Skip to main content
You run security response and SOC work, own audit and compliance posture, and vet how every tool touching your desk handles data and permissions. Thread changes three things for you: security signals arrive already scored and routed, Super Magic does read-only investigation and confirm-before-act response from inside the ticket, and the data-handling story you have to defend to clients and auditors is written down and specific. This is your course — three lessons that cover the ticket flow, the data model, and the runbook bench, plus the skills and ritual built for your day.

The course

Work these in order — each ends with a link to the next. The first two lessons are the operating model; the third is your day-to-day toolkit.
1

How security work flows through Thread

Sentiment and escalation on security threads, Super Magic lookups with confirm-before-act, and NinjaOne device actions from the ticket. Read →
2

How Thread handles your data

Encryption, Magic AI privacy, sub-processors, IP allowlisting, and the exact app permissions to hand an auditor. Read →
3

Your security & compliance runbooks

The Skill Library security and audit bench — incident response, identity, alerts, and evidence collection. Read →

Your starter kit

The Skill Library has a full security and compliance bench. Start with these, then press ⌘K and search (“phishing”, “BEC”, “ransomware”, “audit”, “SOC 2”) for the rest.

Phishing Triage

Assess a reported email and contain it if it’s malicious.

Account Takeover Runbook

The full response for a compromised account, step by step.

Ransomware Response

Contain, communicate, and coordinate recovery under pressure.

Identity & MFA Health Check

Find identity and MFA gaps before an attacker does.

Audit Prep Review

Get ready for an audit or assessment without the scramble.

SOC 2 Evidence Collection

Gather and organize the evidence a SOC 2 cycle demands.

Your SOC ritual

SOC shift handoff

End every shift with a clean handoff — open incidents, what’s watched, what’s next.

Monthly security report

Turn a month of security work into client-ready proof.
Run the SOC shift handoff at the close of every shift so nothing in-flight gets dropped across the seam, and the monthly security report at month-end so the work you did is visible to the clients paying for it. Between those, SOC shift handoff plus a queue scan is your open-and-close.

Pro tips & FAQ

The SOC 2 Type II audit is in progress and the report has not been issued yet — so don’t tell a client Thread “is SOC 2 certified”. A bridge letter is available under NDA through your Customer Success Manager. Full detail, and the links you can send a client, are on Thread’s SOC 2 and compliance status; the Trust Center carries the live status and is what you should link in a questionnaire. These docs also give you the technical detail auditors ask for: data encryption, Magic AI privacy & security, and the sub-processor list. The compliance skills help you assemble your own evidence, not stand in for Thread’s attestations.
No. Super Magic reads freely, but every write action shows a Confirm action card first — the exact ticket, status, or note — and nothing runs until you click Confirm. Confirmed changes are recorded under the member’s own name, not a service account. See the Super Magic admin guide.
You control it. Write access is set to All members, Admins only, or a custom list, with a per-tool toggle on every action. NinjaOne device actions additionally run under each member’s own NinjaOne permissions — a technician can never do more through Super Magic than they could do signed into NinjaOne directly. Details in the Super Magic admin guide.
Thread’s outgoing IPs (for PSA API calls) and the incoming domains Inbox and Messenger need are listed on Thread IP addresses and domains to allowlist. Hand that page to the network team verbatim.
A short, fixed list — contact name and type, the date, and the issue’s summary, description, and transcript — to an isolated Azure OpenAI Service instance that doesn’t store it or train on it. The exact fields are on Magic AI privacy & security.