence already attached to the case without performing the additional investigation used for triage.
Measurement follows the automated review. Case Metrics tracks intervals such as creation to acknowledgment or resolution, allowing MSSPs to compare handling times against internal targets or customer service commitments. Similar measurement can give providers evaluating AI-driven SOC tools something more reliable than vendor automation claims.
Use at scale comes with limits. SaaS customers need an add-on license for Auto-Triage, and MSSPs should confirm their licensed capacity and usage limits before expanding it across customer environments.
APIs extend automation across customer environments
Version 7.0 also moves some repetitive administration outside the product interface. New System Action Center APIs can programmatically create actions tied to cases, infrastructure health, reports, users, privileges, and licensing. These capabilities become useful as multi-tenant security management expands across larger customer bases.
Additional changes include several jobs providers may otherwise repeat customer by customer.
Sensor management
On SaaS deployments, a new API can generate installation tokens for a specified tenant and sensor profile. Another API can initiate remote uninstallation of connected Windows and Linux Server Sensors, helping providers automate onboarding and decommissioning.
Parser administration
Parser Studio can reuse configurations across tenants and disable inactive parsers in bulk. MSSPs managing different telemetry sources across many customers can avoid rebuilding or cleaning up the same parser setup individually.
Response actions
Integrations extend into products customers may already use, including Microsoft Defender for Endpoint and Fortinet FortiGate. Providers involved in Microsoft Defender XDR deployments can keep more investigation and response activity inside the same SOC process without replacing those controls.
Across these changes, MSSPs gain more ways to standardize routine work across their tenant base.
Providers should set boundaries before expanding SOC automation
MSSPs need to evaluate the rollout as a change to the service they deliver. Customer requirements and service economics can vary from tenant to tenant, leaving providers with several decisions to settle before expanding access.
Evaluate four areas before expanding access:
- Start with a defined workflow.
Choose a well-understood customer case type and establish how automated decisions will be evaluated during the initial rollout. Comparing AI verdicts with analysts’ final dispositions can expose inconsistent results before the same approach reaches additional customers. Similar testing will become useful as agentic security workflows enter more managed security environments. - Set rules for capacity and service tiers.
Auto-Triage capacity is shared across an organization’s tenants and cannot be reserved for individual customers. If one customer generates a disproportionate volume of eligible alerts, an MSSP needs a policy for allocating that capacity instead of letting case volume determine consumption. Providers can then decide whether access belongs across standard services or within selected tiers. - Check customer deployment restrictions.
On-premises Auto-Triage remains in Early Access and needs outbound access to Stellar Cyber’s cloud AI service. Providers packaging managed security services should review customer data-handling rules and contract terms before adding the capability to environments with stricter connectivity requirements. - Measure the delivery economics.
Establish a baseline for engineering and support hours before rollout, then compare staffing effort after API automation is in use. Work that moves into maintenance or exception handling produces a different return from work removed from the delivery cycle.
For MSSPs, the longer-term value will depend on whether these controls allow a provider to add customers without adding manual work at the same rate.
More AI news: Cisco’s Webex expansion brings AI agents, RoomOS 27, and new customer experience tools into one broader enterprise collaboration strategy.




