You can also see the walkthrough in this link
In the Users menu you can perform the following actions:
Add a user
Assign role to a user
Reset the password for a user
Reset multi-factor authorization (MFA) for a user
Remove user access
Resend invite email to a user
Delete a user account
Edit users
Send users a Bix instruction
In the Roles and access control menu you can perform Role Based Access Control (RBAC) with the following actions:
Add a role
View and edit roles
Duplicate roles
Delete roles
In the Allowed email domains menu you can perform the following actions:
Add allowed email domain
Remove allowed email domain
Role Parameters for RBAC
Parameter | Possible States |
|---|---|
Exposure Management | |
Simulation | None, View, Full |
Control Findings | None, View, Full |
Analytics | None, View, Full |
Appsec Findings | None, View, Full |
Exceptions | None, Limited, Full |
Settings | None, View, Full |
Remediation And Mitigation | None, View, Full |
Asset Vulnerabilities | None, View, Full |
User Risk Findings | None, View, Full |
Dashboard | |
Dashboard | None, View, Full |
Cyber Risk | |
Analysis | None, View, Full |
Reporting | None, View, Full |
Analytics | None, View, Full |
Settings | None, View, Full |
Inventory | |
Assets | None, View, Full |
Users | None, View, Full |
Settings | None, View, Full |
Apps | None, View, Full |
Controls | None, View, Full |
Group Management | None, View, Full |
Analytics | None, View, Full |
Data Sources | |
Data Sources | None, View, Full |
Automation | |
Automation | None, Limited, Full |
Activity | |
Alerts | None, View, Full |
Exports | None, View, Full |
Logs | None, View, Full |
Company Settings | |
Company Settings | None, View, Full |
Others | |
Create Projects/Tickets | Selected, Not Selected |
BIX | Selected, Not Selected |
Role-Based Access Control (RBAC)
Role-Based Access Control (RBAC) in Balbix is structured as a matrix:
Columns = Roles, which define the actions a user can perform.
Rows = Scopes, which define the set of assets (infrastructure, applications, or users) the role applies to.
This design separates what a user can do from where they can do it, enabling fine-grained and scalable access management.
Balbix simplifies RBAC management through:
Scope Creation – Define groups of assets using 100s of filters (e.g., Tags, Business Units, OS platforms, Subnets, Sites).
Control Scope – Specify the actions a role can perform, with permission levels (None / View / Limited / Full).
User Assignment – Bind users to specific scopes and roles.
RBAC Menus
In the Roles and access control menu, you can perform the following actions:
Add a role
View and edit roles
Duplicate roles
Delete roles
Assign users to roles
Permission Levels
Balbix defines four permission states across modules:
State | Definition |
|---|---|
None | The user has no access. The module is hidden in the UI. |
View | User has read only access. |
Limited | Any exceptions you get to see (beyond whatever you can create/edit/delete, if applicable) are those created by you. |
Full | The user has full read/write access. They can create, edit, configure, and delete in that module. |
Role Parameters for RBAC
Each module in Balbix supports specific permission states:
Module | Possible States |
|---|---|
Exposure Management | None, View, Full |
Control Findings | None, View, Full |
Analytics | None, View, Full |
AppSec Findings | None, View, Full |
Exceptions | None, Limited, Full |
Settings | None, View, Full |
Remediation & Mitigation | None, View, Full |
Asset Vulnerabilities | None, View, Full |
User Risk Findings | None, View, Full |
Dashboard | None, View, Full |
Cyber Risk Analysis | None, View, Full |
Cyber Risk Reporting | None, View, Full |
Cyber Risk Analytics | None, View, Full |
Inventory | None, View, Full |
– Assets | None, View, Full |
– Users | None, View, Full |
– Apps | None, View, Full |
– Controls | None, View, Full |
– Group Management | None, View, Full |
Data Sources | None, View, Full |
Automation | None, Limited, Full |
Activity | None, View, Full |
– Alerts | None, View, Full |
– Exports | None, View, Full |
– Logs | None, View, Full |
Company Settings | None, View, Full |
Others | Selected / Not Selected |
– Create Projects/Tickets | Selected / Not Selected |
– BIX | Selected / Not Selected |
Example Workflow
Create a Scope: Define “Finance Division” using tags and subnet filters.
Define Role: Configure “Finance Risk Analyst” role with View access to dashboards and Limited access to exceptions.
Assign User: Link a user (e.g., jane.doe@company.com) to the Finance Division scope and the Finance Risk Analyst role.
This ensures Jane can only view findings related to the Finance Division and request exceptions, without the ability to modify other business units or system-wide settings.


Key Benefits
Separation of scope and control for clarity and scalability.
Granular asset grouping across infrastructure, apps, and users.
Consistent permission model with standardized states.
Ease of administration for large enterprises with complex environments.