Types of Anomali Users

For each organization using the Anomali platform, there are four types of users: Organization Administrator, Non-administrator, Read Only, and Auditor users. Organization Administrators can perform administrative tasks that impact their entire organization on the Anomali platform, whereas Non-administrators can only manage settings that impact their personal profiles. Read Only users can view and export intelligence on ThreatStream but cannot create intelligence of any kind. Auditor users have read-only access to all ThreatStream pages and admin settings.

On the Anomali platform, you can also find service account users, which are added to your organization by Anomali Customer Support. For more information about service accounts, refer to Service Account Permissions.

Organization Administrator Permissions

The tasks below are reserved for Anomali users with Organization Administrator permissions.

Task Description
Update organization name Update organization name in ThreatStream.
Update PDF export settings Change the number of search results and intelligences included in Search Result and Threat Bulletin PDF downloads respectively .
Configure organization-wide session timeout settings Enable ThreatStream session timeout for users in your organization and decide when timeouts occur after periods of inactivity.
Configure multi-factor authentication (MFA) Decide whether or not the organization requires multi-factor authentication for logging in.
Add/edit/delete organization users Add and remove users from the organization and update roles for existing users.
Enable organization users to approve imports Configure permissions for non-administrator users that enable them to evaluate imported observables.
Bypass MFA for organization users When MFA is enabled, organization administrators can configure users to avoid multi-factor authentication and login with their email address and password only.
Configure organization Exclude List Prevents users from within the organization from accidentally importing an organization CIDR, IP Address, Domain Name, URL, or Email Address.
Activate third-party integrations with ThreatStream Configure ThreatStream to use third-party services such as Farsight and Open DNS.
Manage premium intelligence streams Purchase and evaluate premium threat intelligence streams partnered with Anomali.
Create/leave/join Trusted Circles Enable the sharing of information between your organization and other organizations on ThreatStream.
Delete Threat Model entities Permanently delete Threat Bulletins, Actors, Campaigns, TTPs, Incidents, and Signatures that belong to your organization.
Audit user activity View user activity from the past 7 days.
Unlock Locked Accounts When user accounts in your organization are locked after consecutive failed login attempts, Org Admins can unlock accounts from the User Admin page within settings. See Managing Users for more information.

The email lists below are reserved for Anomali users with Organization Administrator permissions.

Email List Description
Keyword Matches Sends notifications for each keyword match.
Keyword Matches Hourly Digest Sends summaries of all keyword matches from the last hour.

Non-administrator Permissions

The tasks below can be performed by Non-administrators and Organization Administrators.

Task Description
Edit personal contact information Edit personal email address, name, and phone number.
Change password used for ThreatStream login Change personal password used for ThreatStream login.
Update ThreatStream email subscriptions Users can configure which ThreatStream email lists their personal email address is included in.

The email lists below can be subscribed to by Non-administrators and Organization Administrators.

Email List Description

Threat Bulletin Creation

Sends notifications every time a Threat Bulletin is created.
Threat Bulletin Daily Digest Sends summaries of Threat Bulletins created each day.
Trusted Circles Sends notifications when organizations join or leave your trusted circles.

Read Only User Permissions

Read Only users are restricted to viewing intelligence on ThreatStream and cannot create intelligence or related content such as tags, comments, or other metadata.

  • Read Only users do not count toward the number of users allocated to your organization in your ThreatStream license.

  • Read Only users can access ThreatStream OnPrem deployments that are on v4.1.1 and above. Read Only users cannot access ThreatStream OnPrem if it is on an earlier version.

The table below lists the features to which Read Only users have access.

Screen Available Features
Classic Dashboards
  • View dashboards.
  • Add shared custom dashboards created by fellow organization users and themed dashboards created by the Anomali Threat Research team to their homepages on ThreatStream.
Analyze > Overview View and drill down on recent threat model entities.
Analyze > Observables
  • Perform basic observable searches.
  • Perform advanced observable searches.
  • View observable details pages.
  • Export observables from the observables search page and details pages.
Analyze > Threat Model
  • Perform basic Threat Model entity searches.
  • Perform advanced Threat Model entity searches
  • View Threat Model entity details pages.
  • Export Threat Model entities from threat model entity details pages.
Research > Sandbox
  • View sandbox report details.
  • Export sandbox reports.
Research > Collaborate

Chat with organization and trusted circles members.

Note: This menu item is only visible if the Chat User role is enabled for a user on the User & Role Management page. See Using System Roles for more information.
APP Store > APP Store Browse available APP Store services.
Settings > My Profile
  • Update user Email, Name, and Phone.
  • Change account password.
  • Subscribe to the Threat Model Daily Digest email.
  • View API Key if the API User role is enabled for a Read Only user on the User & Role Management page. Refer to Managing Users for details.

Auditor User Permissions

Auditor users have read-only access to all ThreatStream pages as well as all tabs on the ThreatStream Settings page.

Service Account Permissions

Service accounts in Anomali are designed for system-level operations, such as integrations, threat feed ingestion, and automated intelligence distribution to downstream tools like Integrator and other on-premises products. These accounts are provisioned and managed by Anomali Customer Support to ensure consistent, secure connectivity and data flow. They cannot be edited or activated by organization users.

Service account users are assigned elevated permissions—typically equivalent to Organization Administrator rights. This level of access is required to enable functions such as managing integrations, submitting data, and interacting with protected API endpoints. Although the scope of these permissions may appear broad, they are purpose-specific and strictly applied to support operational integrity.

Service accounts follow this naming convention:

devops+<string>@threatstream.com

where <string> is an alphanumeric tag that reflects the purpose of the account.