User Roles and Permissions

Control what each user in your organization can see and do in Nebulock by assigning roles.

Nebulock uses role-based access control (RBAC) to determine what each user in your organization can see and do. Every user is assigned one or more roles, and each role grants a defined set of permissions across the platform.

Roles are assigned per user in Settings → Users. A user's access is the combined total of every role assigned to them.


Available roles

RoleWho it's forWhat it grants
Platform UserAnalysts, threat hunters, detection engineers, and anyone who uses Nebulock day to dayFull access to the threat hunting platform, including Hunts, Detections, Findings, Anomalies, Actors, and AI Usage
Organization AdminThe people who manage your Nebulock tenantAccess to administrative settings only: Users, API Keys, Vespyr Settings, Integrations, and Custom Configurations
Insider Risk AnalystUsers who should only see insider risk dataAccess to Anomalies, Actors, and AI Usage. No access to the rest of the platform
⚠️

Roles do not inherit from one another.

Assigning Organization Admin does not grant access to the platform itself, and assigning Platform User does not grant access to administrative settings. A person who needs to both manage your tenant and run hunts must be assigned both roles.

We are expanding the available roles over time and recommend you follow least privilege best practices rather than assign all roles to all users.

What each role can access

Platform User

Platform User is the standard role for anyone who uses Nebulock. It grants full access to:

  • Hunts and all hunt sub-pages, including Vespyr hunts and hunt reports
  • Detections, including creating, editing, deploying, and version history
  • Findings
  • Anomalies
  • Actors, including the actors watchlist
  • AI Usage
  • Command Center and Insights

A Platform User can't add or remove users, create API keys, configure integrations, manage Vespyr's automated hunt settings, or change custom configurations. Those require Organization Admin.

When a Platform User signs in, they land on the Command Center.

Organization Admin

Organization Admin governs your Nebulock tenant. It grants full access to:

  • Users: add users, remove users, and assign roles
  • API Keys: create, view, and revoke API keys
  • Integrations: connect and configure data sources and destinations
  • Vespyr: configure scheduled and automated hunts
  • Custom Configurations: tenant-level configuration settings

Organization Admin does not grant access to hunts, detections, findings, or any other part of the threat hunting platform. Administrators who also need to use the platform should additionally be assigned Platform User.

Insider Risk Analyst

Insider Risk Analyst is a restricted role for users who should only see insider risk data. It grants full access to:

  • Anomalies and all anomalies sub-pages
  • Actors
  • AI Usage, including AI Usage settings
📘

Insider Risk Analysts can't see findings derived from Anomalies

While the role grants access to the Anomalies dashboard, findings generated from anomalous activity live under Findings, which this role does not include. If an analyst needs to work those findings, they also need Platform User.

An Insider Risk Analyst with no other roles can't see Hunts, Detections, Findings, Insights, or the Command Center. These areas are hidden from navigation and blocked at the API.

When an Insider Risk Analyst signs in without any other role, they land on the Anomalies page.

Assign a role to a user

You must be an Organization Admin to assign roles.

  1. Go to Settings → Users.
  2. Select an existing user, or click Add User to create a new one.
  3. Under Roles, select every role the user needs. Remember that roles don't inherit, so select all that apply.
  4. Save. New users receive a welcome email with first-time login instructions.

Role changes take effect the next time the user signs in.

Common role combinations

The personAssign
Security analyst or threat hunterPlatform User
Detection engineerPlatform User
Tenant administrator who does not huntOrganization Admin
Team lead who administers and huntsOrganization Admin and Platform User
Insider risk specialistInsider Risk Analyst
Insider risk specialist who also investigates findingsInsider Risk Analyst and Platform User

Roles and single sign-on

Roles are assigned in Nebulock, not in your identity provider. If your organization uses Okta SAML SSO or Entra SAML SSO, SSO controls who can sign in. Roles still control what they can do once they're in.


Did this page help you?