The Carbon Black Cloud console comes with six pre-defined, built-in service roles to assign to your users from the Cloud Services Console.
Pre-defined Built-in Roles
The Carbon Black Cloud console comes with the following pre-defined, built-in service roles to assign to your users from the Cloud Services Console.
Role | Description |
---|---|
View All | Views pages, exports data, and adds notes and tags. This role is suitable for new users or users in an oversight capacity. Permissions include:
|
Level 1 Analyst | Triages alerts and places assets in or out of quarantine. Permissions include:
Note: Providing determination feedback is available for
Carbon Black XDR and
Carbon Black Cloud Enterprise EDR customers only.
|
Level 2 Analyst | Initiates Live Response sessions to effect change on files and registry entries. Users can also effect change on endpoints or workloads through Live Response, file deletion, and quarantine. Permissions include all Analyst 1 permissions in addition to:
|
Level 3 Analyst | Manages applications and certificates and uses all Live Response features, including process execution, memory dump, and removal from endpoints. Permissions include all Analyst 2 permissions in addition to:
|
System Admin | Users are responsible for daily admin activities including adding users, managing sensors, and enabling bypass. Users in this role cannot change global settings, delete files, or use Live Response. |
Super Admin | Users have all permissions, including console setup and configuration, Live Response, and policy management, and sensor group rules. |