Skip to main content
Tools Reference

Blackpoint CompassOne Tools

Written By Christopher Scaminaci

Last updated 7 days ago

Blackpoint CompassOne Tools

compassone_ · 148 tools · Free 77 · Pro 71 Managed detection and response, asset inventory and cloud posture. The credential is a bearer token minted in the console; the vendor publishes no token endpoint, so recovery is a new console token. The host is fixed. Two paging families coexist - page with page size on most reads and skip with take on seven - plus a limit capped at 100 on the two top-detections reads. Array filters are sent as repeated query parameters, and the asset list requires a class filter. Scoping differs by family: the cloud tools take an end-customer tenant id as a query parameter, cloud posture takes a scope type and id pair in the path, and the alert-group tools take a tenant id request header that the vendor requires even though its own spec omits it. Eight deletes carry a JSON body and three path-only deletes require query parameters. There are no binary responses anywhere. The vendor documents a 429 on every operation but publishes no numeric quota.

All connector tools · Blackpoint CompassOne setup guide

Blackpoint CompassOne tool groups

Detections

ToolPlanAccessSummary
compassone_get_alert_groupFreeRead-onlyGet one alert group (detection) by id, from compassone_list_alert_groups.
compassone_get_alert_group_countFreeRead-onlyGet the total count of alert groups (detections) in a date window — a cheap way to size a result set before listing it with compassone_list_alert_groups.
compassone_get_alert_groups_by_weekFreeRead-onlyGet detection counts aggregated by week — the trend series behind a SOC activity chart.
compassone_get_top_detections_by_entityFreeRead-onlyGet the top detections grouped by an entity field (for example hostname or username) — answers 'which machines or users generate the most detections'.
compassone_get_top_detections_by_threatFreeRead-onlyGet the top detections grouped by threat type — answers 'what kinds of threats are we seeing most'.
compassone_list_alert_groupsFreeRead-onlyList alert groups (detections) — the SOC's unit of triage, each grouping related alerts.
compassone_list_alerts_for_alert_groupFreeRead-onlyList the individual alerts inside one alert group (detection).

[Blackpoint CompassOne] Get one alert group (detection) by id, from compassone_list_alert_groups. Returns the raw alert-group JSON — status, alert count, alert types, hostname and username. Use compassone_list_alerts_for_alert_group for the individual alerts it contains.

ParamTypeRequiredDefaultDescription
alertGroupIdstringyesThe alert group id (from compassone_list_alert_groups).
tenantIdstringnonullCompassOne tenant (end-customer) id, sent as the x-tenant-id header. CompassOne now REQUIRES this header on every alert-group endpoint — requests without it are rejected upstream with 400. Discover ids with compassone_list_tenants.

[Blackpoint CompassOne] Get the total count of alert groups (detections) in a date window — a cheap way to size a result set before listing it with compassone_list_alert_groups. Both dates default when omitted (start = 90 days ago, end = now). Note status is single-valued here, unlike the comma-separated list compassone_list_alert_groups accepts. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
endDatestringnonullWindow end as an ISO-8601 instant. Defaults to now when omitted.
startDatestringnonullWindow start as an ISO-8601 instant. Defaults to 90 days ago when omitted.
statusstringnonullSingle status to count: OPEN or RESOLVED. Omit for both.
tenantIdstringnonullCompassOne tenant (end-customer) id, sent as the x-tenant-id header. CompassOne now REQUIRES this header on every alert-group endpoint — requests without it are rejected upstream with 400. Discover ids with compassone_list_tenants.
typestringnonullDetection type: CR (Cloud Response) or MDR. Omit for both.

[Blackpoint CompassOne] Get detection counts aggregated by week — the trend series behind a SOC activity chart. Both dates default when omitted (start = 90 days ago, end = now). Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
endDatestringnonullWindow end as an ISO-8601 instant. Defaults to now when omitted.
startDatestringnonullWindow start as an ISO-8601 instant. Defaults to 90 days ago when omitted.
tenantIdstringnonullCompassOne tenant (end-customer) id, sent as the x-tenant-id header. CompassOne now REQUIRES this header on every alert-group endpoint — requests without it are rejected upstream with 400. Discover ids with compassone_list_tenants.
typestringnonullDetection type: CR (Cloud Response) or MDR. Omit for both.

[Blackpoint CompassOne] Get the top detections grouped by an entity field (for example hostname or username) — answers 'which machines or users generate the most detections'. Uses limit rather than paging; CompassOne caps limit at 100. Both dates default when omitted (start = 90 days ago, end = now). See compassone_get_top_detections_by_threat to group by threat type instead. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
detectionTypestringnonullDetection type: CR (Cloud Response) or MDR. Omit for both.
endDatestringnonullWindow end as an ISO-8601 instant. Defaults to now when omitted.
entityNamestringnonullThe alert field to group by (for example hostname or username). Omit for CompassOne's default grouping.
limitintegernonullMax entities to return (1-100). Omit for CompassOne's default.
startDatestringnonullWindow start as an ISO-8601 instant. Defaults to 90 days ago when omitted.
tenantIdstringnonullCompassOne tenant (end-customer) id, sent as the x-tenant-id header. CompassOne now REQUIRES this header on every alert-group endpoint — requests without it are rejected upstream with 400. Discover ids with compassone_list_tenants.

[Blackpoint CompassOne] Get the top detections grouped by threat type — answers 'what kinds of threats are we seeing most'. Uses limit rather than paging; CompassOne caps limit at 100. Both dates default when omitted (start = 90 days ago, end = now). See compassone_get_top_detections_by_entity to group by host or user instead. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
detectionTypestringnonullDetection type: CR (Cloud Response) or MDR. Omit for both.
endDatestringnonullWindow end as an ISO-8601 instant. Defaults to now when omitted.
limitintegernonullMax threat types to return (1-100). Omit for CompassOne's default.
startDatestringnonullWindow start as an ISO-8601 instant. Defaults to 90 days ago when omitted.
tenantIdstringnonullCompassOne tenant (end-customer) id, sent as the x-tenant-id header. CompassOne now REQUIRES this header on every alert-group endpoint — requests without it are rejected upstream with 400. Discover ids with compassone_list_tenants.

[Blackpoint CompassOne] List alert groups (detections) — the SOC's unit of triage, each grouping related alerts. Offset-paged with skip/take, NOT page/pageSize. status accepts a comma-separated list of OPEN and RESOLVED. type is CR (Cloud Response) or MDR. The 'since' window reaches back at most 90 days. Use compassone_get_alert_group for one group's detail and compassone_list_alerts_for_alert_group for the alerts inside it. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
maxAlertsCountintegernonullOnly alert groups with at most this many alerts (minimum 0).
minAlertsCountintegernonullOnly alert groups with at least this many alerts (minimum 0).
searchstringnonullSearch by alert type, username or hostname. Omit for no text filter.
sincestringnonullOnly alert groups created since this ISO-8601 instant. CompassOne allows at most 90 days back. Omit for its default window.
skipintegerno0Number of records to skip for pagination (default 0).
sortByColumnstringnonullSort field. One of: alertCount, alertTypes, created, hostname, status, username. Omit for CompassOne's default ordering.
sortDirectionstringnonullSort direction: ASC or DESC (default ASC).
statusstringnonullComma-separated statuses to include. Valid values: OPEN, RESOLVED. Omit for all statuses.
takeintegerno100Max records to return (default 100, max 1000).
tenantIdstringnonullCompassOne tenant (end-customer) id, sent as the x-tenant-id header. CompassOne now REQUIRES this header on every alert-group endpoint — requests without it are rejected upstream with 400 'x-tenant-id request header is required'. Discover ids with compassone_list_tenants.
tunnelSearchstringnonullSearch by tunnel or proxy name. Omit for no tunnel filter.
typestringnonullDetection type: CR (Cloud Response) or MDR. Omit for both.

[Blackpoint CompassOne] List the individual alerts inside one alert group (detection). Offset-paged with skip/take, NOT page/pageSize. Get the alertGroupId from compassone_list_alert_groups. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
alertGroupIdstringyesThe alert group id whose alerts to list (from compassone_list_alert_groups).
skipintegerno0Number of records to skip for pagination (default 0).
sortByColumnstringnonullSort field. One of: attacker, created, dataset, target, updated. Omit for CompassOne's default ordering.
sortDirectionstringnonullSort direction: ASC or DESC (default ASC).
takeintegerno100Max records to return (default 100, max 1000).
tenantIdstringnonullCompassOne tenant (end-customer) id, sent as the x-tenant-id header. CompassOne now REQUIRES this header on every alert-group endpoint — requests without it are rejected upstream with 400. Discover ids with compassone_list_tenants.

Assets

ToolPlanAccessSummary
compassone_get_assetFreeRead-onlyGet a single asset by id (from compassone_list_assets).
compassone_list_asset_relationshipsFreeRead-onlyList one asset's relationships to other entities.
compassone_list_assetsFreeRead-onlyList assets from the CompassOne inventory.

[Blackpoint CompassOne] Get a single asset by id (from compassone_list_assets). Returns the raw asset JSON — class, type, criticality, status, discovery and last-seen timestamps. Use compassone_list_asset_relationships to see what this asset connects to.

ParamTypeRequiredDefaultDescription
idstringyesThe asset id (from compassone_list_assets).
tenantIdstringnonullCompassOne tenant (end-customer) id, sent as the x-tenant-id header. CompassOne now REQUIRES this header on the asset endpoints — requests without it are rejected upstream with 400. Discover ids with compassone_list_tenants.

[Blackpoint CompassOne] List one asset's relationships to other entities. BOTH entityClass and direction are REQUIRED. entityClass is single-valued here (not a list, unlike compassone_list_assets) and accepts a wider set that includes findings: CONTAINER, DEVICE, FRAMEWORK, NETSTAT, PERSON, PROCESS, SERVICE, SOFTWARE, SOURCE, SURVEY, USER, ALERT, ALERTGROUP, EVENT, INCIDENT, VULNERABILITY. direction is 'out' for relationships this asset points at, 'in' for ones pointing at it. Page-based paging (pageSize max 1000). Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
directionstringyesREQUIRED relationship direction: 'out' (this asset points at the entity) or 'in' (the entity points at this asset).
entityClassstringyesREQUIRED single entity class on the far side of the relationship. Valid values: CONTAINER, DEVICE, FRAMEWORK, NETSTAT, PERSON, PROCESS, SERVICE, SOFTWARE, SOURCE, SURVEY, USER, ALERT, ALERTGROUP, EVENT, INCIDENT, VULNERABILITY.
idstringyesThe asset id whose relationships to list (from compassone_list_assets).
pageintegerno11-based page number (default 1).
pageSizeintegerno50Results per page (default 50, max 1000).
sortBystringnonullSort field. The only accepted value is created_on. Omit for CompassOne's default ordering.
sortOrderstringnonullSort direction: ASC or DESC. Omit for CompassOne's default direction.
tenantIdstringnonullCompassOne tenant (end-customer) id, sent as the x-tenant-id header. CompassOne now REQUIRES this header on the asset endpoints — requests without it are rejected upstream with 400. Discover ids with compassone_list_tenants.
withDeletedbooleannonullInclude soft-deleted relationships when true (default false).

[Blackpoint CompassOne] List assets from the CompassOne inventory. assetClass is REQUIRED — CompassOne rejects the call without it — and accepts several classes at once as a comma-separated list (CONTAINER, DEVICE, FRAMEWORK, NETSTAT, PERSON, PROCESS, SERVICE, SOFTWARE, SOURCE, SURVEY, USER). Page-based paging (pageSize max 1000). Use compassone_get_asset for one asset's full detail and compassone_list_asset_relationships to walk its relationship graph. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
assetClassstringyesREQUIRED comma-separated asset classes to include. Valid values: CONTAINER, DEVICE, FRAMEWORK, NETSTAT, PERSON, PROCESS, SERVICE, SOFTWARE, SOURCE, SURVEY, USER. Example: "DEVICE,USER".
decommissionDatestringnonullComma-separated decommission-date filters.
decommissionedstringnonullComma-separated decommissioned-status filters.
filterstringnonullFilter clause using CompassOne's /v1/search WITH-clause syntax. Omit for no structured filter.
foundOnstringnonullComma-separated foundOn date filters.
lastSeenOnstringnonullComma-separated lastSeenOn date filters.
pageintegerno11-based page number (default 1).
pageSizeintegerno50Results per page (default 50, max 1000).
platformstringnonullComma-separated device operating-system platforms.
searchstringnonullCase-insensitive search term matched across all text fields. Omit for no text filter.
sortBystringnonullSort field. One of: accountId, assetClass, classification, createdBy, createdOn, criticality, deletedBy, deletedOn, description, displayName, foundBy, foundOn, id, lastSeenOn, name, status, summary, tenantId, type, updatedBy, updatedOn, agentLastSeenOn, agentDeactivatedOn, lastLoginOn. Omit for CompassOne's default ordering.
sortOrderstringnonullSort direction: ASC or DESC. Omit for CompassOne's default direction.
sourcesstringnonullComma-separated source ids — limits results to assets related to those sources.
tenantIdstringnonullCompassOne tenant (end-customer) id, sent as the x-tenant-id header. CompassOne now REQUIRES this header on the asset endpoints — requests without it are rejected upstream with 400 'x-tenant-id header is required'. Discover ids with compassone_list_tenants.
typestringnonullComma-separated device types.
wdStatusstringnonullComma-separated Windows Defender status filters.
withDeletedbooleannonullInclude soft-deleted assets when true (default false).

Collections

ToolPlanAccessSummary
compassone_create_collectionProWriteCreate a collection (saved search).
compassone_delete_collectionProDestructiveDelete a collection by id (from compassone_list_collections).
compassone_get_collectionFreeRead-onlyGet a single collection by id (from compassone_list_collections).
compassone_list_collectionsFreeRead-onlyList collections (saved searches) for one context.
compassone_update_collectionProWriteUpdate a collection by id (from compassone_list_collections).

[Blackpoint CompassOne] Create a collection (saved search). All three of context, name and search are required by CompassOne. Returns the raw created collection JSON including its new id.

ParamTypeRequiredDefaultDescription
contextstringyesREQUIRED entity context. One of: ASSET, FINDING, CONTAINER, DEVICE, FRAMEWORK, NETSTAT, PERSON, PROCESS, SERVICE, SOFTWARE, SOURCE, SURVEY, USER, ALERT, ALERTGROUP, EVENT, INCIDENT, VULNERABILITY.
fieldsJsonstringnonullOptional JSON object of additional body fields, merged over the values above.
namestringyesREQUIRED display name for the collection.
searchstringyesREQUIRED saved search expression the collection resolves.

[Blackpoint CompassOne] Delete a collection by id (from compassone_list_collections). Destructive — the saved search is removed. The assets or findings it matched are NOT affected; only the grouping is deleted. Returns the raw CompassOne response.

ParamTypeRequiredDefaultDescription
idstringyesThe collection id to delete (from compassone_list_collections).

[Blackpoint CompassOne] Get a single collection by id (from compassone_list_collections). Returns the raw collection JSON including its context and saved search expression.

ParamTypeRequiredDefaultDescription
idstringyesThe collection id (from compassone_list_collections).

[Blackpoint CompassOne] List collections (saved searches) for one context. The context parameter is REQUIRED — CompassOne scopes collections per entity class and rejects the call without it. Page-based paging (pageSize max 1000). Use compassone_get_collection for one collection's detail; the returned id is what compassone_update_collection and compassone_delete_collection take. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
contextstringyesREQUIRED entity context. One of: ASSET, FINDING, CONTAINER, DEVICE, FRAMEWORK, NETSTAT, PERSON, PROCESS, SERVICE, SOFTWARE, SOURCE, SURVEY, USER, ALERT, ALERTGROUP, EVENT, INCIDENT, VULNERABILITY.
pageintegerno11-based page number (default 1).
pageSizeintegerno50Results per page (default 50, max 1000).
searchstringnonullCase-insensitive search term matched across all text fields. Omit for no text filter.
sortBystringnonullSort field. One of: context, createdBy, createdOn, deletedBy, deletedOn, id, name, search, updatedBy, updatedOn. Omit for CompassOne's default ordering.
sortOrderstringnonullSort direction: ASC or DESC. Omit for CompassOne's default direction.
withDeletedbooleannonullInclude soft-deleted collections when true (default false).

[Blackpoint CompassOne] Update a collection by id (from compassone_list_collections). Every field is optional — supply only what changes. Editable: context, name, search. Returns the raw updated collection JSON.

ParamTypeRequiredDefaultDescription
contextstringnonullNew entity context. One of: ASSET, FINDING, CONTAINER, DEVICE, FRAMEWORK, NETSTAT, PERSON, PROCESS, SERVICE, SOFTWARE, SOURCE, SURVEY, USER, ALERT, ALERTGROUP, EVENT, INCIDENT, VULNERABILITY. Omit to leave unchanged.
fieldsJsonstringnonullOptional JSON object of additional body fields, merged over the values above.
idstringyesThe collection id to update (from compassone_list_collections).
namestringnonullNew display name. Omit to leave unchanged.
searchstringnonullNew saved search expression. Omit to leave unchanged.

Cloud MDR Connections

ToolPlanAccessSummary
compassone_approve_connection_countryProWriteApprove a country for a whole cloud-MDR connection, widening the allow-list so sign-ins from there stop raising impossible-travel detections.
compassone_approve_connection_user_countryProWriteApprove a country for ONE user on a cloud-MDR connection, optionally time-boxed to a travel window.
compassone_get_iso_countryFreeRead-onlyGet one ISO 3166-1 country by its two-letter alpha-2 code (for example US).
compassone_list_connection_approved_countriesFreeRead-onlyList the countries approved for one cloud-MDR connection — the connection-wide allow-list behind CompassOne's impossible-travel detection.
compassone_list_connection_user_approved_countriesFreeRead-onlyList the countries approved for ONE user on a cloud-MDR connection — the per-user overrides on top of the connection-wide list returned by compassone_list_connection_approved_countries.
compassone_list_connection_usersFreeRead-onlyList the users belonging to one cloud-MDR connection.
compassone_list_iso_countriesFreeRead-onlyList the ISO 3166-1 country reference CompassOne recognizes.
compassone_remove_connection_approved_countryProDestructiveRemove an approved country from a whole cloud-MDR connection.
compassone_remove_connection_user_approved_countryProDestructiveRemove an approved country from ONE user on a cloud-MDR connection.

[Blackpoint CompassOne] Approve a country for a whole cloud-MDR connection, widening the allow-list so sign-ins from there stop raising impossible-travel detections. tenantId is REQUIRED and isoCountryCode is a REQUIRED two-letter ISO 3166-1 alpha-2 code (look codes up with compassone_list_iso_countries). To approve a country for a single user instead, use compassone_approve_connection_user_country. Returns the raw CompassOne response.

ParamTypeRequiredDefaultDescription
connectionIdstringyesThe cloud-MDR connection id.
fieldsJsonstringnonullOptional JSON object of additional body fields, merged over the value above.
isoCountryCodestringyesREQUIRED two-letter ISO 3166-1 alpha-2 country code to approve (for example US). List valid codes with compassone_list_iso_countries.
tenantIdstringyesREQUIRED CompassOne tenant (end-customer) id. Discover ids with compassone_list_tenants.

[Blackpoint CompassOne] Approve a country for ONE user on a cloud-MDR connection, optionally time-boxed to a travel window. tenantId is REQUIRED, connectionUserId comes from compassone_list_connection_users, and isoCountryCode is a REQUIRED two-letter ISO 3166-1 alpha-2 code. Supply startDate and endDate to make the approval temporary — ideal for a trip. To widen the whole connection instead, use compassone_approve_connection_country. Returns the raw CompassOne response.

ParamTypeRequiredDefaultDescription
connectionIdstringyesThe cloud-MDR connection id.
connectionUserIdstringyesThe connection user id (from compassone_list_connection_users).
endDatestringnonullISO-8601 instant the approval ends. Omit for an approval that does not expire.
fieldsJsonstringnonullOptional JSON object of additional body fields, merged over the values above.
isoCountryCodestringyesREQUIRED two-letter ISO 3166-1 alpha-2 country code to approve (for example US). List valid codes with compassone_list_iso_countries.
startDatestringnonullISO-8601 instant the approval starts. Omit for an approval with no start bound.
tenantIdstringyesREQUIRED CompassOne tenant (end-customer) id. Discover ids with compassone_list_tenants.

[Blackpoint CompassOne] Get one ISO 3166-1 country by its two-letter alpha-2 code (for example US). Global reference data — takes NO tenantId. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
codestringyesThe ISO 3166-1 alpha-2 country code, two letters (for example US). List valid codes with compassone_list_iso_countries.

[Blackpoint CompassOne] List the countries approved for one cloud-MDR connection — the connection-wide allow-list behind CompassOne's impossible-travel detection. tenantId is REQUIRED. Offset-paged with skip/take. For a single user's overrides use compassone_list_connection_user_approved_countries. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
connectionIdstringyesThe cloud-MDR connection id.
skipintegerno0Number of records to skip for pagination (default 0).
takeintegerno100Max records to return (default 100, max 1000).
tenantIdstringyesREQUIRED CompassOne tenant (end-customer) id. Discover ids with compassone_list_tenants.

[Blackpoint CompassOne] List the countries approved for ONE user on a cloud-MDR connection — the per-user overrides on top of the connection-wide list returned by compassone_list_connection_approved_countries. tenantId is REQUIRED and connectionUserId comes from compassone_list_connection_users. Offset-paged with skip/take. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
connectionIdstringyesThe cloud-MDR connection id.
connectionUserIdstringyesThe connection user id (from compassone_list_connection_users).
skipintegerno0Number of records to skip for pagination (default 0).
takeintegerno100Max records to return (default 100, max 1000).
tenantIdstringyesREQUIRED CompassOne tenant (end-customer) id. Discover ids with compassone_list_tenants.

[Blackpoint CompassOne] List the users belonging to one cloud-MDR connection. tenantId is REQUIRED. Offset-paged with skip/take, NOT page/pageSize. The returned user ids are what the per-user approved-country tools take. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
connectionIdstringyesThe cloud-MDR connection id.
orderBystringnonullOrder by field: email or name. Omit for CompassOne's default ordering.
searchstringnonullSearch term matched against the user list. Omit for no text filter.
skipintegerno0Number of records to skip for pagination (default 0).
sortDirectionstringnonullSort direction: ASC or DESC. Omit for CompassOne's default direction.
takeintegerno100Max records to return (default 100, max 1000).
tenantIdstringyesREQUIRED CompassOne tenant (end-customer) id. Discover ids with compassone_list_tenants.

[Blackpoint CompassOne] List the ISO 3166-1 country reference CompassOne recognizes. This is global reference data — it takes NO tenantId and no paging. Use it to look up the two-letter code that the approve-country tools require. Returns the raw CompassOne JSON.

[Blackpoint CompassOne] Remove an approved country from a whole cloud-MDR connection. Destructive — narrowing the allow-list means sign-ins from that country will raise impossible-travel detections again for every user on the connection. tenantId is REQUIRED and id is the approved-country record id from compassone_list_connection_approved_countries (NOT the two-letter country code). Returns the raw CompassOne response.

ParamTypeRequiredDefaultDescription
connectionIdstringyesThe cloud-MDR connection id.
idstringyesThe approved-country RECORD id to remove (from compassone_list_connection_approved_countries), not the ISO country code.
tenantIdstringyesREQUIRED CompassOne tenant (end-customer) id. Discover ids with compassone_list_tenants.

[Blackpoint CompassOne] Remove an approved country from ONE user on a cloud-MDR connection. Destructive — that user's sign-ins from the country will raise impossible-travel detections again. tenantId is REQUIRED, connectionUserId comes from compassone_list_connection_users, and id is the approved-country record id from compassone_list_connection_user_approved_countries (NOT the two-letter country code). Returns the raw CompassOne response.

ParamTypeRequiredDefaultDescription
connectionIdstringyesThe cloud-MDR connection id.
connectionUserIdstringyesThe connection user id (from compassone_list_connection_users).
idstringyesThe approved-country RECORD id to remove (from compassone_list_connection_user_approved_countries), not the ISO country code.
tenantIdstringyesREQUIRED CompassOne tenant (end-customer) id. Discover ids with compassone_list_tenants.

Cisco Duo Cloud MDR

ToolPlanAccessSummary
compassone_complete_cisco_onboardingProWriteComplete a Cisco Duo cloud-MDR onboarding by verifying everything was set up correctly.
compassone_create_cisco_onboardingProWriteBegin a new Cisco Duo cloud-MDR onboarding for a customer.
compassone_delete_cisco_onboardingProDestructiveAbandon a Cisco Duo cloud-MDR onboarding.
compassone_get_cisco_onboardingFreeRead-onlyGet the state of one Cisco Duo cloud-MDR onboarding.
compassone_list_cisco_onboardingsFreeRead-onlyList the Cisco Duo cloud-MDR onboardings for one CompassOne customer, completed or in progress.
compassone_sync_cisco_usersProWriteVerify the Cisco Duo domain-wide delegation permissions and start the user sync — also the way to restart a sync that never began or stalled.

[Blackpoint CompassOne] Complete a Cisco Duo cloud-MDR onboarding by verifying everything was set up correctly. Takes no body. tenantId is REQUIRED and onboardingId comes from compassone_list_cisco_onboardings. This is the final step after compassone_create_cisco_onboarding and compassone_sync_cisco_users. Returns the raw CompassOne response.

ParamTypeRequiredDefaultDescription
onboardingIdstringyesThe onboarding id (from compassone_list_cisco_onboardings).
suppressTenantLevelNotificationsbooleannonullSuppress the tenant-level completion notifications when true. Omit for CompassOne's default (notifications sent).
tenantIdstringyesREQUIRED CompassOne tenant (end-customer) id. Discover ids with compassone_list_tenants.

[Blackpoint CompassOne] Begin a new Cisco Duo cloud-MDR onboarding for a customer. tenantId is REQUIRED. CompassOne FAILS this call if an onboarding for that Duo domain already exists — check compassone_list_cisco_onboardings first. Supply the customer's Duo admin API credentials (host, ikey, skey); all three are optional in CompassOne's schema, so pass whichever the onboarding flow requires. After creating, run compassone_sync_cisco_users and then compassone_complete_cisco_onboarding. Returns the raw created onboarding JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringnonullOptional JSON object of additional body fields, merged over the values above.
hoststringnonullThe customer's Cisco Duo API hostname (for example api-XXXXXXXX.duosecurity.com). Omit to leave unset.
ikeystringnonullThe Cisco Duo integration key (ikey). Omit to leave unset.
skeystringnonullThe Cisco Duo secret key (skey). Omit to leave unset.
tenantIdstringyesREQUIRED CompassOne tenant (end-customer) id. Discover ids with compassone_list_tenants.

[Blackpoint CompassOne] Abandon a Cisco Duo cloud-MDR onboarding. Destructive — this removes the onboarding records AND deletes the Cisco Duo onboarding app if one was created, so the customer's Duo-side integration is torn down and the onboarding must be started over. tenantId is REQUIRED and onboardingId comes from compassone_list_cisco_onboardings. Returns the raw CompassOne response.

ParamTypeRequiredDefaultDescription
onboardingIdstringyesThe onboarding id to abandon (from compassone_list_cisco_onboardings).
tenantIdstringyesREQUIRED CompassOne tenant (end-customer) id. Discover ids with compassone_list_tenants.

[Blackpoint CompassOne] Get the state of one Cisco Duo cloud-MDR onboarding. tenantId is REQUIRED (discover ids with compassone_list_tenants) and onboardingId comes from compassone_list_cisco_onboardings. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
onboardingIdstringyesThe onboarding id (from compassone_list_cisco_onboardings).
tenantIdstringyesREQUIRED CompassOne tenant (end-customer) id. Discover ids with compassone_list_tenants.

[Blackpoint CompassOne] List the Cisco Duo cloud-MDR onboardings for one CompassOne customer, completed or in progress. tenantId is REQUIRED and identifies the end customer — discover ids with compassone_list_tenants. Use compassone_get_cisco_onboarding for one onboarding's state. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
tenantIdstringyesREQUIRED CompassOne tenant (end-customer) id. Discover ids with compassone_list_tenants.

[Blackpoint CompassOne] Verify the Cisco Duo domain-wide delegation permissions and start the user sync — also the way to restart a sync that never began or stalled. Takes no body. tenantId is REQUIRED and onboardingId comes from compassone_list_cisco_onboardings. Run this after compassone_create_cisco_onboarding and before compassone_complete_cisco_onboarding. Returns the raw CompassOne response.

ParamTypeRequiredDefaultDescription
onboardingIdstringyesThe onboarding id (from compassone_list_cisco_onboardings).
tenantIdstringyesREQUIRED CompassOne tenant (end-customer) id. Discover ids with compassone_list_tenants.

Google Workspace Cloud MDR

ToolPlanAccessSummary
compassone_get_google_onboardingFreeRead-onlyGet the state of one Google Workspace cloud-MDR onboarding.
compassone_list_google_onboardingsFreeRead-onlyList the Google Workspace cloud-MDR onboardings for one CompassOne customer, completed or in progress.

[Blackpoint CompassOne] Get the state of one Google Workspace cloud-MDR onboarding. tenantId is REQUIRED (discover ids with compassone_list_tenants) and onboardingId comes from compassone_list_google_onboardings. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
onboardingIdstringyesThe onboarding id (from compassone_list_google_onboardings).
tenantIdstringyesREQUIRED CompassOne tenant (end-customer) id. Discover ids with compassone_list_tenants.

[Blackpoint CompassOne] List the Google Workspace cloud-MDR onboardings for one CompassOne customer, completed or in progress. tenantId is REQUIRED and identifies the end customer — discover ids with compassone_list_tenants. Use compassone_get_google_onboarding for one onboarding's detail. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
tenantIdstringyesREQUIRED CompassOne tenant (end-customer) id. Discover ids with compassone_list_tenants.

Microsoft 365 Cloud MDR

ToolPlanAccessSummary
compassone_approve_m365_countryProWriteApprove a country for a whole Microsoft 365 connection, so sign-ins from there stop raising impossible-travel detections for every user on the connection.
compassone_approve_m365_user_countryProWriteApprove a country for ONE Microsoft 365 user, optionally time-boxed to a travel window.
compassone_get_m365_connectionFreeRead-onlyGet one Microsoft 365 Defense connection by id.
compassone_list_m365_approved_countriesFreeRead-onlyList the countries approved for a whole Microsoft 365 connection — the connection-wide allow-list behind impossible-travel detection.
compassone_list_m365_connectionsFreeRead-onlyList the Microsoft 365 Defense connections belonging to one CompassOne customer.
compassone_list_m365_user_approved_countriesFreeRead-onlyList the currently-active approved countries for ONE Microsoft 365 user — the per-user overrides on top of the connection-wide list from compassone_list_m365_approved_countries.
compassone_list_m365_usersFreeRead-onlyList the users on one Microsoft 365 Defense connection, filterable by enabled / licensed / billable state and by name-or-email substring.
compassone_remove_m365_approved_countryProDestructiveRemove an approved country from a whole Microsoft 365 connection.
compassone_remove_m365_user_approved_countryProDestructiveRemove an approved country from ONE Microsoft 365 user.

[Blackpoint CompassOne] Approve a country for a whole Microsoft 365 connection, so sign-ins from there stop raising impossible-travel detections for every user on the connection. tenantId is REQUIRED and code is a REQUIRED two-letter ISO 3166-1 alpha-2 country code (look codes up with compassone_list_iso_countries). To approve for a single user instead, use compassone_approve_m365_user_country. Returns the raw CompassOne response.

ParamTypeRequiredDefaultDescription
codestringyesREQUIRED two-letter ISO 3166-1 alpha-2 country code to approve (for example US). List valid codes with compassone_list_iso_countries.
connectionIdstringyesThe M365 connection id (from compassone_list_m365_connections).
fieldsJsonstringnonullOptional JSON object of additional body fields, merged over the value above.
tenantIdstringyesREQUIRED CompassOne tenant (end-customer) id. Discover ids with compassone_list_tenants.

[Blackpoint CompassOne] Approve a country for ONE Microsoft 365 user, optionally time-boxed to a travel window. tenantId is REQUIRED, userId comes from compassone_list_m365_users, and isoCountryCode is a REQUIRED two-letter ISO 3166-1 alpha-2 code. Supply startDate and endDate to make the approval temporary — ideal for a trip. To widen the whole connection instead, use compassone_approve_m365_country. Returns the raw CompassOne response.

ParamTypeRequiredDefaultDescription
connectionIdstringyesThe M365 connection id (from compassone_list_m365_connections).
endDatestringnonullISO-8601 instant the approval ends. Omit for an approval that does not expire.
fieldsJsonstringnonullOptional JSON object of additional body fields, merged over the values above.
isoCountryCodestringyesREQUIRED two-letter ISO 3166-1 alpha-2 country code to approve (for example US). List valid codes with compassone_list_iso_countries.
startDatestringnonullISO-8601 instant the approval starts. Omit for an approval with no start bound.
tenantIdstringyesREQUIRED CompassOne tenant (end-customer) id. Discover ids with compassone_list_tenants.
userIdstringyesThe M365 user id (from compassone_list_m365_users).

[Blackpoint CompassOne] Get one Microsoft 365 Defense connection by id. tenantId is REQUIRED and connectionId comes from compassone_list_m365_connections. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
connectionIdstringyesThe M365 connection id (from compassone_list_m365_connections).
tenantIdstringyesREQUIRED CompassOne tenant (end-customer) id. Discover ids with compassone_list_tenants.

[Blackpoint CompassOne] List the countries approved for a whole Microsoft 365 connection — the connection-wide allow-list behind impossible-travel detection. tenantId is REQUIRED. This endpoint takes no paging params. For one user's overrides use compassone_list_m365_user_approved_countries. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
connectionIdstringyesThe M365 connection id (from compassone_list_m365_connections).
tenantIdstringyesREQUIRED CompassOne tenant (end-customer) id. Discover ids with compassone_list_tenants.

[Blackpoint CompassOne] List the Microsoft 365 Defense connections belonging to one CompassOne customer. tenantId is REQUIRED and identifies the end customer — discover ids with compassone_list_tenants. The returned connection ids feed every other M365 tool. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
tenantIdstringyesREQUIRED CompassOne tenant (end-customer) id. Discover ids with compassone_list_tenants.

[Blackpoint CompassOne] List the currently-active approved countries for ONE Microsoft 365 user — the per-user overrides on top of the connection-wide list from compassone_list_m365_approved_countries. tenantId is REQUIRED and userId comes from compassone_list_m365_users. Offset-paged with skip/take. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
connectionIdstringyesThe M365 connection id (from compassone_list_m365_connections).
skipintegerno0Number of records to skip for pagination (default 0).
takeintegerno100Max records to return (default 100, max 1000).
tenantIdstringyesREQUIRED CompassOne tenant (end-customer) id. Discover ids with compassone_list_tenants.
userIdstringyesThe M365 user id (from compassone_list_m365_users).

[Blackpoint CompassOne] List the users on one Microsoft 365 Defense connection, filterable by enabled / licensed / billable state and by name-or-email substring. tenantId is REQUIRED. Offset-paged with skip/take, NOT page/pageSize. The returned user ids feed the per-user approved-country tools. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
billablebooleannonullLimit to billable (true) or non-billable (false) users. Omit for both.
connectionIdstringyesThe M365 connection id (from compassone_list_m365_connections).
emailOrNameLikestringnonullSubstring matched against user email or name. Omit for no text filter.
enabledbooleannonullLimit to enabled (true) or disabled (false) users. Omit for both.
licensedbooleannonullLimit to licensed (true) or unlicensed (false) users. Omit for both.
orderBystringnonullOrder by field: email, enabled or licensed. Omit for CompassOne's default ordering.
skipintegerno0Number of records to skip for pagination (default 0).
sortDirectionstringnonullSort direction: ASC or DESC. Omit for CompassOne's default direction.
takeintegerno100Max records to return (default 100, max 1000).
tenantIdstringyesREQUIRED CompassOne tenant (end-customer) id. Discover ids with compassone_list_tenants.

[Blackpoint CompassOne] Remove an approved country from a whole Microsoft 365 connection. Destructive — narrowing the allow-list means sign-ins from that country raise impossible-travel detections again for every user on the connection. tenantId is REQUIRED. Note this tool takes the two-letter COUNTRY CODE, unlike compassone_remove_m365_user_approved_country which takes a record id. Returns the raw CompassOne response.

ParamTypeRequiredDefaultDescription
codestringyesREQUIRED two-letter ISO 3166-1 alpha-2 country code to remove (for example US). This is the country code, not a record id.
connectionIdstringyesThe M365 connection id (from compassone_list_m365_connections).
tenantIdstringyesREQUIRED CompassOne tenant (end-customer) id. Discover ids with compassone_list_tenants.

[Blackpoint CompassOne] Remove an approved country from ONE Microsoft 365 user. Destructive — that user's sign-ins from the country raise impossible-travel detections again. tenantId is REQUIRED and userId comes from compassone_list_m365_users. Note this tool takes the approved-country RECORD id from compassone_list_m365_user_approved_countries, unlike compassone_remove_m365_approved_country which takes a country code. Returns the raw CompassOne response.

ParamTypeRequiredDefaultDescription
connectionIdstringyesThe M365 connection id (from compassone_list_m365_connections).
isoCountryIdstringyesThe approved-country RECORD id to remove (from compassone_list_m365_user_approved_countries), not the ISO country code.
tenantIdstringyesREQUIRED CompassOne tenant (end-customer) id. Discover ids with compassone_list_tenants.
userIdstringyesThe M365 user id (from compassone_list_m365_users).

Cloud Posture

ToolPlanAccessSummary
compassone_bulk_delete_managed_policiesProDestructiveDelete several managed policies at once by id.
compassone_create_managed_policyProWriteCreate a managed policy.
compassone_delete_managed_policyProDestructiveDelete one managed policy by id.
compassone_get_managed_policyFreeRead-onlyGet one managed policy by id (from compassone_list_managed_policies_by_scope).
compassone_list_managed_policies_by_scopeFreeRead-onlyList every managed policy applicable to one scope.
compassone_save_managed_policy_as_templateProWriteSave an existing managed policy as a new reusable policy template.
compassone_update_managed_policyProWriteUpdate a managed policy by id.
compassone_update_managed_policy_assignmentsProDestructiveAssign and unassign connections on a managed policy in a single call.

[Blackpoint CompassOne] Delete several managed policies at once by id. Destructive — this is a delete despite using a POST verb (CompassOne exposes it at /bulk-delete), and every listed policy stops being enforced on all its assigned connections. Returns the raw CompassOne response.

ParamTypeRequiredDefaultDescription
idsstringyesREQUIRED comma-separated managed policy ids to delete (from compassone_list_managed_policies_by_scope).

[Blackpoint CompassOne] Create a managed policy. CompassOne REQUIRES name, connectionType, policyType, the policy document, and scopeAssignments. Because policy and scopeAssignments are structured objects/arrays, supply them through fieldsJson — for example {"policy":,"scopeAssignments":[]}. Returns the raw created policy JSON including its new id.

ParamTypeRequiredDefaultDescription
connectionTypestringyesREQUIRED connection type. One of: CISCO_DUO, GOOGLE_WORKSPACES, MICROSOFT_365.
descriptionstringnonullPolicy description. Omit to leave unset.
fieldsJsonstringyesREQUIRED JSON object carrying the structured fields this endpoint needs but that cannot be typed here: policy (the policy document object) and scopeAssignments (an array of scope objects). May also carry description, status (ARCHIVED, DEPRECATED, DRAFT, PUBLISHED), accountId, customerId, sourceTemplateId, defaultAssignmentStatus (DISABLED, ENABLED, REPORT-ONLY) and isGlobal.
namestringyesREQUIRED policy name.
policyTypestringyesREQUIRED policy type. One of: EMPTY_POLICY, MS365_CONDITIONAL_ACCESS.
statusstringnonullInitial policy status. One of: ARCHIVED, DEPRECATED, DRAFT, PUBLISHED. Omit for CompassOne's default.

[Blackpoint CompassOne] Delete one managed policy by id. Destructive — the policy is removed and stops being enforced on every connection it was assigned to. To remove several at once use compassone_bulk_delete_managed_policies. Returns the raw CompassOne response.

ParamTypeRequiredDefaultDescription
idstringyesThe managed policy id to delete (from compassone_list_managed_policies_by_scope).

[Blackpoint CompassOne] Get one managed policy by id (from compassone_list_managed_policies_by_scope). Pass customerId to narrow the effective-policy view to a single customer. Returns the raw policy JSON including its policy document and assignment state.

ParamTypeRequiredDefaultDescription
customerIdstringnonullCustomer id to filter the effective policies by. Omit for all customers.
idstringyesThe managed policy id (from compassone_list_managed_policies_by_scope).

[Blackpoint CompassOne] List every managed policy applicable to one scope. BOTH scopeType and scopeId are REQUIRED path values: scopeType is ACCOUNT, CUSTOMER or CONNECTION, and scopeId is the id of that account, customer or connection. Unlike the cloud-MDR tools this takes no tenantId. Page-based paging (pageSize max 1000). This is the connector's most filterable read — several filters accept comma-separated multi-values. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
adoptionStatesstringnonullComma-separated adoption states. Valid values: ADOPTED, AUTHORED, DETECTED.
connectionTypestringnonullFilter by connection type. One of: CISCO_DUO, GOOGLE_WORKSPACES, MICROSOFT_365.
enforcementStatusstringnonullComma-separated enforcement statuses. Valid values: DELETED, DELETING, DRIFT_PENDING, ENFORCING, FAILED_TO_APPLY, FAILED_TO_DELETE, FAILED_TO_UPDATE, IN_SYNC, PENDING_APPLY, PENDING_DELETION, PENDING_UPDATE, ROLLING_BACK, UPDATING.
idsstringnonullComma-separated policy ids to filter by.
isImportedbooleannonullFilter by import status: true for imported policies only, false for non-imported.
pageintegerno11-based page number (default 1).
pageSizeintegerno50Results per page (default 50, max 1000).
policyStatestringnonullComma-separated policy states. Valid values: DISABLED, ENABLED, REPORT-ONLY.
policyTypestringnonullFilter by policy type. One of: EMPTY_POLICY, MS365_CONDITIONAL_ACCESS.
scopeIdstringyesREQUIRED id of the scope — the account, customer or connection id matching scopeType.
scopeTypestringyesREQUIRED scope type: ACCOUNT, CUSTOMER or CONNECTION.
searchstringnonullSearch term matched against policy name or description. Omit for no text filter.
sortBystringnonullSort field. One of: MANAGED_POLICY_ASSIGNED_COUNT, MANAGED_POLICY_CREATED, MANAGED_POLICY_NAME, MANAGED_POLICY_SOURCE, MANAGED_POLICY_STATE, MANAGED_POLICY_UPDATED. Omit for CompassOne's default ordering.
sortOrderstringnonullSort direction: ASC or DESC (default DESC). Omit for CompassOne's default direction.
sourceBaselineIdstringnonullFilter by source baseline id. Omit for all baselines.
sourceTemplateIdsstringnonullComma-separated source template ids to filter by.
statusstringnonullFilter by policy status. One of: ARCHIVED, DEPRECATED, DRAFT, PUBLISHED.

[Blackpoint CompassOne] Save an existing managed policy as a new reusable policy template. Every field is optional — when name is omitted CompassOne reuses the managed policy's own name. Returns the raw created template JSON.

ParamTypeRequiredDefaultDescription
categorystringnonullComma-separated categories for the new template. Omit for none.
descriptionstringnonullDescription for the new template. Omit to leave unset.
fieldsJsonstringnonullOptional JSON object of additional body fields, merged over the values above.
idstringyesThe managed policy id to template (from compassone_list_managed_policies_by_scope).
namestringnonullName for the new template. Omit to reuse the managed policy's own name.

[Blackpoint CompassOne] Update a managed policy by id. Every field is optional — supply only what changes. Editable: name, description, status, defaultAssignmentStatus, and the policy document (through fieldsJson, since it is a structured object). Returns the raw updated policy JSON.

ParamTypeRequiredDefaultDescription
defaultAssignmentStatusstringnonullNew default assignment status. One of: DISABLED, ENABLED, REPORT-ONLY. Omit to leave unchanged.
descriptionstringnonullNew policy description. Omit to leave unchanged.
fieldsJsonstringnonullOptional JSON object of additional body fields, merged over the values above. Use this to send the structured policy document, for example {"policy":}.
idstringyesThe managed policy id to update (from compassone_list_managed_policies_by_scope).
namestringnonullNew policy name. Omit to leave unchanged.
statusstringnonullNew policy status. One of: ARCHIVED, DEPRECATED, DRAFT, PUBLISHED. Omit to leave unchanged.

[Blackpoint CompassOne] Assign and unassign connections on a managed policy in a single call. Pass connectionsToAdd (an array of connection objects) and/or assignmentIdsToRemove (an array of assignment ids) through fieldsJson — for example {"assignmentIdsToRemove":["a-1"]}. Removing an assignment stops enforcing the policy on that connection. Returns the raw CompassOne response.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body. Optional keys: connectionsToAdd (array of connection assignment objects) and assignmentIdsToRemove (array of assignment id strings).
idstringyesThe managed policy id (from compassone_list_managed_policies_by_scope).

Vulnerabilities

ToolPlanAccessSummary
compassone_bulk_delete_vulnerabilitiesProDestructiveDelete several vulnerabilities outright, across every device they were found on.
compassone_bulk_delete_vulnerabilities_for_deviceProDestructiveDelete several vulnerabilities' records for ONE device.
compassone_bulk_update_vulnerabilitiesProWriteUpdate the status of several vulnerabilities at once, across all their devices.
compassone_bulk_update_vulnerabilities_for_deviceProWriteUpdate the status of several vulnerabilities on ONE device.
compassone_delete_vulnerability_for_devicesProDestructiveDelete one vulnerability's records for specific devices.
compassone_export_vulnerabilitiesProWriteRequest an export of the vulnerability register.
compassone_export_vulnerability_assetsProWriteRequest an export of the assets affected by one vulnerability.
compassone_get_cveFreeRead-onlyGet CVE detail by CVE id.
compassone_get_cve_referencesFreeRead-onlyGet the external reference links for one CVE — advisories, patches and vendor bulletins.
compassone_get_vulnerabilities_count_by_severityFreeRead-onlyGet vulnerability counts grouped by severity — the numbers behind a risk-posture summary.
compassone_get_vulnerabilities_count_by_tenantFreeRead-onlyGet vulnerability counts grouped by CompassOne tenant — the cross-customer view an MSP uses to see which customers carry the most risk.
compassone_get_vulnerabilityFreeRead-onlyGet one vulnerability by id (from compassone_list_vulnerabilities).
compassone_list_vulnerabilitiesFreeRead-onlyList the vulnerability register with the connector's richest filter set.
compassone_list_vulnerability_assetsFreeRead-onlyList the assets affected by one vulnerability — the remediation work list.
compassone_update_vulnerability_status_for_devicesProWriteSet one vulnerability's status on specific devices — how you mark it resolved, accepted or a false positive per machine.

[Blackpoint CompassOne] Delete several vulnerabilities outright, across every device they were found on. Destructive and broad — the finding history is removed everywhere, not marked resolved. Prefer compassone_bulk_update_vulnerabilities to change status, or compassone_bulk_delete_vulnerabilities_for_device to limit the deletion to one machine. ids is REQUIRED. Returns the raw CompassOne response.

ParamTypeRequiredDefaultDescription
idsstringyesREQUIRED comma-separated vulnerability ids to delete (from compassone_list_vulnerabilities).

[Blackpoint CompassOne] Delete several vulnerabilities' records for ONE device. Destructive — that machine's finding history for those vulnerabilities is removed, not marked resolved. Both ids and deviceId are REQUIRED. Prefer compassone_bulk_update_vulnerabilities_for_device to change status instead. Returns the raw CompassOne response.

ParamTypeRequiredDefaultDescription
deviceIdstringyesREQUIRED device id whose records to delete (from compassone_list_vulnerability_assets).
idsstringyesREQUIRED comma-separated vulnerability ids to delete (from compassone_list_vulnerabilities).

[Blackpoint CompassOne] Update the status of several vulnerabilities at once, across all their devices. Both ids and status are REQUIRED. To scope the change to one device use compassone_bulk_update_vulnerabilities_for_device. Returns the raw CompassOne response.

ParamTypeRequiredDefaultDescription
fieldsJsonstringnonullOptional JSON object of additional body fields, merged over the values above.
idsstringyesREQUIRED comma-separated vulnerability ids to update (from compassone_list_vulnerabilities).
statusstringyesREQUIRED new status to apply to every listed vulnerability.

[Blackpoint CompassOne] Update the status of several vulnerabilities on ONE device. All of ids, deviceId and status are REQUIRED. To change status across every affected device use compassone_bulk_update_vulnerabilities. Returns the raw CompassOne response.

ParamTypeRequiredDefaultDescription
deviceIdstringyesREQUIRED device id the update applies to (from compassone_list_vulnerability_assets).
fieldsJsonstringnonullOptional JSON object of additional body fields, merged over the values above.
idsstringyesREQUIRED comma-separated vulnerability ids to update (from compassone_list_vulnerabilities).
statusstringyesREQUIRED new status to apply on that device.

[Blackpoint CompassOne] Delete one vulnerability's records for specific devices. Destructive — the finding history for those machines is removed, not merely marked resolved. To mark it resolved instead, use compassone_update_vulnerability_status_for_devices. deviceIds is REQUIRED. Returns the raw CompassOne response.

ParamTypeRequiredDefaultDescription
deviceIdsstringyesREQUIRED comma-separated device ids whose records to delete (from compassone_list_vulnerability_assets).
idstringyesThe vulnerability id (from compassone_list_vulnerabilities).

[Blackpoint CompassOne] Request an export of the vulnerability register. The body accepts the same filters as compassone_list_vulnerabilities plus 'fields' (an array of column names) and 'fieldAliases' (an object of column headers) — supply them through fieldsJson. CompassOne answers 201 with NO documented payload, so this tool returns whatever arrives, or when the response is empty. Returns the raw CompassOne response.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body. Optional keys mirror compassone_list_vulnerabilities' filters (search, severity, status, ids, prioritized, date bounds, sortBy, sortOrder, page, pageSize) plus fields (array of column names) and fieldAliases (object of column headers). Pass for a full unfiltered export.

[Blackpoint CompassOne] Request an export of the assets affected by one vulnerability. The body REQUIRES 'class' (an array of asset classes: CONTAINER, DEVICE, FRAMEWORK, NETSTAT, PERSON, PROCESS, SERVICE, SOFTWARE, SOURCE, SURVEY, USER) and accepts the same filters as compassone_list_vulnerability_assets plus fields and fieldAliases — supply them through fieldsJson, for example {"class":["DEVICE"]}. CompassOne answers 201 with NO documented payload, so this tool returns whatever arrives, or when the response is empty. Returns the raw CompassOne response.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body. REQUIRED key: class (array of asset classes, CONTAINER, DEVICE, FRAMEWORK, NETSTAT, PERSON, PROCESS, SERVICE, SOFTWARE, SOURCE, SURVEY, USER). Optional keys mirror compassone_list_vulnerability_assets' filters plus fields (array of column names) and fieldAliases (object of column headers).
idstringyesThe vulnerability id (from compassone_list_vulnerabilities).

[Blackpoint CompassOne] Get CVE detail by CVE id. Pass assetId to scope the CVE information to one asset's context. For the CVE's external links use compassone_get_cve_references. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
assetIdstringnonullAsset id to scope the CVE information to. Omit for the unscoped CVE record.
idstringyesThe CVE id.
tenantIdstringnonullCompassOne tenant (end-customer) id, sent as the x-tenant-id header. CompassOne now REQUIRES this header on the vulnerability-management endpoints — requests without it are rejected upstream with 400. Discover ids with compassone_list_tenants.

[Blackpoint CompassOne] Get the external reference links for one CVE — advisories, patches and vendor bulletins. Use compassone_get_cve for the CVE record itself. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
idstringyesThe CVE id.
tenantIdstringnonullCompassOne tenant (end-customer) id, sent as the x-tenant-id header. CompassOne now REQUIRES this header on the vulnerability-management endpoints — requests without it are rejected upstream with 400. Discover ids with compassone_list_tenants.

[Blackpoint CompassOne] Get vulnerability counts grouped by severity — the numbers behind a risk-posture summary. No paging. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
criticalAssetsPrioritizationbooleannonullPrioritize critical assets in the statistics when true.
hasAffectedAssetsbooleannonullLimit to vulnerabilities found on at least one asset when true.
hideResolvedVulnerabilitiesbooleannonullHide resolved vulnerabilities from the statistics when true (default false).
statusstringnonullSingle status value to limit the statistics to. Omit for all statuses.
tenantIdstringnonullCompassOne tenant (end-customer) id, sent as the x-tenant-id header. CompassOne now REQUIRES this header on the vulnerability-management endpoints — requests without it are rejected upstream with 400. Discover ids with compassone_list_tenants.
vulnerabilityStatusstringnonullComma-separated vulnerability-status values to limit the statistics to.

[Blackpoint CompassOne] Get vulnerability counts grouped by CompassOne tenant — the cross-customer view an MSP uses to see which customers carry the most risk. No paging. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
criticalAssetsPrioritizationbooleannonullPrioritize critical assets in the statistics when true.
hasAffectedAssetsbooleannonullLimit to vulnerabilities found on at least one asset when true.
hideResolvedVulnerabilitiesbooleannonullHide resolved vulnerabilities from the statistics when true (default false).
prioritizedbooleannonullLimit to prioritized (true) or non-prioritized (false) vulnerabilities.
severitystringnonullComma-separated severities to limit the statistics to.
tenantIdstringnonullCompassOne tenant (end-customer) id, sent as the x-tenant-id header. CompassOne now REQUIRES this header on the vulnerability-management endpoints — requests without it are rejected upstream with 400. Discover ids with compassone_list_tenants.
vulnerabilityStatusstringnonullComma-separated vulnerability-status values to limit the statistics to.

[Blackpoint CompassOne] Get one vulnerability by id (from compassone_list_vulnerabilities). Returns the raw vulnerability JSON — scores, severity, status, exploitability and affected-asset counts.

ParamTypeRequiredDefaultDescription
idstringyesThe vulnerability id (from compassone_list_vulnerabilities).
tenantIdstringnonullCompassOne tenant (end-customer) id, sent as the x-tenant-id header. CompassOne now REQUIRES this header on the vulnerability-management endpoints — requests without it are rejected upstream with 400. Discover ids with compassone_list_tenants.

[Blackpoint CompassOne] List the vulnerability register with the connector's richest filter set. Page-based paging (pageSize max 1000). Note CompassOne has TWO status filters that mean different things and are not interchangeable: 'status' is single-valued, 'vulnerabilityStatus' takes a comma-separated list. Use compassone_get_vulnerability for one record and compassone_list_vulnerability_assets to see which machines are affected. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
applicationFamilystringnonullComma-separated application families to filter by.
assetEnvironmentalScorestringnonullComma-separated priority (asset environmental) score values to filter by.
baseScorestringnonullComma-separated base-score values to filter by.
criticalAssetsPrioritizationbooleannonullPrioritize critical assets in the returned statistics when true.
deviceIdstringnonullOnly vulnerabilities present on this device id. Omit for all devices.
exploitabilitystringnonullExploitability filter: Attacked or Unreported. Omit for both.
foundAfterstringnonullOnly vulnerabilities first found after this ISO-8601 instant.
foundBeforestringnonullOnly vulnerabilities first found before this ISO-8601 instant.
hasAffectedAssetsbooleannonullLimit to vulnerabilities found on at least one asset when true.
hideResolvedVulnerabilitiesbooleannonullExclude resolved vulnerabilities when true.
idsstringnonullComma-separated vulnerability ids to filter by.
lastSeenAfterstringnonullOnly vulnerabilities last seen after this ISO-8601 instant.
lastSeenBeforestringnonullOnly vulnerabilities last seen before this ISO-8601 instant.
pageintegerno11-based page number (default 1).
pageSizeintegerno50Results per page (default 50, max 1000).
prioritizedbooleannonullLimit to prioritized (true) or non-prioritized (false) vulnerabilities.
searchstringnonullCase-insensitive search term matched across all text fields. Omit for no text filter.
severitystringnonullComma-separated severities to filter by.
sortBystringnonullSort field. One of: assetEnvironmentalScore, assetsAmount, baseScore, cveId, exploitability, foundOn, lastSeenOn, name, prioritized, priorityAssetsAmount, severity, status, applicationFamily, applicationName, applicationVendor, displayName. Omit for CompassOne's default ordering.
sortOrderstringnonullSort direction: ASC or DESC. Omit for CompassOne's default direction.
statusstringnonullSingle status value to filter by. This is NOT the same filter as vulnerabilityStatus.
tenantIdstringnonullCompassOne tenant (end-customer) id, sent as the x-tenant-id header. CompassOne now REQUIRES this header on the vulnerability-management endpoints — requests without it are rejected upstream with 400 'x-tenant-id header is required'. Discover ids with compassone_list_tenants.
vulnerabilityStatusstringnonullComma-separated vulnerability-status values to filter by. This is NOT the same filter as status.
withDeletedbooleannonullInclude soft-deleted vulnerabilities when true (default false).

[Blackpoint CompassOne] List the assets affected by one vulnerability — the remediation work list. assetClass is REQUIRED and accepts several classes as a comma-separated list (CONTAINER, DEVICE, FRAMEWORK, NETSTAT, PERSON, PROCESS, SERVICE, SOFTWARE, SOURCE, SURVEY, USER). Page-based paging (pageSize max 1000). Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
assetClassstringyesREQUIRED comma-separated asset classes to include. Valid values: CONTAINER, DEVICE, FRAMEWORK, NETSTAT, PERSON, PROCESS, SERVICE, SOFTWARE, SOURCE, SURVEY, USER.
decommissionDatestringnonullComma-separated decommission-date filters.
decommissionedstringnonullComma-separated decommissioned-status filters.
filterstringnonullFilter clause using CompassOne's /v1/search WITH-clause syntax. Omit for no structured filter.
foundOnstringnonullComma-separated foundOn date filters.
idstringyesThe vulnerability id (from compassone_list_vulnerabilities).
lastSeenOnstringnonullComma-separated lastSeenOn date filters.
pageintegerno11-based page number (default 1).
pageSizeintegerno50Results per page (default 50, max 1000).
platformstringnonullComma-separated device operating-system platforms.
searchstringnonullCase-insensitive search term matched across all text fields. Omit for no text filter.
sortBystringnonullSort field. One of: displayName, foundOn, lastSeenOn, prioritized, status. Omit for CompassOne's default ordering.
sortOrderstringnonullSort direction: ASC or DESC. Omit for CompassOne's default direction.
sourcesstringnonullComma-separated source ids — limits results to assets related to those sources.
tenantIdstringnonullCompassOne tenant (end-customer) id, sent as the x-tenant-id header. CompassOne now REQUIRES this header on the vulnerability-management endpoints — requests without it are rejected upstream with 400. Discover ids with compassone_list_tenants.
typestringnonullComma-separated device types.
wdStatusstringnonullComma-separated Windows Defender status filters.
withDeletedbooleannonullInclude soft-deleted assets when true (default false).

[Blackpoint CompassOne] Set one vulnerability's status on specific devices — how you mark it resolved, accepted or a false positive per machine. Both deviceIds and status are REQUIRED. This changes status only; it does not remove the vulnerability record (see compassone_delete_vulnerability_for_devices for that). Returns the raw CompassOne response.

ParamTypeRequiredDefaultDescription
deviceIdsstringyesREQUIRED comma-separated device ids to update (from compassone_list_vulnerability_assets).
fieldsJsonstringnonullOptional JSON object of additional body fields, merged over the values above.
idstringyesThe vulnerability id (from compassone_list_vulnerabilities).
statusstringyesREQUIRED new status to apply on those devices.

Scans

ToolPlanAccessSummary
compassone_bulk_delete_scans_and_schedulesProDestructiveBulk delete scans and/or scan schedules by id.
compassone_bulk_update_scan_schedulesProWriteBulk update the status of many scan schedules in one call.
compassone_cancel_scanProDestructiveCancel an in-flight vulnerability-management scan by id.
compassone_create_scanProWriteCreate (queue) a new vulnerability-management scan.
compassone_delete_scanProDestructiveDelete a vulnerability-management scan by id.
compassone_export_scan_cvesProWriteQueue an export of the CVEs found by one scan (documented for network scans).
compassone_export_scansProWriteQueue an export of scans and schedules.
compassone_get_scanFreeRead-onlyGet a single vulnerability-management scan by id, including its type, status, configuration and result.
compassone_get_scan_statsFreeRead-onlyGet aggregate scan statistics across the account (counts by type/status as CompassOne reports them).
compassone_list_scan_cvesFreeRead-onlyList the CVEs a specific scan found, with severity, CVSS base score and CompassOne's asset-environmental (priority) score.
compassone_list_scansFreeRead-onlyList vulnerability-management scan runs (schedules excluded — use compassone_list_scan_schedules for those).
compassone_list_scans_and_schedulesFreeRead-onlyList vulnerability-management scans AND scan schedules in one combined index, so a single call shows both completed runs and the recurring definitions that produce them.
compassone_update_scanProWriteUpdate a vulnerability-management scan by id.

[Blackpoint CompassOne] Bulk delete scans and/or scan schedules by id. The ids parameter is REQUIRED. Destructive — every id given is removed; deleting a schedule stops all of its future runs. Ids come from compassone_list_scans_and_schedules (which also tells you, via sourceTable, whether an id is a scan or a schedule). Returns the raw CompassOne response.

ParamTypeRequiredDefaultDescription
fieldsJsonstringnonullOptional JSON object of additional body fields, merged over the values above.
idsstringyesREQUIRED comma-separated scan and/or scan-schedule ids to delete (from compassone_list_scans_and_schedules).

[Blackpoint CompassOne] Bulk update the status of many scan schedules in one call. Both ids and status are REQUIRED. This is the bulk counterpart to compassone_update_scan_schedule and applies the same status to every id given. Not destructive — the schedules are retained, only their status changes; use compassone_bulk_delete_scans_and_schedules to remove them. Returns the raw CompassOne response.

ParamTypeRequiredDefaultDescription
fieldsJsonstringnonullOptional JSON object of additional body fields, merged over the values above. Supply the whole data object here to set fields beyond status, e.g. {"data":{"status":"disabled"}}.
idsstringyesREQUIRED comma-separated scan-schedule ids to update (from compassone_list_scan_schedules).
statusstringyesREQUIRED new status applied to every id. One of: active, completed, disabled.

[Blackpoint CompassOne] Cancel an in-flight vulnerability-management scan by id. The id parameter is REQUIRED. Destructive despite being a PATCH: it aborts the running scan and the partial run is NOT resumable — the only way forward is to queue a new scan with compassone_create_scan. Use compassone_list_scans filtered to status in-progress to find cancellable scans. Returns the raw CompassOne response.

ParamTypeRequiredDefaultDescription
idstringyesREQUIRED scan id to cancel (from compassone_list_scans).

[Blackpoint CompassOne] Create (queue) a new vulnerability-management scan. Both type and triggeredByType are REQUIRED. Pass the scan's type-specific config object through fieldsJson — CompassOne types it as a free-form object, so it is not modelled as a typed parameter here. To scan on a recurring basis create a schedule with compassone_create_scan_schedule instead. Returns the raw created scan JSON including its new id.

ParamTypeRequiredDefaultDescription
assetIdstringnonullAsset id the scan targets (from the asset tools). Omit for an account-wide scan.
createdBystringnonullCreator attribution to record on the scan. Omit to let CompassOne attribute it to the API token.
fieldsJsonstringnonullOptional JSON object of additional body fields, merged over the values above. This is how you supply the object-typed config property, e.g. {"config":{"targets":["10.0.0.0/24"]}}.
triggeredBystringnonullIdentifier of the entity that triggered the scan (pairs with triggeredByType). Omit to let CompassOne attribute it.
triggeredByTypestringyesREQUIRED trigger source. One of: schedule, system, user.
typestringyesREQUIRED scan type. One of: darkweb, external, local, network.
updatedBystringnonullUpdater attribution to record on the scan. Omit to let CompassOne attribute it to the API token.

[Blackpoint CompassOne] Delete a vulnerability-management scan by id. The id parameter is REQUIRED. Destructive — the scan record and its CVE findings are removed from the index. Use compassone_bulk_delete_scans_and_schedules to remove several at once. Returns the raw CompassOne response.

ParamTypeRequiredDefaultDescription
idstringyesREQUIRED scan id to delete (from compassone_list_scans).

[Blackpoint CompassOne] Queue an export of the CVEs found by one scan (documented for network scans). The id parameter is REQUIRED; the remaining parameters are optional and mirror the filters on compassone_list_scan_cves. CompassOne documents no response payload for an export (it answers 201 with an empty body), so StackJack passes through whatever arrives — an empty is the normal success shape, not an error.

ParamTypeRequiredDefaultDescription
assetEnvironmentalScorestringnonullComma-separated asset-environmental (priority) scores to match exactly. Omit for all scores.
baseScorestringnonullComma-separated CVSS base scores to match exactly. Omit for all scores.
fieldsstringnonullComma-separated column names to include in the export file. Omit to export CompassOne's default column set.
fieldsJsonstringnonullOptional JSON object of additional body fields, merged over the values above. This is how you supply the object-typed fieldAliases property, e.g. {"fieldAliases":{"baseScore":"CVSS"}}.
idstringyesREQUIRED scan id (ScanTypeID, from compassone_list_scans).
pageintegernonull1-based page number of the export (body field, default 1). Omit unless you are deliberately exporting one page.
pageSizeintegernonullRows per export page (body field; CompassOne defaults to 65535). Omit to take that default.
prioritizedbooleannonullFilter to prioritized (true) or non-prioritized (false) vulnerabilities. Omit for both.
scanCveIdsstringnonullComma-separated scan-CVE ids — limits the export to those specific records. Omit for all.
searchstringnonullCase-insensitive search term matched across all text fields. Omit for no text filter.
severitystringnonullComma-separated severities to include. Omit for all severities.
sortBystringnonullSort field. One of: app, assetEnvironmentalScore, baseScore, prioritized, severity. Omit for CompassOne's default ordering.
sortOrderstringnonullSort direction: ASC or DESC. Omit for CompassOne's default direction.
withDeletedbooleannonullInclude soft-deleted CVE records when true (default false).

[Blackpoint CompassOne] Queue an export of scans and schedules. Every parameter is optional and mirrors the filters on compassone_list_scans_and_schedules. CompassOne documents no response payload for an export (it answers 201 with an empty body), so StackJack passes through whatever arrives — an empty is the normal success shape, not an error. Retrieve the finished file through the CompassOne console or the report tools.

ParamTypeRequiredDefaultDescription
fieldsstringnonullComma-separated column names to include in the export file. Omit to export CompassOne's default column set.
fieldsJsonstringnonullOptional JSON object of additional body fields, merged over the values above. This is how you supply the object-typed fieldAliases property, e.g. {"fieldAliases":{"createdOn":"Created"}}.
pageintegernonull1-based page number of the export (body field, default 1). Omit unless you are deliberately exporting one page.
pageSizeintegernonullRows per export page (body field; CompassOne defaults to 65535). Omit to take that default.
searchstringnonullCase-insensitive search term matched across all text fields. Omit for no text filter.
sortBystringnonullSort field. One of: id, accountId, createdBy, createdOn, tenantId, updatedOn, type, name, status, sourceTable, scansCount. Omit for CompassOne's default ordering.
sortOrderstringnonullSort direction: ASC or DESC. Omit for CompassOne's default direction.
sourceTablestringnonullComma-separated source tables to include. Values: scan, scanschedule. Omit to export both.
statusstringnonullComma-separated statuses to include. Values: canceled, completed, failed, in-progress, new, active, disabled. Omit for all statuses.
typestringnonullComma-separated scan types to include. Values: darkweb, external, local, network. Omit for all types.
withDeletedbooleannonullInclude soft-deleted scans and schedules when true (default false).

[Blackpoint CompassOne] Get a single vulnerability-management scan by id, including its type, status, configuration and result. The id parameter is REQUIRED. Use compassone_list_scans or compassone_list_scans_and_schedules to discover ids. Returns the raw scan JSON.

ParamTypeRequiredDefaultDescription
idstringyesREQUIRED scan id (ScanTypeID, from compassone_list_scans).

[Blackpoint CompassOne] Get aggregate scan statistics across the account (counts by type/status as CompassOne reports them). Every parameter is optional; there is no paging on this endpoint. Use compassone_list_scans_and_schedules for the itemized index behind these numbers. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
typestringnonullComma-separated scan types to include. Values: darkweb, external, local, network. Omit for all types.
withDeletedbooleannonullInclude soft-deleted scans in the statistics when true (default false).

[Blackpoint CompassOne] List the CVEs a specific scan found, with severity, CVSS base score and CompassOne's asset-environmental (priority) score. The id parameter is REQUIRED. Page-based paging (pageSize max 1000). Use compassone_list_scans for scan ids and compassone_export_scan_cves to queue a full export of the same result set. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
assetEnvironmentalScorestringnonullComma-separated asset-environmental (priority) scores to match exactly. Omit for all scores.
baseScorestringnonullComma-separated CVSS base scores to match exactly. Omit for all scores.
idstringyesREQUIRED scan id (ScanTypeID, from compassone_list_scans).
pageintegerno11-based page number (default 1).
pageSizeintegerno50Results per page (default 50, max 1000).
prioritizedbooleannonullFilter to prioritized (true) or non-prioritized (false) vulnerabilities. Omit for both.
scanCveIdsstringnonullComma-separated scan-CVE ids — limits results to those specific records. Omit for all.
searchstringnonullCase-insensitive search term matched across all text fields. Omit for no text filter.
severitystringnonullComma-separated severities to include. Omit for all severities.
sortBystringnonullSort field. One of: app, assetEnvironmentalScore, baseScore, prioritized, severity. Omit for CompassOne's default ordering.
sortOrderstringnonullSort direction: ASC or DESC. Omit for CompassOne's default direction.
withDeletedbooleannonullInclude soft-deleted CVE records when true (default false).

[Blackpoint CompassOne] List vulnerability-management scan runs (schedules excluded — use compassone_list_scan_schedules for those). Every parameter is optional. Page-based paging (pageSize max 1000). Returned ids feed compassone_get_scan, compassone_list_scan_cves, compassone_update_scan, compassone_cancel_scan and compassone_delete_scan. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
assetIdstringnonullComma-separated asset ids — limits results to scans for those assets. Omit for all assets.
createdOnEndstringnonullReturn only scans created on or before this ISO-8601 date-time (e.g. 2026-07-31T23:59:59Z).
createdOnStartstringnonullReturn only scans created on or after this ISO-8601 date-time (e.g. 2026-07-01T00:00:00Z).
pageintegerno11-based page number (default 1).
pageSizeintegerno50Results per page (default 50, max 1000).
searchstringnonullCase-insensitive search term matched across all text fields. Omit for no text filter.
sortBystringnonullSort field. One of: id, accountId, createdBy, createdOn, tenantId, deletedBy, deletedOn, updatedBy, updatedOn, type, assetId, status, triggeredByType, triggeredBy. Omit for CompassOne's default ordering.
sortOrderstringnonullSort direction: ASC or DESC. Omit for CompassOne's default direction.
statusstringnonullComma-separated statuses to include. Values: canceled, completed, failed, in-progress, new. Omit for all statuses.
triggeredBystringnonullLimit results to scans triggered by this specific entity (single value, not a list).
typestringnonullComma-separated scan types to include. Values: darkweb, external, local, network. Omit for all types.
withDeletedbooleannonullInclude soft-deleted scans when true (default false).

[Blackpoint CompassOne] List vulnerability-management scans AND scan schedules in one combined index, so a single call shows both completed runs and the recurring definitions that produce them. Every parameter is optional. Use sourceTable to restrict to one kind: scan (a run) or scanschedule (a definition). Page-based paging (pageSize max 1000). Returned ids feed compassone_get_scan / compassone_get_scan_schedule; for scans only use compassone_list_scans, for schedules only use compassone_list_scan_schedules. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
pageintegerno11-based page number (default 1).
pageSizeintegerno50Results per page (default 50, max 1000).
searchstringnonullCase-insensitive search term matched across all text fields. Omit for no text filter.
sortBystringnonullSort field. One of: id, accountId, createdBy, createdOn, tenantId, updatedOn, type, name, status, sourceTable, scansCount. Omit for CompassOne's default ordering.
sortOrderstringnonullSort direction: ASC or DESC. Omit for CompassOne's default direction.
sourceTablestringnonullComma-separated source tables to include. Values: scan, scanschedule. Omit to return both.
statusstringnonullComma-separated statuses to include. Values: canceled, completed, failed, in-progress, new, active, disabled (the last two apply to schedules). Omit for all statuses.
typestringnonullComma-separated scan types to include. Values: darkweb, external, local, network. Omit for all types.
withDeletedbooleannonullInclude soft-deleted scans and schedules when true (default false).

[Blackpoint CompassOne] Update a vulnerability-management scan by id. The id parameter is REQUIRED; every field is optional — supply only what changes. Pass the object-typed config and result properties through fieldsJson. To abort a running scan use compassone_cancel_scan instead of setting status. Returns the raw updated scan JSON.

ParamTypeRequiredDefaultDescription
assetIdstringnonullNew target asset id. Omit to leave unchanged.
fieldsJsonstringnonullOptional JSON object of additional body fields, merged over the values above. This is how you supply the object-typed config and result properties, e.g. {"config":,"result":}.
idstringyesREQUIRED scan id to update (from compassone_list_scans).
statusstringnonullNew status. One of: canceled, completed, failed, in-progress, new. Omit to leave unchanged.
updatedBystringnonullUpdater attribution to record on the scan. Omit to let CompassOne attribute it to the API token.

Scan Schedules

ToolPlanAccessSummary
compassone_create_scan_scheduleProWriteCreate a recurring vulnerability-management scan schedule.
compassone_delete_scan_scheduleProDestructiveDelete a vulnerability-management scan schedule by id.
compassone_get_scan_scheduleFreeRead-onlyGet a single vulnerability-management scan schedule by id, including its type, frequency, next run time and status.
compassone_list_scan_schedulesFreeRead-onlyList vulnerability-management scan schedules — the recurring definitions, not the runs they produce (use compassone_list_scans for runs).
compassone_run_scan_scheduleProWriteTrigger a scan schedule to run now, outside its normal recurrence.
compassone_update_scan_scheduleProWriteUpdate a vulnerability-management scan schedule by id.

[Blackpoint CompassOne] Create a recurring vulnerability-management scan schedule. Four fields are REQUIRED: type, time, frequency and name. Pass the object-typed config and frequencyConfig properties through fieldsJson — CompassOne types them as free-form objects, so they are not modelled as typed parameters here. For a one-off scan use compassone_create_scan instead. Returns the raw created scan-schedule JSON including its new id.

ParamTypeRequiredDefaultDescription
assetIdstringnonullAsset id the scheduled scans target (from the asset tools). Omit for an account-wide scan.
createdBystringnonullCreator attribution to record on the schedule. Omit to let CompassOne attribute it to the API token.
fieldsJsonstringnonullOptional JSON object of additional body fields, merged over the values above. This is how you supply the object-typed config and frequencyConfig properties, e.g. {"frequencyConfig":{"daysOfWeek":[1]},"config":}.
frequencystringyesREQUIRED recurrence. One of: daily, monthly, once, weekly.
namestringyesREQUIRED display name for the schedule.
timestringyesREQUIRED first/next run time as an ISO-8601 date-time (e.g. 2026-08-01T02:00:00Z).
typestringyesREQUIRED scan type. One of: darkweb, external, local, network.
updatedBystringnonullUpdater attribution to record on the schedule. Omit to let CompassOne attribute it to the API token.

[Blackpoint CompassOne] Delete a vulnerability-management scan schedule by id. The id parameter is REQUIRED. Destructive — the schedule is removed and all of its future runs stop. To pause a schedule reversibly instead, set status to disabled via compassone_update_scan_schedule. Returns the raw CompassOne response.

ParamTypeRequiredDefaultDescription
idstringyesREQUIRED scan-schedule id to delete (from compassone_list_scan_schedules).

[Blackpoint CompassOne] Get a single vulnerability-management scan schedule by id, including its type, frequency, next run time and status. The id parameter is REQUIRED. Set withScansCount to true to have CompassOne also report how many scans this schedule has produced. Use compassone_list_scan_schedules to discover ids. Returns the raw scan-schedule JSON.

ParamTypeRequiredDefaultDescription
idstringyesREQUIRED scan-schedule id (ScanScheduleTypeID, from compassone_list_scan_schedules).
withScansCountbooleannonullWhen true, include the number of scans this schedule has produced. Omit for CompassOne's default (count not returned).

[Blackpoint CompassOne] List vulnerability-management scan schedules — the recurring definitions, not the runs they produce (use compassone_list_scans for runs). Every parameter is optional. Page-based paging (pageSize max 1000). Returned ids feed compassone_get_scan_schedule, compassone_update_scan_schedule, compassone_run_scan_schedule and compassone_delete_scan_schedule. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
assetIdstringnonullComma-separated asset ids — limits results to schedules for those assets. Omit for all assets.
pageintegerno11-based page number (default 1).
pageSizeintegerno50Results per page (default 50, max 1000).
searchstringnonullCase-insensitive search term matched across all text fields. Omit for no text filter.
sortBystringnonullSort field. One of: id, accountId, createdBy, createdOn, tenantId, deletedBy, deletedOn, updatedBy, updatedOn, type, assetId. Omit for CompassOne's default ordering.
sortOrderstringnonullSort direction: ASC or DESC. Omit for CompassOne's default direction.
typestringnonullComma-separated scan types to include. Values: darkweb, external, local, network. Omit for all types.
withDeletedbooleannonullInclude soft-deleted scan schedules when true (default false).

[Blackpoint CompassOne] Trigger a scan schedule to run now, outside its normal recurrence. The id parameter is REQUIRED and there is no request body. This starts a real scan against the schedule's configured target, so it consumes scanning capacity; the resulting run then appears in compassone_list_scans and can be aborted with compassone_cancel_scan. Returns the raw CompassOne response.

ParamTypeRequiredDefaultDescription
idstringyesREQUIRED scan-schedule id to run (ScanScheduleTypeID, from compassone_list_scan_schedules).

[Blackpoint CompassOne] Update a vulnerability-management scan schedule by id. The id parameter is REQUIRED; every field is optional — supply only what changes. Set status to disabled to pause a schedule without deleting it. Pass the object-typed config and frequencyConfig properties through fieldsJson. Use compassone_bulk_update_scan_schedules to change status on many schedules at once. Returns the raw updated scan-schedule JSON.

ParamTypeRequiredDefaultDescription
assetIdstringnonullNew target asset id. Omit to leave unchanged.
fieldsJsonstringnonullOptional JSON object of additional body fields, merged over the values above. This is how you supply the object-typed config and frequencyConfig properties, e.g. {"frequencyConfig":{"daysOfWeek":[1]}}.
frequencystringnonullNew recurrence. One of: daily, monthly, once, weekly. Omit to leave unchanged.
idstringyesREQUIRED scan-schedule id to update (from compassone_list_scan_schedules).
namestringnonullNew display name. Omit to leave unchanged.
statusstringnonullNew status. One of: active, completed, disabled. Omit to leave unchanged.
timestringnonullNew next run time as an ISO-8601 date-time (e.g. 2026-08-01T02:00:00Z). Omit to leave unchanged.
updatedBystringnonullUpdater attribution to record on the schedule. Omit to let CompassOne attribute it to the API token.

Exposures

ToolPlanAccessSummary
compassone_get_darkweb_report_urlFreeRead-onlyGet a signed download URL for the most recent dark-web scan report.
compassone_get_darkweb_scan_exposuresFreeRead-onlyList the credential exposures found by the MOST RECENT dark-web scan — there is no scan-id parameter; CompassOne always reports the latest scan.
compassone_get_external_scan_exposuresFreeRead-onlyGet the exposures found by one external attack-surface scan, as JSON.
compassone_get_external_scan_report_urlFreeRead-onlyGet a signed download URL for one external scan's PDF report.

[Blackpoint CompassOne] Get a signed download URL for the most recent dark-web scan report. Takes no parameters. This returns the URL as a JSON string, NOT the PDF bytes — fetch the URL separately to download the file. For the same findings as structured data use compassone_get_darkweb_scan_exposures. Returns the raw CompassOne JSON.

[Blackpoint CompassOne] List the credential exposures found by the MOST RECENT dark-web scan — there is no scan-id parameter; CompassOne always reports the latest scan. Filter by whether the password or username was exposed, and by impacted domain. Page-based paging (pageSize max 1000). For a shareable PDF use compassone_get_darkweb_report_url. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
domainstringnonullLimit to exposures impacting this domain. Omit for all domains.
pageintegerno11-based page number (default 1).
pageSizeintegerno50Results per page (default 50, max 1000).
passwordExposedbooleannonullLimit to exposures where the password was exposed when true.
searchstringnonullCase-insensitive search term matched across all text fields. Omit for no text filter.
sortBystringnonullSort field. One of: breachCreatedAt, password, username, impactedDomain, breachName. Omit for CompassOne's default ordering.
sortOrderstringnonullSort direction: ASC or DESC. Omit for CompassOne's default direction.
usernameExposedbooleannonullLimit to exposures where the username was exposed when true.

[Blackpoint CompassOne] Get the exposures found by one external attack-surface scan, as JSON. Takes the external scan id — find scans with compassone_list_scans (filter type=external). For a shareable PDF of the same scan use compassone_get_external_scan_report_url. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
idstringyesThe external scan id (from compassone_list_scans with type=external).

[Blackpoint CompassOne] Get a signed download URL for one external scan's PDF report. This returns the URL as a JSON string, NOT the PDF bytes — fetch the URL separately to download the file. For the same findings as structured data use compassone_get_external_scan_exposures. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
idstringyesThe external scan id (from compassone_list_scans with type=external).

Email Channels

ToolPlanAccessSummary
compassone_create_email_channelProWriteCreate an email notification channel.
compassone_delete_email_channelProDestructiveSoft-delete an email notification channel by id (from compassone_list_email_channels).
compassone_duplicate_email_channelProWriteDuplicate an email notification channel by id (from compassone_list_email_channels), copying its recipients and settings under a new name.
compassone_get_email_channelFreeRead-onlyGet a single email notification channel by id (from compassone_list_email_channels).
compassone_list_email_channelsFreeRead-onlySearch email notification channels.
compassone_test_email_channelProWriteSend a test email through an email notification channel by id (from compassone_list_email_channels).
compassone_update_email_channelProWriteUpdate an email notification channel by id (from compassone_list_email_channels).

[Blackpoint CompassOne] Create an email notification channel. All four of name, emails, enabled and accountId are REQUIRED by CompassOne; tenantId is optional and scopes the channel to one end customer. Returns the raw created channel JSON including its new id.

ParamTypeRequiredDefaultDescription
accountIdstringyesREQUIRED CompassOne account id that owns the channel.
emailsstringyesREQUIRED comma-separated list of recipient email addresses. Sent as a JSON array.
enabledbooleanyesREQUIRED. True to deliver notifications through this channel immediately, false to create it dormant.
fieldsJsonstringnonullOptional JSON object of additional body fields, merged over the values above.
namestringyesREQUIRED display name for the channel.
tenantIdstringnonullOptional CompassOne end-customer tenant id to scope the channel to (from compassone_list_tenants). This is CompassOne's customer scoping, NOT your StackJack tenant.

[Blackpoint CompassOne] Soft-delete an email notification channel by id (from compassone_list_email_channels). Destructive — every notification currently routed through this channel stops being emailed. Returns the raw CompassOne response.

ParamTypeRequiredDefaultDescription
idstringyesREQUIRED email channel id to delete (from compassone_list_email_channels).

[Blackpoint CompassOne] Duplicate an email notification channel by id (from compassone_list_email_channels), copying its recipients and settings under a new name. The name parameter is REQUIRED. Returns the raw new channel JSON including its new id.

ParamTypeRequiredDefaultDescription
fieldsJsonstringnonullOptional JSON object of additional body fields, merged over the name above.
idstringyesREQUIRED email channel id to copy (from compassone_list_email_channels).
namestringyesREQUIRED display name for the new copy.

[Blackpoint CompassOne] Get a single email notification channel by id (from compassone_list_email_channels). Returns the raw channel JSON including its recipient list, enabled flag and owning account/tenant.

ParamTypeRequiredDefaultDescription
idstringyesREQUIRED email channel id (from compassone_list_email_channels).

[Blackpoint CompassOne] Search email notification channels. This is a READ that does not modify anything — CompassOne exposes it as a POST only because the accountId/tenantId scoping travels in the request body while paging, sorting and filtering travel as query params. No parameter is required; omit them all to list every channel the token can see. Page-based paging (pageSize max 1000). Use compassone_get_email_channel for one channel's detail; the returned id is what compassone_update_email_channel, compassone_delete_email_channel, compassone_duplicate_email_channel and compassone_test_email_channel take. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
accountIdstringnonullScope the search to one CompassOne account id (request-body scoping). Omit for every account the token can see.
createdstringnonullFilter by creation timestamp. Omit for no creation-date filter.
emailsstringnonullComma-separated list of email addresses to filter by — returns channels that deliver to any of them. Sent as repeated query params, not comma-joined.
enabledbooleannonullFilter to enabled (true) or disabled (false) channels only. Omit for both.
fieldsJsonstringnonullOptional JSON object of additional request-body fields, merged over accountId/tenantId above.
pageintegerno11-based page number (default 1).
pageSizeintegerno50Results per page (default 50, max 1000).
searchstringnonullCase-insensitive search term matched across the channel's text fields. Omit for no text filter.
sortBystringnonullSort field. One of: id, name, enabled, accountId, tenantId, created, updated. Omit for CompassOne's default ordering.
sortOrderstringnonullSort direction: ASC or DESC. Omit for CompassOne's default direction.
tenantIdstringnonullScope the search to one CompassOne end-customer tenant id (request-body scoping; from compassone_list_tenants). This is CompassOne's customer scoping, NOT your StackJack tenant. Omit for every tenant the token can see.
updatedstringnonullFilter by last-update timestamp. Omit for no update-date filter.

[Blackpoint CompassOne] Send a test email through an email notification channel by id (from compassone_list_email_channels). This really delivers mail to every recipient configured on the channel, so it is a write rather than a read, but it changes no configuration. Takes no body beyond the id. Returns the raw CompassOne response.

ParamTypeRequiredDefaultDescription
idstringyesREQUIRED email channel id to send the test through (from compassone_list_email_channels).

[Blackpoint CompassOne] Update an email notification channel by id (from compassone_list_email_channels). Every field is optional — supply only what changes. Editable: name, emails, enabled. Supplying emails REPLACES the whole recipient list rather than appending to it. Returns the raw updated channel JSON.

ParamTypeRequiredDefaultDescription
emailsstringnonullNew comma-separated list of recipient email addresses. REPLACES the existing list entirely. Omit to leave unchanged.
enabledbooleannonullNew enabled state: true to deliver, false to silence this channel. Omit to leave unchanged.
fieldsJsonstringnonullOptional JSON object of additional body fields, merged over the values above.
idstringyesREQUIRED email channel id to update (from compassone_list_email_channels).
namestringnonullNew display name. Omit to leave unchanged.

Webhook Channels

ToolPlanAccessSummary
compassone_create_webhook_channelProWriteCreate a webhook notification channel.
compassone_delete_webhook_channelProDestructiveSoft-delete a webhook notification channel by id (from compassone_list_webhook_channels).
compassone_duplicate_webhook_channelProWriteDuplicate a webhook notification channel by id (from compassone_list_webhook_channels), copying its url, headers and settings under a new name.
compassone_get_webhook_channelFreeRead-onlyGet a single webhook notification channel by id (from compassone_list_webhook_channels).
compassone_list_webhook_channelsFreeRead-onlySearch webhook notification channels.
compassone_test_webhook_channelProWriteSend a test notification through a webhook notification channel by id (from compassone_list_webhook_channels).
compassone_update_webhook_channelProWriteUpdate a webhook notification channel by id (from compassone_list_webhook_channels).

[Blackpoint CompassOne] Create a webhook notification channel. Six fields are REQUIRED by CompassOne: name, enabled, accountId, url, apiSecretNameHeader and headers. tenantId is optional and scopes the channel to one end customer. Returns the raw created channel JSON including its new id.

ParamTypeRequiredDefaultDescription
accountIdstringyesREQUIRED CompassOne account id that owns the channel.
apiSecretNameHeaderstringyesREQUIRED name of the HTTP header that carries the shared API secret on each delivery (the header NAME, not its value).
enabledbooleanyesREQUIRED. True to deliver notifications through this channel immediately, false to create it dormant.
fieldsJsonstringnonullOptional JSON object of additional body fields, merged over the values above.
headersJsonstringyesREQUIRED JSON object of custom HTTP headers to send with each delivery, e.g. {"X-Source":"CompassOne"}. Pass for none.
namestringyesREQUIRED display name for the channel.
tenantIdstringnonullOptional CompassOne end-customer tenant id to scope the channel to (from compassone_list_tenants). This is CompassOne's customer scoping, NOT your StackJack tenant.
urlstringyesREQUIRED destination URL CompassOne POSTs each notification to.

[Blackpoint CompassOne] Soft-delete a webhook notification channel by id (from compassone_list_webhook_channels). Destructive — every notification currently routed through this channel stops being delivered to its endpoint. Returns the raw CompassOne response.

ParamTypeRequiredDefaultDescription
idstringyesREQUIRED webhook channel id to delete (from compassone_list_webhook_channels).

[Blackpoint CompassOne] Duplicate a webhook notification channel by id (from compassone_list_webhook_channels), copying its url, headers and settings under a new name. The name parameter is REQUIRED. Returns the raw new channel JSON including its new id.

ParamTypeRequiredDefaultDescription
fieldsJsonstringnonullOptional JSON object of additional body fields, merged over the name above.
idstringyesREQUIRED webhook channel id to copy (from compassone_list_webhook_channels).
namestringyesREQUIRED display name for the new copy.

[Blackpoint CompassOne] Get a single webhook notification channel by id (from compassone_list_webhook_channels). Returns the raw channel JSON including its target url, custom headers, enabled flag and owning account/tenant.

ParamTypeRequiredDefaultDescription
idstringyesREQUIRED webhook channel id (from compassone_list_webhook_channels).

[Blackpoint CompassOne] Search webhook notification channels. This is a READ that does not modify anything — CompassOne exposes it as a POST only because the accountId/tenantId scoping travels in the request body while paging, sorting and filtering travel as query params. No parameter is required; omit them all to list every channel the token can see. Page-based paging (pageSize max 1000). Use compassone_get_webhook_channel for one channel's detail; the returned id is what compassone_update_webhook_channel, compassone_delete_webhook_channel, compassone_duplicate_webhook_channel and compassone_test_webhook_channel take. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
accountIdstringnonullScope the search to one CompassOne account id (request-body scoping). Omit for every account the token can see.
createdstringnonullFilter by creation timestamp. Omit for no creation-date filter.
enabledbooleannonullFilter to enabled (true) or disabled (false) channels only. Omit for both.
fieldsJsonstringnonullOptional JSON object of additional request-body fields, merged over accountId/tenantId above.
pageintegerno11-based page number (default 1).
pageSizeintegerno50Results per page (default 50, max 1000).
searchstringnonullCase-insensitive search term matched across the channel's text fields. Omit for no text filter.
sortBystringnonullSort field. One of: id, name, enabled, accountId, tenantId, created, updated. Omit for CompassOne's default ordering.
sortOrderstringnonullSort direction: ASC or DESC. Omit for CompassOne's default direction.
tenantIdstringnonullScope the search to one CompassOne end-customer tenant id (request-body scoping; from compassone_list_tenants). This is CompassOne's customer scoping, NOT your StackJack tenant. Omit for every tenant the token can see.
updatedstringnonullFilter by last-update timestamp. Omit for no update-date filter.

[Blackpoint CompassOne] Send a test notification through a webhook notification channel by id (from compassone_list_webhook_channels). This really POSTs to the channel's configured url, so it is a write rather than a read, but it changes no configuration. Takes no body beyond the id. Returns the raw CompassOne response.

ParamTypeRequiredDefaultDescription
idstringyesREQUIRED webhook channel id to send the test through (from compassone_list_webhook_channels).

[Blackpoint CompassOne] Update a webhook notification channel by id (from compassone_list_webhook_channels). Every field is optional — supply only what changes. Editable: name, enabled, url, apiSecretNameHeader, headers. Supplying headers REPLACES the whole header object rather than merging into it. Returns the raw updated channel JSON.

ParamTypeRequiredDefaultDescription
apiSecretNameHeaderstringnonullNew name of the HTTP header that carries the shared API secret (the header NAME, not its value). Omit to leave unchanged.
enabledbooleannonullNew enabled state: true to deliver, false to silence this channel. Omit to leave unchanged.
fieldsJsonstringnonullOptional JSON object of additional body fields, merged over the values above.
headersJsonstringnonullNew JSON object of custom HTTP headers, e.g. {"X-Source":"CompassOne"}. REPLACES the existing header object entirely. Omit to leave unchanged.
idstringyesREQUIRED webhook channel id to update (from compassone_list_webhook_channels).
namestringnonullNew display name. Omit to leave unchanged.
urlstringnonullNew destination URL CompassOne POSTs each notification to. Omit to leave unchanged.

Notification Routing

ToolPlanAccessSummary
compassone_block_notification_tenantProDestructiveBlock one CompassOne tenant from receiving one notification type.
compassone_check_notification_blocklistFreeRead-onlyCheck whether one CompassOne tenant is currently blocked from receiving one notification type.
compassone_list_notification_channelsFreeRead-onlySearch notification channels of every type (email and webhook together) in one call.
compassone_unblock_notification_tenantProDestructiveUnblock one CompassOne tenant for one notification type, restoring delivery of that type.

[Blackpoint CompassOne] Block one CompassOne tenant from receiving one notification type. BOTH emailType and tenantId are REQUIRED. Destructive — this suppresses that entire class of notification for that customer for as long as the block stands, so blocking a security type such as DarkWebAlertNotification silences those alerts outright. Check the current state first with compassone_check_notification_blocklist, and reverse with compassone_unblock_notification_tenant. Returns the raw CompassOne response.

ParamTypeRequiredDefaultDescription
emailTypestringyesREQUIRED notification type to suppress. One of: AccountDeprovisionFailedNotification, AccountInviteNotification, AccountVendorChangeRequestNotification, BillingBiReportBlackpointNotification, BillingBiReportWebrootNotification, BillingExceptionReportNotification, BillingWarningNotification, CiscoDuoNotification, CloudResponseNotification, CompassOnePax8TenantCreatedOrConvertedPaid, CompassOneTenantCreatedOrConvertedPaid, CompassOneTenantCreatedOrConvertedPaidBlackpointInternal, CompassOneUserInviteNotification, CompassOneUserResetPasswordNotification, CompassOneWebrootTenantCreatedOrConvertedPaid, ConnectWiseCustomerAgreementDeletedNotification, ConnectWiseCustomerDeletedNotification, ConnectWiseProductDeletedNotification, CustomerCreatedOrConvertedPaid, CustomerCreatedOrConvertedPaidBlackpointInternal, DarkWebAlertNotification, MS365DefenseNewPermsNotification, MS365DefenseNotification, MS365DefensePackageDeletedNotification, MdeNewPermsNotification, MdrReportToDirectNotification, MdrReportToPartnerCustomerNotification, MdrReportToPartnerNotification, PackageHealthStatus, Pax8CustomerCreatedOrConvertedPaid, PerformedActionNotification, ResetPasswordNotification, TestNotification, UsageExceededNotification, UsageReportNotification, UserInviteNotification, VulnMgmtScanCompletedNotification, WebrootCustomerCreatedOrConvertedPaid, ZtacNotification.
fieldsJsonstringnonullOptional JSON object of additional body fields, merged over the values above.
tenantIdstringyesREQUIRED CompassOne end-customer tenant id to block (from compassone_list_tenants). This is CompassOne's customer scoping, NOT your StackJack tenant.

[Blackpoint CompassOne] Check whether one CompassOne tenant is currently blocked from receiving one notification type. BOTH emailType and tenantId are REQUIRED. Use this before compassone_block_notification_tenant or compassone_unblock_notification_tenant to confirm the current state. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
emailTypestringyesREQUIRED notification type to check. One of: AccountDeprovisionFailedNotification, AccountInviteNotification, AccountVendorChangeRequestNotification, BillingBiReportBlackpointNotification, BillingBiReportWebrootNotification, BillingExceptionReportNotification, BillingWarningNotification, CiscoDuoNotification, CloudResponseNotification, CompassOnePax8TenantCreatedOrConvertedPaid, CompassOneTenantCreatedOrConvertedPaid, CompassOneTenantCreatedOrConvertedPaidBlackpointInternal, CompassOneUserInviteNotification, CompassOneUserResetPasswordNotification, CompassOneWebrootTenantCreatedOrConvertedPaid, ConnectWiseCustomerAgreementDeletedNotification, ConnectWiseCustomerDeletedNotification, ConnectWiseProductDeletedNotification, CustomerCreatedOrConvertedPaid, CustomerCreatedOrConvertedPaidBlackpointInternal, DarkWebAlertNotification, MS365DefenseNewPermsNotification, MS365DefenseNotification, MS365DefensePackageDeletedNotification, MdeNewPermsNotification, MdrReportToDirectNotification, MdrReportToPartnerCustomerNotification, MdrReportToPartnerNotification, PackageHealthStatus, Pax8CustomerCreatedOrConvertedPaid, PerformedActionNotification, ResetPasswordNotification, TestNotification, UsageExceededNotification, UsageReportNotification, UserInviteNotification, VulnMgmtScanCompletedNotification, WebrootCustomerCreatedOrConvertedPaid, ZtacNotification.
tenantIdstringyesREQUIRED CompassOne end-customer tenant id to check (from compassone_list_tenants). This is CompassOne's customer scoping, NOT your StackJack tenant.

[Blackpoint CompassOne] Search notification channels of every type (email and webhook together) in one call. This is a READ that does not modify anything — CompassOne exposes it as a POST only because the accountId/tenantId scoping travels in the request body while paging, sorting and filtering travel as query params. No parameter is required; omit them all to list every channel the token can see. Page-based paging (pageSize max 1000). For type-specific detail and editing use compassone_get_email_channel / compassone_get_webhook_channel. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
accountIdstringnonullScope the search to one CompassOne account id (request-body scoping). Omit for every account the token can see.
createdstringnonullFilter by creation timestamp. Omit for no creation-date filter.
enabledbooleannonullFilter to enabled (true) or disabled (false) channels only. Omit for both.
fieldsJsonstringnonullOptional JSON object of additional request-body fields, merged over accountId/tenantId above.
pageintegerno11-based page number (default 1).
pageSizeintegerno50Results per page (default 50, max 1000).
searchstringnonullCase-insensitive search term matched across the channel's text fields. Omit for no text filter.
sortBystringnonullSort field. One of: id, name, enabled, accountId, tenantId, created, updated, type. Omit for CompassOne's default ordering.
sortOrderstringnonullSort direction: ASC or DESC. Omit for CompassOne's default direction.
tenantIdstringnonullScope the search to one CompassOne end-customer tenant id (request-body scoping; from compassone_list_tenants). This is CompassOne's customer scoping, NOT your StackJack tenant. Omit for every tenant the token can see.
typestringnonullFilter to one channel type. CompassOne types this as a free-form string and publishes no fixed value list — use a type value as returned in this tool's own results. Omit for all types.
updatedstringnonullFilter by last-update timestamp. Omit for no update-date filter.

[Blackpoint CompassOne] Unblock one CompassOne tenant for one notification type, restoring delivery of that type. BOTH emailType and tenantId are REQUIRED, and are sent as a request body on the DELETE. Flagged destructive because it changes notification routing for a customer — it restores rather than removes delivery, so the flag errs deliberately toward prompting. Check the current state first with compassone_check_notification_blocklist. Returns the raw CompassOne response.

ParamTypeRequiredDefaultDescription
emailTypestringyesREQUIRED notification type to restore. One of: AccountDeprovisionFailedNotification, AccountInviteNotification, AccountVendorChangeRequestNotification, BillingBiReportBlackpointNotification, BillingBiReportWebrootNotification, BillingExceptionReportNotification, BillingWarningNotification, CiscoDuoNotification, CloudResponseNotification, CompassOnePax8TenantCreatedOrConvertedPaid, CompassOneTenantCreatedOrConvertedPaid, CompassOneTenantCreatedOrConvertedPaidBlackpointInternal, CompassOneUserInviteNotification, CompassOneUserResetPasswordNotification, CompassOneWebrootTenantCreatedOrConvertedPaid, ConnectWiseCustomerAgreementDeletedNotification, ConnectWiseCustomerDeletedNotification, ConnectWiseProductDeletedNotification, CustomerCreatedOrConvertedPaid, CustomerCreatedOrConvertedPaidBlackpointInternal, DarkWebAlertNotification, MS365DefenseNewPermsNotification, MS365DefenseNotification, MS365DefensePackageDeletedNotification, MdeNewPermsNotification, MdrReportToDirectNotification, MdrReportToPartnerCustomerNotification, MdrReportToPartnerNotification, PackageHealthStatus, Pax8CustomerCreatedOrConvertedPaid, PerformedActionNotification, ResetPasswordNotification, TestNotification, UsageExceededNotification, UsageReportNotification, UserInviteNotification, VulnMgmtScanCompletedNotification, WebrootCustomerCreatedOrConvertedPaid, ZtacNotification.
fieldsJsonstringnonullOptional JSON object of additional body fields, merged over the values above.
tenantIdstringyesREQUIRED CompassOne end-customer tenant id to unblock (from compassone_list_tenants). This is CompassOne's customer scoping, NOT your StackJack tenant.

Reports

ToolPlanAccessSummary
compassone_get_report_binaryFreeRead-onlyGet one report's PDF as a BASE64-ENCODED STRING INSIDE A JSON OBJECT — despite the name this is not a byte stream, and the payload can be large.
compassone_get_report_jsonFreeRead-onlyGet one report's structured data as JSON — the best choice when an agent needs to read or summarize report contents rather than hand a file to a human.
compassone_get_report_urlFreeRead-onlyGet a signed download URL for one report's PDF — the right choice for sharing a report with a person.
compassone_list_reportsFreeRead-onlyList the generated reports for the authenticated tenant, optionally filtered by type and interval-start date range.

[Blackpoint CompassOne] Get one report's PDF as a BASE64-ENCODED STRING INSIDE A JSON OBJECT — despite the name this is not a byte stream, and the payload can be large. Prefer compassone_get_report_url when a downloadable link will do, or compassone_get_report_json when you need the data rather than the document. Get the id from compassone_list_reports. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
idstringyesThe report id (from compassone_list_reports).
tenantIdstringnonullCompassOne tenant (end-customer) id, sent as the x-tenant-id header. CompassOne now REQUIRES this header on the report endpoints — requests without it are rejected upstream with 400. Discover ids with compassone_list_tenants.

[Blackpoint CompassOne] Get one report's structured data as JSON — the best choice when an agent needs to read or summarize report contents rather than hand a file to a human. Get the id from compassone_list_reports. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
idstringyesThe report id (from compassone_list_reports).
tenantIdstringnonullCompassOne tenant (end-customer) id, sent as the x-tenant-id header. CompassOne now REQUIRES this header on the report endpoints — requests without it are rejected upstream with 400. Discover ids with compassone_list_tenants.

[Blackpoint CompassOne] Get a signed download URL for one report's PDF — the right choice for sharing a report with a person. This returns the URL as JSON, NOT the PDF bytes; fetch the URL separately to download the file. Get the id from compassone_list_reports. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
idstringyesThe report id (from compassone_list_reports).
tenantIdstringnonullCompassOne tenant (end-customer) id, sent as the x-tenant-id header. CompassOne now REQUIRES this header on the report endpoints — requests without it are rejected upstream with 400. Discover ids with compassone_list_tenants.

[Blackpoint CompassOne] List the generated reports for the authenticated tenant, optionally filtered by type and interval-start date range. reportType is one of Cloud, Executive, MDR. Page-based paging (default pageSize 100, max 1000). Note this endpoint's sortOrder values are LOWERCASE (asc / desc), unlike the uppercase ASC / DESC used elsewhere in the CompassOne API. Use the returned id with compassone_get_report_json (data), compassone_get_report_url (shareable link) or compassone_get_report_binary (base64 PDF). Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
endDatestringnonullOnly reports whose intervalStart is on or before this ISO-8601 date. Omit for no upper bound.
pageintegerno11-based page number (default 1).
pageSizeintegerno100Results per page (default 100, max 1000).
reportTypestringnonullFilter by report type: Cloud, Executive or MDR. Omit for all types.
sortBystringnonullSort field. The only accepted value is intervalStart. Omit for CompassOne's default ordering.
sortOrderstringnonullSort order, LOWERCASE on this endpoint: asc or desc. Omit for CompassOne's default direction.
startDatestringnonullOnly reports whose intervalStart is on or after this ISO-8601 date. Omit for no lower bound.
tenantIdstringnonullCompassOne tenant (end-customer) id, sent as the x-tenant-id header. CompassOne now REQUIRES this header on the report endpoints — requests without it are rejected upstream with 400 'x-tenant-id header is required'. Discover ids with compassone_list_tenants.

Security Posture

ToolPlanAccessSummary
compassone_bulk_attest_metricsProDestructiveAttest one metric across many customers in a single call.
compassone_bulk_delete_metric_attestationsProDestructiveDelete one metric's attestations across many customers in a single call.
compassone_create_metric_attestationProDestructiveCreate a metric attestation, suppressing that metric's deduction from the Security Posture Rating.
compassone_delete_metric_attestationProDestructiveDelete a metric attestation by calculation id.
compassone_get_all_tenant_ratingsFreeRead-onlyGet the security posture rating for every tenant on the account, one row per tenant — the fleet-wide comparison view.
compassone_get_metric_attestationFreeRead-onlyGet one active metric attestation by the calculation id it is attached to.
compassone_get_rating_categoriesFreeRead-onlyGet the security posture rating broken out by Operational and NIST category — the per-category scores behind the single number returned by compassone_get_security_posture_rating.
compassone_get_rating_historyFreeRead-onlyGet the security posture rating history — the SPR trend over time.
compassone_get_security_posture_ratingFreeRead-onlyGet the most recent Security Posture Rating (SPR) with its calculation results.
compassone_list_attestable_metricsFreeRead-onlyList every active attestable metric calculation — the candidates you can attest with compassone_create_metric_attestation or compassone_bulk_attest_metrics.
compassone_list_metric_attestationsFreeRead-onlyList every active metric attestation for the tenant.

[Blackpoint CompassOne] Attest one metric across many customers in a single call. Both metricCalculationId (from compassone_list_attestable_metrics) and accountId (from compassone_list_accounts) are REQUIRED. Set applyToAllCustomers to true to cover every customer under the account; when it is false or omitted, supply the customerIds to target. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
accountIdstringyesREQUIRED UUID of the account the attestation applies under (from compassone_list_accounts).
applyToAllCustomersbooleannonullApply the attestation to every customer under the account when true. When false or omitted, customerIds is what selects the targets.
customerIdsstringnonullComma-separated customer ids to attest. Required when applyToAllCustomers is false or omitted; ignored when it is true.
expiresAtstringnonullOptional expiry as an ISO-8601 date-time (e.g. 2026-12-31T00:00:00Z). Omit for an attestation that does not auto-expire.
fieldsJsonstringnonullOptional JSON object of additional body fields, merged over the values above.
metricCalculationIdstringyesREQUIRED metric calculation id to attest (from compassone_list_attestable_metrics).
reasonstringnonullOptional justification text, max 1024 characters.

[Blackpoint CompassOne] Delete one metric's attestations across many customers in a single call. Destructive and broad — every targeted customer's suppression is removed and the metric starts deducting from their Security Posture Rating again. Both metricCalculationId and accountId (from compassone_list_accounts) are REQUIRED. Set applyToAllCustomers to true to clear every customer under the account; when it is false or omitted, customerIds is REQUIRED and selects the targets. Prefer compassone_delete_metric_attestation for a single tenant. Returns the raw CompassOne response.

ParamTypeRequiredDefaultDescription
accountIdstringyesREQUIRED UUID of the account the attestations live under (from compassone_list_accounts).
applyToAllCustomersbooleannonullDelete the attestation for every customer under the account when true. When false or omitted, customerIds is required and selects the targets.
customerIdsstringnonullComma-separated customer ids whose attestations to delete. Required when applyToAllCustomers is false or omitted; ignored when it is true.
fieldsJsonstringnonullOptional JSON object of additional body fields, merged over the values above.
metricCalculationIdstringyesREQUIRED metric calculation id whose attestations to delete (from compassone_list_metric_attestations).

[Blackpoint CompassOne] Create a metric attestation, suppressing that metric's deduction from the Security Posture Rating. metricCalculationId is REQUIRED (from compassone_list_attestable_metrics). Optionally set expiresAt so the attestation lapses automatically, and reason to record why. Use compassone_bulk_attest_metrics to attest one metric across many customers at once. Returns the raw created attestation JSON.

ParamTypeRequiredDefaultDescription
expiresAtstringnonullOptional expiry as an ISO-8601 date-time (e.g. 2026-12-31T00:00:00Z). Omit for an attestation that does not auto-expire.
fieldsJsonstringnonullOptional JSON object of additional body fields, merged over the values above.
metricCalculationIdstringyesREQUIRED metric calculation id to attest (from compassone_list_attestable_metrics).
reasonstringnonullOptional justification text, max 1024 characters.

[Blackpoint CompassOne] Delete a metric attestation by calculation id. Destructive — the suppression is removed and the metric starts deducting from the Security Posture Rating again. metricCalculationId is REQUIRED (note the sibling read tool spells the same value calculationId — that difference is CompassOne's). Returns the raw CompassOne response.

ParamTypeRequiredDefaultDescription
metricCalculationIdstringyesREQUIRED metric calculation id whose attestation to delete (from compassone_list_metric_attestations).

[Blackpoint CompassOne] Get the security posture rating for every tenant on the account, one row per tenant — the fleet-wide comparison view. Use compassone_get_security_posture_rating for the current tenant's own rating detail. Page-based paging (pageSize max 1000). Optionally restrict to specific tenants with tenantIds (ids from compassone_list_tenants). No parameter is required. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
pageintegerno11-based page number (default 1).
pageSizeintegerno50Results per page (default 50, max 1000).
sortBystringnonullSort field. One of: score, tenantId. Omit for CompassOne's default ordering.
sortOrderstringnonullSort direction: ASC or DESC. Omit for CompassOne's default direction.
tenantIdsstringnonullComma-separated tenant ids (from compassone_list_tenants) to restrict the results to. A single id is fine. Omit for every tenant on the account.

[Blackpoint CompassOne] Get one active metric attestation by the calculation id it is attached to. calculationId is REQUIRED (get calculation ids from compassone_list_attestable_metrics or compassone_list_metric_attestations). Note the sibling delete tool names the same value metricCalculationId — that spelling difference is CompassOne's, not a typo. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
calculationIdstringyesREQUIRED metric calculation id the attestation is attached to (from compassone_list_attestable_metrics or compassone_list_metric_attestations).

[Blackpoint CompassOne] Get the security posture rating broken out by Operational and NIST category — the per-category scores behind the single number returned by compassone_get_security_posture_rating. Takes no parameters. Returns the raw CompassOne JSON.

[Blackpoint CompassOne] Get the security posture rating history — the SPR trend over time. historyRange is REQUIRED and must be exactly one of: months_1, months_6, months_12. Use compassone_get_security_posture_rating for the current point-in-time rating. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
historyRangestringyesREQUIRED history window. Exactly one of: months_1, months_6, months_12.

[Blackpoint CompassOne] Get the most recent Security Posture Rating (SPR) with its calculation results. By default only metrics that deducted points are returned; set includeNonDeductions to true to also see the metrics that passed. Use compassone_get_rating_categories for the Operational/NIST category breakdown, compassone_get_rating_history for the trend, and compassone_get_all_tenant_ratings for every tenant at once. No parameter is required. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
includeNonDeductionsbooleannonullInclude non-deducted metrics in the SPR calculation results when true (default false).

[Blackpoint CompassOne] List every active attestable metric calculation — the candidates you can attest with compassone_create_metric_attestation or compassone_bulk_attest_metrics. Each entry's calculation id is the metricCalculationId those tools require. Takes no parameters. Returns the raw CompassOne JSON.

[Blackpoint CompassOne] List every active metric attestation for the tenant. An attestation suppresses a metric's deduction from the Security Posture Rating until it expires. Takes no parameters. Use compassone_list_attestable_metrics to see which metric calculations can be attested, and compassone_get_metric_attestation to look one up by calculation id. Returns the raw CompassOne JSON.

Accounts

ToolPlanAccessSummary
compassone_get_accountFreeRead-onlyGet one CompassOne account's full detail.
compassone_list_accountsFreeRead-onlyList CompassOne accounts (the partner/MSP-level records that own tenants).

[Blackpoint CompassOne] Get one CompassOne account's full detail. accountId is REQUIRED and is a path segment — get it from compassone_list_accounts. Set includeBranding to pull the account's branding block and includeLogo to pull its logo; both are omitted by default to keep the response small. Returns the raw account JSON.

ParamTypeRequiredDefaultDescription
accountIdstringyesREQUIRED UUID of the account to retrieve (from compassone_list_accounts).
includeBrandingbooleannonullInclude branding information in the response when true (default false).
includeLogobooleannonullInclude the logo in the response when true. Omit for CompassOne's default.

[Blackpoint CompassOne] List CompassOne accounts (the partner/MSP-level records that own tenants). START HERE for id discovery: the id of each account returned is the accountId that compassone_get_account, compassone_get_tenant, the user tools and the contact-group tools all take, and that compassone_list_tenants accepts as a filter. Page-based paging (pageSize max 1000). No parameter is required. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
billingVersionstringnonullFilter accounts with the given billing version. One of: 1, 2. Omit for no billing-version filter.
pageintegerno11-based page number of results to return (default 1).
pageSizeintegerno50Results per page (default 50, max 1000).
partnershipTypestringnonullFilter accounts with the given partnership type. One of: 1, 2. Omit for no partnership-type filter.
searchstringnonullSearch term matched against account id and name. Omit for no text filter.
sortBystringnonullSort field. One of: id, name, created, partnershipType, billingVersion. Omit for CompassOne's default ordering.
sortOrderstringnonullSort direction: ASC or DESC. Omit for CompassOne's default direction.

Tenants

ToolPlanAccessSummary
compassone_get_tenantFreeRead-onlyGet one CompassOne tenant's full detail.
compassone_list_tenantsFreeRead-onlyList CompassOne tenants (end customers).

[Blackpoint CompassOne] Get one CompassOne tenant's full detail. BOTH accountId and tenantId are REQUIRED and are path segments — accountId is the UUID of the account that owns the tenant (from compassone_list_accounts) and tenantId is the UUID of the tenant itself (from compassone_list_tenants, which also reports each tenant's account). Returns the raw tenant JSON.

ParamTypeRequiredDefaultDescription
accountIdstringyesREQUIRED UUID of the account that owns the tenant (from compassone_list_accounts).
tenantIdstringyesREQUIRED UUID of the tenant to retrieve (from compassone_list_tenants).

[Blackpoint CompassOne] List CompassOne tenants (end customers). START HERE for id discovery: the id of each tenant returned is the tenantId that every CompassOne cloud-* tool requires (compassone_list_cloud_* / compassone_get_cloud_* and the Microsoft 365, Google Workspace and Cisco Duo Cloud MDR tools). Optionally narrow to one account with accountId (from compassone_list_accounts). Page-based paging (pageSize max 1000). No parameter is required. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
accountIdstringnonullFilter tenants by the UUID of the associated account (from compassone_list_accounts). Omit to list tenants across every account the token can see.
pageintegerno11-based page number of results to return (default 1).
pageSizeintegerno50Results per page (default 50, max 1000).
searchstringnonullSearch term matched against tenant id and name. Omit for no text filter.
sortBystringnonullSort field. One of: id, name, created, type, description, domain. Omit for CompassOne's default ordering.
sortOrderstringnonullSort direction: ASC or DESC. Omit for CompassOne's default direction.

Users

ToolPlanAccessSummary
compassone_assign_users_to_tenantProWriteAssign one or more existing users to a tenant, granting them access to that tenant's data.
compassone_delete_account_userProDestructiveDelete a user FROM ONE ACCOUNT — the user must have been created under that account.
compassone_delete_userProDestructiveDelete a user OUTRIGHT by user id — the broadest of the three CompassOne user removals and not undoable: the user record itself is removed, along with every account and tenant assignment it had.
compassone_invite_user_to_accountProWriteInvite a user to an account.
compassone_list_account_usersFreeRead-onlyList every user with access to one account AND to that account's tenants.
compassone_list_tenant_usersFreeRead-onlyList the users that ARE assigned to one tenant.
compassone_list_unassigned_tenant_usersFreeRead-onlyList the tenant users that are NOT assigned to the given tenant — the candidate pool for compassone_assign_users_to_tenant.
compassone_list_usersFreeRead-onlyList every user visible to the CompassOne token, across all accounts it can see.
compassone_reset_user_passwordProDestructiveSend a password-reset email to one user.
compassone_unassign_users_from_tenantProDestructiveUnassign one or more users FROM ONE TENANT — the mildest of the three CompassOne user removals: the user accounts survive and keep every other tenant assignment, they simply lose access to this…
compassone_update_account_userProDestructiveUpdate another account user's name, RBAC roles and tenant assignments.

[Blackpoint CompassOne] Assign one or more existing users to a tenant, granting them access to that tenant's data. accountId and tenantId are REQUIRED path parameters; userIds is a REQUIRED list of 1 to 200 user UUIDs. Get candidates from compassone_list_unassigned_tenant_users. The inverse is compassone_unassign_users_from_tenant. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
accountIdstringyesREQUIRED. The UUID of the account that owns the tenant (from compassone_list_accounts).
fieldsJsonstringnonullOptional JSON object of additional body fields, merged over the values above.
tenantIdstringyesREQUIRED. The UUID of the tenant to which the users will be assigned (from compassone_list_tenants).
userIdsstringyesREQUIRED comma-separated user UUIDs to assign (from compassone_list_unassigned_tenant_users). At least 1 and at most 200 values.

[Blackpoint CompassOne] Delete a user FROM ONE ACCOUNT — the user must have been created under that account. Destructive and not undoable. This is the middle of the three CompassOne user removals: compassone_unassign_users_from_tenant only revokes one tenant's access, while compassone_delete_user removes the user record outright regardless of account. Both accountId and userId are REQUIRED path parameters. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
accountIdstringyesREQUIRED. The UUID of the account which created the user (from compassone_list_accounts).
userIdstringyesREQUIRED. The UUID of the user to delete; the user must have been created from the given account (from compassone_list_account_users).

[Blackpoint CompassOne] Delete a user OUTRIGHT by user id — the broadest of the three CompassOne user removals and not undoable: the user record itself is removed, along with every account and tenant assignment it had. Prefer compassone_delete_account_user to remove them from a single account, or compassone_unassign_users_from_tenant to revoke only one tenant's access. userId is REQUIRED (from compassone_list_users). Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
userIdstringyesREQUIRED. The UUID of the user to delete (from compassone_list_users).

[Blackpoint CompassOne] Invite a user to an account. accountId is REQUIRED (from compassone_list_accounts); name and email are REQUIRED body fields. Optionally grant RBAC roles and assign the invitee to tenants up front. CompassOne emails the invitation. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
accountIdstringyesREQUIRED. The UUID of the account to invite the user into (from compassone_list_accounts).
emailstringyesREQUIRED. The invitee's email address — the invitation is sent here.
fieldsJsonstringnonullOptional JSON object of additional body fields, merged over the values above.
namestringyesREQUIRED. The full name of the person being invited.
rolesstringnonullComma-separated RBAC roles to grant. Each value must be one of: AccountAdmin, AccountBillingAbility, AccountUser, BlackpointAdmin, BlackpointSuperAdmin, BlackpointUser, CustomerAdmin, CustomerUser. Omit to let CompassOne apply its default role; if supplied, supply at least one value.
tenantIdsToAssignstringnonullComma-separated tenant UUIDs to assign the invitee to (from compassone_list_tenants). Omit to assign no tenants; if supplied, supply at least one value.

[Blackpoint CompassOne] List every user with access to one account AND to that account's tenants. accountId is REQUIRED (from compassone_list_accounts). Page-based paging (pageSize max 1000). For the narrower per-tenant roster use compassone_list_tenant_users. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
accountIdstringyesREQUIRED. The UUID of the account whose users are being listed (from compassone_list_accounts).
pageintegerno11-based page number (default 1).
pageSizeintegerno50Results per page (default 50, max 1000).
searchstringnonullSearch term matched against user id, email, name or nickname. Omit for no text filter.
sortBystringnonullSort field. One of: email, name, role, billingAbility. Omit for CompassOne's default ordering.
sortOrderstringnonullSort direction: ASC or DESC. Omit for CompassOne's default direction.

[Blackpoint CompassOne] List the users that ARE assigned to one tenant. Both accountId (REQUIRED, from compassone_list_accounts) and tenantId (REQUIRED, from compassone_list_tenants) are path parameters. This is the assigned half of a pair — for the users of the account that are NOT yet assigned to this tenant, use compassone_list_unassigned_tenant_users. Page-based paging (pageSize max 1000). Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
accountIdstringyesREQUIRED. The UUID of the account that owns the tenant (from compassone_list_accounts).
pageintegerno11-based page number (default 1).
pageSizeintegerno50Results per page (default 50, max 1000).
searchstringnonullSearch term matched against user id, email, name or nickname. Omit for no text filter.
sortBystringnonullSort field. One of: email, name, role, billingAbility. Omit for CompassOne's default ordering.
sortOrderstringnonullSort direction: ASC or DESC. Omit for CompassOne's default direction.
tenantIdstringyesREQUIRED. The UUID of the tenant whose users are being listed (from compassone_list_tenants).

[Blackpoint CompassOne] List the tenant users that are NOT assigned to the given tenant — the candidate pool for compassone_assign_users_to_tenant. Both accountId (REQUIRED, from compassone_list_accounts) and tenantId (REQUIRED, from compassone_list_tenants) are path parameters. This is the unassigned half of a pair: compassone_list_tenant_users returns the users that ARE assigned. Page-based paging (pageSize max 1000). Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
accountIdstringyesREQUIRED. The UUID of the account that owns the tenant (from compassone_list_accounts).
pageintegerno11-based page number (default 1).
pageSizeintegerno50Results per page (default 50, max 1000).
searchstringnonullSearch term matched against user id, email, name or nickname. Omit for no text filter.
sortBystringnonullSort field. One of: email, name, role, billingAbility. Omit for CompassOne's default ordering.
sortOrderstringnonullSort direction: ASC or DESC. Omit for CompassOne's default direction.
tenantIdstringyesREQUIRED. The UUID of the tenant for which to retrieve unassigned users (from compassone_list_tenants).

[Blackpoint CompassOne] List every user visible to the CompassOne token, across all accounts it can see. Page-based paging (pageSize max 1000). Use compassone_list_account_users to scope to one account, or compassone_list_tenant_users to scope to one tenant. The returned user id is what compassone_delete_user, compassone_reset_user_password and compassone_update_account_user take. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
pageintegerno11-based page number (default 1).
pageSizeintegerno50Results per page (default 50, max 1000).
searchstringnonullSearch term matched against user id, email, name or nickname. Omit for no text filter.
sortBystringnonullSort field. One of: email, name, role, billingAbility. Omit for CompassOne's default ordering.
sortOrderstringnonullSort direction: ASC or DESC. Omit for CompassOne's default direction.

[Blackpoint CompassOne] Send a password-reset email to one user. Marked destructive even though it is a POST with no body: it invalidates the user's live credential, so the user cannot sign in until they complete the emailed reset, and the action cannot be undone. userId is REQUIRED (from compassone_list_users). Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
userIdstringyesREQUIRED. The UUID of the user whose password will be reset (from compassone_list_users).

[Blackpoint CompassOne] Unassign one or more users FROM ONE TENANT — the mildest of the three CompassOne user removals: the user accounts survive and keep every other tenant assignment, they simply lose access to this tenant's data. Compare compassone_delete_account_user (removes the user from one account) and compassone_delete_user (deletes the user outright). accountId and tenantId are REQUIRED path parameters; userIds is a REQUIRED list of 1 to 200 user UUIDs (from compassone_list_tenant_users). Destructive — sent as a DELETE with a JSON body. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
accountIdstringyesREQUIRED. The UUID of the account that owns the tenant (from compassone_list_accounts).
fieldsJsonstringnonullOptional JSON object of additional body fields, merged over the values above.
tenantIdstringyesREQUIRED. The UUID of the tenant from which the users will be unassigned (from compassone_list_tenants).
userIdsstringyesREQUIRED comma-separated user UUIDs to unassign (from compassone_list_tenant_users). At least 1 and at most 200 values.

[Blackpoint CompassOne] Update another account user's name, RBAC roles and tenant assignments. accountId and userId are REQUIRED path parameters; CompassOne requires all three body fields (name, roles, tenantIdsToAssign) on every call, so both lists are full REPLACEMENTS of the user's current roles and tenant assignments — read the user first with compassone_list_account_users and resend the full sets. This endpoint cannot update the calling user's own record. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
accountIdstringyesREQUIRED. The UUID of the account with access to the user (from compassone_list_accounts).
fieldsJsonstringnonullOptional JSON object of additional body fields, merged over the values above.
namestringyesREQUIRED. The user's full name.
rolesstringyesREQUIRED comma-separated RBAC roles — a full replacement of the user's roles, at least one value. Each value must be one of: AccountAdmin, AccountBillingAbility, AccountUser, BlackpointAdmin, BlackpointSuperAdmin, BlackpointUser, CustomerAdmin, CustomerUser.
tenantIdsToAssignstringyesREQUIRED comma-separated tenant UUIDs (from compassone_list_tenants) — a full replacement of the user's tenant assignments. Pass an empty string to assign no tenants.
userIdstringyesREQUIRED. The UUID of the user to update (from compassone_list_account_users).

Contact Groups

ToolPlanAccessSummary
compassone_assign_contact_group_tenantsProWriteAssign tenants to a contact group, so CompassOne escalates those tenants' incidents to this group's members.
compassone_create_contact_groupProWriteCreate a contact group for an account.
compassone_create_contact_group_memberProWriteAdd one member (escalation contact) to an existing contact group.
compassone_delete_contact_groupProDestructiveDelete ONE contact group by id.
compassone_delete_contact_group_memberProDestructiveDelete one member from a contact group.
compassone_delete_contact_groupsProDestructiveDelete MULTIPLE contact groups in one call.
compassone_get_contact_groupFreeRead-onlyGet one contact group by id.
compassone_get_contact_group_memberFreeRead-onlyGet one contact group member by id.
compassone_list_contact_group_membersFreeRead-onlyList one contact group's members (the escalation contacts, in priority order).
compassone_list_contact_group_tenantsFreeRead-onlyList the tenants that ARE assigned to one contact group.
compassone_list_contact_group_unassigned_tenantsFreeRead-onlyList the tenants that are NOT assigned to the given contact group — the candidate pool for compassone_assign_contact_group_tenants.
compassone_list_contact_groupsFreeRead-onlyList an account's contact groups (escalation contact lists).
compassone_update_contact_groupProDestructiveUpdate one contact group.

[Blackpoint CompassOne] Assign tenants to a contact group, so CompassOne escalates those tenants' incidents to this group's members. accountId and contactGroupId are REQUIRED path parameters; tenantIds is a REQUIRED list of tenant UUIDs. Get candidates from compassone_list_contact_group_unassigned_tenants. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
accountIdstringyesREQUIRED. The UUID of the account that owns the contact group (from compassone_list_accounts).
contactGroupIdstringyesREQUIRED. The UUID of the contact group to which the tenants will be assigned (from compassone_list_contact_groups).
fieldsJsonstringnonullOptional JSON object of additional body fields, merged over the values above.
tenantIdsstringyesREQUIRED comma-separated tenant UUIDs to assign (from compassone_list_contact_group_unassigned_tenants or compassone_list_tenants).

[Blackpoint CompassOne] Create a contact group for an account. accountId is REQUIRED (from compassone_list_accounts); name (max 100 chars) and members are REQUIRED body fields. members is a JSON ARRAY of member objects, each with all six of name, phoneNumber, email, availability, timezone and priority — CompassOne accepts a minimum of 1 member but documents that at least 3 are required for a usable escalation list. Attach tenants afterwards with compassone_assign_contact_group_tenants. Returns the raw created contact group JSON including its new id.

ParamTypeRequiredDefaultDescription
accountIdstringyesREQUIRED. The UUID of the account that will own the contact group (from compassone_list_accounts).
fieldsJsonstringnonullOptional JSON object of additional body fields, merged over the values above.
membersJsonstringyesREQUIRED JSON array of member objects. Each object needs all six fields: name (max 250), phoneNumber (max 100), email (max 254), availability (one of: After Hours, All Hours, Business Hours), timezone, and priority (a number, minimum 1). Example: [{"name":"Jane Doe","phoneNumber":"+15550001111","email":"jane@example.com","availability":"All Hours","timezone":"America/New_York","priority":1}]
namestringyesREQUIRED display name for the contact group (max 100 characters).

[Blackpoint CompassOne] Add one member (escalation contact) to an existing contact group. accountId and contactGroupId are REQUIRED path parameters, and CompassOne requires ALL SIX body fields: name, phoneNumber, email, availability, timezone and priority. availability must be one of: After Hours, All Hours, Business Hours. priority is a number with a minimum of 1 and orders the escalation. This adds a member without touching the rest of the roster — compassone_update_contact_group replaces the whole roster instead. Returns the raw created member JSON.

ParamTypeRequiredDefaultDescription
accountIdstringyesREQUIRED. The UUID of the account that owns the contact group (from compassone_list_accounts).
availabilitystringyesREQUIRED availability window. One of: After Hours, All Hours, Business Hours.
contactGroupIdstringyesREQUIRED. The UUID of the contact group that will own the member (from compassone_list_contact_groups).
emailstringyesREQUIRED. The member's email address (max 254 characters).
fieldsJsonstringnonullOptional JSON object of additional body fields, merged over the values above.
namestringyesREQUIRED. The member's name (max 250 characters).
phoneNumberstringyesREQUIRED. The member's phone number (max 100 characters).
priorityintegeryesREQUIRED escalation priority — a number, minimum 1 (1 is contacted first).
timezonestringyesREQUIRED. The member's timezone, e.g. America/New_York.

[Blackpoint CompassOne] Delete ONE contact group by id. Destructive and not undoable — the group's member roster and tenant assignments go with it, and the affected tenants lose that escalation path. accountId and contactGroupId are REQUIRED path parameters. To remove a single contact instead of the whole group, use compassone_delete_contact_group_member. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
accountIdstringyesREQUIRED. The UUID of the account that owns the contact group (from compassone_list_accounts).
contactGroupIdstringyesREQUIRED. The UUID of the contact group to delete (from compassone_list_contact_groups).

[Blackpoint CompassOne] Delete one member from a contact group. Destructive and not undoable — that contact stops being escalated to, while the group itself and its other members survive. All three of accountId, contactGroupId and memberId are REQUIRED path parameters (memberId from compassone_list_contact_group_members). Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
accountIdstringyesREQUIRED. The UUID of the account that owns the contact group (from compassone_list_accounts).
contactGroupIdstringyesREQUIRED. The UUID of the contact group that owns the member (from compassone_list_contact_groups).
memberIdstringyesREQUIRED. The UUID of the member to delete (from compassone_list_contact_group_members).

[Blackpoint CompassOne] Delete MULTIPLE contact groups in one call. Destructive and not undoable — each group's member roster and tenant assignments go with it, and the affected tenants lose that escalation path. accountId is a REQUIRED path parameter; contactGroupIds is a REQUIRED list of at least 1 contact group UUID (from compassone_list_contact_groups). Sent as a DELETE with a JSON body. For a single group prefer compassone_delete_contact_group. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
accountIdstringyesREQUIRED. The UUID of the account that owns the contact groups (from compassone_list_accounts).
contactGroupIdsstringyesREQUIRED comma-separated contact group UUIDs to delete (from compassone_list_contact_groups). At least 1 value.
fieldsJsonstringnonullOptional JSON object of additional body fields, merged over the values above.

[Blackpoint CompassOne] Get one contact group by id. accountId and contactGroupId are REQUIRED path parameters (from compassone_list_accounts and compassone_list_contact_groups). Set includeMembers and/or includeAssignedTenants to true to inline those collections — both default to omitted, in which case CompassOne returns the group without them. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
accountIdstringyesREQUIRED. The UUID of the account that owns the contact group (from compassone_list_accounts).
contactGroupIdstringyesREQUIRED. The UUID of the contact group to retrieve (from compassone_list_contact_groups).
includeAssignedTenantsbooleannonullSet true to include the contact group's assigned tenants in the response.
includeMembersbooleannonullSet true to include the contact group's members in the response.

[Blackpoint CompassOne] Get one contact group member by id. All three of accountId, contactGroupId and memberId are REQUIRED path parameters (memberId comes from compassone_list_contact_group_members). Returns the raw member JSON including name, phoneNumber, email, availability, timezone and priority.

ParamTypeRequiredDefaultDescription
accountIdstringyesREQUIRED. The UUID of the account that owns the contact group (from compassone_list_accounts).
contactGroupIdstringyesREQUIRED. The UUID of the contact group that owns the member (from compassone_list_contact_groups).
memberIdstringyesREQUIRED. The UUID of the member to retrieve (from compassone_list_contact_group_members).

[Blackpoint CompassOne] List one contact group's members (the escalation contacts, in priority order). accountId and contactGroupId are REQUIRED path parameters. Page-based paging (pageSize max 1000). The returned member id is what compassone_get_contact_group_member and compassone_delete_contact_group_member take. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
accountIdstringyesREQUIRED. The UUID of the account that owns the contact group (from compassone_list_accounts).
contactGroupIdstringyesREQUIRED. The UUID of the contact group whose members are being listed (from compassone_list_contact_groups).
pageintegerno11-based page number (default 1).
pageSizeintegerno50Results per page (default 50, max 1000).
sortBystringnonullSort field. The only supported value is: priority. Omit for CompassOne's default ordering.
sortOrderstringnonullSort direction: ASC or DESC. Omit for CompassOne's default direction.

[Blackpoint CompassOne] List the tenants that ARE assigned to one contact group. accountId and contactGroupId are REQUIRED path parameters. This is the assigned half of a pair — for the account's tenants NOT yet attached to this group, use compassone_list_contact_group_unassigned_tenants. Page-based paging (pageSize max 1000). Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
accountIdstringyesREQUIRED. The UUID of the account that owns the contact group (from compassone_list_accounts).
contactGroupIdstringyesREQUIRED. The UUID of the contact group whose assigned tenants are being listed (from compassone_list_contact_groups).
pageintegerno11-based page number (default 1).
pageSizeintegerno50Results per page (default 50, max 1000).
searchstringnonullSearch term matched against tenant.id and tenant.name. Omit for no text filter.
sortBystringnonullSort field. The only supported value is: tenant.name. Omit for CompassOne's default ordering.
sortOrderstringnonullSort direction: ASC or DESC. Omit for CompassOne's default direction.

[Blackpoint CompassOne] List the tenants that are NOT assigned to the given contact group — the candidate pool for compassone_assign_contact_group_tenants. accountId and contactGroupId are REQUIRED path parameters. This is the unassigned half of a pair: compassone_list_contact_group_tenants returns the tenants that ARE assigned. Page-based paging (pageSize max 1000). Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
accountIdstringyesREQUIRED. The UUID of the account that owns the contact group (from compassone_list_accounts).
contactGroupIdstringyesREQUIRED. The UUID of the contact group for which to retrieve tenants that are not currently assigned to it (from compassone_list_contact_groups).
pageintegerno11-based page number (default 1).
pageSizeintegerno50Results per page (default 50, max 1000).
searchstringnonullSearch term matched against tenant.id, tenant.name or contactGroup.name. Omit for no text filter.
sortBystringnonullSort field. One of: tenant.name, contactGroup.name. Omit for CompassOne's default ordering.
sortOrderstringnonullSort direction: ASC or DESC. Omit for CompassOne's default direction.

[Blackpoint CompassOne] List an account's contact groups (escalation contact lists). accountId is REQUIRED (from compassone_list_accounts). Page-based paging (pageSize max 1000). Two extra nested page sizes control how much of each group is inlined: tenantsPageSize (0-200, default 0) and membersPageSize (0-25, default 0) — 0 omits that collection entirely, so ask for what you need rather than fetching every roster. The returned contact group id is what every other contact-group tool takes. Returns the raw CompassOne JSON.

ParamTypeRequiredDefaultDescription
accountIdstringyesREQUIRED. The UUID of the account that owns the contact groups (from compassone_list_accounts).
membersPageSizeintegernonullHow many members to inline per contact group (0-25, default 0 = none). Values above 25 are clamped.
pageintegerno11-based page number (default 1).
pageSizeintegerno50Results per page (default 50, max 1000).
searchstringnonullSearch term matched against contact group id and name. Omit for no text filter.
sortBystringnonullSort field. The only supported value is: name. Omit for CompassOne's default ordering.
sortOrderstringnonullSort direction: ASC or DESC. Omit for CompassOne's default direction.
tenantsPageSizeintegernonullHow many assigned tenants to inline per contact group (0-200, default 0 = none). Values above 200 are clamped.

[Blackpoint CompassOne] Update one contact group. accountId and contactGroupId are REQUIRED path parameters; name and members are REQUIRED body fields on every call. The members array is a FULL REPLACEMENT of the roster: include a member's id to update it, omit the id to add a new member, and leave a member out entirely to remove it. Read the current roster first with compassone_list_contact_group_members so you do not drop contacts by accident. To add a single member without resending the roster, use compassone_create_contact_group_member instead. Returns the raw updated contact group JSON.

ParamTypeRequiredDefaultDescription
accountIdstringyesREQUIRED. The UUID of the account that owns the contact group (from compassone_list_accounts).
contactGroupIdstringyesREQUIRED. The UUID of the contact group to update (from compassone_list_contact_groups).
fieldsJsonstringnonullOptional JSON object of additional body fields, merged over the values above.
membersJsonstringyesREQUIRED JSON array replacing the ENTIRE member roster. Each object needs all six of name (max 250), phoneNumber (max 100), email (max 254), availability (one of: After Hours, All Hours, Business Hours), timezone, and priority (a number, minimum 1); add an id to update that existing member, or omit id to create a new one. Example: [{"id":"3f1c...","name":"Jane Doe","phoneNumber":"+15550001111","email":"jane@example.com","availability":"All Hours","timezone":"America/New_York","priority":1}]
namestringyesREQUIRED display name for the contact group (max 100 characters).