The SOAR I wanted to work in, built for managed security teams.
meshSOAR is a self-hosted, multi-tenant platform for security operations teams that look after many client organizations. It brings together the strongest ideas from today's SOAR products, alongside the features I've wanted after years of working inside one. It covers cases, automation, ticketing, client communication, scheduling and reporting.
One platform, assembled from the best of the category
Each SOAR product gets something right. One has clear incident layouts and playbooks. Another shows exactly why alerts were grouped together. Another makes HTTP integrations quick to build and lets you replay any automation step. meshSOAR puts those strengths into a single product and adds what operations teams usually work around: real ticketing, a governed channel to clients, shift-aware dispatch, and version control for every piece of content.
Capabilities
Cases and alerts
Alert grouping you can see and explain, a case wall, entities, evidence, and closure rules the team agrees on.
Playbook automation
Playbooks are stored as YAML graphs with a visual canvas. They run durably on Temporal, and every step can be replayed.
Integrations
Simple HTTP actions are templates. Complex ones are Python on a versioned SDK. Webhooks work in both directions.
Service desk
Requests and tickets sit beside cases, with SLAs that meshSOAR calculates itself instead of taking them from each source.
Client console
Clients sign in to one console to see their cases, answer questions and receive reports, limited to their own data.
Shifts and dispatch
Built in from day one, and fully configurable: rosters, on-shift assignment pools, workload rebalancing, and your own shift patterns and dispatch rules.
Reporting
Executive reports an MSSP is proud to send and a client's executive is impressed to receive. They're delivered per client as PDFs and dashboards.
Versioned content
Every definition you can edit in the UI keeps its history: playbooks, layouts, settings and guides.
Principles
- Your choice of deployment. Run it fully local, with your data on your own infrastructure, or use the hosted SaaS version in the cloud.
- Tenant isolation is enforced by the database. Every tenant table has row-level security, and isolation is proven in CI.
- Configurable, not hardcoded. Settings live in a registry, down to the product name, so it can be white-labeled.
- AI where it helps, under your control. AI features are optional, and the operator decides whether to turn them on.
- Operable by a small team. It's designed for two or three engineers to run.
In active development
meshSOAR is an independent project with one founder. I build it with Claude Code, working alongside AI agents for implementation and review. A working self-hosted beta runs today, and a company will be formed around it ahead of the first release.
Meshari Alhazmi
I have 6+ years across SOC analysis, detection engineering, SOC engineering, and security automation and DevSecOps. meshSOAR is the platform I wanted in every one of those roles.
Something great is being built
To follow progress or talk about meshSOAR, write to m.alhazmi@meshsoar.com.