Managing Access to Detection Rules

Detection rule access is governed by two independent permission layers that both must pass:

  • Permissions determine what actions a user can perform on detection rules as a class. For example, viewing rules or managing (creating, editing, deleting, enabling/disabling) them.

  • Per-object access control (ACL) determines which users can access a specific detection rule, and at what level.

Detection Rule Actions and Their Required Permissions

The following table lists the available detection rule actions and the required combination of permissions and ACL access levels for each action. Both requirements must be met. If either check fails, the action is denied. Users who do not have an ACL access level assigned to them cannot view detection rules.

Notes: 
  • Organization Administrators can view, edit, enable, disable, and delete any detection rule regardless of their ACL.

  • The creator is the owner of the detection rule by default. The owner can restrict a rule to Private or share it to specific roles.

  • New detection rules default to Read ACL. All users with the View Detection Rules permission can see them.

Action Permission Required Access Level Required
View a detection rule View Detection Rules Read or higher
Create a detection rule Manage Detection Rules n/a
Edit a detection rule Manage Detection Rules Write or Owner
Delete a detection rule Manage Detection Rules Owner
Enable or disable a detection rule Manage Detection Rules Write or Owner
Transfer ownership n/a Owner
Configure sharing n/a Owner

Managing Access to an Individual Detection Rule

To manage access to a detection rule:

  1. Navigate to ThreatStream Next GenSecurity Operations > Detection Rules.

  2. Click the more options menu and select Manage Access.

  3. If necessary, change the owner.

  4. Select roles to which you want grant Write ACL.

  5. Click Save Changes.

    Access permissions to the rule have been updated.