Resource-Permission Matrix for Custom Roles
Resource | Create | Read | Update | Delete | Privileged |
|---|---|---|---|---|---|
Platform | ✓ | ✓ | ✓ | ||
Platform-Settings | ✓ | ✓ | ✓ | ✓ | |
Support | ✓ | ✓ | ✓ | ✓ | |
Case-Monitoring | ✓ | ✓ | ✓ | ✓ | |
MITRE | ✓ | ✓ | |||
Assets | ✓ | ✓ | |||
Vulnerabilities | ✓ | ✓ | |||
Patching | ✓ | ✓ | |||
Compliance | ✓ | ✓ | ✓ | ✓ | ✓ |
Risk | ✓ | ✓ | ✓ | ✓ | ✓ |
Maturity | ✓ | ✓ | ✓ | ✓ | ✓ |
Evidence | ✓ | ✓ | ✓ | ✓ | |
Threat Intel | ✓ | ✓ | ✓ | ||
Threat Hunt | ✓ | ✓ | ✓ | ||
Self-Assessment | ✓ | ✓ |
Privileged - Required to give roles for that module, feature, or data to other users.
Admin roles - Require Privileged for managed resources. Platform Admin can give a role without product data access. Module Admins can give roles for resources where they have Privileged permissions.
Custom role creation - Administrator must have Privileged permission for each resource they give permissions to other users. Custom roles inherit the permission constraints of the role that created them.
Module access requires explicit roles for licensed modules.