Enterprise roles and access
← Back to Index | Previous: Appendix
12.1 What this chapter covers
After install, customer access is managed in the Enterprise workspace at https://<dai-host>/dashboard/enterprise — not in Control (/control). Control remains for platform settings, DAP enroll, certificates, and Updates.
This chapter explains:
- How organization, tenants, teams, roles, and capabilities fit together
- What role scope changes for what a person can do
- The seeded role presets and how to use them
Before inviting many users, rename the default System tenant (and organization if needed) — Chapter 8 §8.3.
12.2 Access model
Organization
└── Tenants (hard isolation boundary)
└── Teams (assignment / visibility only — not a security boundary)
└── Roles (named sets of capabilities)
└── Bindings (role granted to a member or team, with a scope)
| Concept | Meaning for operators |
|---|---|
| Organization | Your enterprise management boundary. Groups tenants, users, teams, and role definitions. |
| Tenant | Hard security boundary. App data and execution stay tenant-scoped. |
| Team | Groups people for work assignment and directory visibility. Team membership alone does not grant sensitive access. |
| Role | A named set of capabilities (permission strings). Authorization checks capabilities, not the role label. |
| Binding | Assigns a role to a member (or to everyone on a team). The binding’s scope decides where those capabilities apply. |
Multiple bindings stack: a member receives the union of capabilities from every active binding that applies to the current tenant.
12.3 Role scope — impact
When you create or assign a role, scope decides the authorization boundary.
| Scope | Effect |
|---|---|
| Organization | Capabilities apply across tenants in the org. Required for enterprise workspace admin surfaces (enterprise:view / enterprise:manage come from org-scoped grants). |
| Tenant | Capabilities apply only in that tenant. A tenant-scoped role cannot be bound organization-wide. |
| Host (on a binding) | Narrows a grant to a specific inventory host. Host-narrowed bindings do not unlock tenant-wide access or org enterprise admin by themselves. |
| Team | Teams are not a role-definition security scope. Access still comes from role bindings on the member or on the team. |
Practical guidance
- Keep Enterprise Owner and Enterprise Admin as organization-scoped roles so they can manage the Enterprise workspace.
- Prefer tenant-scoped grants for Tenant Admin, Analyst, and similar day-to-day product roles (least privilege).
- Use host-narrowed bindings only when you intentionally limit access to a specific host (for example future investigation / decrypt paths).
12.4 Role presets
Enterprise installs seed system presets. You can create roles from a preset (capabilities are copied onto the new role). Presets do not lock scope — you choose organization or tenant when you create or assign the role.
| Preset name | Label | Typical use | Suggested scope |
|---|---|---|---|
enterprise_owner | Enterprise Owner | Full customer-side ownership: users, tenants, roles, billing manage, DAP platform, inventory, host assign | Organization |
enterprise_admin | Enterprise Admin | Same management surface as owner without billing:manage | Organization |
tenant_admin | Tenant Admin | Manage assigned tenants, teams, members, integrations, DAP; no host assign | Tenant |
team_manager | Team Manager | Team membership and usage visibility | Tenant |
platform_engineer | Platform Engineer | Agents, workflows, integrations, DAP, inventory, host assign | Tenant (or org when org-wide ops is intended) |
security_officer | Security Officer | Role policy, guardrails, audit, host assign | Organization or tenant |
security_investigator | Security Investigator | Investigation work; host view; future decrypt-on-assigned | Tenant (often with host-narrowed binding later) |
analyst | Analyst | Create agents/workflows; DAP view and manage; inventory view | Tenant |
billing_manager | Billing Manager | Billing view and manage | Organization |
auditor | Auditor | Read-only across org surfaces and DAP product view | Organization |
viewer | Viewer | Minimal read of enterprise/tenant/role/integration/inventory and DAP product view | Tenant |
Capability themes (not an exhaustive string list):
- Enterprise Owner — enterprise + tenant + team + member + role + billing manage + integrations + DAP platform + guardrails + audit + inventory + host assign
- Enterprise Admin — same as owner except no billing manage
- Tenant Admin — enterprise view; tenant/team/member manage; role assign (not role definition manage); DAP; inventory; no host assign
- Platform Engineer — agents/workflows CRUD, integrations, DAP, inventory, host assign
- Security Officer — role manage/assign, security policy, guardrails, audit, host assign
- Analyst — create agents/workflows; DAP platform view/manage; product view; inventory view
12.5 How to use presets
- Open Enterprise → Roles (
/dashboard/enterprise/roles). - Create a role from a preset (or inspect a seeded system preset).
- Set scope to Organization or Tenant as required by §12.3.
- Open Members (or bind via a team) and assign the role.
- Sign in as that member (or use You) and confirm they see the expected tenants and Enterprise sections.
System presets are read-only templates. Customize by creating a new role from a preset and adjusting capabilities, or by assigning a different preset.
12.6 Out of scope
- Deslicer Control platform admin roles (
super_admin, support, and related admin capabilities) — Deslicer-internal operators only - Splunk host worker enrollment and DAP product runbooks after the platform is up