Skip to main content

User Knowledge Base

RBAC Roles: What Users Can Do in Products

RBAC roles are permissions that control what functions a user can operate in each BlueVoyant product for which they have access.

Cyber Defense Platform (CDP)

  • Platform Roles (all of CDP):

    • Platform-Viewer: Can see Marketplace and information (everyone gets this automatically)

    • Platform-Analyst: Can create support tickets and run operations

    • Platform-Admin: Can manage users and IT configurations

  • Module Roles (for each licensed module in CDP):

    If your organization has the Detection & Response, Cyber Posture Management (CPM), or Proactive Defense modules, you may have roles for each module:

    • Viewer: Can see information and make reports

    • Analyst: Can see data and use all functions

    • Admin: Can see everything and manage other users' access

  • Multiple Module Access: Users can have different permissions for different modules. For example, a user may be an Analyst for Detection & Response but only a Viewer for CPM.

Next-Gen BlueVoyant AI

BlueVoyant AI uses application roles selected in Entra ID for permissions:

  • external-read-only: View reports and evidence

  • external-admin: Approve actions and manage local users

  • soc-analyst: Investigate and respond to incidents

  • soc-admin: Full system management