Documentation Index

Fetch the complete documentation index at: https://docs.safe.security/llms.txt

Use this file to discover all available pages before exploring further.

Configure Users and Access

Prev Next


You can also see the walkthrough in this link

In the Users menu you can perform the following actions:

  • Add a user

  • Assign role to a user

  • Reset the password for a user

  • Reset multi-factor authorization (MFA) for a user

  • Remove user access

  • Resend invite email to a user

  • Delete a user account

  • Edit users

  • Send users a Bix instruction

In the Roles and access control menu you can perform Role Based Access Control (RBAC) with the following actions:

  • Add a role

  • View and edit roles

  • Duplicate roles

  • Delete roles

In the Allowed email domains menu you can perform the following actions:

  • Add allowed email domain

  • Remove allowed email domain

Role Parameters for RBAC

Parameter

Possible States

Exposure Management

Simulation

None, View, Full

Control Findings

None, View, Full

Analytics

None, View, Full

Appsec Findings

None, View, Full

Exceptions

None, Limited, Full

Settings

None, View, Full

Remediation And Mitigation

None, View, Full

Asset Vulnerabilities

None, View, Full

User Risk Findings

None, View, Full

Dashboard

Dashboard

None, View, Full

Cyber Risk

Analysis

None, View, Full

Reporting

None, View, Full

Analytics

None, View, Full

Settings

None, View, Full

Inventory

Assets

None, View, Full

Users

None, View, Full

Settings

None, View, Full

Apps

None, View, Full

Controls

None, View, Full

Group Management

None, View, Full

Analytics

None, View, Full

Data Sources

Data Sources

None, View, Full

Automation

Automation

None, Limited, Full

Activity

Alerts

None, View, Full

Exports

None, View, Full

Logs

None, View, Full

Company Settings

Company Settings

None, View, Full

Others

Create Projects/Tickets

Selected, Not Selected

BIX

Selected, Not Selected

Role-Based Access Control (RBAC)

Role-Based Access Control (RBAC) in Balbix is structured as a matrix:

  • Columns = Roles, which define the actions a user can perform.

  • Rows = Scopes, which define the set of assets (infrastructure, applications, or users) the role applies to.

This design separates what a user can do from where they can do it, enabling fine-grained and scalable access management.

Balbix simplifies RBAC management through:

  1. Scope Creation – Define groups of assets using 100s of filters (e.g., Tags, Business Units, OS platforms, Subnets, Sites).

  2. Control Scope – Specify the actions a role can perform, with permission levels (None / View / Limited / Full).

  3. User Assignment – Bind users to specific scopes and roles.

RBAC Menus

In the Roles and access control menu, you can perform the following actions:

  • Add a role

  • View and edit roles

  • Duplicate roles

  • Delete roles

  • Assign users to roles

Permission Levels

Balbix defines four permission states across modules:

State

Definition

None

The user has no access. The module is hidden in the UI.

View

User has read only access.

Limited

Any exceptions you get to see (beyond whatever you can create/edit/delete, if applicable) are those created by you.

Full

The user has full read/write access. They can create, edit, configure, and delete in that module.

Role Parameters for RBAC

Each module in Balbix supports specific permission states:

Module

Possible States

Exposure Management

None, View, Full

Control Findings

None, View, Full

Analytics

None, View, Full

AppSec Findings

None, View, Full

Exceptions

None, Limited, Full

Settings

None, View, Full

Remediation & Mitigation

None, View, Full

Asset Vulnerabilities

None, View, Full

User Risk Findings

None, View, Full

Dashboard

None, View, Full

Cyber Risk Analysis

None, View, Full

Cyber Risk Reporting

None, View, Full

Cyber Risk Analytics

None, View, Full

Inventory

None, View, Full

– Assets

None, View, Full

– Users

None, View, Full

– Apps

None, View, Full

– Controls

None, View, Full

– Group Management

None, View, Full

Data Sources

None, View, Full

Automation

None, Limited, Full

Activity

None, View, Full

– Alerts

None, View, Full

– Exports

None, View, Full

– Logs

None, View, Full

Company Settings

None, View, Full

Others

Selected / Not Selected

– Create Projects/Tickets

Selected / Not Selected

– BIX

Selected / Not Selected

Example Workflow

  1. Create a Scope: Define “Finance Division” using tags and subnet filters.

  2. Define Role: Configure “Finance Risk Analyst” role with View access to dashboards and Limited access to exceptions.

  3. Assign User: Link a user (e.g., jane.doe@company.com) to the Finance Division scope and the Finance Risk Analyst role.

This ensures Jane can only view findings related to the Finance Division and request exceptions, without the ability to modify other business units or system-wide settings.

Key Benefits

  • Separation of scope and control for clarity and scalability.

  • Granular asset grouping across infrastructure, apps, and users.

  • Consistent permission model with standardized states.

  • Ease of administration for large enterprises with complex environments.