Managing Access to Alert Rules

Alert rule access is governed by two independent permission layers that both must pass:

  • Permissions determine what actions a user can perform on alert rules as a class. For example, viewing rules or managing (creating, editing, deleting, enabling/disabling, suppressing) them. See Managing Roles for details on permissions that can be assigned to roles.

  • Per-object access control (ACL) determines which users can access a specific alert rule, and at what level.

Alert Rule Actions and Their Required Permissions

The following table lists the available alert rule actions and the required combination of permissions and ACL access levels for each action. Both requirements must be met. If either check fails, the action is denied. Users who do not have an ACL access level assigned to them cannot view alert rules.

Notes: 
  • Organization Administrators can view, edit, and delete any alert rule, regardless of their ACL.

  • The creator is the owner of the alert rule by default. The owner can restrict a rule to Private or share it to specific roles.

  • New alert rules default to Read. All users with the View Alert Rules permission can see them.

  • Suppressing an alert rule requires the Suppress Alert Rules permission specifically. This permission does not by itself grant the ability to edit or delete the rule.

Action Permission Required Access Level Required
View an alert rule View Alert Rules Read or higher
Create an alert rule Manage Alert Rules n/a
Edit an alert rule Manage Alert Rules Write or Owner
Delete an alert rule Manage Alert Rules Owner
Enable or disable an alert rule Manage Alert Rules Write or Owner
Suppress an alert rule Suppress Alert Rules Write or Owner
Transfer ownership n/a Owner
Configure sharing n/a Owner

Managing Access to an Individual Alert Rule

The Sharing & Permissions dialog box controls who besides the rule owner and organizational administrators can access the rule. It shows the current Owner and a Write Access table listing roles, with the option to grant that role write access to the rule. Organization Administrators always have full access regardless of these settings.

To manage access to an alert rule:

  1. Navigate to ThreatStream Next GenSecurity Operations > Alert Rules.

  2. Open the more options menu (...) for the rule and click Manage Access.

  3. If necessary, change the owner.

  4. Select the Write permission to grant that role write access.

  5. Click Save Changes.

    Access permissions to the rule have been updated.