Skip to main content

Access check and member summary

Two screens answer questions about access without changing it. Access check answers "can this person do this to that, and why?" for one item. The member summary answers "what can this person do?" across the whole organization.

Beta

This feature is currently rolling out and may not be enabled for your organization. See Access control overview.

Access check​

Go to Settings › [Organization] › Access check, under People & access, or follow any Why? link. Access check replaces the older Access inspector: it answers the same question for every kind of item and for teams, and links to the inspector open it instead. The page reads Can someone do something to one thing, and why? Pick a person or team, a resource and what they want to do.

Access check answering Yes for the SOC team publishing a script, with the decision step "Shared with the team: Use + Publish"

Run a check​

Fill in all four fields. Until you do, the page says Fill in all four to see the answer.

FieldWhat to pick
Person or teamAnyone in the organization, or a team.
Resource typeAction, Script, Connection, Endpoint tag, Hunt or Query.
The resourceSearch for it and pick it from the list. For an endpoint tag, pick the connection first, then the tag. If you'd rather, choose Paste an id instead and paste the item's ID from its URL; the item's name shows under the field when Huntbase can find it.
Wants toA level or a special ability, from the ones that type supports. Abilities are marked (special ability).

Why? links fill every field for you, so you rarely need to look up an ID. The fields are kept in the page's URL, so you can share an answer as a link.

Read the answer​

The answer is green or red: Yes — SOC can Publish "Isolate host (demo)" or No — … can't …. Under it is the chain of steps that decided it, read left to right:

StepMeans
Org role: Member (or Admin, Owner)What their base role gives on this kind of item.
Role Responder: Use + RespondWhat their template or custom role adds across the organization.
Team SOC uplift: UseWhat a team they're on gives across the organization (team access).
Override: manage connectionsAn admin capability given to them on its own, before roles.
Direct uplift: ApproveAn ability given to them directly across the organization, for example Approve when approval was limited to people with Approve.
Team IR: UseA team they're on holds that grant.
Shared directly: EditThe item is shared with them by name.
Shared with the team: …When you check a team: the grant the team holds.
CreatorThey created the item.
Personal ownerThe item is in their personal workspace.
RestrictedGeneral access is restricted, so their role's default doesn't apply. Shown with a red outline.
Not a memberThey aren't in this organization.
Organization permissionTheir access comes from an organization-wide permission rather than the item.

Hover a step to see its detail. A red answer often ends with a hint, such as Invite them to the organization first.

Who can check​

You can always check your own access. To check someone else, or a team, on an item, you need to be able to see who has access to that item (the same rule as its Share panel). Otherwise the page says You can't check other people's access in this organization. Members & access: View is needed. An item, person or team from another organization gives That person, team or resource isn't in this organization.

Member summary​

In Settings › [Organization] › Members, click a member's email. A side sheet opens with everything about their access in one place.

Member side sheet for an owner: role, teams, What … can do with a level and ability per capability, and Direct grants

SectionWhat it shows
RoleTheir role, including templates and custom roles. If you can change roles, it's a menu you can change here.
TeamsThe teams they're on, each a link to the team. Not on any team. if none.
What … can do (with their first name)One row per capability: Actions, Scripts, Connections, Endpoint tags, Hunts, Queries, Telemetry, Detections, Intelligence, Members & access and Settings. Each row has their level and abilities and where they come from, for example Org role: Member (except restricted ones), Role Responder, Team SOC uplift or Team IR: 2 scripts, and a Why? link to Access check.
Summary lineFrom role Member, team IR and 2 direct grants. Why?
Direct grantsEvery item shared with them by name, with the level and a Why? link.
KeysTheir personal API keys in this organization, with Expiring soon and Never used called out. Each opens the key.

Rows on the summary describe what their role, teams and grants give on that kind of item in general. A single item can differ, for example when it is restricted; use Why? to check one item.

Who sees what​

Everyone in the organization can open the sheet. Direct grants, and their count in the summary line, show only on your own sheet or if you manage members. Keys shows on your own sheet, and to admins and people who manage members. If you can't see a member's access, the sheet says You can't see this member's access.

Next steps​

  • Sharing — change what someone has
  • Teams — see what a team holds
  • Access log — see when access changed and who changed it