Roles
| Role | Can |
|---|---|
| Admin | Everything, including users, organizations, integrations, AI settings and system settings. |
| Lead | Work and manage alerts, cases, detections, playbooks, suppressions and reports for granted organizations; reopen closed cases. |
| Analyst | Work alerts, cases, logs and response for granted organizations; run manual playbooks; confirm staged actions. |
| Viewer | Read-only access to granted organizations. |
Roles are enforced on the server for every request, and the console shows each role the actions available to it.
Grants
Each account is granted specific organizations or all. Grants apply to every module. An admin always sees everything.
Creating accounts
Settings › Team & roles › Add. Enter the email, choose the role and grants. The person sets a password from the invitation, or signs in with Fluence Account if single sign-on is configured; in that case the console account must exist first. See Single sign-on.
Removing access
Disable the account; its sessions end on their next request. History attributed to the account is kept. Reassign owned cases before disabling.
Multi-factor authentication
For multi-factor authentication on console accounts, use single sign-on through Fluence Account, which applies the identity provider's controls. Keep the bootstrap administrator account for recovery. The customer portal requires an authenticator app for every account.