Back Arrow Back to All Integrations

Role-Based Administration

Role-Based Administration

What is Role-Based Administration?

This enables Blumira administrators to define granular administrative roles for new users that they add to Blumira’s platform. It allows you to determine different roles (analyst, responder, manager, etc.), and determine what they have access to within Blumira.

Adding New Users to Blumira and User Roles

When logged in as a manager or admin account, you can add new users to the Blumira app with different levels of access.

    • Navigate to Infrastructure > Users

    • Click on “Add New User” on the upper right hand side of the screen

  • Enter the User information and what roles they should have.

Analyst – Analysts have access to the Analyst and Security dashboards. They can also perform searches on data and Findings for any needed investigation. They can access blocklist management as well. They cannot access or manage sensors or the company within Blumira.

Responder – Responders have access to the Responder and Security dashboards. The goal of the Responder role is to act on Findings and answer workflows/perform remediations associated with the Findings. They can also perform searches on data and Findings for any needed investigation. They can access blocklist management as well. They cannot access or manage sensors or the company within Blumira.

Manager – Managers have access to the Responder, Security, and Manager dashboards, as well as ad hoc access to the Monitor Mode via the Manager Dashboard. They can perform oversight on current Findings within the Manager dashboard and can interact with Findings as a Responder would, but they do not act as a Responder unless they also take the role. They can perform searches on data and Findings for any needed investigation. They have broad access to manage the organization as a whole, from sensors to blocklists to users.

Administrator – Administrators have access to the organization management side of Blumira, essentially the entire Infrastructure area. Administrators can also perform searches on data and Findings for any needed investigation to confirm data flow.

NOTE: All above roles can be combined to create additional access.

Monitor – Monitor roles can only be picked as a sole role. The user can stay logged in for up to a month and can only access the Monitor dashboard, this is intended to be put up on a TV or similar public area where a locked down account is needed.

  • By default, all new users will only receive email alerts on findings.