Blackpoint CompassOne Tools
Written By Christopher Scaminaci
Last updated 7 days ago
Blackpoint CompassOne Tools
compassone_ · 148 tools · Free 77 · Pro 71
Managed detection and response, asset inventory and cloud posture. The credential is a bearer token minted in the console; the vendor publishes no token endpoint, so recovery is a new console token. The host is fixed. Two paging families coexist - page with page size on most reads and skip with take on seven - plus a limit capped at 100 on the two top-detections reads. Array filters are sent as repeated query parameters, and the asset list requires a class filter. Scoping differs by family: the cloud tools take an end-customer tenant id as a query parameter, cloud posture takes a scope type and id pair in the path, and the alert-group tools take a tenant id request header that the vendor requires even though its own spec omits it. Eight deletes carry a JSON body and three path-only deletes require query parameters. There are no binary responses anywhere. The vendor documents a 429 on every operation but publishes no numeric quota.
All connector tools · Blackpoint CompassOne setup guide
Blackpoint CompassOne tool groups
- Detections — 7 tools
- Assets — 3 tools
- Collections — 5 tools
- Cloud MDR Connections — 9 tools
- Cisco Duo Cloud MDR — 6 tools
- Google Workspace Cloud MDR — 2 tools
- Microsoft 365 Cloud MDR — 9 tools
- Cloud Posture — 8 tools
- Vulnerabilities — 15 tools
- Scans — 13 tools
- Scan Schedules — 6 tools
- Exposures — 4 tools
- Email Channels — 7 tools
- Webhook Channels — 7 tools
- Notification Routing — 4 tools
- Reports — 4 tools
- Security Posture — 11 tools
- Accounts — 2 tools
- Tenants — 2 tools
- Users — 11 tools
- Contact Groups — 13 tools
Detections
compassone_get_alert_group details
compassone_get_alert_group details
[Blackpoint CompassOne] Get one alert group (detection) by id, from compassone_list_alert_groups. Returns the raw alert-group JSON — status, alert count, alert types, hostname and username. Use compassone_list_alerts_for_alert_group for the individual alerts it contains.
compassone_get_alert_group_count details
compassone_get_alert_group_count details
[Blackpoint CompassOne] Get the total count of alert groups (detections) in a date window — a cheap way to size a result set before listing it with compassone_list_alert_groups. Both dates default when omitted (start = 90 days ago, end = now). Note status is single-valued here, unlike the comma-separated list compassone_list_alert_groups accepts. Returns the raw CompassOne JSON.
compassone_get_alert_groups_by_week details
compassone_get_alert_groups_by_week details
[Blackpoint CompassOne] Get detection counts aggregated by week — the trend series behind a SOC activity chart. Both dates default when omitted (start = 90 days ago, end = now). Returns the raw CompassOne JSON.
compassone_get_top_detections_by_entity details
compassone_get_top_detections_by_entity details
[Blackpoint CompassOne] Get the top detections grouped by an entity field (for example hostname or username) — answers 'which machines or users generate the most detections'. Uses limit rather than paging; CompassOne caps limit at 100. Both dates default when omitted (start = 90 days ago, end = now). See compassone_get_top_detections_by_threat to group by threat type instead. Returns the raw CompassOne JSON.
compassone_get_top_detections_by_threat details
compassone_get_top_detections_by_threat details
[Blackpoint CompassOne] Get the top detections grouped by threat type — answers 'what kinds of threats are we seeing most'. Uses limit rather than paging; CompassOne caps limit at 100. Both dates default when omitted (start = 90 days ago, end = now). See compassone_get_top_detections_by_entity to group by host or user instead. Returns the raw CompassOne JSON.
compassone_list_alert_groups details
compassone_list_alert_groups details
[Blackpoint CompassOne] List alert groups (detections) — the SOC's unit of triage, each grouping related alerts. Offset-paged with skip/take, NOT page/pageSize. status accepts a comma-separated list of OPEN and RESOLVED. type is CR (Cloud Response) or MDR. The 'since' window reaches back at most 90 days. Use compassone_get_alert_group for one group's detail and compassone_list_alerts_for_alert_group for the alerts inside it. Returns the raw CompassOne JSON.
compassone_list_alerts_for_alert_group details
compassone_list_alerts_for_alert_group details
[Blackpoint CompassOne] List the individual alerts inside one alert group (detection). Offset-paged with skip/take, NOT page/pageSize. Get the alertGroupId from compassone_list_alert_groups. Returns the raw CompassOne JSON.
Assets
compassone_get_asset details
compassone_get_asset details
[Blackpoint CompassOne] Get a single asset by id (from compassone_list_assets). Returns the raw asset JSON — class, type, criticality, status, discovery and last-seen timestamps. Use compassone_list_asset_relationships to see what this asset connects to.
compassone_list_asset_relationships details
compassone_list_asset_relationships details
[Blackpoint CompassOne] List one asset's relationships to other entities. BOTH entityClass and direction are REQUIRED. entityClass is single-valued here (not a list, unlike compassone_list_assets) and accepts a wider set that includes findings: CONTAINER, DEVICE, FRAMEWORK, NETSTAT, PERSON, PROCESS, SERVICE, SOFTWARE, SOURCE, SURVEY, USER, ALERT, ALERTGROUP, EVENT, INCIDENT, VULNERABILITY. direction is 'out' for relationships this asset points at, 'in' for ones pointing at it. Page-based paging (pageSize max 1000). Returns the raw CompassOne JSON.
compassone_list_assets details
compassone_list_assets details
[Blackpoint CompassOne] List assets from the CompassOne inventory. assetClass is REQUIRED — CompassOne rejects the call without it — and accepts several classes at once as a comma-separated list (CONTAINER, DEVICE, FRAMEWORK, NETSTAT, PERSON, PROCESS, SERVICE, SOFTWARE, SOURCE, SURVEY, USER). Page-based paging (pageSize max 1000). Use compassone_get_asset for one asset's full detail and compassone_list_asset_relationships to walk its relationship graph. Returns the raw CompassOne JSON.
Collections
compassone_create_collection details
compassone_create_collection details
[Blackpoint CompassOne] Create a collection (saved search). All three of context, name and search are required by CompassOne. Returns the raw created collection JSON including its new id.
compassone_delete_collection details
compassone_delete_collection details
[Blackpoint CompassOne] Delete a collection by id (from compassone_list_collections). Destructive — the saved search is removed. The assets or findings it matched are NOT affected; only the grouping is deleted. Returns the raw CompassOne response.
compassone_get_collection details
compassone_get_collection details
[Blackpoint CompassOne] Get a single collection by id (from compassone_list_collections). Returns the raw collection JSON including its context and saved search expression.
compassone_list_collections details
compassone_list_collections details
[Blackpoint CompassOne] List collections (saved searches) for one context. The context parameter is REQUIRED — CompassOne scopes collections per entity class and rejects the call without it. Page-based paging (pageSize max 1000). Use compassone_get_collection for one collection's detail; the returned id is what compassone_update_collection and compassone_delete_collection take. Returns the raw CompassOne JSON.
compassone_update_collection details
compassone_update_collection details
[Blackpoint CompassOne] Update a collection by id (from compassone_list_collections). Every field is optional — supply only what changes. Editable: context, name, search. Returns the raw updated collection JSON.
Cloud MDR Connections
compassone_approve_connection_country details
compassone_approve_connection_country details
[Blackpoint CompassOne] Approve a country for a whole cloud-MDR connection, widening the allow-list so sign-ins from there stop raising impossible-travel detections. tenantId is REQUIRED and isoCountryCode is a REQUIRED two-letter ISO 3166-1 alpha-2 code (look codes up with compassone_list_iso_countries). To approve a country for a single user instead, use compassone_approve_connection_user_country. Returns the raw CompassOne response.
compassone_approve_connection_user_country details
compassone_approve_connection_user_country details
[Blackpoint CompassOne] Approve a country for ONE user on a cloud-MDR connection, optionally time-boxed to a travel window. tenantId is REQUIRED, connectionUserId comes from compassone_list_connection_users, and isoCountryCode is a REQUIRED two-letter ISO 3166-1 alpha-2 code. Supply startDate and endDate to make the approval temporary — ideal for a trip. To widen the whole connection instead, use compassone_approve_connection_country. Returns the raw CompassOne response.
compassone_get_iso_country details
compassone_get_iso_country details
[Blackpoint CompassOne] Get one ISO 3166-1 country by its two-letter alpha-2 code (for example US). Global reference data — takes NO tenantId. Returns the raw CompassOne JSON.
compassone_list_connection_approved_countries details
compassone_list_connection_approved_countries details
[Blackpoint CompassOne] List the countries approved for one cloud-MDR connection — the connection-wide allow-list behind CompassOne's impossible-travel detection. tenantId is REQUIRED. Offset-paged with skip/take. For a single user's overrides use compassone_list_connection_user_approved_countries. Returns the raw CompassOne JSON.
compassone_list_connection_user_approved_countries details
compassone_list_connection_user_approved_countries details
[Blackpoint CompassOne] List the countries approved for ONE user on a cloud-MDR connection — the per-user overrides on top of the connection-wide list returned by compassone_list_connection_approved_countries. tenantId is REQUIRED and connectionUserId comes from compassone_list_connection_users. Offset-paged with skip/take. Returns the raw CompassOne JSON.
compassone_list_connection_users details
compassone_list_connection_users details
[Blackpoint CompassOne] List the users belonging to one cloud-MDR connection. tenantId is REQUIRED. Offset-paged with skip/take, NOT page/pageSize. The returned user ids are what the per-user approved-country tools take. Returns the raw CompassOne JSON.
compassone_list_iso_countries details
compassone_list_iso_countries details
[Blackpoint CompassOne] List the ISO 3166-1 country reference CompassOne recognizes. This is global reference data — it takes NO tenantId and no paging. Use it to look up the two-letter code that the approve-country tools require. Returns the raw CompassOne JSON.
compassone_remove_connection_approved_country details
compassone_remove_connection_approved_country details
[Blackpoint CompassOne] Remove an approved country from a whole cloud-MDR connection. Destructive — narrowing the allow-list means sign-ins from that country will raise impossible-travel detections again for every user on the connection. tenantId is REQUIRED and id is the approved-country record id from compassone_list_connection_approved_countries (NOT the two-letter country code). Returns the raw CompassOne response.
compassone_remove_connection_user_approved_country details
compassone_remove_connection_user_approved_country details
[Blackpoint CompassOne] Remove an approved country from ONE user on a cloud-MDR connection. Destructive — that user's sign-ins from the country will raise impossible-travel detections again. tenantId is REQUIRED, connectionUserId comes from compassone_list_connection_users, and id is the approved-country record id from compassone_list_connection_user_approved_countries (NOT the two-letter country code). Returns the raw CompassOne response.
Cisco Duo Cloud MDR
compassone_complete_cisco_onboarding details
compassone_complete_cisco_onboarding details
[Blackpoint CompassOne] Complete a Cisco Duo cloud-MDR onboarding by verifying everything was set up correctly. Takes no body. tenantId is REQUIRED and onboardingId comes from compassone_list_cisco_onboardings. This is the final step after compassone_create_cisco_onboarding and compassone_sync_cisco_users. Returns the raw CompassOne response.
compassone_create_cisco_onboarding details
compassone_create_cisco_onboarding details
[Blackpoint CompassOne] Begin a new Cisco Duo cloud-MDR onboarding for a customer. tenantId is REQUIRED. CompassOne FAILS this call if an onboarding for that Duo domain already exists — check compassone_list_cisco_onboardings first. Supply the customer's Duo admin API credentials (host, ikey, skey); all three are optional in CompassOne's schema, so pass whichever the onboarding flow requires. After creating, run compassone_sync_cisco_users and then compassone_complete_cisco_onboarding. Returns the raw created onboarding JSON.
compassone_delete_cisco_onboarding details
compassone_delete_cisco_onboarding details
[Blackpoint CompassOne] Abandon a Cisco Duo cloud-MDR onboarding. Destructive — this removes the onboarding records AND deletes the Cisco Duo onboarding app if one was created, so the customer's Duo-side integration is torn down and the onboarding must be started over. tenantId is REQUIRED and onboardingId comes from compassone_list_cisco_onboardings. Returns the raw CompassOne response.
compassone_get_cisco_onboarding details
compassone_get_cisco_onboarding details
[Blackpoint CompassOne] Get the state of one Cisco Duo cloud-MDR onboarding. tenantId is REQUIRED (discover ids with compassone_list_tenants) and onboardingId comes from compassone_list_cisco_onboardings. Returns the raw CompassOne JSON.
compassone_list_cisco_onboardings details
compassone_list_cisco_onboardings details
[Blackpoint CompassOne] List the Cisco Duo cloud-MDR onboardings for one CompassOne customer, completed or in progress. tenantId is REQUIRED and identifies the end customer — discover ids with compassone_list_tenants. Use compassone_get_cisco_onboarding for one onboarding's state. Returns the raw CompassOne JSON.
compassone_sync_cisco_users details
compassone_sync_cisco_users details
[Blackpoint CompassOne] Verify the Cisco Duo domain-wide delegation permissions and start the user sync — also the way to restart a sync that never began or stalled. Takes no body. tenantId is REQUIRED and onboardingId comes from compassone_list_cisco_onboardings. Run this after compassone_create_cisco_onboarding and before compassone_complete_cisco_onboarding. Returns the raw CompassOne response.
Google Workspace Cloud MDR
compassone_get_google_onboarding details
compassone_get_google_onboarding details
[Blackpoint CompassOne] Get the state of one Google Workspace cloud-MDR onboarding. tenantId is REQUIRED (discover ids with compassone_list_tenants) and onboardingId comes from compassone_list_google_onboardings. Returns the raw CompassOne JSON.
compassone_list_google_onboardings details
compassone_list_google_onboardings details
[Blackpoint CompassOne] List the Google Workspace cloud-MDR onboardings for one CompassOne customer, completed or in progress. tenantId is REQUIRED and identifies the end customer — discover ids with compassone_list_tenants. Use compassone_get_google_onboarding for one onboarding's detail. Returns the raw CompassOne JSON.
Microsoft 365 Cloud MDR
compassone_approve_m365_country details
compassone_approve_m365_country details
[Blackpoint CompassOne] Approve a country for a whole Microsoft 365 connection, so sign-ins from there stop raising impossible-travel detections for every user on the connection. tenantId is REQUIRED and code is a REQUIRED two-letter ISO 3166-1 alpha-2 country code (look codes up with compassone_list_iso_countries). To approve for a single user instead, use compassone_approve_m365_user_country. Returns the raw CompassOne response.
compassone_approve_m365_user_country details
compassone_approve_m365_user_country details
[Blackpoint CompassOne] Approve a country for ONE Microsoft 365 user, optionally time-boxed to a travel window. tenantId is REQUIRED, userId comes from compassone_list_m365_users, and isoCountryCode is a REQUIRED two-letter ISO 3166-1 alpha-2 code. Supply startDate and endDate to make the approval temporary — ideal for a trip. To widen the whole connection instead, use compassone_approve_m365_country. Returns the raw CompassOne response.
compassone_get_m365_connection details
compassone_get_m365_connection details
[Blackpoint CompassOne] Get one Microsoft 365 Defense connection by id. tenantId is REQUIRED and connectionId comes from compassone_list_m365_connections. Returns the raw CompassOne JSON.
compassone_list_m365_approved_countries details
compassone_list_m365_approved_countries details
[Blackpoint CompassOne] List the countries approved for a whole Microsoft 365 connection — the connection-wide allow-list behind impossible-travel detection. tenantId is REQUIRED. This endpoint takes no paging params. For one user's overrides use compassone_list_m365_user_approved_countries. Returns the raw CompassOne JSON.
compassone_list_m365_connections details
compassone_list_m365_connections details
[Blackpoint CompassOne] List the Microsoft 365 Defense connections belonging to one CompassOne customer. tenantId is REQUIRED and identifies the end customer — discover ids with compassone_list_tenants. The returned connection ids feed every other M365 tool. Returns the raw CompassOne JSON.
compassone_list_m365_user_approved_countries details
compassone_list_m365_user_approved_countries details
[Blackpoint CompassOne] List the currently-active approved countries for ONE Microsoft 365 user — the per-user overrides on top of the connection-wide list from compassone_list_m365_approved_countries. tenantId is REQUIRED and userId comes from compassone_list_m365_users. Offset-paged with skip/take. Returns the raw CompassOne JSON.
compassone_list_m365_users details
compassone_list_m365_users details
[Blackpoint CompassOne] List the users on one Microsoft 365 Defense connection, filterable by enabled / licensed / billable state and by name-or-email substring. tenantId is REQUIRED. Offset-paged with skip/take, NOT page/pageSize. The returned user ids feed the per-user approved-country tools. Returns the raw CompassOne JSON.
compassone_remove_m365_approved_country details
compassone_remove_m365_approved_country details
[Blackpoint CompassOne] Remove an approved country from a whole Microsoft 365 connection. Destructive — narrowing the allow-list means sign-ins from that country raise impossible-travel detections again for every user on the connection. tenantId is REQUIRED. Note this tool takes the two-letter COUNTRY CODE, unlike compassone_remove_m365_user_approved_country which takes a record id. Returns the raw CompassOne response.
compassone_remove_m365_user_approved_country details
compassone_remove_m365_user_approved_country details
[Blackpoint CompassOne] Remove an approved country from ONE Microsoft 365 user. Destructive — that user's sign-ins from the country raise impossible-travel detections again. tenantId is REQUIRED and userId comes from compassone_list_m365_users. Note this tool takes the approved-country RECORD id from compassone_list_m365_user_approved_countries, unlike compassone_remove_m365_approved_country which takes a country code. Returns the raw CompassOne response.
Cloud Posture
compassone_bulk_delete_managed_policies details
compassone_bulk_delete_managed_policies details
[Blackpoint CompassOne] Delete several managed policies at once by id. Destructive — this is a delete despite using a POST verb (CompassOne exposes it at /bulk-delete), and every listed policy stops being enforced on all its assigned connections. Returns the raw CompassOne response.
compassone_create_managed_policy details
compassone_create_managed_policy details
[Blackpoint CompassOne] Create a managed policy. CompassOne REQUIRES name, connectionType, policyType, the policy document, and scopeAssignments. Because policy and scopeAssignments are structured objects/arrays, supply them through fieldsJson — for example {"policy":,"scopeAssignments":[]}. Returns the raw created policy JSON including its new id.
compassone_delete_managed_policy details
compassone_delete_managed_policy details
[Blackpoint CompassOne] Delete one managed policy by id. Destructive — the policy is removed and stops being enforced on every connection it was assigned to. To remove several at once use compassone_bulk_delete_managed_policies. Returns the raw CompassOne response.
compassone_get_managed_policy details
compassone_get_managed_policy details
[Blackpoint CompassOne] Get one managed policy by id (from compassone_list_managed_policies_by_scope). Pass customerId to narrow the effective-policy view to a single customer. Returns the raw policy JSON including its policy document and assignment state.
compassone_list_managed_policies_by_scope details
compassone_list_managed_policies_by_scope details
[Blackpoint CompassOne] List every managed policy applicable to one scope. BOTH scopeType and scopeId are REQUIRED path values: scopeType is ACCOUNT, CUSTOMER or CONNECTION, and scopeId is the id of that account, customer or connection. Unlike the cloud-MDR tools this takes no tenantId. Page-based paging (pageSize max 1000). This is the connector's most filterable read — several filters accept comma-separated multi-values. Returns the raw CompassOne JSON.
compassone_save_managed_policy_as_template details
compassone_save_managed_policy_as_template details
[Blackpoint CompassOne] Save an existing managed policy as a new reusable policy template. Every field is optional — when name is omitted CompassOne reuses the managed policy's own name. Returns the raw created template JSON.
compassone_update_managed_policy details
compassone_update_managed_policy details
[Blackpoint CompassOne] Update a managed policy by id. Every field is optional — supply only what changes. Editable: name, description, status, defaultAssignmentStatus, and the policy document (through fieldsJson, since it is a structured object). Returns the raw updated policy JSON.
compassone_update_managed_policy_assignments details
compassone_update_managed_policy_assignments details
[Blackpoint CompassOne] Assign and unassign connections on a managed policy in a single call. Pass connectionsToAdd (an array of connection objects) and/or assignmentIdsToRemove (an array of assignment ids) through fieldsJson — for example {"assignmentIdsToRemove":["a-1"]}. Removing an assignment stops enforcing the policy on that connection. Returns the raw CompassOne response.
Vulnerabilities
compassone_bulk_delete_vulnerabilities details
compassone_bulk_delete_vulnerabilities details
[Blackpoint CompassOne] Delete several vulnerabilities outright, across every device they were found on. Destructive and broad — the finding history is removed everywhere, not marked resolved. Prefer compassone_bulk_update_vulnerabilities to change status, or compassone_bulk_delete_vulnerabilities_for_device to limit the deletion to one machine. ids is REQUIRED. Returns the raw CompassOne response.
compassone_bulk_delete_vulnerabilities_for_device details
compassone_bulk_delete_vulnerabilities_for_device details
[Blackpoint CompassOne] Delete several vulnerabilities' records for ONE device. Destructive — that machine's finding history for those vulnerabilities is removed, not marked resolved. Both ids and deviceId are REQUIRED. Prefer compassone_bulk_update_vulnerabilities_for_device to change status instead. Returns the raw CompassOne response.
compassone_bulk_update_vulnerabilities details
compassone_bulk_update_vulnerabilities details
[Blackpoint CompassOne] Update the status of several vulnerabilities at once, across all their devices. Both ids and status are REQUIRED. To scope the change to one device use compassone_bulk_update_vulnerabilities_for_device. Returns the raw CompassOne response.
compassone_bulk_update_vulnerabilities_for_device details
compassone_bulk_update_vulnerabilities_for_device details
[Blackpoint CompassOne] Update the status of several vulnerabilities on ONE device. All of ids, deviceId and status are REQUIRED. To change status across every affected device use compassone_bulk_update_vulnerabilities. Returns the raw CompassOne response.
compassone_delete_vulnerability_for_devices details
compassone_delete_vulnerability_for_devices details
[Blackpoint CompassOne] Delete one vulnerability's records for specific devices. Destructive — the finding history for those machines is removed, not merely marked resolved. To mark it resolved instead, use compassone_update_vulnerability_status_for_devices. deviceIds is REQUIRED. Returns the raw CompassOne response.
compassone_export_vulnerabilities details
compassone_export_vulnerabilities details
[Blackpoint CompassOne] Request an export of the vulnerability register. The body accepts the same filters as compassone_list_vulnerabilities plus 'fields' (an array of column names) and 'fieldAliases' (an object of column headers) — supply them through fieldsJson. CompassOne answers 201 with NO documented payload, so this tool returns whatever arrives, or when the response is empty. Returns the raw CompassOne response.
compassone_export_vulnerability_assets details
compassone_export_vulnerability_assets details
[Blackpoint CompassOne] Request an export of the assets affected by one vulnerability. The body REQUIRES 'class' (an array of asset classes: CONTAINER, DEVICE, FRAMEWORK, NETSTAT, PERSON, PROCESS, SERVICE, SOFTWARE, SOURCE, SURVEY, USER) and accepts the same filters as compassone_list_vulnerability_assets plus fields and fieldAliases — supply them through fieldsJson, for example {"class":["DEVICE"]}. CompassOne answers 201 with NO documented payload, so this tool returns whatever arrives, or when the response is empty. Returns the raw CompassOne response.
compassone_get_cve details
compassone_get_cve details
[Blackpoint CompassOne] Get CVE detail by CVE id. Pass assetId to scope the CVE information to one asset's context. For the CVE's external links use compassone_get_cve_references. Returns the raw CompassOne JSON.
compassone_get_cve_references details
compassone_get_cve_references details
[Blackpoint CompassOne] Get the external reference links for one CVE — advisories, patches and vendor bulletins. Use compassone_get_cve for the CVE record itself. Returns the raw CompassOne JSON.
compassone_get_vulnerabilities_count_by_severity details
compassone_get_vulnerabilities_count_by_severity details
[Blackpoint CompassOne] Get vulnerability counts grouped by severity — the numbers behind a risk-posture summary. No paging. Returns the raw CompassOne JSON.
compassone_get_vulnerabilities_count_by_tenant details
compassone_get_vulnerabilities_count_by_tenant details
[Blackpoint CompassOne] Get vulnerability counts grouped by CompassOne tenant — the cross-customer view an MSP uses to see which customers carry the most risk. No paging. Returns the raw CompassOne JSON.
compassone_get_vulnerability details
compassone_get_vulnerability details
[Blackpoint CompassOne] Get one vulnerability by id (from compassone_list_vulnerabilities). Returns the raw vulnerability JSON — scores, severity, status, exploitability and affected-asset counts.
compassone_list_vulnerabilities details
compassone_list_vulnerabilities details
[Blackpoint CompassOne] List the vulnerability register with the connector's richest filter set. Page-based paging (pageSize max 1000). Note CompassOne has TWO status filters that mean different things and are not interchangeable: 'status' is single-valued, 'vulnerabilityStatus' takes a comma-separated list. Use compassone_get_vulnerability for one record and compassone_list_vulnerability_assets to see which machines are affected. Returns the raw CompassOne JSON.
compassone_list_vulnerability_assets details
compassone_list_vulnerability_assets details
[Blackpoint CompassOne] List the assets affected by one vulnerability — the remediation work list. assetClass is REQUIRED and accepts several classes as a comma-separated list (CONTAINER, DEVICE, FRAMEWORK, NETSTAT, PERSON, PROCESS, SERVICE, SOFTWARE, SOURCE, SURVEY, USER). Page-based paging (pageSize max 1000). Returns the raw CompassOne JSON.
compassone_update_vulnerability_status_for_devices details
compassone_update_vulnerability_status_for_devices details
[Blackpoint CompassOne] Set one vulnerability's status on specific devices — how you mark it resolved, accepted or a false positive per machine. Both deviceIds and status are REQUIRED. This changes status only; it does not remove the vulnerability record (see compassone_delete_vulnerability_for_devices for that). Returns the raw CompassOne response.
Scans
compassone_bulk_delete_scans_and_schedules details
compassone_bulk_delete_scans_and_schedules details
[Blackpoint CompassOne] Bulk delete scans and/or scan schedules by id. The ids parameter is REQUIRED. Destructive — every id given is removed; deleting a schedule stops all of its future runs. Ids come from compassone_list_scans_and_schedules (which also tells you, via sourceTable, whether an id is a scan or a schedule). Returns the raw CompassOne response.
compassone_bulk_update_scan_schedules details
compassone_bulk_update_scan_schedules details
[Blackpoint CompassOne] Bulk update the status of many scan schedules in one call. Both ids and status are REQUIRED. This is the bulk counterpart to compassone_update_scan_schedule and applies the same status to every id given. Not destructive — the schedules are retained, only their status changes; use compassone_bulk_delete_scans_and_schedules to remove them. Returns the raw CompassOne response.
compassone_cancel_scan details
compassone_cancel_scan details
[Blackpoint CompassOne] Cancel an in-flight vulnerability-management scan by id. The id parameter is REQUIRED. Destructive despite being a PATCH: it aborts the running scan and the partial run is NOT resumable — the only way forward is to queue a new scan with compassone_create_scan. Use compassone_list_scans filtered to status in-progress to find cancellable scans. Returns the raw CompassOne response.
compassone_create_scan details
compassone_create_scan details
[Blackpoint CompassOne] Create (queue) a new vulnerability-management scan. Both type and triggeredByType are REQUIRED. Pass the scan's type-specific config object through fieldsJson — CompassOne types it as a free-form object, so it is not modelled as a typed parameter here. To scan on a recurring basis create a schedule with compassone_create_scan_schedule instead. Returns the raw created scan JSON including its new id.
compassone_delete_scan details
compassone_delete_scan details
[Blackpoint CompassOne] Delete a vulnerability-management scan by id. The id parameter is REQUIRED. Destructive — the scan record and its CVE findings are removed from the index. Use compassone_bulk_delete_scans_and_schedules to remove several at once. Returns the raw CompassOne response.
compassone_export_scan_cves details
compassone_export_scan_cves details
[Blackpoint CompassOne] Queue an export of the CVEs found by one scan (documented for network scans). The id parameter is REQUIRED; the remaining parameters are optional and mirror the filters on compassone_list_scan_cves. CompassOne documents no response payload for an export (it answers 201 with an empty body), so StackJack passes through whatever arrives — an empty is the normal success shape, not an error.
compassone_export_scans details
compassone_export_scans details
[Blackpoint CompassOne] Queue an export of scans and schedules. Every parameter is optional and mirrors the filters on compassone_list_scans_and_schedules. CompassOne documents no response payload for an export (it answers 201 with an empty body), so StackJack passes through whatever arrives — an empty is the normal success shape, not an error. Retrieve the finished file through the CompassOne console or the report tools.
compassone_get_scan details
compassone_get_scan details
[Blackpoint CompassOne] Get a single vulnerability-management scan by id, including its type, status, configuration and result. The id parameter is REQUIRED. Use compassone_list_scans or compassone_list_scans_and_schedules to discover ids. Returns the raw scan JSON.
compassone_get_scan_stats details
compassone_get_scan_stats details
[Blackpoint CompassOne] Get aggregate scan statistics across the account (counts by type/status as CompassOne reports them). Every parameter is optional; there is no paging on this endpoint. Use compassone_list_scans_and_schedules for the itemized index behind these numbers. Returns the raw CompassOne JSON.
compassone_list_scan_cves details
compassone_list_scan_cves details
[Blackpoint CompassOne] List the CVEs a specific scan found, with severity, CVSS base score and CompassOne's asset-environmental (priority) score. The id parameter is REQUIRED. Page-based paging (pageSize max 1000). Use compassone_list_scans for scan ids and compassone_export_scan_cves to queue a full export of the same result set. Returns the raw CompassOne JSON.
compassone_list_scans details
compassone_list_scans details
[Blackpoint CompassOne] List vulnerability-management scan runs (schedules excluded — use compassone_list_scan_schedules for those). Every parameter is optional. Page-based paging (pageSize max 1000). Returned ids feed compassone_get_scan, compassone_list_scan_cves, compassone_update_scan, compassone_cancel_scan and compassone_delete_scan. Returns the raw CompassOne JSON.
compassone_list_scans_and_schedules details
compassone_list_scans_and_schedules details
[Blackpoint CompassOne] List vulnerability-management scans AND scan schedules in one combined index, so a single call shows both completed runs and the recurring definitions that produce them. Every parameter is optional. Use sourceTable to restrict to one kind: scan (a run) or scanschedule (a definition). Page-based paging (pageSize max 1000). Returned ids feed compassone_get_scan / compassone_get_scan_schedule; for scans only use compassone_list_scans, for schedules only use compassone_list_scan_schedules. Returns the raw CompassOne JSON.
compassone_update_scan details
compassone_update_scan details
[Blackpoint CompassOne] Update a vulnerability-management scan by id. The id parameter is REQUIRED; every field is optional — supply only what changes. Pass the object-typed config and result properties through fieldsJson. To abort a running scan use compassone_cancel_scan instead of setting status. Returns the raw updated scan JSON.
Scan Schedules
compassone_create_scan_schedule details
compassone_create_scan_schedule details
[Blackpoint CompassOne] Create a recurring vulnerability-management scan schedule. Four fields are REQUIRED: type, time, frequency and name. Pass the object-typed config and frequencyConfig properties through fieldsJson — CompassOne types them as free-form objects, so they are not modelled as typed parameters here. For a one-off scan use compassone_create_scan instead. Returns the raw created scan-schedule JSON including its new id.
compassone_delete_scan_schedule details
compassone_delete_scan_schedule details
[Blackpoint CompassOne] Delete a vulnerability-management scan schedule by id. The id parameter is REQUIRED. Destructive — the schedule is removed and all of its future runs stop. To pause a schedule reversibly instead, set status to disabled via compassone_update_scan_schedule. Returns the raw CompassOne response.
compassone_get_scan_schedule details
compassone_get_scan_schedule details
[Blackpoint CompassOne] Get a single vulnerability-management scan schedule by id, including its type, frequency, next run time and status. The id parameter is REQUIRED. Set withScansCount to true to have CompassOne also report how many scans this schedule has produced. Use compassone_list_scan_schedules to discover ids. Returns the raw scan-schedule JSON.
compassone_list_scan_schedules details
compassone_list_scan_schedules details
[Blackpoint CompassOne] List vulnerability-management scan schedules — the recurring definitions, not the runs they produce (use compassone_list_scans for runs). Every parameter is optional. Page-based paging (pageSize max 1000). Returned ids feed compassone_get_scan_schedule, compassone_update_scan_schedule, compassone_run_scan_schedule and compassone_delete_scan_schedule. Returns the raw CompassOne JSON.
compassone_run_scan_schedule details
compassone_run_scan_schedule details
[Blackpoint CompassOne] Trigger a scan schedule to run now, outside its normal recurrence. The id parameter is REQUIRED and there is no request body. This starts a real scan against the schedule's configured target, so it consumes scanning capacity; the resulting run then appears in compassone_list_scans and can be aborted with compassone_cancel_scan. Returns the raw CompassOne response.
compassone_update_scan_schedule details
compassone_update_scan_schedule details
[Blackpoint CompassOne] Update a vulnerability-management scan schedule by id. The id parameter is REQUIRED; every field is optional — supply only what changes. Set status to disabled to pause a schedule without deleting it. Pass the object-typed config and frequencyConfig properties through fieldsJson. Use compassone_bulk_update_scan_schedules to change status on many schedules at once. Returns the raw updated scan-schedule JSON.
Exposures
compassone_get_darkweb_report_url details
compassone_get_darkweb_report_url details
[Blackpoint CompassOne] Get a signed download URL for the most recent dark-web scan report. Takes no parameters. This returns the URL as a JSON string, NOT the PDF bytes — fetch the URL separately to download the file. For the same findings as structured data use compassone_get_darkweb_scan_exposures. Returns the raw CompassOne JSON.
compassone_get_darkweb_scan_exposures details
compassone_get_darkweb_scan_exposures details
[Blackpoint CompassOne] List the credential exposures found by the MOST RECENT dark-web scan — there is no scan-id parameter; CompassOne always reports the latest scan. Filter by whether the password or username was exposed, and by impacted domain. Page-based paging (pageSize max 1000). For a shareable PDF use compassone_get_darkweb_report_url. Returns the raw CompassOne JSON.
compassone_get_external_scan_exposures details
compassone_get_external_scan_exposures details
[Blackpoint CompassOne] Get the exposures found by one external attack-surface scan, as JSON. Takes the external scan id — find scans with compassone_list_scans (filter type=external). For a shareable PDF of the same scan use compassone_get_external_scan_report_url. Returns the raw CompassOne JSON.
compassone_get_external_scan_report_url details
compassone_get_external_scan_report_url details
[Blackpoint CompassOne] Get a signed download URL for one external scan's PDF report. This returns the URL as a JSON string, NOT the PDF bytes — fetch the URL separately to download the file. For the same findings as structured data use compassone_get_external_scan_exposures. Returns the raw CompassOne JSON.
Email Channels
compassone_create_email_channel details
compassone_create_email_channel details
[Blackpoint CompassOne] Create an email notification channel. All four of name, emails, enabled and accountId are REQUIRED by CompassOne; tenantId is optional and scopes the channel to one end customer. Returns the raw created channel JSON including its new id.
compassone_delete_email_channel details
compassone_delete_email_channel details
[Blackpoint CompassOne] Soft-delete an email notification channel by id (from compassone_list_email_channels). Destructive — every notification currently routed through this channel stops being emailed. Returns the raw CompassOne response.
compassone_duplicate_email_channel details
compassone_duplicate_email_channel details
[Blackpoint CompassOne] Duplicate an email notification channel by id (from compassone_list_email_channels), copying its recipients and settings under a new name. The name parameter is REQUIRED. Returns the raw new channel JSON including its new id.
compassone_get_email_channel details
compassone_get_email_channel details
[Blackpoint CompassOne] Get a single email notification channel by id (from compassone_list_email_channels). Returns the raw channel JSON including its recipient list, enabled flag and owning account/tenant.
compassone_list_email_channels details
compassone_list_email_channels details
[Blackpoint CompassOne] Search email notification channels. This is a READ that does not modify anything — CompassOne exposes it as a POST only because the accountId/tenantId scoping travels in the request body while paging, sorting and filtering travel as query params. No parameter is required; omit them all to list every channel the token can see. Page-based paging (pageSize max 1000). Use compassone_get_email_channel for one channel's detail; the returned id is what compassone_update_email_channel, compassone_delete_email_channel, compassone_duplicate_email_channel and compassone_test_email_channel take. Returns the raw CompassOne JSON.
compassone_test_email_channel details
compassone_test_email_channel details
[Blackpoint CompassOne] Send a test email through an email notification channel by id (from compassone_list_email_channels). This really delivers mail to every recipient configured on the channel, so it is a write rather than a read, but it changes no configuration. Takes no body beyond the id. Returns the raw CompassOne response.
compassone_update_email_channel details
compassone_update_email_channel details
[Blackpoint CompassOne] Update an email notification channel by id (from compassone_list_email_channels). Every field is optional — supply only what changes. Editable: name, emails, enabled. Supplying emails REPLACES the whole recipient list rather than appending to it. Returns the raw updated channel JSON.
Webhook Channels
compassone_create_webhook_channel details
compassone_create_webhook_channel details
[Blackpoint CompassOne] Create a webhook notification channel. Six fields are REQUIRED by CompassOne: name, enabled, accountId, url, apiSecretNameHeader and headers. tenantId is optional and scopes the channel to one end customer. Returns the raw created channel JSON including its new id.
compassone_delete_webhook_channel details
compassone_delete_webhook_channel details
[Blackpoint CompassOne] Soft-delete a webhook notification channel by id (from compassone_list_webhook_channels). Destructive — every notification currently routed through this channel stops being delivered to its endpoint. Returns the raw CompassOne response.
compassone_duplicate_webhook_channel details
compassone_duplicate_webhook_channel details
[Blackpoint CompassOne] Duplicate a webhook notification channel by id (from compassone_list_webhook_channels), copying its url, headers and settings under a new name. The name parameter is REQUIRED. Returns the raw new channel JSON including its new id.
compassone_get_webhook_channel details
compassone_get_webhook_channel details
[Blackpoint CompassOne] Get a single webhook notification channel by id (from compassone_list_webhook_channels). Returns the raw channel JSON including its target url, custom headers, enabled flag and owning account/tenant.
compassone_list_webhook_channels details
compassone_list_webhook_channels details
[Blackpoint CompassOne] Search webhook notification channels. This is a READ that does not modify anything — CompassOne exposes it as a POST only because the accountId/tenantId scoping travels in the request body while paging, sorting and filtering travel as query params. No parameter is required; omit them all to list every channel the token can see. Page-based paging (pageSize max 1000). Use compassone_get_webhook_channel for one channel's detail; the returned id is what compassone_update_webhook_channel, compassone_delete_webhook_channel, compassone_duplicate_webhook_channel and compassone_test_webhook_channel take. Returns the raw CompassOne JSON.
compassone_test_webhook_channel details
compassone_test_webhook_channel details
[Blackpoint CompassOne] Send a test notification through a webhook notification channel by id (from compassone_list_webhook_channels). This really POSTs to the channel's configured url, so it is a write rather than a read, but it changes no configuration. Takes no body beyond the id. Returns the raw CompassOne response.
compassone_update_webhook_channel details
compassone_update_webhook_channel details
[Blackpoint CompassOne] Update a webhook notification channel by id (from compassone_list_webhook_channels). Every field is optional — supply only what changes. Editable: name, enabled, url, apiSecretNameHeader, headers. Supplying headers REPLACES the whole header object rather than merging into it. Returns the raw updated channel JSON.
Notification Routing
compassone_block_notification_tenant details
compassone_block_notification_tenant details
[Blackpoint CompassOne] Block one CompassOne tenant from receiving one notification type. BOTH emailType and tenantId are REQUIRED. Destructive — this suppresses that entire class of notification for that customer for as long as the block stands, so blocking a security type such as DarkWebAlertNotification silences those alerts outright. Check the current state first with compassone_check_notification_blocklist, and reverse with compassone_unblock_notification_tenant. Returns the raw CompassOne response.
compassone_check_notification_blocklist details
compassone_check_notification_blocklist details
[Blackpoint CompassOne] Check whether one CompassOne tenant is currently blocked from receiving one notification type. BOTH emailType and tenantId are REQUIRED. Use this before compassone_block_notification_tenant or compassone_unblock_notification_tenant to confirm the current state. Returns the raw CompassOne JSON.
compassone_list_notification_channels details
compassone_list_notification_channels details
[Blackpoint CompassOne] Search notification channels of every type (email and webhook together) in one call. This is a READ that does not modify anything — CompassOne exposes it as a POST only because the accountId/tenantId scoping travels in the request body while paging, sorting and filtering travel as query params. No parameter is required; omit them all to list every channel the token can see. Page-based paging (pageSize max 1000). For type-specific detail and editing use compassone_get_email_channel / compassone_get_webhook_channel. Returns the raw CompassOne JSON.
compassone_unblock_notification_tenant details
compassone_unblock_notification_tenant details
[Blackpoint CompassOne] Unblock one CompassOne tenant for one notification type, restoring delivery of that type. BOTH emailType and tenantId are REQUIRED, and are sent as a request body on the DELETE. Flagged destructive because it changes notification routing for a customer — it restores rather than removes delivery, so the flag errs deliberately toward prompting. Check the current state first with compassone_check_notification_blocklist. Returns the raw CompassOne response.
Reports
compassone_get_report_binary details
compassone_get_report_binary details
[Blackpoint CompassOne] Get one report's PDF as a BASE64-ENCODED STRING INSIDE A JSON OBJECT — despite the name this is not a byte stream, and the payload can be large. Prefer compassone_get_report_url when a downloadable link will do, or compassone_get_report_json when you need the data rather than the document. Get the id from compassone_list_reports. Returns the raw CompassOne JSON.
compassone_get_report_json details
compassone_get_report_json details
[Blackpoint CompassOne] Get one report's structured data as JSON — the best choice when an agent needs to read or summarize report contents rather than hand a file to a human. Get the id from compassone_list_reports. Returns the raw CompassOne JSON.
compassone_get_report_url details
compassone_get_report_url details
[Blackpoint CompassOne] Get a signed download URL for one report's PDF — the right choice for sharing a report with a person. This returns the URL as JSON, NOT the PDF bytes; fetch the URL separately to download the file. Get the id from compassone_list_reports. Returns the raw CompassOne JSON.
compassone_list_reports details
compassone_list_reports details
[Blackpoint CompassOne] List the generated reports for the authenticated tenant, optionally filtered by type and interval-start date range. reportType is one of Cloud, Executive, MDR. Page-based paging (default pageSize 100, max 1000). Note this endpoint's sortOrder values are LOWERCASE (asc / desc), unlike the uppercase ASC / DESC used elsewhere in the CompassOne API. Use the returned id with compassone_get_report_json (data), compassone_get_report_url (shareable link) or compassone_get_report_binary (base64 PDF). Returns the raw CompassOne JSON.
Security Posture
compassone_bulk_attest_metrics details
compassone_bulk_attest_metrics details
[Blackpoint CompassOne] Attest one metric across many customers in a single call. Both metricCalculationId (from compassone_list_attestable_metrics) and accountId (from compassone_list_accounts) are REQUIRED. Set applyToAllCustomers to true to cover every customer under the account; when it is false or omitted, supply the customerIds to target. Returns the raw CompassOne JSON.
compassone_bulk_delete_metric_attestations details
compassone_bulk_delete_metric_attestations details
[Blackpoint CompassOne] Delete one metric's attestations across many customers in a single call. Destructive and broad — every targeted customer's suppression is removed and the metric starts deducting from their Security Posture Rating again. Both metricCalculationId and accountId (from compassone_list_accounts) are REQUIRED. Set applyToAllCustomers to true to clear every customer under the account; when it is false or omitted, customerIds is REQUIRED and selects the targets. Prefer compassone_delete_metric_attestation for a single tenant. Returns the raw CompassOne response.
compassone_create_metric_attestation details
compassone_create_metric_attestation details
[Blackpoint CompassOne] Create a metric attestation, suppressing that metric's deduction from the Security Posture Rating. metricCalculationId is REQUIRED (from compassone_list_attestable_metrics). Optionally set expiresAt so the attestation lapses automatically, and reason to record why. Use compassone_bulk_attest_metrics to attest one metric across many customers at once. Returns the raw created attestation JSON.
compassone_delete_metric_attestation details
compassone_delete_metric_attestation details
[Blackpoint CompassOne] Delete a metric attestation by calculation id. Destructive — the suppression is removed and the metric starts deducting from the Security Posture Rating again. metricCalculationId is REQUIRED (note the sibling read tool spells the same value calculationId — that difference is CompassOne's). Returns the raw CompassOne response.
compassone_get_all_tenant_ratings details
compassone_get_all_tenant_ratings details
[Blackpoint CompassOne] Get the security posture rating for every tenant on the account, one row per tenant — the fleet-wide comparison view. Use compassone_get_security_posture_rating for the current tenant's own rating detail. Page-based paging (pageSize max 1000). Optionally restrict to specific tenants with tenantIds (ids from compassone_list_tenants). No parameter is required. Returns the raw CompassOne JSON.
compassone_get_metric_attestation details
compassone_get_metric_attestation details
[Blackpoint CompassOne] Get one active metric attestation by the calculation id it is attached to. calculationId is REQUIRED (get calculation ids from compassone_list_attestable_metrics or compassone_list_metric_attestations). Note the sibling delete tool names the same value metricCalculationId — that spelling difference is CompassOne's, not a typo. Returns the raw CompassOne JSON.
compassone_get_rating_categories details
compassone_get_rating_categories details
[Blackpoint CompassOne] Get the security posture rating broken out by Operational and NIST category — the per-category scores behind the single number returned by compassone_get_security_posture_rating. Takes no parameters. Returns the raw CompassOne JSON.
compassone_get_rating_history details
compassone_get_rating_history details
[Blackpoint CompassOne] Get the security posture rating history — the SPR trend over time. historyRange is REQUIRED and must be exactly one of: months_1, months_6, months_12. Use compassone_get_security_posture_rating for the current point-in-time rating. Returns the raw CompassOne JSON.
compassone_get_security_posture_rating details
compassone_get_security_posture_rating details
[Blackpoint CompassOne] Get the most recent Security Posture Rating (SPR) with its calculation results. By default only metrics that deducted points are returned; set includeNonDeductions to true to also see the metrics that passed. Use compassone_get_rating_categories for the Operational/NIST category breakdown, compassone_get_rating_history for the trend, and compassone_get_all_tenant_ratings for every tenant at once. No parameter is required. Returns the raw CompassOne JSON.
compassone_list_attestable_metrics details
compassone_list_attestable_metrics details
[Blackpoint CompassOne] List every active attestable metric calculation — the candidates you can attest with compassone_create_metric_attestation or compassone_bulk_attest_metrics. Each entry's calculation id is the metricCalculationId those tools require. Takes no parameters. Returns the raw CompassOne JSON.
compassone_list_metric_attestations details
compassone_list_metric_attestations details
[Blackpoint CompassOne] List every active metric attestation for the tenant. An attestation suppresses a metric's deduction from the Security Posture Rating until it expires. Takes no parameters. Use compassone_list_attestable_metrics to see which metric calculations can be attested, and compassone_get_metric_attestation to look one up by calculation id. Returns the raw CompassOne JSON.
Accounts
compassone_get_account details
compassone_get_account details
[Blackpoint CompassOne] Get one CompassOne account's full detail. accountId is REQUIRED and is a path segment — get it from compassone_list_accounts. Set includeBranding to pull the account's branding block and includeLogo to pull its logo; both are omitted by default to keep the response small. Returns the raw account JSON.
compassone_list_accounts details
compassone_list_accounts details
[Blackpoint CompassOne] List CompassOne accounts (the partner/MSP-level records that own tenants). START HERE for id discovery: the id of each account returned is the accountId that compassone_get_account, compassone_get_tenant, the user tools and the contact-group tools all take, and that compassone_list_tenants accepts as a filter. Page-based paging (pageSize max 1000). No parameter is required. Returns the raw CompassOne JSON.
Tenants
compassone_get_tenant details
compassone_get_tenant details
[Blackpoint CompassOne] Get one CompassOne tenant's full detail. BOTH accountId and tenantId are REQUIRED and are path segments — accountId is the UUID of the account that owns the tenant (from compassone_list_accounts) and tenantId is the UUID of the tenant itself (from compassone_list_tenants, which also reports each tenant's account). Returns the raw tenant JSON.
compassone_list_tenants details
compassone_list_tenants details
[Blackpoint CompassOne] List CompassOne tenants (end customers). START HERE for id discovery: the id of each tenant returned is the tenantId that every CompassOne cloud-* tool requires (compassone_list_cloud_* / compassone_get_cloud_* and the Microsoft 365, Google Workspace and Cisco Duo Cloud MDR tools). Optionally narrow to one account with accountId (from compassone_list_accounts). Page-based paging (pageSize max 1000). No parameter is required. Returns the raw CompassOne JSON.
Users
compassone_assign_users_to_tenant details
compassone_assign_users_to_tenant details
[Blackpoint CompassOne] Assign one or more existing users to a tenant, granting them access to that tenant's data. accountId and tenantId are REQUIRED path parameters; userIds is a REQUIRED list of 1 to 200 user UUIDs. Get candidates from compassone_list_unassigned_tenant_users. The inverse is compassone_unassign_users_from_tenant. Returns the raw CompassOne JSON.
compassone_delete_account_user details
compassone_delete_account_user details
[Blackpoint CompassOne] Delete a user FROM ONE ACCOUNT — the user must have been created under that account. Destructive and not undoable. This is the middle of the three CompassOne user removals: compassone_unassign_users_from_tenant only revokes one tenant's access, while compassone_delete_user removes the user record outright regardless of account. Both accountId and userId are REQUIRED path parameters. Returns the raw CompassOne JSON.
compassone_delete_user details
compassone_delete_user details
[Blackpoint CompassOne] Delete a user OUTRIGHT by user id — the broadest of the three CompassOne user removals and not undoable: the user record itself is removed, along with every account and tenant assignment it had. Prefer compassone_delete_account_user to remove them from a single account, or compassone_unassign_users_from_tenant to revoke only one tenant's access. userId is REQUIRED (from compassone_list_users). Returns the raw CompassOne JSON.
compassone_invite_user_to_account details
compassone_invite_user_to_account details
[Blackpoint CompassOne] Invite a user to an account. accountId is REQUIRED (from compassone_list_accounts); name and email are REQUIRED body fields. Optionally grant RBAC roles and assign the invitee to tenants up front. CompassOne emails the invitation. Returns the raw CompassOne JSON.
compassone_list_account_users details
compassone_list_account_users details
[Blackpoint CompassOne] List every user with access to one account AND to that account's tenants. accountId is REQUIRED (from compassone_list_accounts). Page-based paging (pageSize max 1000). For the narrower per-tenant roster use compassone_list_tenant_users. Returns the raw CompassOne JSON.
compassone_list_tenant_users details
compassone_list_tenant_users details
[Blackpoint CompassOne] List the users that ARE assigned to one tenant. Both accountId (REQUIRED, from compassone_list_accounts) and tenantId (REQUIRED, from compassone_list_tenants) are path parameters. This is the assigned half of a pair — for the users of the account that are NOT yet assigned to this tenant, use compassone_list_unassigned_tenant_users. Page-based paging (pageSize max 1000). Returns the raw CompassOne JSON.
compassone_list_unassigned_tenant_users details
compassone_list_unassigned_tenant_users details
[Blackpoint CompassOne] List the tenant users that are NOT assigned to the given tenant — the candidate pool for compassone_assign_users_to_tenant. Both accountId (REQUIRED, from compassone_list_accounts) and tenantId (REQUIRED, from compassone_list_tenants) are path parameters. This is the unassigned half of a pair: compassone_list_tenant_users returns the users that ARE assigned. Page-based paging (pageSize max 1000). Returns the raw CompassOne JSON.
compassone_list_users details
compassone_list_users details
[Blackpoint CompassOne] List every user visible to the CompassOne token, across all accounts it can see. Page-based paging (pageSize max 1000). Use compassone_list_account_users to scope to one account, or compassone_list_tenant_users to scope to one tenant. The returned user id is what compassone_delete_user, compassone_reset_user_password and compassone_update_account_user take. Returns the raw CompassOne JSON.
compassone_reset_user_password details
compassone_reset_user_password details
[Blackpoint CompassOne] Send a password-reset email to one user. Marked destructive even though it is a POST with no body: it invalidates the user's live credential, so the user cannot sign in until they complete the emailed reset, and the action cannot be undone. userId is REQUIRED (from compassone_list_users). Returns the raw CompassOne JSON.
compassone_unassign_users_from_tenant details
compassone_unassign_users_from_tenant details
[Blackpoint CompassOne] Unassign one or more users FROM ONE TENANT — the mildest of the three CompassOne user removals: the user accounts survive and keep every other tenant assignment, they simply lose access to this tenant's data. Compare compassone_delete_account_user (removes the user from one account) and compassone_delete_user (deletes the user outright). accountId and tenantId are REQUIRED path parameters; userIds is a REQUIRED list of 1 to 200 user UUIDs (from compassone_list_tenant_users). Destructive — sent as a DELETE with a JSON body. Returns the raw CompassOne JSON.
compassone_update_account_user details
compassone_update_account_user details
[Blackpoint CompassOne] Update another account user's name, RBAC roles and tenant assignments. accountId and userId are REQUIRED path parameters; CompassOne requires all three body fields (name, roles, tenantIdsToAssign) on every call, so both lists are full REPLACEMENTS of the user's current roles and tenant assignments — read the user first with compassone_list_account_users and resend the full sets. This endpoint cannot update the calling user's own record. Returns the raw CompassOne JSON.
Contact Groups
compassone_assign_contact_group_tenants details
compassone_assign_contact_group_tenants details
[Blackpoint CompassOne] Assign tenants to a contact group, so CompassOne escalates those tenants' incidents to this group's members. accountId and contactGroupId are REQUIRED path parameters; tenantIds is a REQUIRED list of tenant UUIDs. Get candidates from compassone_list_contact_group_unassigned_tenants. Returns the raw CompassOne JSON.
compassone_create_contact_group details
compassone_create_contact_group details
[Blackpoint CompassOne] Create a contact group for an account. accountId is REQUIRED (from compassone_list_accounts); name (max 100 chars) and members are REQUIRED body fields. members is a JSON ARRAY of member objects, each with all six of name, phoneNumber, email, availability, timezone and priority — CompassOne accepts a minimum of 1 member but documents that at least 3 are required for a usable escalation list. Attach tenants afterwards with compassone_assign_contact_group_tenants. Returns the raw created contact group JSON including its new id.
compassone_create_contact_group_member details
compassone_create_contact_group_member details
[Blackpoint CompassOne] Add one member (escalation contact) to an existing contact group. accountId and contactGroupId are REQUIRED path parameters, and CompassOne requires ALL SIX body fields: name, phoneNumber, email, availability, timezone and priority. availability must be one of: After Hours, All Hours, Business Hours. priority is a number with a minimum of 1 and orders the escalation. This adds a member without touching the rest of the roster — compassone_update_contact_group replaces the whole roster instead. Returns the raw created member JSON.
compassone_delete_contact_group details
compassone_delete_contact_group details
[Blackpoint CompassOne] Delete ONE contact group by id. Destructive and not undoable — the group's member roster and tenant assignments go with it, and the affected tenants lose that escalation path. accountId and contactGroupId are REQUIRED path parameters. To remove a single contact instead of the whole group, use compassone_delete_contact_group_member. Returns the raw CompassOne JSON.
compassone_delete_contact_group_member details
compassone_delete_contact_group_member details
[Blackpoint CompassOne] Delete one member from a contact group. Destructive and not undoable — that contact stops being escalated to, while the group itself and its other members survive. All three of accountId, contactGroupId and memberId are REQUIRED path parameters (memberId from compassone_list_contact_group_members). Returns the raw CompassOne JSON.
compassone_delete_contact_groups details
compassone_delete_contact_groups details
[Blackpoint CompassOne] Delete MULTIPLE contact groups in one call. Destructive and not undoable — each group's member roster and tenant assignments go with it, and the affected tenants lose that escalation path. accountId is a REQUIRED path parameter; contactGroupIds is a REQUIRED list of at least 1 contact group UUID (from compassone_list_contact_groups). Sent as a DELETE with a JSON body. For a single group prefer compassone_delete_contact_group. Returns the raw CompassOne JSON.
compassone_get_contact_group details
compassone_get_contact_group details
[Blackpoint CompassOne] Get one contact group by id. accountId and contactGroupId are REQUIRED path parameters (from compassone_list_accounts and compassone_list_contact_groups). Set includeMembers and/or includeAssignedTenants to true to inline those collections — both default to omitted, in which case CompassOne returns the group without them. Returns the raw CompassOne JSON.
compassone_get_contact_group_member details
compassone_get_contact_group_member details
[Blackpoint CompassOne] Get one contact group member by id. All three of accountId, contactGroupId and memberId are REQUIRED path parameters (memberId comes from compassone_list_contact_group_members). Returns the raw member JSON including name, phoneNumber, email, availability, timezone and priority.
compassone_list_contact_group_members details
compassone_list_contact_group_members details
[Blackpoint CompassOne] List one contact group's members (the escalation contacts, in priority order). accountId and contactGroupId are REQUIRED path parameters. Page-based paging (pageSize max 1000). The returned member id is what compassone_get_contact_group_member and compassone_delete_contact_group_member take. Returns the raw CompassOne JSON.
compassone_list_contact_group_tenants details
compassone_list_contact_group_tenants details
[Blackpoint CompassOne] List the tenants that ARE assigned to one contact group. accountId and contactGroupId are REQUIRED path parameters. This is the assigned half of a pair — for the account's tenants NOT yet attached to this group, use compassone_list_contact_group_unassigned_tenants. Page-based paging (pageSize max 1000). Returns the raw CompassOne JSON.
compassone_list_contact_group_unassigned_tenants details
compassone_list_contact_group_unassigned_tenants details
[Blackpoint CompassOne] List the tenants that are NOT assigned to the given contact group — the candidate pool for compassone_assign_contact_group_tenants. accountId and contactGroupId are REQUIRED path parameters. This is the unassigned half of a pair: compassone_list_contact_group_tenants returns the tenants that ARE assigned. Page-based paging (pageSize max 1000). Returns the raw CompassOne JSON.
compassone_list_contact_groups details
compassone_list_contact_groups details
[Blackpoint CompassOne] List an account's contact groups (escalation contact lists). accountId is REQUIRED (from compassone_list_accounts). Page-based paging (pageSize max 1000). Two extra nested page sizes control how much of each group is inlined: tenantsPageSize (0-200, default 0) and membersPageSize (0-25, default 0) — 0 omits that collection entirely, so ask for what you need rather than fetching every roster. The returned contact group id is what every other contact-group tool takes. Returns the raw CompassOne JSON.
compassone_update_contact_group details
compassone_update_contact_group details
[Blackpoint CompassOne] Update one contact group. accountId and contactGroupId are REQUIRED path parameters; name and members are REQUIRED body fields on every call. The members array is a FULL REPLACEMENT of the roster: include a member's id to update it, omit the id to add a new member, and leave a member out entirely to remove it. Read the current roster first with compassone_list_contact_group_members so you do not drop contacts by accident. To add a single member without resending the roster, use compassone_create_contact_group_member instead. Returns the raw updated contact group JSON.
More in Tools Reference
Atera ToolsAuvik ToolsAvanan (Check Point Harmony Email) ToolsConnectWise Sell ToolsStill need help? Ask the team