User Roles for Data Security
Introduction
Data Security uses the same Eyeglass Role-Based Access Control (RBAC) system as the rest of the Eyeglass platform, managed from the User Roles menu in the Eyeglass UI. This page covers the specific roles and permissions relevant to Ransomware Defender and Easy Auditor.
Data Security Roles and Permissions
| Role/Permission | Purpose |
|---|---|
| RANSOMWARE_DEFENDER | View and configure Ransomware Defender. |
| RANSOMWARE_READONLY | Read-only view of Ransomware Defender. |
| EASY_AUDITOR_VIEW | View existing reports, queries, and wiretaps. |
| EASY_AUDITOR_MODIFY | Add and update reports, queries, schedules, and wiretaps. |
A built-in role and user account separate the management of Ransomware Defender settings from event monitoring: the Ransomware Defender role manages and monitors the product, while RANSOMWARE_READONLY limits a user to viewing events without the ability to change configuration.
Easy Auditor has its own built-in account for separation of duties.
Assigning Data Security Roles
Follow the Create Roles → Assign Permissions → Assign Roles to Users/Groups workflow in the Eyeglass UI, selecting the Data Security permissions above when assigning permissions to a role:
- Create Roles: Open the User Roles menu and select Create New Role. Define the role's name.
- Assign Permissions: Select the created role and assign the appropriate Data Security permissions (for example,
RANSOMWARE_DEFENDERorEASY_AUDITOR_MODIFY). - Assign Roles to Users/Groups: In the Roles tab, select the role, then go to the Users or Groups tab and select the plus sign (+) to add a user or AD group to the role. Enter the username or group name, specify whether the account is a remote or local user, and confirm.
- Verify Permissions: Log in as a test user to confirm they have the correct access.
AD groups can also be mapped directly to a role: select the role, then use the + button in the Groups section to add the AD group by name.
Prerequisites
Role assignment requires an Active Directory (AD) authentication provider, per the general installation requirements.
See Also
- Installation Requirements — Active Directory and RBAC prerequisites.
- SupernaOne — Example of granting a specific permission (
APP_REGISTER) from the User Roles menu.