Connect Blackpoint CompassOne
Blackpoint CompassOne is a managed detection and response (MDR) and security operations platform for MSPs — the SOC detections Blackpoint raises on your customers, the asset inventory behind them,…
Written By Christopher Scaminaci
Last updated 6 days ago
Blackpoint CompassOne is a managed detection and response (MDR) and security operations platform for MSPs — the SOC detections Blackpoint raises on your customers, the asset inventory behind them, cloud MDR for Microsoft 365, Google Workspace and Cisco Duo, cloud posture policy, vulnerability management, dark-web and external exposure findings, and the customer, user and contact-group administration around it all. StackJack talks to CompassOne through the CompassOne public API.
Connecting CompassOne to StackJack gives your AI assistant a broad family of compassone_ MCP tools — MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:
- Triage detections — list and inspect alert groups, drill into the individual alerts inside one, and pull the aggregate views (counts, weekly trend, top detections by host, user or threat type)
- Inventory assets across every entity class — devices, people, software, services, containers and more — and walk the relationship graph between them
- Assess risk — the vulnerability register with its affected assets, CVE detail and references, severity and per-customer rollups, dark-web credential exposures, and external attack-surface scan findings
- Report — list generated MDR, Cloud and Executive reports and fetch each as structured data or a shareable download link
- Review posture — security-posture ratings, category scores and history, plus the metric attestations behind them
- Manage (on Pro plans) cloud MDR onboardings and approved-country policy, cloud posture policies and their assignments, scans and schedules, vulnerability status, notification channels, and your customers' users and contact groups
How StackJack authenticates to CompassOne
CompassOne uses a single API key. You generate the key in the CompassOne console, and StackJack sends it on every request as a bearer credential. There is no client ID, sign-in redirect, or refresh flow.
Blackpoint's public API contract confirms the Bearer scheme and fixed API host, but it does not publish an exact lifetime for keys, selectable per-key scopes, or a guaranteed mapping from the creating user's console role to API access. Treat the key as high privilege. Create it only from an authorized account admin, verify its effective reach with read-only calls before you rely on it, and use StackJack's per-tool permissions to limit what an AI may call. If a narrow set of calls returns 403, confirm the account's subscription and access with Blackpoint support instead of assuming how the key is scoped.
CompassOne is a global service with one address (https://api.blackpointcyber.com) — there are no regional endpoints, so there is no region to choose.
Working across your customers
Most of the cloud MDR tools act on one of your customers at a time and take that customer's tenant id. Two read tools are the entry points for finding those ids, and the other tools' descriptions point back at them:
compassone_list_tenants— your customers, and the tenant id each cloud tool needscompassone_list_accounts— the account ids the user and contact-group tools need
If a cloud tool returns "not found" for an id that looks correct, the usual cause is that the id belongs to a different customer than the one being scoped.
Before you begin
- In StackJack: you need a role that can manage connectors (tenant Owner, a co-owner, or an Administrator).
- In CompassOne: you need an account admin who is authorized to create an account-level API key.
Step 1 — Generate an API key in the CompassOne console
- Sign in to the Blackpoint CompassOne console as an account admin who is authorized to create account-level API keys.
- Open avatar → API Keys.
- Choose + Add API Key, give the key a name that identifies StackJack, and create it.
- Record any expiry or access details shown in your tenant. The public API contract does not publish an exact lifetime or per-key scope model.
- Copy the key immediately and store it securely — treat it like a password. Blackpoint's public API contract does not say whether the secret can be displayed again.
Step 2 — Add the credential in StackJack
- In the StackJack portal, open Connectors.
- Find the Blackpoint CompassOne card. Click How To Connect for the same steps inline, or Configure to enter the API key.
- Paste your API key. There is no client ID or URL to enter — the address is fixed.
- Click Save.
What happens when you save
- The key is stored encrypted in Azure Key Vault — never in the StackJack database, and never shown back to you.
- If this is the first time you configure CompassOne, a Free-tier subscription for the connector is created automatically so its Free tools work right away.
- StackJack immediately live-validates the API key by making a cheap authenticated read against your CompassOne account. Validation never blocks the save: you'll either see a success confirmation or a "saved but validation failed" warning with the reason.
- The connector card shows the current connection and validity status from then on.
Plans and available tools
- Free includes reads for detections and alerts plus aggregate views; asset inventory and relationships; collections; the vulnerability register, affected assets, CVE detail and references, and severity/customer rollups; scans and schedules; dark-web and external exposure findings; reports; security-posture ratings, categories, history and attestations; notification channels and blocklist checks; and accounts, customers, users and contact groups.
- Pro adds cloud MDR onboarding and approved-country policy actions; cloud posture policy lifecycle, assignment and templating; scan and schedule lifecycle and exports; vulnerability status changes and deletions; notification channel management, test sends and blocklisting; metric attestations; and user invitations, updates, tenant assignment and contact-group management.
- Business offers the same tool set as Pro with a higher monthly call quota.
See the generated Blackpoint CompassOne tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.
CompassOne has no per-user sign-in through StackJack (the key is a shared account credential), so API calls are not attributed to the individual person using the AI. Current pricing and quotas are shown in the portal's Billing page and at checkout.
A note on sensitive actions. StackJack marks the Pro operations that permanently remove data, hide a finding, or change what your customers are protected against as destructive — deleting policies, scans, vulnerability history, collections, contact groups and users; abandoning a cloud onboarding, which also tears down the integration on the customer's side; cancelling a scan that is already running; resetting a user's password; blocking a whole class of notification for a customer, which silences those alerts until you unblock it; attesting a security-posture metric, which suppresses that rating deduction (and in the bulk form, for every customer under the account at once); and updates that replace a contact group's membership, a user's tenant assignments, or a policy's connection assignments wholesale, where leaving a list out removes what was there. Whether your AI application asks you to confirm before running one depends on that application's own settings — see Destructive tools and confirmation. Review those settings, and scope your AI's access deliberately: use the tool selections on the MCP Setup page and the Permissions page to enable only the actions you want an AI to take.
Two ways to close a vulnerability. Marking a vulnerability resolved and deleting its records are different outcomes, and the delete is not reversible — it removes the finding history for those machines rather than recording that you handled it. If you want your AI to triage vulnerabilities without discarding history, enable the status-update tools and leave the delete tools switched off.
Rate limits
CompassOne meters API traffic per account but does not publish a specific numeric allowance. StackJack paces requests conservatively. When CompassOne returns a rate-limit response, replay-safe reads may be retried with backoff; writes are never replayed automatically, and any read that is still rate-limited after its retry budget fails. Wait briefly and retry deliberately with less parallelism or smaller pages.
Rotating or replacing the key
The API key is the recovery secret. StackJack cannot refresh or renew it. If the key is revoked, expires, or is replaced in the CompassOne console, the stored credential stops working. To restore access, create a current key under avatar → API Keys, then open Connectors → Blackpoint CompassOne → Configure in StackJack, paste the key, and Save.
To change what an AI can reach, first narrow its allowed tools in StackJack. If CompassOne itself returns a permission error, confirm the required subscription and account access with Blackpoint support; the public API contract does not document a per-key scope editor or promise that recreating a key under a different console user changes its reach.
Troubleshooting
Blackpoint CompassOne tools
compassone_ · 148 tools · Free 77 · Pro 71
Detections
Assets
Collections
Cloud MDR Connections
Cisco Duo Cloud MDR
Google Workspace Cloud MDR
Microsoft 365 Cloud MDR
Cloud Posture
Vulnerabilities
Scans
Scan Schedules
Exposures
Email Channels
Webhook Channels
Notification Routing
Reports
Security Posture
Accounts
Tenants
Users
Contact Groups
More in Connector guides
Connect Acronis Cyber Protect CloudConnect Action1Connect AddigyConnect AlertOpsStill need help? Ask the team