On this page:
Related topics:
Managing Access to Detection Rules
Detection rule access is governed by two independent permission layers that both must pass:
-
Permissions determine what actions a user can perform on detection rules as a class. For example, viewing rules or managing (creating, editing, deleting, enabling/disabling) them.
-
Per-object access control (ACL) determines which users can access a specific detection rule, and at what level.
Detection Rule Actions and Their Required Permissions
The following table lists the available detection rule actions and the required combination of permissions and ACL access levels for each action. Both requirements must be met. If either check fails, the action is denied. Users who do not have an ACL access level assigned to them cannot view detection rules.
Organization Administrators can view, edit, enable, disable, and delete any detection rule regardless of their ACL.
The creator is the owner of the detection rule by default. The owner can restrict a rule to Private or share it to specific roles.
New detection rules default to Read ACL. All users with the View Detection Rules permission can see them.
| Action | Permission Required | Access Level Required |
|---|---|---|
| View a detection rule | View Detection Rules | Read or higher |
| Create a detection rule | Manage Detection Rules | n/a |
| Edit a detection rule | Manage Detection Rules | Write or Owner |
| Delete a detection rule | Manage Detection Rules | Owner |
| Enable or disable a detection rule | Manage Detection Rules | Write or Owner |
| Transfer ownership | n/a | Owner |
| Configure sharing | n/a | Owner |
Managing Access to an Individual Detection Rule
To manage access to a detection rule:
-
Navigate to ThreatStream Next Gen > Security Operations > Detection Rules.
-
Click the more options menu and select Manage Access.
-
If necessary, change the owner.
-
Select roles to which you want grant Write ACL.
-
Click Save Changes.
Access permissions to the rule have been updated.