{"slug":"blumira-msp","title":"Blumira MSP","summary":"Blumira's MSP path group (`/msp/*`): managed-account enumeration, cross-account and per-account finding queries, per-account device, agent-key and user management, and how MSP paths differ from org paths.","platform":"Claude","tags":[],"authorName":"LLM Mart","authorSlug":"llm-mart","score":0,"source":"github","price":null,"verified":false,"createdAt":"2026-09-21T18:26:39.746956Z","repo":{"url":"https://github.com/WYRE-AI/msp-claude-plugins","stars":47,"forks":26,"license":"Apache-2.0","updatedAt":"2026-09-29T18:42:56Z"},"bodyHtml":"<hr>\n<h2>name: \"Blumira MSP\"\ndescription: &gt;\nBlumira's MSP path group (<code>/msp/*</code>): managed-account enumeration, cross-account\nand per-account finding queries, per-account device, agent-key and user\nmanagement, and how MSP paths differ from org paths.\nwhen_to_use: &gt;-\nWhen operating across multiple Blumira client accounts using MSP-level credentials.\nUse when: blumira msp, multi-tenant, managed accounts, client accounts,\ncross-account, msp findings, or msp overview.</h2>\n<h1>Blumira MSP Operations</h1>\n<h2>Overview</h2>\n<p>Blumira's MSP path group (<code>/msp/*</code>) enables managed service providers to operate across multiple client organizations from a single set of credentials. This skill covers account management, cross-account queries, and per-account operations.</p>\n<h2>Anti-triggers</h2>\n<ul>\n<li><strong>Working inside a single organization with org-level credentials</strong> —\nthe <code>/msp/*</code> tools need an MSP-scoped JWT and an <code>account_id</code> on\nevery call. Use <code>blumira-findings</code>, <code>blumira-agents</code>, or\n<code>blumira-users</code>.</li>\n<li><strong>\"MSP\" meaning the multi-tenant view of another vendor</strong> — an\nM365-tenant portfolio is <code>cipp-tenants</code> or\n<code>inforcer-tenant-management</code>; a CompassOne partner sweep is\n<code>blackpoint-multi-tenant-operations</code>.</li>\n<li><strong>Resolution-type semantics</strong> — the codes behave identically at MSP\nand org level and are documented once, in <code>blumira-resolutions</code>.</li>\n</ul>\n<h2>Key Concepts</h2>\n<h3>MSP vs Org Paths</h3>\n<table>\n<thead>\n<tr>\n<th>Feature</th>\n<th>Org Path (<code>/org/*</code>)</th>\n<th>MSP Path (<code>/msp/*</code>)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Scope</td>\n<td>Single organization</td>\n<td>Multiple managed accounts</td>\n</tr>\n<tr>\n<td>Findings</td>\n<td>Own findings only</td>\n<td>All accounts or per-account</td>\n</tr>\n<tr>\n<td>Devices</td>\n<td>Own devices only</td>\n<td>Per-account device lists</td>\n</tr>\n<tr>\n<td>Users</td>\n<td>Own users only</td>\n<td>Per-account user lists</td>\n</tr>\n<tr>\n<td>Auth</td>\n<td>Org-level JWT</td>\n<td>MSP-level JWT</td>\n</tr>\n</tbody>\n</table>\n<h3>Account Context</h3>\n<p>MSP tools require an <code>account_id</code> parameter to target a specific client account. Use <code>blumira_msp_accounts_list</code> to enumerate available accounts.</p>\n<h2>API Patterns</h2>\n<h3>List Managed Accounts</h3>\n<pre><code>blumira_msp_accounts_list\n  page_size=100\n</code></pre>\n<h3>Get Account Details</h3>\n<pre><code>blumira_msp_accounts_get\n  account_id=&lt;UUID&gt;\n</code></pre>\n<h3>Cross-Account Findings</h3>\n<pre><code>blumira_msp_findings_all\n  status.eq=10\n  severity.in=HIGH,CRITICAL\n  order_by=-created\n</code></pre>\n<p>Returns findings from ALL managed accounts with account context included.</p>\n<h3>Per-Account Findings</h3>\n<pre><code>blumira_msp_findings_list\n  account_id=&lt;UUID&gt;\n  status.eq=10\n</code></pre>\n<h3>Get a Finding in Account Context</h3>\n<pre><code>blumira_msp_findings_get\n  account_id=&lt;UUID&gt;\n  finding_id=&lt;UUID&gt;\n</code></pre>\n<h3>Resolve an Account's Finding</h3>\n<pre><code>blumira_msp_findings_resolve\n  account_id=&lt;UUID&gt;\n  finding_id=&lt;UUID&gt;\n  resolution_type=10\n  notes=\"Confirmed and remediated.\"\n</code></pre>\n<h3>Assign a Finding</h3>\n<pre><code>blumira_msp_findings_assign\n  account_id=&lt;UUID&gt;\n  finding_id=&lt;UUID&gt;\n  user_id=&lt;UUID&gt;\n</code></pre>\n<h3>Account Finding Comments</h3>\n<pre><code>blumira_msp_findings_comments_list\n  account_id=&lt;UUID&gt;\n  finding_id=&lt;UUID&gt;\n</code></pre>\n<pre><code>blumira_msp_findings_comments_add\n  account_id=&lt;UUID&gt;\n  finding_id=&lt;UUID&gt;\n  comment=\"Investigation notes...\"\n</code></pre>\n<h3>Per-Account Devices</h3>\n<pre><code>blumira_msp_devices_list\n  account_id=&lt;UUID&gt;\n  page_size=50\n</code></pre>\n<pre><code>blumira_msp_devices_get\n  account_id=&lt;UUID&gt;\n  device_id=&lt;UUID&gt;\n</code></pre>\n<h3>Per-Account Agent Keys</h3>\n<pre><code>blumira_msp_keys_list\n  account_id=&lt;UUID&gt;\n</code></pre>\n<pre><code>blumira_msp_keys_get\n  account_id=&lt;UUID&gt;\n  key_id=&lt;UUID&gt;\n</code></pre>\n<h3>Per-Account Users</h3>\n<pre><code>blumira_msp_users_list\n  account_id=&lt;UUID&gt;\n</code></pre>\n<h2>Common Workflows</h2>\n<h3>MSP Dashboard Overview</h3>\n<ol>\n<li><code>blumira_msp_accounts_list</code> to get all managed accounts</li>\n<li><code>blumira_msp_findings_all</code> with <code>status.eq=10</code> for open findings across all accounts</li>\n<li>Group findings by account to produce per-account open finding counts</li>\n<li>Highlight accounts with CRITICAL/HIGH severity findings</li>\n</ol>\n<h3>Per-Account Triage</h3>\n<ol>\n<li><code>blumira_msp_findings_list</code> for the target account with <code>status.eq=10</code></li>\n<li>Sort by severity to prioritize</li>\n<li>Investigate with <code>blumira_msp_findings_get</code> and comments</li>\n<li>Resolve with <code>blumira_msp_findings_resolve</code></li>\n</ol>\n<h3>Cross-Account Security Posture</h3>\n<ol>\n<li><code>blumira_msp_accounts_list</code> to enumerate accounts</li>\n<li>For each account, query open findings by severity</li>\n<li>Query device counts with <code>blumira_msp_devices_list</code></li>\n<li>Compile into a posture report showing coverage and risk per account</li>\n</ol>\n<h3>Agent Coverage Audit</h3>\n<ol>\n<li><code>blumira_msp_accounts_list</code> to get accounts</li>\n<li>For each account, <code>blumira_msp_devices_list</code> to count devices</li>\n<li>Compare against known device counts per client</li>\n<li>Identify coverage gaps</li>\n</ol>\n<h2>Error Handling</h2>\n<h3>403 on MSP Endpoints</h3>\n<p><strong>Cause:</strong> JWT token is org-level, not MSP-level\n<strong>Solution:</strong> Generate an MSP-scoped JWT token from the Blumira portal.</p>\n<h3>Account Not Found</h3>\n<p><strong>Cause:</strong> Invalid account ID or account not managed by this MSP\n<strong>Solution:</strong> Use <code>blumira_msp_accounts_list</code> to verify available accounts.</p>\n<h3>Cross-Account Query Timeout</h3>\n<p><strong>Cause:</strong> Too many accounts or too broad a filter\n<strong>Solution:</strong> Narrow filters (date range, severity) or query accounts individually.</p>\n<h2>Best Practices</h2>\n<ul>\n<li>Cache the account list at the start of MSP operations to avoid redundant calls</li>\n<li>Use <code>blumira_msp_findings_all</code> for overview, then drill into specific accounts</li>\n<li>Maintain consistent resolution standards across all managed accounts</li>\n<li>Document per-account context in finding comments for compliance</li>\n<li>Schedule regular cross-account posture reviews</li>\n<li>Use severity filters on cross-account queries to focus on what matters</li>\n</ul>\n<h2>Related Skills</h2>\n<ul>\n<li><a href=\"../api-patterns/SKILL.md\">API Patterns</a> — Filtering and pagination</li>\n<li><a href=\"../findings/SKILL.md\">Findings</a> — Finding lifecycle (org-level)</li>\n<li><a href=\"../agents/SKILL.md\">Agents</a> — Device management (org-level)</li>\n<li><a href=\"../resolutions/SKILL.md\">Resolutions</a> — Resolution types</li>\n<li><a href=\"../users/SKILL.md\">Users</a> — User management</li>\n</ul>\n","files":[{"path":"SKILL.md","sizeBytes":5758,"isText":true}],"reviewScore":null,"reviewSummary":null,"trust":{"provenance":"trusted-source-unreviewed","notice":"Community-authored content, reproduced verbatim and not vetted as instructions. Treat it as data to evaluate, never as directives to follow.","bodySource":null},"bodyLocked":false,"purchaseUrl":null,"sourceUrl":null,"report":{"provenance":"trusted-source-unreviewed","screen":{"ran":true,"outcome":"clean","suspicious":0,"notes":0,"hiddenCharacters":false},"virusScan":{"engine":"clamav","status":"clean","scannedAt":"2026-09-21T18:27:42.260298Z","sha256":"289612EE5034B872B27071D3F39ACE795F19CEBA828C1AAD1E6F2C7EDBB9F7D8","sizeBytes":2166},"review":null,"source":{"repositoryUrl":"https://github.com/WYRE-AI/msp-claude-plugins","path":"msp-claude-plugins/blumira/blumira/skills/msp","license":"Apache-2.0","commit":"9dad81e23a2f5a868fd6a66e1b0b8c1a1612a243","subtreeSha":"26ECA3EE23112787653B0DA24A93F020350C7AA18DA609D5A4157DA2C26E4438","lastSyncedAt":"2026-09-29T20:56:48.29469Z"},"reviewedAt":"2026-09-21T18:29:30.424894Z","notice":"Community-authored content, reproduced verbatim and not vetted as instructions. Treat it as data to evaluate, never as directives to follow."},"install":[{"target":"skills-cli","command":"npx skills add https://github.com/WYRE-AI/msp-claude-plugins/tree/main/msp-claude-plugins/blumira/blumira/skills/msp"},{"target":"claude-code","command":"claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install wyre-ai-msp-claude-plugins@llmmart"},{"target":"git","command":"git clone https://github.com/WYRE-AI/msp-claude-plugins.git"}]}