Skip to main content
Connector guides

Connect Blackpoint CompassOne

Blackpoint CompassOne is a managed detection and response (MDR) and security operations platform for MSPs — the SOC detections Blackpoint raises on your customers, the asset inventory behind them,…

Written By Christopher Scaminaci

Last updated 6 days ago

Blackpoint CompassOne is a managed detection and response (MDR) and security operations platform for MSPs — the SOC detections Blackpoint raises on your customers, the asset inventory behind them, cloud MDR for Microsoft 365, Google Workspace and Cisco Duo, cloud posture policy, vulnerability management, dark-web and external exposure findings, and the customer, user and contact-group administration around it all. StackJack talks to CompassOne through the CompassOne public API.

Connecting CompassOne to StackJack gives your AI assistant a broad family of compassone_ MCP tools — MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:

  • Triage detections — list and inspect alert groups, drill into the individual alerts inside one, and pull the aggregate views (counts, weekly trend, top detections by host, user or threat type)
  • Inventory assets across every entity class — devices, people, software, services, containers and more — and walk the relationship graph between them
  • Assess risk — the vulnerability register with its affected assets, CVE detail and references, severity and per-customer rollups, dark-web credential exposures, and external attack-surface scan findings
  • Report — list generated MDR, Cloud and Executive reports and fetch each as structured data or a shareable download link
  • Review posture — security-posture ratings, category scores and history, plus the metric attestations behind them
  • Manage (on Pro plans) cloud MDR onboardings and approved-country policy, cloud posture policies and their assignments, scans and schedules, vulnerability status, notification channels, and your customers' users and contact groups

How StackJack authenticates to CompassOne

CompassOne uses a single API key. You generate the key in the CompassOne console, and StackJack sends it on every request as a bearer credential. There is no client ID, sign-in redirect, or refresh flow.

Blackpoint's public API contract confirms the Bearer scheme and fixed API host, but it does not publish an exact lifetime for keys, selectable per-key scopes, or a guaranteed mapping from the creating user's console role to API access. Treat the key as high privilege. Create it only from an authorized account admin, verify its effective reach with read-only calls before you rely on it, and use StackJack's per-tool permissions to limit what an AI may call. If a narrow set of calls returns 403, confirm the account's subscription and access with Blackpoint support instead of assuming how the key is scoped.

CompassOne is a global service with one address (https://api.blackpointcyber.com) — there are no regional endpoints, so there is no region to choose.

Working across your customers

Most of the cloud MDR tools act on one of your customers at a time and take that customer's tenant id. Two read tools are the entry points for finding those ids, and the other tools' descriptions point back at them:

  • compassone_list_tenants — your customers, and the tenant id each cloud tool needs
  • compassone_list_accounts — the account ids the user and contact-group tools need

If a cloud tool returns "not found" for an id that looks correct, the usual cause is that the id belongs to a different customer than the one being scoped.

Before you begin

  • In StackJack: you need a role that can manage connectors (tenant Owner, a co-owner, or an Administrator).
  • In CompassOne: you need an account admin who is authorized to create an account-level API key.

Step 1 — Generate an API key in the CompassOne console

  1. Sign in to the Blackpoint CompassOne console as an account admin who is authorized to create account-level API keys.
  2. Open avatar → API Keys.
  3. Choose + Add API Key, give the key a name that identifies StackJack, and create it.
  4. Record any expiry or access details shown in your tenant. The public API contract does not publish an exact lifetime or per-key scope model.
  5. Copy the key immediately and store it securely — treat it like a password. Blackpoint's public API contract does not say whether the secret can be displayed again.

Step 2 — Add the credential in StackJack

  1. In the StackJack portal, open Connectors.
  2. Find the Blackpoint CompassOne card. Click How To Connect for the same steps inline, or Configure to enter the API key.
  3. Paste your API key. There is no client ID or URL to enter — the address is fixed.
  4. Click Save.

What happens when you save

  • The key is stored encrypted in Azure Key Vault — never in the StackJack database, and never shown back to you.
  • If this is the first time you configure CompassOne, a Free-tier subscription for the connector is created automatically so its Free tools work right away.
  • StackJack immediately live-validates the API key by making a cheap authenticated read against your CompassOne account. Validation never blocks the save: you'll either see a success confirmation or a "saved but validation failed" warning with the reason.
  • The connector card shows the current connection and validity status from then on.

Plans and available tools

  • Free includes reads for detections and alerts plus aggregate views; asset inventory and relationships; collections; the vulnerability register, affected assets, CVE detail and references, and severity/customer rollups; scans and schedules; dark-web and external exposure findings; reports; security-posture ratings, categories, history and attestations; notification channels and blocklist checks; and accounts, customers, users and contact groups.
  • Pro adds cloud MDR onboarding and approved-country policy actions; cloud posture policy lifecycle, assignment and templating; scan and schedule lifecycle and exports; vulnerability status changes and deletions; notification channel management, test sends and blocklisting; metric attestations; and user invitations, updates, tenant assignment and contact-group management.
  • Business offers the same tool set as Pro with a higher monthly call quota.

See the generated Blackpoint CompassOne tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.

CompassOne has no per-user sign-in through StackJack (the key is a shared account credential), so API calls are not attributed to the individual person using the AI. Current pricing and quotas are shown in the portal's Billing page and at checkout.

A note on sensitive actions. StackJack marks the Pro operations that permanently remove data, hide a finding, or change what your customers are protected against as destructive — deleting policies, scans, vulnerability history, collections, contact groups and users; abandoning a cloud onboarding, which also tears down the integration on the customer's side; cancelling a scan that is already running; resetting a user's password; blocking a whole class of notification for a customer, which silences those alerts until you unblock it; attesting a security-posture metric, which suppresses that rating deduction (and in the bulk form, for every customer under the account at once); and updates that replace a contact group's membership, a user's tenant assignments, or a policy's connection assignments wholesale, where leaving a list out removes what was there. Whether your AI application asks you to confirm before running one depends on that application's own settings — see Destructive tools and confirmation. Review those settings, and scope your AI's access deliberately: use the tool selections on the MCP Setup page and the Permissions page to enable only the actions you want an AI to take.

Two ways to close a vulnerability. Marking a vulnerability resolved and deleting its records are different outcomes, and the delete is not reversible — it removes the finding history for those machines rather than recording that you handled it. If you want your AI to triage vulnerabilities without discarding history, enable the status-update tools and leave the delete tools switched off.

Rate limits

CompassOne meters API traffic per account but does not publish a specific numeric allowance. StackJack paces requests conservatively. When CompassOne returns a rate-limit response, replay-safe reads may be retried with backoff; writes are never replayed automatically, and any read that is still rate-limited after its retry budget fails. Wait briefly and retry deliberately with less parallelism or smaller pages.

Rotating or replacing the key

The API key is the recovery secret. StackJack cannot refresh or renew it. If the key is revoked, expires, or is replaced in the CompassOne console, the stored credential stops working. To restore access, create a current key under avatar → API Keys, then open Connectors → Blackpoint CompassOne → Configure in StackJack, paste the key, and Save.

To change what an AI can reach, first narrow its allowed tools in StackJack. If CompassOne itself returns a permission error, confirm the required subscription and account access with Blackpoint support; the public API contract does not document a per-key scope editor or promise that recreating a key under a different console user changes its reach.

Troubleshooting

SymptomLikely causeWhat to do
"Saved but validation failed" right after savingThe key was mis-pasted, revoked, expired, or replaced in the CompassOne consoleCreate or re-copy a current key under avatar → API Keys and paste it again in Connectors → Blackpoint CompassOne → Configure
Tools worked, then started failing with an auth errorThe key was revoked, expired, or replaced in CompassOneCreate a current key and update the credential in Connectors → Blackpoint CompassOne → Configure
One tool returns a 403 while others succeedThe account's subscription or effective API access does not include that operationCheck the operation in CompassOne and contact Blackpoint support. The public API contract does not publish a per-key scope model, so do not broaden console roles on guesswork
A cloud tool returns "not found" for an id you can see in CompassOneThe id belongs to a different customer than the one being scopedConfirm the customer with compassone_list_tenants, then re-run with that customer's tenant id
An asset or collection tool fails saying a value is requiredThose tools need an entity class (and collections need a context) — CompassOne rejects the call without itAsk your AI to include the class or context, for example DEVICE or USER for assets
Write or action tools missing from your AI's tool listConnector is on the Free tier, or the tools aren't selected for your clientUpgrade the Blackpoint CompassOne connector plan and check your tool selections on the MCP Setup page
HTTP 429 under heavy useCompassOne's unpublished account allowance was exceededReplay-safe reads may retry with backoff, but writes are not replayed and exhausted reads fail; wait briefly, reduce parallelism or page size, then retry deliberately
A report download link stops workingTreat returned report URLs as short-lived credentials; Blackpoint's public contract does not publish their exact TTLRe-run the report link tool to get a fresh link, and do not store or forward an old URL

Blackpoint CompassOne tools

compassone_ · 148 tools · Free 77 · Pro 71

Detections

ToolWhat it does
compassone_get_alert_group
Free · Read-only
Get one alert group (detection) by id, from compassone_list_alert_groups.
compassone_get_alert_group_count
Free · Read-only
Get the total count of alert groups (detections) in a date window — a cheap way to size a result set before listing it with compassone_list_alert_groups.
compassone_get_alert_groups_by_week
Free · Read-only
Get detection counts aggregated by week — the trend series behind a SOC activity chart.
compassone_get_top_detections_by_entity
Free · Read-only
Get the top detections grouped by an entity field (for example hostname or username) — answers 'which machines or users generate the most detections'.
compassone_get_top_detections_by_threat
Free · Read-only
Get the top detections grouped by threat type — answers 'what kinds of threats are we seeing most'.
compassone_list_alert_groups
Free · Read-only
List alert groups (detections) — the SOC's unit of triage, each grouping related alerts.
compassone_list_alerts_for_alert_group
Free · Read-only
List the individual alerts inside one alert group (detection).

Assets

ToolWhat it does
compassone_get_asset
Free · Read-only
Get a single asset by id (from compassone_list_assets).
compassone_list_asset_relationships
Free · Read-only
List one asset's relationships to other entities.
compassone_list_assets
Free · Read-only
List assets from the CompassOne inventory.

Collections

ToolWhat it does
compassone_create_collection
Pro · Write
Create a collection (saved search).
compassone_delete_collection
Pro · Destructive
Delete a collection by id (from compassone_list_collections).
compassone_get_collection
Free · Read-only
Get a single collection by id (from compassone_list_collections).
compassone_list_collections
Free · Read-only
List collections (saved searches) for one context.
compassone_update_collection
Pro · Write
Update a collection by id (from compassone_list_collections).

Cloud MDR Connections

ToolWhat it does
compassone_approve_connection_country
Pro · Write
Approve a country for a whole cloud-MDR connection, widening the allow-list so sign-ins from there stop raising impossible-travel detections.
compassone_approve_connection_user_country
Pro · Write
Approve a country for ONE user on a cloud-MDR connection, optionally time-boxed to a travel window.
compassone_get_iso_country
Free · Read-only
Get one ISO 3166-1 country by its two-letter alpha-2 code (for example US).
compassone_list_connection_approved_countries
Free · Read-only
List the countries approved for one cloud-MDR connection — the connection-wide allow-list behind CompassOne's impossible-travel detection.
compassone_list_connection_user_approved_countries
Free · Read-only
List the countries approved for ONE user on a cloud-MDR connection — the per-user overrides on top of the connection-wide list returned by compassone_list_connection_approved_countries.
compassone_list_connection_users
Free · Read-only
List the users belonging to one cloud-MDR connection.
compassone_list_iso_countries
Free · Read-only
List the ISO 3166-1 country reference CompassOne recognizes.
compassone_remove_connection_approved_country
Pro · Destructive
Remove an approved country from a whole cloud-MDR connection.
compassone_remove_connection_user_approved_country
Pro · Destructive
Remove an approved country from ONE user on a cloud-MDR connection.

Cisco Duo Cloud MDR

ToolWhat it does
compassone_complete_cisco_onboarding
Pro · Write
Complete a Cisco Duo cloud-MDR onboarding by verifying everything was set up correctly.
compassone_create_cisco_onboarding
Pro · Write
Begin a new Cisco Duo cloud-MDR onboarding for a customer.
compassone_delete_cisco_onboarding
Pro · Destructive
Abandon a Cisco Duo cloud-MDR onboarding.
compassone_get_cisco_onboarding
Free · Read-only
Get the state of one Cisco Duo cloud-MDR onboarding.
compassone_list_cisco_onboardings
Free · Read-only
List the Cisco Duo cloud-MDR onboardings for one CompassOne customer, completed or in progress.
compassone_sync_cisco_users
Pro · Write
Verify the Cisco Duo domain-wide delegation permissions and start the user sync — also the way to restart a sync that never began or stalled.

Google Workspace Cloud MDR

ToolWhat it does
compassone_get_google_onboarding
Free · Read-only
Get the state of one Google Workspace cloud-MDR onboarding.
compassone_list_google_onboardings
Free · Read-only
List the Google Workspace cloud-MDR onboardings for one CompassOne customer, completed or in progress.

Microsoft 365 Cloud MDR

ToolWhat it does
compassone_approve_m365_country
Pro · Write
Approve a country for a whole Microsoft 365 connection, so sign-ins from there stop raising impossible-travel detections for every user on the connection.
compassone_approve_m365_user_country
Pro · Write
Approve a country for ONE Microsoft 365 user, optionally time-boxed to a travel window.
compassone_get_m365_connection
Free · Read-only
Get one Microsoft 365 Defense connection by id.
compassone_list_m365_approved_countries
Free · Read-only
List the countries approved for a whole Microsoft 365 connection — the connection-wide allow-list behind impossible-travel detection.
compassone_list_m365_connections
Free · Read-only
List the Microsoft 365 Defense connections belonging to one CompassOne customer.
compassone_list_m365_user_approved_countries
Free · Read-only
List the currently-active approved countries for ONE Microsoft 365 user — the per-user overrides on top of the connection-wide list from compassone_list_m365_approved_countries.
compassone_list_m365_users
Free · Read-only
List the users on one Microsoft 365 Defense connection, filterable by enabled / licensed / billable state and by name-or-email substring.
compassone_remove_m365_approved_country
Pro · Destructive
Remove an approved country from a whole Microsoft 365 connection.
compassone_remove_m365_user_approved_country
Pro · Destructive
Remove an approved country from ONE Microsoft 365 user.

Cloud Posture

ToolWhat it does
compassone_bulk_delete_managed_policies
Pro · Destructive
Delete several managed policies at once by id.
compassone_create_managed_policy
Pro · Write
Create a managed policy.
compassone_delete_managed_policy
Pro · Destructive
Delete one managed policy by id.
compassone_get_managed_policy
Free · Read-only
Get one managed policy by id (from compassone_list_managed_policies_by_scope).
compassone_list_managed_policies_by_scope
Free · Read-only
List every managed policy applicable to one scope.
compassone_save_managed_policy_as_template
Pro · Write
Save an existing managed policy as a new reusable policy template.
compassone_update_managed_policy
Pro · Write
Update a managed policy by id.
compassone_update_managed_policy_assignments
Pro · Destructive
Assign and unassign connections on a managed policy in a single call.

Vulnerabilities

ToolWhat it does
compassone_bulk_delete_vulnerabilities
Pro · Destructive
Delete several vulnerabilities outright, across every device they were found on.
compassone_bulk_delete_vulnerabilities_for_device
Pro · Destructive
Delete several vulnerabilities' records for ONE device.
compassone_bulk_update_vulnerabilities
Pro · Write
Update the status of several vulnerabilities at once, across all their devices.
compassone_bulk_update_vulnerabilities_for_device
Pro · Write
Update the status of several vulnerabilities on ONE device.
compassone_delete_vulnerability_for_devices
Pro · Destructive
Delete one vulnerability's records for specific devices.
compassone_export_vulnerabilities
Pro · Write
Request an export of the vulnerability register.
compassone_export_vulnerability_assets
Pro · Write
Request an export of the assets affected by one vulnerability.
compassone_get_cve
Free · Read-only
Get CVE detail by CVE id.
compassone_get_cve_references
Free · Read-only
Get the external reference links for one CVE — advisories, patches and vendor bulletins.
compassone_get_vulnerabilities_count_by_severity
Free · Read-only
Get vulnerability counts grouped by severity — the numbers behind a risk-posture summary.
compassone_get_vulnerabilities_count_by_tenant
Free · Read-only
Get vulnerability counts grouped by CompassOne tenant — the cross-customer view an MSP uses to see which customers carry the most risk.
compassone_get_vulnerability
Free · Read-only
Get one vulnerability by id (from compassone_list_vulnerabilities).
compassone_list_vulnerabilities
Free · Read-only
List the vulnerability register with the connector's richest filter set.
compassone_list_vulnerability_assets
Free · Read-only
List the assets affected by one vulnerability — the remediation work list.
compassone_update_vulnerability_status_for_devices
Pro · Write
Set one vulnerability's status on specific devices — how you mark it resolved, accepted or a false positive per machine.

Scans

ToolWhat it does
compassone_bulk_delete_scans_and_schedules
Pro · Destructive
Bulk delete scans and/or scan schedules by id.
compassone_bulk_update_scan_schedules
Pro · Write
Bulk update the status of many scan schedules in one call.
compassone_cancel_scan
Pro · Destructive
Cancel an in-flight vulnerability-management scan by id.
compassone_create_scan
Pro · Write
Create (queue) a new vulnerability-management scan.
compassone_delete_scan
Pro · Destructive
Delete a vulnerability-management scan by id.
compassone_export_scan_cves
Pro · Write
Queue an export of the CVEs found by one scan (documented for network scans).
compassone_export_scans
Pro · Write
Queue an export of scans and schedules.
compassone_get_scan
Free · Read-only
Get a single vulnerability-management scan by id, including its type, status, configuration and result.
compassone_get_scan_stats
Free · Read-only
Get aggregate scan statistics across the account (counts by type/status as CompassOne reports them).
compassone_list_scan_cves
Free · Read-only
List the CVEs a specific scan found, with severity, CVSS base score and CompassOne's asset-environmental (priority) score.
compassone_list_scans
Free · Read-only
List vulnerability-management scan runs (schedules excluded — use compassone_list_scan_schedules for those).
compassone_list_scans_and_schedules
Free · Read-only
List vulnerability-management scans AND scan schedules in one combined index, so a single call shows both completed runs and the recurring definitions that produce them.
compassone_update_scan
Pro · Write
Update a vulnerability-management scan by id.

Scan Schedules

ToolWhat it does
compassone_create_scan_schedule
Pro · Write
Create a recurring vulnerability-management scan schedule.
compassone_delete_scan_schedule
Pro · Destructive
Delete a vulnerability-management scan schedule by id.
compassone_get_scan_schedule
Free · Read-only
Get a single vulnerability-management scan schedule by id, including its type, frequency, next run time and status.
compassone_list_scan_schedules
Free · Read-only
List vulnerability-management scan schedules — the recurring definitions, not the runs they produce (use compassone_list_scans for runs).
compassone_run_scan_schedule
Pro · Write
Trigger a scan schedule to run now, outside its normal recurrence.
compassone_update_scan_schedule
Pro · Write
Update a vulnerability-management scan schedule by id.

Exposures

ToolWhat it does
compassone_get_darkweb_report_url
Free · Read-only
Get a signed download URL for the most recent dark-web scan report.
compassone_get_darkweb_scan_exposures
Free · Read-only
List the credential exposures found by the MOST RECENT dark-web scan — there is no scan-id parameter; CompassOne always reports the latest scan.
compassone_get_external_scan_exposures
Free · Read-only
Get the exposures found by one external attack-surface scan, as JSON.
compassone_get_external_scan_report_url
Free · Read-only
Get a signed download URL for one external scan's PDF report.

Email Channels

ToolWhat it does
compassone_create_email_channel
Pro · Write
Create an email notification channel.
compassone_delete_email_channel
Pro · Destructive
Soft-delete an email notification channel by id (from compassone_list_email_channels).
compassone_duplicate_email_channel
Pro · Write
Duplicate an email notification channel by id (from compassone_list_email_channels), copying its recipients and settings under a new name.
compassone_get_email_channel
Free · Read-only
Get a single email notification channel by id (from compassone_list_email_channels).
compassone_list_email_channels
Free · Read-only
Search email notification channels.
compassone_test_email_channel
Pro · Write
Send a test email through an email notification channel by id (from compassone_list_email_channels).
compassone_update_email_channel
Pro · Write
Update an email notification channel by id (from compassone_list_email_channels).

Webhook Channels

ToolWhat it does
compassone_create_webhook_channel
Pro · Write
Create a webhook notification channel.
compassone_delete_webhook_channel
Pro · Destructive
Soft-delete a webhook notification channel by id (from compassone_list_webhook_channels).
compassone_duplicate_webhook_channel
Pro · Write
Duplicate a webhook notification channel by id (from compassone_list_webhook_channels), copying its url, headers and settings under a new name.
compassone_get_webhook_channel
Free · Read-only
Get a single webhook notification channel by id (from compassone_list_webhook_channels).
compassone_list_webhook_channels
Free · Read-only
Search webhook notification channels.
compassone_test_webhook_channel
Pro · Write
Send a test notification through a webhook notification channel by id (from compassone_list_webhook_channels).
compassone_update_webhook_channel
Pro · Write
Update a webhook notification channel by id (from compassone_list_webhook_channels).

Notification Routing

ToolWhat it does
compassone_block_notification_tenant
Pro · Destructive
Block one CompassOne tenant from receiving one notification type.
compassone_check_notification_blocklist
Free · Read-only
Check whether one CompassOne tenant is currently blocked from receiving one notification type.
compassone_list_notification_channels
Free · Read-only
Search notification channels of every type (email and webhook together) in one call.
compassone_unblock_notification_tenant
Pro · Destructive
Unblock one CompassOne tenant for one notification type, restoring delivery of that type.

Reports

ToolWhat it does
compassone_get_report_binary
Free · Read-only
Get one report's PDF as a BASE64-ENCODED STRING INSIDE A JSON OBJECT — despite the name this is not a byte stream, and the payload can be large.
compassone_get_report_json
Free · Read-only
Get one report's structured data as JSON — the best choice when an agent needs to read or summarize report contents rather than hand a file to a human.
compassone_get_report_url
Free · Read-only
Get a signed download URL for one report's PDF — the right choice for sharing a report with a person.
compassone_list_reports
Free · Read-only
List the generated reports for the authenticated tenant, optionally filtered by type and interval-start date range.

Security Posture

ToolWhat it does
compassone_bulk_attest_metrics
Pro · Destructive
Attest one metric across many customers in a single call.
compassone_bulk_delete_metric_attestations
Pro · Destructive
Delete one metric's attestations across many customers in a single call.
compassone_create_metric_attestation
Pro · Destructive
Create a metric attestation, suppressing that metric's deduction from the Security Posture Rating.
compassone_delete_metric_attestation
Pro · Destructive
Delete a metric attestation by calculation id.
compassone_get_all_tenant_ratings
Free · Read-only
Get the security posture rating for every tenant on the account, one row per tenant — the fleet-wide comparison view.
compassone_get_metric_attestation
Free · Read-only
Get one active metric attestation by the calculation id it is attached to.
compassone_get_rating_categories
Free · Read-only
Get the security posture rating broken out by Operational and NIST category — the per-category scores behind the single number returned by compassone_get_security_posture_rating.
compassone_get_rating_history
Free · Read-only
Get the security posture rating history — the SPR trend over time.
compassone_get_security_posture_rating
Free · Read-only
Get the most recent Security Posture Rating (SPR) with its calculation results.
compassone_list_attestable_metrics
Free · Read-only
List every active attestable metric calculation — the candidates you can attest with compassone_create_metric_attestation or compassone_bulk_attest_metrics.
compassone_list_metric_attestations
Free · Read-only
List every active metric attestation for the tenant.

Accounts

ToolWhat it does
compassone_get_account
Free · Read-only
Get one CompassOne account's full detail.
compassone_list_accounts
Free · Read-only
List CompassOne accounts (the partner/MSP-level records that own tenants).

Tenants

ToolWhat it does
compassone_get_tenant
Free · Read-only
Get one CompassOne tenant's full detail.
compassone_list_tenants
Free · Read-only
List CompassOne tenants (end customers).

Users

ToolWhat it does
compassone_assign_users_to_tenant
Pro · Write
Assign one or more existing users to a tenant, granting them access to that tenant's data.
compassone_delete_account_user
Pro · Destructive
Delete a user FROM ONE ACCOUNT — the user must have been created under that account.
compassone_delete_user
Pro · Destructive
Delete a user OUTRIGHT by user id — the broadest of the three CompassOne user removals and not undoable: the user record itself is removed, along with every account and tenant assignment it had.
compassone_invite_user_to_account
Pro · Write
Invite a user to an account.
compassone_list_account_users
Free · Read-only
List every user with access to one account AND to that account's tenants.
compassone_list_tenant_users
Free · Read-only
List the users that ARE assigned to one tenant.
compassone_list_unassigned_tenant_users
Free · Read-only
List the tenant users that are NOT assigned to the given tenant — the candidate pool for compassone_assign_users_to_tenant.
compassone_list_users
Free · Read-only
List every user visible to the CompassOne token, across all accounts it can see.
compassone_reset_user_password
Pro · Destructive
Send a password-reset email to one user.
compassone_unassign_users_from_tenant
Pro · Destructive
Unassign one or more users FROM ONE TENANT — the mildest of the three CompassOne user removals: the user accounts survive and keep every other tenant assignment, they simply lose access to this tenant's data.
compassone_update_account_user
Pro · Destructive
Update another account user's name, RBAC roles and tenant assignments.

Contact Groups

ToolWhat it does
compassone_assign_contact_group_tenants
Pro · Write
Assign tenants to a contact group, so CompassOne escalates those tenants' incidents to this group's members.
compassone_create_contact_group
Pro · Write
Create a contact group for an account.
compassone_create_contact_group_member
Pro · Write
Add one member (escalation contact) to an existing contact group.
compassone_delete_contact_group
Pro · Destructive
Delete ONE contact group by id.
compassone_delete_contact_group_member
Pro · Destructive
Delete one member from a contact group.
compassone_delete_contact_groups
Pro · Destructive
Delete MULTIPLE contact groups in one call.
compassone_get_contact_group
Free · Read-only
Get one contact group by id.
compassone_get_contact_group_member
Free · Read-only
Get one contact group member by id.
compassone_list_contact_group_members
Free · Read-only
List one contact group's members (the escalation contacts, in priority order).
compassone_list_contact_group_tenants
Free · Read-only
List the tenants that ARE assigned to one contact group.
compassone_list_contact_group_unassigned_tenants
Free · Read-only
List the tenants that are NOT assigned to the given contact group — the candidate pool for compassone_assign_contact_group_tenants.
compassone_list_contact_groups
Free · Read-only
List an account's contact groups (escalation contact lists).
compassone_update_contact_group
Pro · Destructive
Update one contact group.