Roles and permissions
The three tenant roles in Advisor, the capabilities of each one and the permissions outside the default roles.
Updated View as Markdown
Access in Advisor is granted by role within each tenant. A user can have different roles in different tenants. Menu items show up according to the role's permissions. An address opened without permission shows an access-denied screen.
Tenant roles
| Role | For whom |
|---|---|
| Tenant Admin | Setting up and operating Advisor for the customer: connection, members, SSO, risks, spikes and responses. |
| Tenant Manager | Access administration: viewing and managing members and invites. |
| Tenant User | Monitoring: viewing posture, metrics, incidents and responses, without permission to change them. |
Roles are assigned in Administração (Administration) > Membros (Members).
What each role can do
| Capability | Permission | Tenant Admin | Tenant Manager | Tenant User |
|---|---|---|---|---|
| See Overview, Risks, Inventory, Evolution, Cloudflare and Integrations | connections.read |
Yes | No | Yes |
| Add, edit or delete the connection | connections.write |
Yes | No | No |
| Accept and restore risks | posture.ignores.write |
Yes | No | No |
| Delete a zone already removed in Cloudflare | connections.zones.delete |
Yes | No | No |
| See members | tenants.members.read |
Yes | Yes | No |
| Invite, change roles and remove members | tenants.members.write |
Yes | Yes | No |
| Set up SSO | tenants.sso.manage |
Yes | No | No |
| Make two-step verification mandatory | tenants.security.manage |
Yes | No | No |
| See the tenant audit trail | audit.read |
Yes | No | No |
| See spike rules and incidents | spikes.rules.read, spikes.incidents.read |
Yes | No | Yes |
| Create and edit rules; resolve, ignore and reopen incidents | spikes.rules.write |
Yes | No | No |
| See responses, analyses and the knowledge base | responder.read |
Yes | No | Yes |
| Approve, reject and run actions; reanalyze | responder.actions.execute |
Yes | No | No |
| Edit playbooks | responder.playbooks.write |
Yes | No | No |
| Edit the knowledge base | responder.knowledge.write |
Yes | No | No |
| See notification destinations | notifications.read |
Yes | No | Yes |
| Create and edit notification destinations | notifications.write |
Yes | No | No |
| See domain expiry | domains.expiry.read |
Yes | No | Yes |
| Set up expiry warnings | domains.expiry.write |
Yes | No | No |
Permissions outside the default roles
Some features are not included in any tenant role. To get access, contact Guardnet.
| Feature | Permission |
|---|---|
| Sincronizar (manual sync) and Sincronizar alterações (Sync changes) | connections.scan |
| Recalcular (Recalculate) a zone's score | posture.rules.write |
| Ao Vivo (Live) menu, the request map | map.read |
| Origem do mapa (Map origin) | map.write |