Permissions to access settings

The permission structure in the Intelligence Center separates permissions in the following groups:

  • Permissions users require to configure and to manage Intelligence Center settings, features, and functionality.

  • Permissions users require to access and to consume Intelligence Center data.

Actions and permissions to access settings and configuration

The following table shows the permissions roles and users require to carry out actions affecting Intelligence Center settings and configuration.

Action

Steps

Permissions

Search entities and observables.

In the side navigation bar click the search icon images/download/attachments/82474974/search.svg-x24.png .

  • read entities

  • read extracts

View available incoming feeds.

In the left navigation bar click Data configuration > Incoming feeds.

  • read content-types

  • read incoming-feeds

  • read transports

  • read users

  • read workspaces

View an incoming feed detail pane, including any content in the detail pane tabs.

In the left navigation bar click Data configuration > Incoming feeds, select a feed in the overview, and open the corresponding feed detail pane.

  • read blob-uploads

  • read content-types

  • read entities

  • read history-events

  • read transports

  • read users

Create a new incoming feed.

Edit an existing incoming feed.

In the left navigation bar click Data configuration > Incoming feeds > + (Create incoming feed).

Or select a feed in the overview, and then in the feed detail pane click images/download/attachments/82474974/ellipsis-v.svg-x24.png > Edit.

  • modify incoming-feeds

  • read content-types

  • read transports

Manually trigger an incoming feed task run to download new packages, if available.

In the left navigation bar click Data configuration > Incoming feeds, select a feed in the overview, and open the corresponding feed detail pane.

In the Overview tab of the feed detail pane, click Download now.

  • modify incoming-feeds

View available outgoing feeds.

In the left navigation bar click Data configuration > Outgoing feeds.

  • read content-types

  • read outgoing-feeds

  • read transports

View an outgoing feed detail pane, including any content in the detail pane tabs.

In the left navigation bar click Data configuration > Outgoing feeds, select a feed in the overview, and open the corresponding feed detail pane.

  • read content-blocks

  • read content-types

  • read entities

  • read extracts

  • read history-events

  • read intel-sets

  • read transports

  • read users

Create a new outgoing feed.

Edit an existing outgoing feed.

In the left navigation bar click Data configuration > Outgoing feeds > + (Create incoming feed).

Or select a feed in the overview, and then in the feed detail pane click images/download/attachments/82474974/ellipsis-v.svg-x24.png , Edit.

  • modify outgoing-feeds

  • read content-types

  • read extracts

  • read groups

  • read intel-sets

  • read transports

  • read users

Manually trigger an outgoing feed task run to publish new packages, if available.

In the left navigation bar click Data configuration > Outgoing feeds, select a feed in the overview, and open the corresponding feed detail pane.

In the Overview tab of the feed detail pane, click Run now.

  • modify outgoing-feeds

View the taxonomy.

In the left navigation bar click Data configuration > Taxonomies.

  • read taxonomies

Create a new taxonomy entry.

Edit an existing taxonomy entry.

Delete an existing taxonomy entry.

In the left navigation bar click Data configuration > Taxonomies > + (Create taxonomy).

Alternatively: in the row corresponding to the taxonomy entry you want to modify or remove, click images/download/attachments/82474974/ellipsis-v.svg-x24.png > Edit; or click images/download/attachments/82474974/ellipsis-v.svg-x24.png > Delete.

  • modify taxonomies

View available enrichers.

In the left navigation bar click Data configuration >Enrichers.

  • read enrichers

Edit an existing enricher.

In the left navigation bar click Data configuration > Enrichers, select an enricher in the overview, and open the corresponding detail pane.

In the enricher detail pane, click Edit.

  • modify enrichers

Enable and disable enrichers.

In the left navigation bar click Data configuration > Enrichers, and then on an enricher tile click Enable.

  • modify enrichers

View available rules.

In the left navigation bar click Data configuration > Rules.

At least one of the following permissions:

  • read discovery-rules

  • read enrichment-rules

  • read rules

View an observable rule detail pane, including any content in the detail pane tabs.

In the left navigation bar click Data configuration > Rules > Observable tab, and then select an observable rule to open the corresponding detail pane.

  • read extracts

  • read history-events

  • read rules

  • read users

Create a new observable rule.

Edit an existing observable rule.

Delete an existing observable rule.

In the left navigation bar click Data configuration > Rules > Observable tab, and then click + (Create rule).

Alternatively: in the row corresponding to the rule you want to modify or remove, click images/download/attachments/82474974/ellipsis-v.svg-x24.png > Edit; or click images/download/attachments/82474974/ellipsis-v.svg-x24.png > Delete.

  • modify rules

Create and preview a new observable rule.

In the left navigation bar click Data configuration > Rules > Observable tab, and then click + (Create rule).

Define the new rule, and then click Preview rule.

  • modify rules

  • read extracts

Manually run an observable rule.

In the left navigation bar click Data configuration > Rules > Observable tab, select a rule in the overview, and open the corresponding rule detail pane.

In the Overview tab of the rule detail pane, click Run now.

  • modify rules

View an entity rule detail pane, including any content in the detail pane tabs.

In the left navigation bar click Data configuration > Rules > Entity tab, select a rule in the overview, and open the corresponding rule detail pane.

  • read entities

  • read history-events

  • read rules

  • read users

Create a new entity rule.

Edit an existing entity rule.

Delete an existing entity rule.

In the left navigation bar click Data configuration > Rules > Entity tab, and then click + (Create rule).

Alternatively: in the row corresponding to the rule you want to modify or remove, click images/download/attachments/82474974/ellipsis-v.svg-x24.png > Edit; or click images/download/attachments/82474974/ellipsis-v.svg-x24.png > Delete.

  • modify rules

  • read sources

  • read taxonomies

Create and preview a new entity rule.

In the left navigation bar click Data configuration > Rules > Entity tab, and then click + (Create rule).

Define the new rule, and then click Preview rule.

  • modify rules

  • read entities

  • read sources

Manually run an entity rule.

In the left navigation bar click Data configuration > Rules > Entity tab, select a rule in the overview, and open the corresponding rule detail pane.

In the Overview tab of the rule detail pane, click Run now.

  • modify rules

View an enrichment rule detail pane, including any content in the detail pane tabs.

In the left navigation bar click Data configuration > Rules > Enrichment tab, select a rule in the overview, and open the corresponding rule detail pane.

  • read enrichers

  • read enrichment-rules

  • read history-events

  • read source

  • read users

Create a new enrichment rule.

Edit an existing enrichment rule.

Delete an existing enrichment rule.

In the left navigation bar click Data configuration > Rules > Enrichment tab, and then click + (Create rule).

Alternatively: in the row corresponding to the rule you want to modify or remove, click images/download/attachments/82474974/ellipsis-v.svg-x24.png > Edit; or click images/download/attachments/82474974/ellipsis-v.svg-x24.png > Delete.

  • modify enrichment-rules

Manually run an enrichment rule.

In the left navigation bar click Data configuration > Rules > Enrichment tab, select a rule in the overview, and open the corresponding rule detail pane.

In the Overview tab of the rule detail pane, click Run now.

  • modify enrichment-rules

View a discovery rule detail pane, including any content in the detail pane tabs.

In the left navigation bar click Data configuration > Rules > Discovery tab, select a rule in the overview, and open the corresponding rule detail pane.

  • read discovery-rules

  • read history-events

  • read users

Create a new discovery rule.

Edit an existing discovery rule.

Delete an existing discovery rule.

In the left navigation bar click Data configuration > Rules > Discovery tab, and then click + (Create rule).

Alternatively: in the row corresponding to the rule you want to modify or remove, click images/download/attachments/82474974/ellipsis-v.svg-x24.png > Edit; or click images/download/attachments/82474974/ellipsis-v.svg-x24.png > Delete.

  • modify discovery-rules

  • read workspaces

Manually run a discovery rule.

In the left navigation bar click Data configuration > Rules > Discovery tab, select a rule in the overview, and open the corresponding rule detail pane.

In the Overview tab of the rule detail pane, click Run now.

  • modify discovery-rules

View available policies.

In the left navigation bar click Data configuration > Policies.

  • read retention-policies

View a policy detail pane, including any content in the detail pane tabs.

In the left navigation bar click Data configuration > Policies, select a policy in the overview, and open the corresponding policy detail pane.

  • read entities

  • read history-events

  • read retention-policies

  • read sources

  • read tasks

  • read taxonomies

  • read users

Create a new policy.

Edit an existing policy.

Delete an existing policy.

In the left navigation bar click Data configuration > Policies > + (Create retention policy).

Alternatively: in the row corresponding to the policy you want to modify or remove, click images/download/attachments/82474974/ellipsis-v.svg-x24.png > Edit; or click images/download/attachments/82474974/ellipsis-v.svg-x24.png > Delete.

  • modify retention-policies

  • read sources

  • read taxonomies