// Administration

Users and access

Who can act inside the platform, and at what level. Roles are provisioned by the identity provider and cannot be edited here, so privilege cannot be granted from inside the console it protects.

3accounts1administrators

Accounts

The last administrator cannot be demoted.

NameEmailRoleCasesActionsJoined
Zain Khanzkhan@aegis.localAdministrator03
Analystanalyst@aegis.localAnalyst26
Viewerviewer@aegis.localViewer01

What each role can do

Enforced server-side on every mutation, not just hidden in the interface.

CapabilityViewerAnalystAdministrator
View incidents, alerts and telemetry
Set alert disposition
Escalate alerts into incidents
Change incident status
Assign incidents
Add case notes
Run containment actions
Arm and disarm detection rules
Run detection sweeps and rescore entities
Save and delete hunt queries
Manage the entity watchlist
Create and remove alert suppressions
Add and retire threat indicators
Attach playbooks and complete their steps
Maintain the asset inventory
Author and edit response playbooks
Run non-destructive automations
Run destructive automations (offboarding, lockout, isolation)
Change vulnerability status
Write, test and delete detection rules
Apply the retention policy and delete aged telemetry
Change platform settings