Skip to main content

Access control overview

Every Action, script, connection, endpoint tag, hunt and query in an organization has the same short answer to "who can do what with this?": a level, sometimes with a special ability, held by a person or a team. This page explains the words Huntbase uses for access and where each person's access comes from. The pages after it show you how to change it.

Beta

These screens are currently rolling out and may not be enabled for your organization. Until they are, you keep the previous screens: the Access tab on Actions and scripts, the hunt's access chip, Connection access and Access inspector in Settings, and Add person on the Endpoints Access tab. Nobody's access changes when the new screens are turned on: they show and change the same access in a different way.

The four levels​

Each level includes everything the levels before it allow.

LevelIn generalExample (a script)
ViewSee it and its results.See the script and its versions.
UseRun or use it, without changing it.Run the script.
EditChange it.Change the script and upload versions.
ManageChange it, delete it and decide who has access.Change, delete and share the script.

Not every item can be given every level. A connection or a query has no separate View, because Use already covers seeing it. The Share dialog lists only the levels the item supports, and the level menu describes each one for that kind of item.

Special abilities​

Some powers are too sensitive to come with a level. They are granted on their own, as an extra on top of a level (or without one).

AbilityOnWhat it allows
ApproveActionsApprove runs of an Action that need sign-off.
PublishScriptsSign and publish new versions of a script.
RespondEndpoint tagsCollect files and run commands on the endpoints that carry the tag, beyond operating them.

Manage does not include an ability. Someone can manage an Action and still not be able to approve its runs, unless they are also given Approve.

Levels and abilities look the same everywhere: a level is a badge (View, Use, Edit, Manage) and an ability is an amber chip (Approve, Publish, Respond).

Where access comes from​

A person's access to one item is the highest of these:

SourceWhat it is
RoleTheir organization role: Owner, Admin or Member, a template such as Responder, or a custom role. Every role gives a level on each kind of item across the organization. See Roles.
Team accessWhat a team they're on gives across the organization, on top of their role.
TeamWhat is shared with a team they belong to, item by item.
Direct grantWhat is shared with them by name, in the item's Share dialog.
CreatorThe person who created an Action, script, hunt or query manages it.
OverrideAn admin capability given to one member before roles existed, such as managing connections. Overrides keep working until an admin turns them into teams.

One thing takes access away: Restricted general access. When an item is restricted, plain members lose their role's default on it, role and team access across the organization don't reach it, and only the people and teams named on it (plus owners and admins) keep access. Grants only ever add access; there is no "everyone except".

Access check shows these steps for one person and one item, in order, with the one that decided the answer.

What each role gets by default​

While an item's general access is Everyone at your organization, members get the levels below. Templates and custom roles raise them; see Roles.

ItemMembersOwners and admins
ActionsViewManage + Approve
ScriptsViewManage + Publish
ConnectionsUseManage
Endpoint tagsViewManage + Respond
HuntsViewManage
QueriesUseManage

Hunts start private to the people on them, so members see a hunt only once it is opened to the organization or shared with them. See Collaborators and visibility.

An Owner of an organization reads as Manage on everything in it. In a Share dialog, owners and admins are listed under Also has access through roles, not one by one. The creator of an Action or script is listed by name with Manage; that row can't be changed or removed, because creating the item is what gives it.

Where to find it​

ToGo to
Set what each role can doSettings › [Organization] › Roles. See Roles.
Share one itemThe item's Share… button or Access tab. See Sharing.
Group peopleSettings › [Organization] › Teams. See Teams.
See everything one person can doClick their email in Settings › [Organization] › Members. See Member summary.
Find out why someone can or can'tSettings › [Organization] › Access check, or any Why? link. See Access check.
Let scripts and tools call the APISettings › [Organization] › API keys. See API keys.
See who changed accessSettings › [Organization] › Access log. See Access log.

All of these are under the People & access heading of an organization's settings. See Settings overview.

Next steps​

  • Roles — templates, custom roles and who can approve runs
  • Sharing — give people and teams access to one item
  • Access check — answer "why can they?"
  • API keys — access for scripts and integrations