Background: Sophos Managed Detection and Response (MDR) is a fully managed 24/7 security service in which a team of security experts and AI actively detects, investigates, and responds to cyber threats in a customer’s IT infrastructure. When Sophos MDR identifies an active security incident (known as a “case”), rapid visibility and responsiveness are critical for the MSP providing support.
Feature Request: We would like to see native integration of Sophos MDR into octoja so that active MDR cases can be displayed and processed directly within the octoja interface.
Specifically, the following would be helpful:
Display of open Sophos MDR cases on the octoja dashboard (e.g., as an alert or a separate widget)
Automatic assignment of a case to the corresponding customer/client in octoja
Notification (e.g., via Teams or email) upon receipt of a new MDR case
Technical Approach (Suggestion): Sophos MDR provides an API through which cases can be retrieved. Alternatively, a webhook-based integration could be considered, in which Sophos actively sends a trigger to octoja as soon as a new case is created. Since octoja already includes an open REST API and supports webhooks, such an integration should, in principle, be technically feasible.
Benefits: MSPs that use Sophos MDR for their customers could view and handle security incidents directly within their central RMM tool—without having to switch between multiple portals. This reduces response times and significantly improves visibility.
We would be very pleased to see this topic on the roadmap and are happy to answer any questions you may have.
Please authenticate to join the conversation.
In Review
Feature Request
About 1 month ago
Get notified by email when there are changes.
In Review
Feature Request
About 1 month ago
Get notified by email when there are changes.