Halo ITSM Implementation & Multi-Tenant Gold Build

One Platform for Every Client: A Managed Security Provider’s Multi-Tenant SOC Build with Halo

A UK managed security services provider, a group of specialist cyber-security businesses running a single 24/7 Security Operations Centre, needed one platform to run SOC operations across every one of its customers. Allied ESM, powered by Halo, delivered a fully configured, validated multi-tenant “Gold Build” of Halo ITSM on the Halo AWS UK Cluster in five weeks: with automated security-alert ingestion, per-customer data segregation and SLA management, and a repeatable template designed to onboard new customers at pace. Just as important, the engagement set the customer’s own team on the path to running and extending the platform themselves, through Halo University training, enablement sessions, and structured knowledge transfer.

Analysts working in a 24/7 Security Operations Centre, monitoring dashboards across multiple screens Allied ESM
5 Weeks
Design to Production Go-Live
Multi-Tenant
One Platform, Every Customer
24/7
SOC SLA Coverage (P1/P2)
Gold Build
Reusable Onboarding Template

A Managed Security Provider Scaling Its 24/7 SOC

The client is a UK managed security services provider that brings together several specialist cyber-security businesses under a single Security Operations Centre. Its analysts work across many customer environments at once, each with its own access requirements, SLA commitments, and escalation paths.

Growth sits at the centre of the model. Having standardised the group under one SOC, the business needed a single, purpose-built service management platform to run those operations across every customer. It had to segregate each customer’s data, enforce per-customer SLAs, and be replicated quickly as new customers are onboarded.

Many Customers, Many Requirements: One Platform to Run Them All

Running a SOC for multiple customers at once places heavy demands on a service management platform. Each customer needs its own data segregation, role-based access (including security-cleared access where required), SLA profiles, and escalation paths, all within a single instance that analysts can work across without friction. Security alerts arrive from more than one source and must be triaged, escalated to the right customer, and resolved against strict, often 24/7, SLA targets.

The provider also needed to onboard new customers quickly. Building each customer’s environment by hand would not scale, so the operation needed a validated, repeatable template it could replicate at pace, on a fixed timeline, without disrupting live services.

Key pressures driving the decision to act:

  • A single, multi-tenant platform purpose-built for a security provider running many customers at once
  • Per-customer data segregation, role-based access, and SLA management, all within one instance
  • Automated alert-to-ticket ingestion from the SOC toolchain, with no manual re-keying of security alerts
  • Strict, tiered SLAs (24/7 for critical events) with clear triage, escalation, and resolution targets
  • A repeatable “Gold Build” template to onboard future customers at pace, on a fixed timeline
  • UK data residency, and a hard go-live date with no room for slippage

A Multi-Tenant Gold Build, Delivered Remotely in Five Weeks

Rather than a bespoke build per customer, Allied ESM, powered by Halo, delivered a standardised, fully tested multi-tenant “Gold Build”: a validated, production-ready Halo ITSM configuration that serves as the reusable template for every future customer onboarding. The engagement followed an out-of-the-box-first approach, configuring Halo’s native capabilities wherever possible rather than resorting to bespoke development.

The platform was built on the Halo AWS UK Cluster, aligned to UK data residency, and delivered across a structured five-week programme covering design workshops, build, customer-led UAT, and a hard-cutover go-live.

The following capabilities were delivered:

  • Multi-Tenant Architecture — a Gold Build organisation structure with per-customer data segregation: analysts work across all customers, while customer-side users see only their own data
  • Role-Based Access Control — per-customer roles and permissions, including security-cleared access rules where non-cleared analysts can view but only cleared analysts can act
  • SOC Ticket Lifecycle & SLAs — a full SOC incident workflow with a priority matrix and tiered SLA targets (24/7 for critical events), including out-of-the-box Major Incident Management
  • Azure Sentinel Integration — security alerts ingested directly from the SOC’s Sentinel workspace and turned into tickets automatically, with priority mapping and routing
  • Email Alert Ingestion — automated ticket creation and routing from the provider’s security-management platform, using subject-line differentiation to route each alert to the correct customer and queue
  • Single Sign-On — Microsoft Entra ID SSO configured for agents and customer users via the group’s existing identity platform
  • Queues, Escalation & Approvals — per-customer queues, assignment rules, and escalation paths configured within the single instance
  • Reporting Dashboards — SOC, analyst-level, and team-level views for visibility of volumes, performance, and SLAs
  • Enablement & Knowledge Transfer — Halo University training, hands-on enablement sessions, and structured knowledge transfer, so the team can administer, extend, and onboard new customers onto the platform themselves

Delivery was remote throughout, staffed by a Halo-certified consultant and a project manager. The programme was governed with weekly progress calls, a live RAID log, and structured User Acceptance Testing with formal sign-off before go-live. That discipline protected both the timeline and the quality of what was delivered.

Enabling the customer to become self-sufficient ran through the whole engagement. The team began Halo University training during delivery, and Allied ESM ran hands-on enablement sessions and knowledge transfer, covering reporting and dashboards, so that by go-live the provider’s own analysts and platform owners could administer the environment, build on it, and onboard new customers without relying on outside help.

One Multi-Tenant Platform Live. A Repeatable Template Built for Growth.

The platform went live on target. The provider now runs its SOC operations for multiple customers from a single, multi-tenant Halo ITSM instance, with each customer’s data segregated, SLAs enforced, and security alerts flowing automatically into tickets.

  • Live on the Halo AWS UK Cluster — a single multi-tenant SOC platform, delivered and validated within a five-week programme
  • Repeatable Gold Build — a validated template that lets the provider onboard new customers quickly, rather than building each environment from scratch
  • Automated alert-to-ticket — Azure Sentinel and email-based security alerts create and route tickets automatically, removing manual re-keying
  • Per-customer segregation & SLA management — data separation, role-based access, and tiered SLAs across all customers within one instance
  • Clean UAT and on-time go-live — customer-led testing with formal sign-off; no critical defects outstanding at cutover
  • A self-sufficient customer team — analysts and platform owners trained through Halo University and enablement sessions, with knowledge transfer complete, ready to run the platform and onboard customers independently

The provider is now positioned to scale, onboarding new customers onto a proven template, with a platform its analysts own and understand and, for the first time, a consistent and auditable view of SOC performance.

Seen enough? Let’s talk.

Tell us about your SOC operations and we’ll show you what Halo ITSM can do for your organisation.

Schedule a Consultation