- 1 Minute to read
-
Print
-
PDF
User Role
- 1 Minute to read
-
Print
-
PDF
Introduction
Users Roles restrict/allow users to access data and perform actions on the SAFE application.
This document allows users to understand the level of data they can access and perform actions based on the assigned User Roles.
The following four pre-configured User Roles are available in SAFE:
- Admin
- Auditor
- Viewer
- Limited User
Admin
The users with Admin Role have complete access to all system features, functions, and data.
Auditor
The users with Auditor Role have complete access to certain features, functions, and data related to assessment, reporting, etc. Still, they do not have access to certain administrative functions such as configuring global policies, custom control policies, assessment and management tools, etc.
Viewer
The users with Viewer Role have only view access to system features, functions, and data.
Limited User
The users with Limited User Role have complete access to all features, functions, and data w.r.t to assets that the user owns.
User Role Access
Module | Sub-Module | Admin | Auditor | Viewer | Limited User |
---|---|---|---|---|---|
Dashboard | Overall Score/Score Trend | View | View | View | Not Visible |
Score Change | View | View | View | Not Visible | |
Technology Distribution | View | View | View | View for only assets assigned to the user | |
Asset Groups | View | View | View | View(only for self-created groups) | |
Technology Spider Graph | View | View | View | Not Visible | |
Asset Group Spider Graph | View | View | View | Not Visible | |
Location wise Score | View | View | View | Not Visible | |
Gap Report | View | View | View | Not Visible | |
Actionable Insight | View | View | View | View(only for assets/asset groups assigned to him) | |
Master Control List | Read-Write | Read-Write | View | View for Assets assigned to the user | |
About Page | View | View | View | View | |
Policy | View | View | View | Not Visible | |
Compliance | View | View | View | Not Visible | |
Assessment | People | Read-Write | Read-Write | Read Only | Not Visible |
Policy | Read-Write | Read-Write | Read Only | Not Visible | |
Technology | Read-Write | Read-Write | Read Only | Read-Write for user’s assets. | |
CSP | Read-Write | Read-Write | Read Only | Not Visible | |
External | Read-Write | Read-Write | Read Only | Not Visible | |
Compliance | Read-Write | Read-Write | Read Only | Not Visible | |
Reports | Overall Report | Generate/Schedule | Generate/Schedule | Generate/Schedule | Not Visible |
Technology Report | Generate/Schedule | Generate/Schedule | Generate/Schedule | Not Visible | |
Asset Report | Generate/Schedule | Generate/Schedule | Generate/Schedule | Generate/Schedule for assets assigned to the user | |
Asset Group Report | Generate/Schedule | Generate/Schedule for user’s local group + All global group | Generate/Schedule for user’s local group + All global group | Generate/Schedule for user’s groups | |
Compliance Report | Generate/Schedule | Generate/Schedule | Generate/Schedule | Not Visible | |
External Report | Generate/Schedule | Generate/Schedule | Generate/Schedule | Not Visible | |
Scheduled Report | Read/Write | Read/Write for his own reports | Read/Write for his own reports | Read/Write for his own reports | |
History Report | Read/Write | Read/Write for his own reports | Read/Write for his own reports | Read/Write for his own reports | |
Miscellaneous Report | Generate/Schedule | Generate/Schedule | Generate/Schedule | Not Visibile | |
Notifications | Asset Score Change | Read-Write | Read-Write | Read-Write | Read-Write |
Vertical Score Change | Read-Write | Read-Write | Read-Write | Not Visible | |
Asset Group Score Change | Read-Write | Read-Write | Read-Write | Read-Write | |
Overall Score Change | Read-Write | Read-Write | Read-Write | Not Visible | |
Asset Offboarding - Auto Retire | Read-Write | Not Visible | Read-Write | Not Visible | |
Asset Offboarding - Auto Delete | Read-Write | Not Visible | Read-Write | Not Visible | |
Financial Risk Exposure | Read-Write | Not Visibile | Not Visibile | Not Visibile | |
Manage Agent | Read-Write | Read-Write | Read Only | Read- Write for user’s assets | |
Administration | User Management | Read-Write | Read Only | Read Only | Not Visible |
Company Management | Read-Write | Read Only | Read Only | Not Visible | |
Department Management | Read-Write | Read Only | Read Only | Not Visible | |
Location Management | Read-Write | Read Only | Read Only | Not Visible | |
Company Profile | Read-Write | Read Only | Read Only | Not Visible | |
Asset Management | Read-Write | Read Only | Read Only | Visible(only his assets) | |
Manage Assets | Read-Write | Read Only | Read Only | Not Visible | |
Asset Group Management | Read-Write | Read-Write for user-created groups | Read-Write for user-created groups | Read-Write(for his own assets) | |
Custom Fields | Read-Write | Read Only | Read Only | Not Visible | |
Agent Global Policy | Read-Write | Not Visible | Not Visible | Not Visible | |
Asset Offboarding Policy[Cycle 7] | Read-Write | Not Visible | Not Visible | Not Visible | |
Agent & Site management | Read-Write | Read Only | Read Only | Read Only | |
Governance Management | Read-Write | Read Only | Read Only | Not Visible | |
SAFE Hooks | Read-Write | Read-Write | Not Visible | Not Visible | |
Assessment Tools | Read-Write | Read-Write Note: Auditor has only Read access for AWS Configuration. | Not Visible | Not Visible | |
Management Tools | Read-Write | Not Visible | Not Visible | Not Visible | |
Enrichment Tools | Read-Write | Not Visible | Not Visible | Not Visible | |
Settings | Read-Write | Read Only | Read Only | Visible | |
Settings > Customizable Dashboard | Read-Write | Read-Write | Read Only | Read-Write | |
Control Policies | Read-Write | Not Visible | Not Visible | Not Visible |