Using System Roles

On the Anomali platform, system roles define common user permissions, which represent specific actions, capabilities, or tasks that users can perform on the Anomali platform. These roles are predefined, cannot be modified or deleted, and are marked with the system role icon ().

System roles are maintained primarily for backward compatibility with earlier versions of ThreatStream. For this reason, Anomali recommends transitioning to custom roles, and using system roles only when no equivalent permissions are available within a custom role. Custom roles allow multiple permissions to be grouped under a single role and support the configuration of event log access and maximum search-back visibility.

For information on creating custom roles, see Creating a Role.

For information on adding and configuring users, see Adding a User and Editing User Roles.

For the description of system roles and their corresponding permissions, refer to the table below.

System Role Permission Description
API User N/A

A user-specific API key is generated when an organization administrator assigns the API User role to a user. This API key can be viewed on the My Profile tab within ThreatStream settings. The role also enables the user to view software downloads on the ThreatStream Downloads page.

When the role is removed from a user, the user loses access to their API key and the Download page.

Note: The API User system role does not have a corresponding permission that can be included into a custom role. Therefore, to grant a user the permission to use API and access the Downloads page, the API User system role must be assigned to this user.
Auditor View All Objects Grants a user read-only access to all ThreatStream pages and settings.
Cannot Use Copilot N/A

Restricts a user from accessing Anomali Copilot.

Note: This is a limited availability permission. You cannot assign it to users.
Cannot Use ThreatStream N/A

Restricts a user from accessing ThreatStream.

Note: This is a limited availability permission. You cannot assign it to users.
Chat User N/A

Enables a user to use chat on ThreatStream. See Enabling Chat for Your Organization for more information.

Note: The Chat User system role does not have a corresponding permission. Therefore, to grant a user the permission to use chat, the Chat User system role must be assigned to this user.
Community Contributor Create community intelligence

Enables a user to create intelligence shared with the Anomali Community. This includes importing observables, creating Sandbox Reports, as well as modifying tags and commenting on observables and Sandbox Reports shared with the Anomali Community.

Intelligence Approver Approve intelligence

Enables a user to approve imported intelligence.

MFA Exempt Bypass MFA

Makes a user exempt from multi-factor authentication.

Note: This role is only applicable to organizations that require MFA.
Organization Administrator Edit All Objects

Grants a user organization administrator privileges. For more on user roles in ThreatStream, see Types of Anomali Users.

For organizations that use Anomali Security Analytics, the Organization Administrator role in ThreatStream also gives users administrator permissions in Anomali Security Analytics. Note that, for organizations that have the Anomali Security Analytics subscription, users must have the Security Analytics User role enabled for them to access the Security Analytics user interface.

PIR Manager  

Grants non-Read-Only users permission to view, create, update, delete, run on demand, pause, and resume PIR configurations.

Note: This role is only applicable to organizations that use ThreatStream Next Gen.
PIR Viewer  

Grants Read-Only users permission to view PIR configurations.

Note: This role is only applicable to organizations that use ThreatStream Next Gen.
Read Only N/A

Provides read-only access to ThreatStream, regardless of other assigned permissions. Read Only users can view and export intelligence on ThreatStream but cannot create, edit or delete intelligence of any kind. For more information, see Read Only User Privileges.

Notes:
  • The Read Only system role does not have a corresponding permission. Therefore, to grant a user the Read Only permission, the Read Only system role must be assigned to the user.
  • The Read Only system role cannot be combined with the Intelligence Approver, Community Contributor, TAXII Importer, Rule Editor, Organization Administrator, and Sandbox Submitter system roles.

Rule Editor Edit rules Enables a user to edit rules.
Sandbox Submitter Submit to sandbox

Enables a user to submit malware to a sandbox for detonation. This privilege also applies to sandbox submissions made through phishing mailboxes. See Analyzing Malware with the ThreatStream Sandbox for more information.

Security Analytics User Use Security Analytics

Enables a user to access Anomali Security Analytics.

Note: The Security Analytics User system role requires an active Security Analytics subscription.
SSO_User N/A

Enables a user to use SSO for authentication. This role must be assigned to all users who use SSO for authenticating to the Anomali platform.

Note: The SSO_User system role does not have a corresponding permission. Therefore, to grant a user the permission to use SSO for authentication, the SSO_User system role must be assigned to this user.
TAXII Importer Import to TAXII Feeds

Enables a user to push data from TAXII clients to your ThreatStream TAXII server.