Access control overview
Every Action, script, connection, endpoint tag, hunt and query in an organization has the same short answer to "who can do what with this?": a level, sometimes with a special ability, held by a person or a team. This page explains the words Huntbase uses for access and where each person's access comes from. The pages after it show you how to change it.
These screens are currently rolling out and may not be enabled for your organization. Until they are, you keep the previous screens: the Access tab on Actions and scripts, the hunt's access chip, Connection access and Access inspector in Settings, and Add person on the Endpoints Access tab. Nobody's access changes when the new screens are turned on: they show and change the same access in a different way.
The four levels
Each level includes everything the levels before it allow.
| Level | In general | Example (a script) |
|---|---|---|
| View | See it and its results. | See the script and its versions. |
| Use | Run or use it, without changing it. | Run the script. |
| Edit | Change it. | Change the script and upload versions. |
| Manage | Change it, delete it and decide who has access. | Change, delete and share the script. |
Not every item can be given every level. A connection or a query has no separate View, because Use already covers seeing it. The Share dialog lists only the levels the item supports, and the level menu describes each one for that kind of item.
Special abilities
Some powers are too sensitive to come with a level. They are granted on their own, as an extra on top of a level (or without one).
| Ability | On | What it allows |
|---|---|---|
| Approve | Actions | Approve runs of an Action that need sign-off. |
| Publish | Scripts | Sign and publish new versions of a script. |
| Respond | Endpoint tags | Collect files and run commands on the endpoints that carry the tag, beyond operating them. |
Manage does not include an ability. Someone can manage an Action and still not be able to approve its runs, unless they are also given Approve.
Levels and abilities look the same everywhere: a level is a badge (View, Use, Edit, Manage) and an ability is an amber chip (Approve, Publish, Respond).
Where access comes from
A person's access to one item is the highest of these:
| Source | What it is |
|---|---|
| Role | Their organization role: Owner, Admin or Member, a template such as Responder, or a custom role. Every role gives a level on each kind of item across the organization. See Roles. |
| Team access | What a team they're on gives across the organization, on top of their role. |
| Team | What is shared with a team they belong to, item by item. |
| Direct grant | What is shared with them by name, in the item's Share dialog. |
| Creator | The person who created an Action, script, hunt or query manages it. |
| Override | An admin capability given to one member before roles existed, such as managing connections. Overrides keep working until an admin turns them into teams. |
One thing takes access away: Restricted general access. When an item is restricted, plain members lose their role's default on it, role and team access across the organization don't reach it, and only the people and teams named on it (plus owners and admins) keep access. Grants only ever add access; there is no "everyone except".
Access check shows these steps for one person and one item, in order, with the one that decided the answer.
What each role gets by default
While an item's general access is Everyone at your organization, members get the levels below. Templates and custom roles raise them; see Roles.
| Item | Members | Owners and admins |
|---|---|---|
| Actions | View | Manage + Approve |
| Scripts | View | Manage + Publish |
| Connections | Use | Manage |
| Endpoint tags | View | Manage + Respond |
| Hunts | View | Manage |
| Queries | Use | Manage |
Hunts start private to the people on them, so members see a hunt only once it is opened to the organization or shared with them. See Collaborators and visibility.
An Owner of an organization reads as Manage on everything in it. In a Share dialog, owners and admins are listed under Also has access through roles, not one by one. The creator of an Action or script is listed by name with Manage; that row can't be changed or removed, because creating the item is what gives it.
Where to find it
| To | Go to |
|---|---|
| Set what each role can do | Settings › [Organization] › Roles. See Roles. |
| Share one item | The item's Share… button or Access tab. See Sharing. |
| Group people | Settings › [Organization] › Teams. See Teams. |
| See everything one person can do | Click their email in Settings › [Organization] › Members. See Member summary. |
| Find out why someone can or can't | Settings › [Organization] › Access check, or any Why? link. See Access check. |
| Let scripts and tools call the API | Settings › [Organization] › API keys. See API keys. |
| See who changed access | Settings › [Organization] › Access log. See Access log. |
All of these are under the People & access heading of an organization's settings. See Settings overview.
Next steps
- Roles — templates, custom roles and who can approve runs
- Sharing — give people and teams access to one item
- Access check — answer "why can they?"
- API keys — access for scripts and integrations