Skip to main content

Enterprise roles and access

← Back to Index | Previous: Appendix


12.1 What this chapter covers​

After install, customer access is managed in the Enterprise workspace at https://<dai-host>/dashboard/enterprise — not in Control (/control). Control remains for platform settings, DAP enroll, certificates, and Updates.

This chapter explains:

  • How organization, tenants, teams, roles, and capabilities fit together
  • What role scope changes for what a person can do
  • The seeded role presets and how to use them

Before inviting many users, rename the default System tenant (and organization if needed) — Chapter 8 §8.3.

12.2 Access model​

Organization
└── Tenants (hard isolation boundary)
└── Teams (assignment / visibility only — not a security boundary)
└── Roles (named sets of capabilities)
└── Bindings (role granted to a member or team, with a scope)
ConceptMeaning for operators
OrganizationYour enterprise management boundary. Groups tenants, users, teams, and role definitions.
TenantHard security boundary. App data and execution stay tenant-scoped.
TeamGroups people for work assignment and directory visibility. Team membership alone does not grant sensitive access.
RoleA named set of capabilities (permission strings). Authorization checks capabilities, not the role label.
BindingAssigns a role to a member (or to everyone on a team). The binding’s scope decides where those capabilities apply.

Multiple bindings stack: a member receives the union of capabilities from every active binding that applies to the current tenant.

12.3 Role scope — impact​

When you create or assign a role, scope decides the authorization boundary.

ScopeEffect
OrganizationCapabilities apply across tenants in the org. Required for enterprise workspace admin surfaces (enterprise:view / enterprise:manage come from org-scoped grants).
TenantCapabilities apply only in that tenant. A tenant-scoped role cannot be bound organization-wide.
Host (on a binding)Narrows a grant to a specific inventory host. Host-narrowed bindings do not unlock tenant-wide access or org enterprise admin by themselves.
TeamTeams are not a role-definition security scope. Access still comes from role bindings on the member or on the team.

Practical guidance

  • Keep Enterprise Owner and Enterprise Admin as organization-scoped roles so they can manage the Enterprise workspace.
  • Prefer tenant-scoped grants for Tenant Admin, Analyst, and similar day-to-day product roles (least privilege).
  • Use host-narrowed bindings only when you intentionally limit access to a specific host (for example future investigation / decrypt paths).

12.4 Role presets​

Enterprise installs seed system presets. You can create roles from a preset (capabilities are copied onto the new role). Presets do not lock scope — you choose organization or tenant when you create or assign the role.

Preset nameLabelTypical useSuggested scope
enterprise_ownerEnterprise OwnerFull customer-side ownership: users, tenants, roles, billing manage, DAP platform, inventory, host assignOrganization
enterprise_adminEnterprise AdminSame management surface as owner without billing:manageOrganization
tenant_adminTenant AdminManage assigned tenants, teams, members, integrations, DAP; no host assignTenant
team_managerTeam ManagerTeam membership and usage visibilityTenant
platform_engineerPlatform EngineerAgents, workflows, integrations, DAP, inventory, host assignTenant (or org when org-wide ops is intended)
security_officerSecurity OfficerRole policy, guardrails, audit, host assignOrganization or tenant
security_investigatorSecurity InvestigatorInvestigation work; host view; future decrypt-on-assignedTenant (often with host-narrowed binding later)
analystAnalystCreate agents/workflows; DAP view and manage; inventory viewTenant
billing_managerBilling ManagerBilling view and manageOrganization
auditorAuditorRead-only across org surfaces and DAP product viewOrganization
viewerViewerMinimal read of enterprise/tenant/role/integration/inventory and DAP product viewTenant

Capability themes (not an exhaustive string list):

  • Enterprise Owner — enterprise + tenant + team + member + role + billing manage + integrations + DAP platform + guardrails + audit + inventory + host assign
  • Enterprise Admin — same as owner except no billing manage
  • Tenant Admin — enterprise view; tenant/team/member manage; role assign (not role definition manage); DAP; inventory; no host assign
  • Platform Engineer — agents/workflows CRUD, integrations, DAP, inventory, host assign
  • Security Officer — role manage/assign, security policy, guardrails, audit, host assign
  • Analyst — create agents/workflows; DAP platform view/manage; product view; inventory view

12.5 How to use presets​

  1. Open Enterprise → Roles (/dashboard/enterprise/roles).
  2. Create a role from a preset (or inspect a seeded system preset).
  3. Set scope to Organization or Tenant as required by §12.3.
  4. Open Members (or bind via a team) and assign the role.
  5. Sign in as that member (or use You) and confirm they see the expected tenants and Enterprise sections.

System presets are read-only templates. Customize by creating a new role from a preset and adjusting capabilities, or by assigning a different preset.

12.6 Out of scope​

  • Deslicer Control platform admin roles (super_admin, support, and related admin capabilities) — Deslicer-internal operators only
  • Splunk host worker enrollment and DAP product runbooks after the platform is up

← Back to Index | Previous: Appendix