Types of Anomali Users
For each organization using the Anomali platform, there are four types of users: Organization Administrator, Non-administrator, Read Only, and Auditor users. Organization Administrators can perform administrative tasks that impact their entire organization on the Anomali platform, whereas Non-administrators can only manage settings that impact their personal profiles. Read Only users can view and export intelligence on ThreatStream but cannot create intelligence of any kind. Auditor users have read-only access to all ThreatStream pages and admin settings.
On the Anomali platform, you can also find service account users, which are added to your organization by Anomali Customer Support. For more information about service accounts, refer to Service Account Permissions.
Organization Administrator Permissions
The tasks below are reserved for Anomali users with Organization Administrator permissions.
| Task | Description |
|---|---|
| Update organization name | Update organization name in ThreatStream. |
| Update PDF export settings | Change the number of search results and intelligences included in Search Result and Threat Bulletin PDF downloads respectively . |
| Configure organization-wide session timeout settings | Enable ThreatStream session timeout for users in your organization and decide when timeouts occur after periods of inactivity. |
| Configure multi-factor authentication (MFA) | Decide whether or not the organization requires multi-factor authentication for logging in. |
| Add/edit/delete organization users | Add and remove users from the organization and update roles for existing users. |
| Enable organization users to approve imports | Configure permissions for non-administrator users that enable them to evaluate imported observables. |
| Bypass MFA for organization users | When MFA is enabled, organization administrators can configure users to avoid multi-factor authentication and login with their email address and password only. |
| Configure organization Exclude List | Prevents users from within the organization from accidentally importing an organization CIDR, IP Address, Domain Name, URL, or Email Address. |
| Activate third-party integrations with ThreatStream | Configure ThreatStream to use third-party services such as Farsight and Open DNS. |
| Manage premium intelligence streams | Purchase and evaluate premium threat intelligence streams partnered with Anomali. |
| Create/leave/join Trusted Circles | Enable the sharing of information between your organization and other organizations on ThreatStream. |
| Delete Threat Model entities | Permanently delete Threat Bulletins, Actors, Campaigns, TTPs, Incidents, and Signatures that belong to your organization. |
| Audit user activity | View user activity from the past 7 days. |
| Unlock Locked Accounts | When user accounts in your organization are locked after consecutive failed login attempts, Org Admins can unlock accounts from the User Admin page within settings. See Managing Users for more information. |
The email lists below are reserved for Anomali users with Organization Administrator permissions.
| Email List | Description |
|---|---|
| Keyword Matches | Sends notifications for each keyword match. |
| Keyword Matches Hourly Digest | Sends summaries of all keyword matches from the last hour. |
Non-administrator Permissions
The tasks below can be performed by Non-administrators and Organization Administrators.
| Task | Description |
|---|---|
| Edit personal contact information | Edit personal email address, name, and phone number. |
| Change password used for ThreatStream login | Change personal password used for ThreatStream login. |
| Update ThreatStream email subscriptions | Users can configure which ThreatStream email lists their personal email address is included in. |
The email lists below can be subscribed to by Non-administrators and Organization Administrators.
| Email List | Description |
|---|---|
|
Threat Bulletin Creation |
Sends notifications every time a Threat Bulletin is created. |
| Threat Bulletin Daily Digest | Sends summaries of Threat Bulletins created each day. |
| Trusted Circles | Sends notifications when organizations join or leave your trusted circles. |
Read Only User Permissions
Read Only users are restricted to viewing intelligence on ThreatStream and cannot create intelligence or related content such as tags, comments, or other metadata.
-
Read Only users do not count toward the number of users allocated to your organization in your ThreatStream license.
-
Read Only users can access ThreatStream OnPrem deployments that are on v4.1.1 and above. Read Only users cannot access ThreatStream OnPrem if it is on an earlier version.
The table below lists the features to which Read Only users have access.
| Screen | Available Features |
|---|---|
| Classic Dashboards |
|
| Analyze > Overview | View and drill down on recent threat model entities. |
| Analyze > Observables |
|
| Analyze > Threat Model |
|
| Research > Sandbox |
|
| Research > Collaborate |
Chat with organization and trusted circles members. Note: This menu item is only visible if the Chat User role is enabled for a user on the User & Role Management page. See Using System Roles for more information.
|
| APP Store > APP Store | Browse available APP Store services. |
| Settings > My Profile |
|
Auditor User Permissions
Auditor users have read-only access to all ThreatStream pages as well as all tabs on the ThreatStream Settings page.
Service Account Permissions
Service accounts in Anomali are designed for system-level operations, such as integrations, threat feed ingestion, and automated intelligence distribution to downstream tools like Integrator and other on-premises products. These accounts are provisioned and managed by Anomali Customer Support to ensure consistent, secure connectivity and data flow. They cannot be edited or activated by organization users.
Service account users are assigned elevated permissions—typically equivalent to Organization Administrator rights. This level of access is required to enable functions such as managing integrations, submitting data, and interacting with protected API endpoints. Although the scope of these permissions may appear broad, they are purpose-specific and strictly applied to support operational integrity.
Service accounts follow this naming convention:
devops+<string>@threatstream.com
where <string> is an alphanumeric tag that reflects the purpose of the account.