User and Role Management on the Anomali Platform

If you are an organization administrator, you can establish role-based access control for the Anomali platform on the User & Role Management page.

Overview

Users created on the Anomali platform must be assigned roles. Roles are collections of permissions that determine what actions and tasks users can perform and what data they can access on the Anomali platform. To grant permissions to a user, at least one role must be assigned to them.

On the Anomali platform, you can assign system and custom roles to users.

  • System roles are defined by Anomali and cannot be deleted or modified. They determine the actions, capabilities, and tasks a user can perform, as well as which Anomali products they can access. System roles are maintained primarily for backward compatibility with earlier versions of ThreatStream. Anomali recommends using system roles only when there are no equivalent permissions available through custom roles—for example, the API User or Chat User roles.

  • Custom roles are defined by an organization. When creating a custom role, you can select out-of-the-box permissions to align them with specific job responsibilities of your organization users. For example, a role assigned to a security analyst may grant them a permission to approve ThreatStream intelligence and submit sandbox reports while restricting them from creating community intelligence.

    If your organization has a Security Analytics subscription, you can also control user access to the organization event log source data by adding relevant eventlog filters to custom roles. For example, a network security analyst may be granted access to network logs but be restricted from accessing endpoint logs. Similarly, an operations analyst may be authorized to access both network and endpoint logs but not logs from applications used by the Human Resources or Finance departments.
    For organizations using both ThreatStream and Security Analytics, a role can include both a set of out-of-the-box permissions and an event log filter, ensuring fine-grained access control across the Anomali platform. For organizations using OCSF data, you can also configure OCSF filters on roles to control access to specific OCSF event categories.

For each organization using the Anomali platform, there are four types of users: Organization Administrator, Non-administrator, Read Only, and Auditor users.

  • Organization Administrators can perform administrative tasks that impact their entire organization on the Anomali platform.

  • Non-administrators can only manage settings that impact their personal profiles.

  • Read Only users can view and export intelligence on ThreatStream but cannot create intelligence of any kind.

  • Auditors have read-only access to all ThreatStream pages and admin pages.

How Users and Roles are Managed

Users and roles can be created and managed locally on the User & Role Management page or through a supported third-party user management service.

To manage users locally, you must do the following:

  1. Define and create roles

  2. Add users to your organization and assign roles to them

To manage users outside of the Anomali platform user interface, you must first configure Single Sign-On (SSO) on the Anomali platform using one of the following options:

  • A SAML 2.0-compliant identity provider

  • An identity provider available through the Okta Marketplace

After configuring a single sign-on, you must enable the Anomali platform integration with Microsoft Active Directory, Azure Entra ID or a SAML 2.0-compliant IdP for user management.

For more details on user and role management, refer to the following topics:

Additionally, you can take the Managing Users and Roles course at Anomali University to learn more about types of roles and user management.