// Administration
Users and access
Who can act inside the platform, and at what level. Roles are provisioned by the identity provider and cannot be edited here, so privilege cannot be granted from inside the console it protects.
3accounts1administrators
Accounts
The last administrator cannot be demoted.
| Name | Role | Cases | Actions | Joined | |
|---|---|---|---|---|---|
| Zain Khan | zkhan@aegis.local | Administrator | 0 | 3 | |
| Analyst | analyst@aegis.local | Analyst | 2 | 6 | |
| Viewer | viewer@aegis.local | Viewer | 0 | 1 |
What each role can do
Enforced server-side on every mutation, not just hidden in the interface.
| Capability | Viewer | Analyst | Administrator |
|---|---|---|---|
| View incidents, alerts and telemetry | |||
| Set alert disposition | |||
| Escalate alerts into incidents | |||
| Change incident status | |||
| Assign incidents | |||
| Add case notes | |||
| Run containment actions | |||
| Arm and disarm detection rules | |||
| Run detection sweeps and rescore entities | |||
| Save and delete hunt queries | |||
| Manage the entity watchlist | |||
| Create and remove alert suppressions | |||
| Add and retire threat indicators | |||
| Attach playbooks and complete their steps | |||
| Maintain the asset inventory | |||
| Author and edit response playbooks | |||
| Run non-destructive automations | |||
| Run destructive automations (offboarding, lockout, isolation) | |||
| Change vulnerability status | |||
| Write, test and delete detection rules | |||
| Apply the retention policy and delete aged telemetry | |||
| Change platform settings |