Quick Links

Cohort views for MSPs

Overview

The Cohort pages show you all the client organizations you manage in Hearth in one place. Use them to see how each client uses Hearth, which action plans are blocked, what you need from each customer, and each client's external exposure. You do not need to open each client workspace one at a time.

Note: Hearth shows these views only in an MSP parent workspace. A standalone workspace or a single client tenant cannot see them.

How it works

The Cohort views pull together information from every client organization under your MSP parent workspace. Because they cover more than one client, Hearth shows them only when it recognizes your workspace as an MSP parent.

The MSP parent workspace has the following views:

ViewWhere to find itWhat it shows
Cohort analysisSetup > Cohort

A summary of the shared credit pool, plus a table with the following details about each tenant:

  • Conversations (all-time total)
  • Artifacts (all-time total)
  • Automation health 
  • Credits used this month

Clients with failing automations appear first.

Fleet action plansMore > Fleet action plansAction plans across all clients, on three tabs: Blocked, Recurring entities, and Per-customer export.
Cohort exposureMore > Cohort exposureExternal exposure for all of your clients in one view.
Cohort coverageMore > Cohort coverageAccounts Hearth found through your shared integrations, and whether each one is mapped to a managed client.
Token capsMore > Credit capsA monthly credit limit for each client on the shared credit pool, so one customer cannot use up the whole balance.

Reviewing your clients

To review your clients and open one client's workspace, do the following:

  1. From your MSP parent workspace, navigate to Cohort.
  2. Review the Cohort analysis.
  3. In the Accounts table, click a client's name to open their Home page.
  4. To return to your parent workspace, click ← <parent MSP account name> in the upper-left corner of the screen.

Reviewing fleet action plans

Fleet action plans

The Fleet action plans page includes the following options:

TabWhat it shows
BlockedBlocked plans across all clients, with how many hours each has been blocked, the reason, time since last update, and priority. Use the time-based or “waiting” filters to narrow the list.
Recurring entitiesUsers, hosts, or other items that show up in action plans for two or more clients. Select one to see the plans it appears in.
Per-customer exportA status summary for one client that you can share with that customer.

Reviewing blocked action plans

Review blocked action plans by doing the following:

  1. Navigate to More > Fleet action plans.
  2. Click Blocked.
  3. Use the filters to narrow the list. For example, set Older than to 72 hours to find plans that have been stuck longest.
  4. Select a plan to open it.

Exporting a customer status update

To copy a weekly status update that you can share with a client, do the following:

  1. On Fleet action plans, click the Per-customer export tab.
  2. In the client’s row, click Export.
  3. Review the summary. It covers these details about your action plans:
    • What we caught this week: The plans your team marked as resolved and benign true-positives in the last 7 days.
    • What we're working on: The plans your team marked as false positives, duplicates, out of scope, or escalated.
    • What we need from you: Any plan still open that your team has marked as Blocked, customer_pending.
    • Coverage posture: This is shown when a coverage scorecard exists from the current window.
  4. Click Copy as markdown, and then share it with your customer.

Asking Hearth about fleet health

Some cross-client views do not have their own page. Ask Hearth for them in a conversation from your MSP parent workspace using questions like the following:

  • Which clients need attention this week?
  • Are any clients showing churn signals?
  • Which clients saw a given IP or pattern?
  • Who is doing <some action>, per client?
  • Which client has the most frequent findings?
  • List which rules are firing for two or more of my clients.
  • What are our most <noisy or precise> detection rules?
  • Which clients have <some integration> connected?
  • List all of the MDR cases across my cohort.