Configure a set of workspace settings once, then apply it to every workspace on the profile: access, modules, notifications, Gamebook approvers, and agents.
A Workspace Profile is a reusable template of workspace settings. Configure it once, attach the workspaces it should manage, and apply it. ContraForce pushes the same configuration to every workspace on the profile.Without profiles, every configuration change is multiplied by the size of your fleet: 200 workspaces means 200 manual edits. With a profile, it is one edit and one apply.
Who is this for?
MSP/MSSP partners managing more than a handful of customer workspaces
Organizational Admins who set access, notification, and module standards across the fleet
A profile is made up of five sections. Configure only the ones you need. A section you leave empty is left alone on every workspace.
Section
What it sets
IAM
Users and groups that should have access to the workspace, and the role each one gets
Modules
Detection and response modules the workspace should have
Notifications
Notification preferences and the recipients for incident, Gamebook, and agent run notifications
Gamebooks
The Gamebook approvers responsible for authorizing manual response actions
Agent
Security Delivery Agent policy, and optionally whether ContraForce should create an agent where the workspace has none
Notification recipients must be your own people: your team members, your groups, or any email address. A person who exists only inside one customer’s tenant has no identity in the other workspaces on the profile, so their notifications would silently go nowhere.
From the left navigation, select Workspaces, then click the Profiles tab.
2
Click New Profile
Give the profile a name, an optional description, and optional tags. Tags make profiles easier to find as your library grows.
3
Configure the sections you need
Move through the IAM, Modules, Notifications, Gamebooks, and Agent tabs and set the values you want every workspace on this profile to have.
4
Save
There is one save bar for the whole profile. Everything you edited across the tabs publishes together as a single new version. You should see a confirmation such as “1 section saved. Profile is now v2.”
Editing the name, description, or tags does not create a new version. Only section changes do, because only section changes need to be pushed to workspaces.
Attaching declares which workspaces the profile manages. It does not configure anything on its own.
1
Open the profile
Click the profile card on the Profiles tab.
2
Click Attach workspaces
Select the workspaces this profile should manage and confirm.
3
Expect them to show as not yet applied
Newly attached workspaces carry the profile’s label but not yet its configuration. That is correct. Applying is the next, separate step.
Detaching a workspace stops the profile from managing it, but it does not remove configuration the profile already applied. Removing settings across a fleet is a deliberate action, not a side effect of detaching.
Applying is what makes attached workspaces match the profile.
A profile with workspaces waiting to be applied
1
Click Apply
ContraForce shows a preview before anything changes.
2
Read the preview
The preview lists, workspace by workspace, exactly what will be added, updated, or removed. For example, “removes 2 approvers, adds 1”. It also calls out any workspace where the profile’s modules would change the workspace’s plan and add a recurring charge.
3
Acknowledge any charges
If the preview names workspaces that would be repriced, you must acknowledge that before those workspaces are configured. Nothing billable happens without your confirmation.
4
Confirm
The apply runs in the background. You can leave the page. Progress is recorded as each workspace finishes.
Applying the same profile twice is safe. ContraForce brings each workspace towards the profile rather than duplicating what is already there, and settings a workspace admin added by hand are left untouched.
The Activity tab on a profile records every apply as a numbered run, with the version that was pushed, who pushed it, and the result for each workspace.
Activity tab showing an apply run and its per-workspace result
Most workspaces succeeded; the ones that did not are named on their own rows. This is a successful push with notes, not a failure
Skipped
Nothing was attempted, with a stated reason you can act on
Failed
The workspace could not be configured
Provisioning
An agent deployment started by this run is still finishing. The result settles automatically once the deployment completes
A run tells you what changed as well as whether it worked. A run showing +0 ~0 -0 with “Already matched. Nothing to change” means the workspace was already exactly as the profile describes.
Use Retry on a run to pick up the workspaces that did not fully succeed, including skipped ones, which are often waiting on something you have since fixed.A retry is a new run, and it pushes the same version the original run pushed, not whatever you have edited since. Workspaces that already succeeded are never touched again.
The Agent tab sets the Security Delivery Agent policy for every workspace on the profile, and can create the agent where a workspace does not have one yet.
Setting
What it does
Enabled
Turns the agent section on for this profile
Triage policy
The agent behavior every workspace on the profile should use
Model (optional)
Preferred AI model. If it is not available in your Agent Center’s region, ContraForce uses the default model and says so in the preview
Provisioning
Configure only (default): a workspace with no agent is skipped. Provision: ContraForce creates the agent, then applies the policy
Your environment must have committed an agent deployment model in Agent Center. Until it has, agent provisioning is skipped with a message telling you so. That choice is permanent, so ContraForce never makes it for you from a profile.
Deployment model
What you need
ContraForce Cloud
ContraForce Cloud agents enabled for your environment, and an available pool agent
Your Cloud
An Agent Center in a Deployed state, and Owner rights on its Azure subscription for the person applying the profile
Provisioning creates billable infrastructure. It happens only when the profile is set to Provision and the preview showed it. The preview names the action and the number of workspaces affected before anything is committed.
Agent deployments take minutes. The run reports those workspaces as Provisioning and settles them automatically once the deployment finishes. A single apply deploys up to 50 agents; anything beyond that is skipped with a reason and picked up by your next apply.
Most fleets need only a few profiles, for example one per detection stack or per service tier. Tags make them easy to find later.
Batch your edits into one save
Everything you change across the tabs publishes as one version and one rollout. Six separate saves means six versions and six pushes.
Always read the preview
The preview is produced by the same engine that performs the apply, so what it shows is what will happen. Pay particular attention to removals and to any workspace flagged for repricing.
Attach first, apply when you are ready
Attaching is reversible and configures nothing, so you can stage a profile’s reach and review it before anything fans out.
Clear skips before your next big rollout
Skips almost always point at a prerequisite: an undeployed Agent Center, a missing permission, or an unacknowledged charge. Resolving them once makes every future apply cleaner.