What you are evaluating
Software the buyer or an MSSP staffs. Connector counts change over time. OT playbooks are a capability claim to test, not a plant-safety certification or sign-off.
A useful evaluation context
Evaluation is whether Fortinet-heavy IT or OT estates want orchestration inside the Fortinet fabric rather than a standalone tool.
Documented capabilities
The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.
- Playbooks and case management across Fortinet and third-party tools the buyer connects.
- Expert agents plus API and MCP connections for actions the customer authorizes.
- Multi-tenancy for managed service providers and advertised OT-oriented content packs that still require the buyer to validate plant impact.
Where it fits in the work
- Decide SaaS versus self-managed deployment and which tenants an MSSP would isolate.
- Encode a playbook that enriches an alert and requires human approval before OT-adjacent actions.
- Inventory connectors actually in use rather than relying on published connector counts.
APPLY THE IDEA / ILLUSTRATIVE EXERCISE
Make the outcome observable.
In an authorized lab tenant that is not connected to plant networks, run a synthetic workstation alert playbook that enriches asset data, pauses before any isolation, and never targets a safety-instrumented system.
Evidence to look for
The case shows enrichment and the human pause, and no OT or production host received a containment action.
Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.
Questions for your evaluation
- Which OT detections are read-only, and who authorizes any process-impacting containment?
- Does an MSSP tenant model match how you separate customers or plants?
- How are playbooks and cases exported if FortiSOAR is later replaced, including MSSP tenant separation?