Partners
Work a book of customers from one console, with each estate reached as that customer's own account and every action kept on the record.
In this chapter
- Firms, Customers, EndpointsThe four levels the portal counts in, from the company you sign in as down to the address one machine answers on.
- Join a FirmTwo calls put partner authority on an operator's key: one from an administrator, and one from the person taking it up.
- Onboard a CustomerTake one company live end to end, from naming it to a first endpoint that answers, with checks anyone can repeat.
- Customer Keys and GrantsHow a firm holds the authority to act inside an estate, where that authority lives, and what ends it.
- The QueueWhich of your customers needs a human right now, worst first, and the change feed that list is drawn from.
- Incidents and CasesA detection is something the plane saw; the record you open from it is the thing you work, and it keeps the evidence.
- Hunt Across the BookOne indicator, every customer at once: which estates have it in their records, and what the graph says about it.
- Shared InfrastructureWhat two or more of your customers reached, the verdict on each destination, and how one answer becomes a rule for all of them.
- Response VerbsEach containment action the portal can dispatch, what it changes, whether it needs the sensor, and what it writes to a case.
- PlaybooksA written response the portal runs unattended, the questions it still hands back to a person, and the version each run records.
- Policy Across CustomersWhat each estate's resolver blocks, allows and answers by default, and the one decision you can take for a whole book at once.
- Prove and ReportAnswer the negative question for a customer, then hand over the answer, the census behind it and the identity checks.
- Audit and ComplianceWho did what in whose estate, how much of a framework the book covers, and the export that reconciles what you delivered.
- Your Team and RolesWho in the firm may read, respond, tune, provision and act on people, and the screen where each of those is set.
Partners Documentation
The partner portal at https://partners.whisper.online is where a firm that runs security for other companies works. You sign in as your own firm and reach each customer's estate as that customer's own account, so what the portal reads is exactly what that account can read.
Every endpoint a firm brings live holds a routable IPv6 address published in public DNS and in the public registry, so a customer can check their own machine with no key and nothing installed:
curl -s https://rdap.whisper.online/ip/2a04:2a01:b69a:6717:e3b0:51ff:3bf7:f478
Firms, customers, accounts and endpoints are separate things, and the model settles which is which. An operator gains authority over a firm in two calls, and a company goes live through four steps that end with a machine you watch check in. The authority itself is the customer's own key, held by the firm and ended by rotating it.
The day starts at the queue, which puts the customers needing a human first, and moves into detections and the cases you open from them. One indicator can be searched across every customer at once, and destinations two or more of them reached are where a single answer becomes a rule for the rest. Containment is a fixed set of response verbs, and a playbook runs them in an order without waiting for you.
Resolver, zone, mesh and footprint settings are held on the customer they belong to. When a customer asks what happened, the negative answer and the document around it is what you hand over, the record of who did what is read from their own estate, and who in your firm may do any of it is set once.