Users and roles

Analyst accounts, the four roles, organization grants and single sign-on.

Roles

RoleCan
AdminEverything, including users, organizations, integrations, AI settings and system settings.
LeadWork and manage alerts, cases, detections, playbooks, suppressions and reports for granted organizations; reopen closed cases.
AnalystWork alerts, cases, logs and response for granted organizations; run manual playbooks; confirm staged actions.
ViewerRead-only access to granted organizations.

Roles are enforced on the server for every request, and the console shows each role the actions available to it.

Grants

Each account is granted specific organizations or all. Grants apply to every module. An admin always sees everything.

Creating accounts

Settings › Team & roles › Add. Enter the email, choose the role and grants. The person sets a password from the invitation, or signs in with Fluence Account if single sign-on is configured; in that case the console account must exist first. See Single sign-on.

Removing access

Disable the account; its sessions end on their next request. History attributed to the account is kept. Reassign owned cases before disabling.

Multi-factor authentication

For multi-factor authentication on console accounts, use single sign-on through Fluence Account, which applies the identity provider's controls. Keep the bootstrap administrator account for recovery. The customer portal requires an authenticator app for every account.