User Roles for Data Security
Introduction
Data Security uses the same Eyeglass Role-Based Access Control (RBAC) system as the rest of the Eyeglass platform. This page covers the specific roles and permissions relevant to Ransomware Defender and Data Auditing. For the full RBAC setup procedure — creating roles, assigning permissions, mapping AD groups or users to roles, and logging in with a role account — see the User Role Guide, which documents the complete Eyeglass-wide workflow.
Data Security Roles and Permissions
| Role/Permission | Purpose |
|---|---|
| RANSOMWARE_DEFENDER | View and configure Ransomware Defender. |
| RANSOMWARE_READONLY | Read-only view of Ransomware Defender. |
| EASY_AUDITOR_VIEW | View existing reports, queries, and wiretaps. |
| EASY_AUDITOR_MODIFY | Add and update reports, queries, schedules, and wiretaps. |
| EyeglassAdmin (OneFS role) | Requires ISI_PRIV_IFS_BACKUP (and ISI_PRIV_IFS_RESTORE on OneFS 8.2+) on the PowerScale side, for REST API audit ingestion. See Storage Platform Agent Configuration — Enable REST API audit ingestion. |
A built-in role and user account separate the management of Ransomware Defender settings from event monitoring: the Ransomware Defender role manages and monitors the product, while RANSOMWARE_READONLY limits a user to viewing events without the ability to change configuration.
Easy Auditor has its own built-in account for separation of duties — see Easy Auditor Planning and Design.
Assigning Data Security Roles
Follow the Create Roles → Assign Permissions → Assign Roles to Users/Groups workflow in the User Role Guide, selecting the Data Security permissions above when assigning permissions to a role. Licensing for each writable PowerScale or ECS cluster (agent license and agent maintenance, which govern which clusters Ransomware Defender actively protects) is covered separately in Pre-Requisites — Licensing and is not controlled by RBAC role assignment.
Prerequisites
Role assignment depends on the same Active Directory and system-zone authentication prerequisites as the rest of Eyeglass RBAC — an AD authentication provider in the PowerScale system zone, SMB/SMB2 enabled between the Eyeglass VM and the cluster, and system zone authentication as the supported proxy login method. See User Role Guide — Requirements for the complete list.
See also
- Easy Auditor Planning and Design — The built-in auditor account and separation-of-duties considerations for Easy Auditor.
- User Role Guide — Full Eyeglass RBAC setup: creating roles, assigning permissions, AD group mapping, and logging in with a role account.
- Storage Platform Agent Configuration — PowerScale-side roles and permissions required for audit ingestion.
- Pre-Requisites — Licensing — Agent licensing per writable cluster.