Skip to main content
A Workspace Profile is a reusable template of workspace settings. Configure it once, attach the workspaces it should manage, and apply it. ContraForce pushes the same configuration to every workspace on the profile. Without profiles, every configuration change is multiplied by the size of your fleet: 200 workspaces means 200 manual edits. With a profile, it is one edit and one apply.
Who is this for?
  • MSP/MSSP partners managing more than a handful of customer workspaces
  • Organizational Admins who set access, notification, and module standards across the fleet
Profiles tab in Workspace Center showing a profile card

Workspace Center → Profiles


What Can You Do Here?

Standardize Your Fleet

Define one baseline for access, modules, notifications, Gamebooks, and agents.

Roll Out in One Action

Push a change to every attached workspace without opening any of them.

See What Is Out of Sync

Every profile shows which workspaces are still on an older version.

Prerequisites


What a Profile Covers

A profile is made up of five sections. Configure only the ones you need. A section you leave empty is left alone on every workspace.
Notification recipients must be your own people: your team members, your groups, or any email address. A person who exists only inside one customer’s tenant has no identity in the other workspaces on the profile, so their notifications would silently go nowhere.

Creating a Profile

1

Open the Profiles tab

From the left navigation, select Workspaces, then click the Profiles tab.
2

Click New Profile

Give the profile a name, an optional description, and optional tags. Tags make profiles easier to find as your library grows.
3

Configure the sections you need

Move through the IAM, Modules, Notifications, Gamebooks, and Agent tabs and set the values you want every workspace on this profile to have.
4

Save

There is one save bar for the whole profile. Everything you edited across the tabs publishes together as a single new version. You should see a confirmation such as “1 section saved. Profile is now v2.”
Editing the name, description, or tags does not create a new version. Only section changes do, because only section changes need to be pushed to workspaces.

Attaching Workspaces

Attaching declares which workspaces the profile manages. It does not configure anything on its own.
1

Open the profile

Click the profile card on the Profiles tab.
2

Click Attach workspaces

Select the workspaces this profile should manage and confirm.
3

Expect them to show as not yet applied

Newly attached workspaces carry the profile’s label but not yet its configuration. That is correct. Applying is the next, separate step.
Detaching a workspace stops the profile from managing it, but it does not remove configuration the profile already applied. Removing settings across a fleet is a deliberate action, not a side effect of detaching.

Previewing and Applying

Applying is what makes attached workspaces match the profile.
Profile detail page showing the waiting to be applied banner and the Apply button

A profile with workspaces waiting to be applied

1

Click Apply

ContraForce shows a preview before anything changes.
2

Read the preview

The preview lists, workspace by workspace, exactly what will be added, updated, or removed. For example, “removes 2 approvers, adds 1”. It also calls out any workspace where the profile’s modules would change the workspace’s plan and add a recurring charge.
3

Acknowledge any charges

If the preview names workspaces that would be repriced, you must acknowledge that before those workspaces are configured. Nothing billable happens without your confirmation.
4

Confirm

The apply runs in the background. You can leave the page. Progress is recorded as each workspace finishes.
Applying the same profile twice is safe. ContraForce brings each workspace towards the profile rather than duplicating what is already there, and settings a workspace admin added by hand are left untouched.

Versions and Sync Status

Every profile carries a version number, and every workspace records the version it last received. A workspace shows as waiting whenever it was just attached, whenever you save a section change, or whenever an apply did not fully land on it.

Tracking a Rollout

The Activity tab on a profile records every apply as a numbered run, with the version that was pushed, who pushed it, and the result for each workspace.
Profile Activity tab showing Run 1 applied to one workspace

Activity tab showing an apply run and its per-workspace result

Run and workspace statuses

A run tells you what changed as well as whether it worked. A run showing +0 ~0 -0 with “Already matched. Nothing to change” means the workspace was already exactly as the profile describes.

Retrying

Use Retry on a run to pick up the workspaces that did not fully succeed, including skipped ones, which are often waiting on something you have since fixed. A retry is a new run, and it pushes the same version the original run pushed, not whatever you have edited since. Workspaces that already succeeded are never touched again.

Agents in a Profile

The Agent tab sets the Security Delivery Agent policy for every workspace on the profile, and can create the agent where a workspace does not have one yet.

Before a profile can create agents

Your environment must have committed an agent deployment model in Agent Center. Until it has, agent provisioning is skipped with a message telling you so. That choice is permanent, so ContraForce never makes it for you from a profile.
Provisioning creates billable infrastructure. It happens only when the profile is set to Provision and the preview showed it. The preview names the action and the number of workspaces affected before anything is committed.
Agent deployments take minutes. The run reports those workspaces as Provisioning and settles them automatically once the deployment finishes. A single apply deploys up to 50 agents; anything beyond that is skipped with a reason and picked up by your next apply.

Troubleshooting

If a workspace keeps failing across multiple runs, contact support@contraforce.com with the profile name, the run number, and the workspace name.

Best Practices

Most fleets need only a few profiles, for example one per detection stack or per service tier. Tags make them easy to find later.
Everything you change across the tabs publishes as one version and one rollout. Six separate saves means six versions and six pushes.
The preview is produced by the same engine that performs the apply, so what it shows is what will happen. Pay particular attention to removals and to any workspace flagged for repricing.
Attaching is reversible and configures nothing, so you can stage a profile’s reach and review it before anything fans out.
Skips almost always point at a prerequisite: an undeployed Agent Center, a missing permission, or an unacknowledged charge. Resolving them once makes every future apply cleaner.

Onboarding Workspaces at Scale

Onboard one customer with a profile, or import a whole batch from a CSV.

Workspace Center

Manage individual workspaces, health, and per-workspace settings.

Configuring Security Delivery Agents

Set up agents and choose an adoption mode.

Roles and Permissions

Understand which role can do what across the platform.

Questions about Workspace Profiles? Contact us at support@contraforce.com.