Skip to main content

Responses are generated using AI and may contain mistakes.

DashboardDashboards Guide

Table of Contents

User Management

Dashboards user access and permissions are managed through a combination of universal role-based access (URBA), which are configured in Settings on the Exabeam Security Operations Platform (see Universal Role-Based Access), and Role-Based Access Controls (RBAC), which are configured in the Dashboards service itself. They work together to define which roles have what kind of access to specific dashboards:

  • URBA – Controls what kind of access (read, write, delete) specific user roles are granted. When users are assigned to roles, they acquire that access.

  • RBAC – Controls which user roles are assigned to specific dashboards. When a user role is assigne to a dashboard, users assigned to that role acquire the specified access to the dashboard.

Dashboard User Roles

URBA roles include two permission levels for Dashboards users:

  • Viewer Access – Read only permissions

  • Developer Access – Read, write, and delete permissions

A separate permission is also available to allow administrators full access to all scheduled reports by any user.

There are two methods to assign Dashboards permissions to user roles in your Exabeam subscription. You can assign default roles that have Dashboards permissions built in or you can create custom roles and define specific permissions. The table below shows the Dashboards permissions that are available to assign when creating a custom user role. It also shows which default user roles already include those permissions.

For more information about managing user role permissions and creating custom roles, see User Roles and Local Users in the Security Operations Platform Guide.

Permission

Description

Access

Default User Roles

Dashboards

View or manage dashboards.

Read, Write, Delete

  • Administrator

  • Security Engineer

  • Tier 3 Analyst

  • Tier 2 Analyst

Dashboards

View or manage dashboards.

Read

  • Tier 1 Analyst

  • Compliance Manager

Manage All Schedule Reports

View, edit, or delete scheduled dashboard reports created by any user

Read, Write, Delete

Administrator

Note

Assigning these permissions may not be sufficient to view or access dashboard data for specific products. You must also assign whichever of the following data-specific dashboard permissions is appropriate:

  • Dashboards Anomalies

  • Dashboards Case Management

  • Dashboards Data Lake

  • Threat Center Alerts

Dashboard Role-Based Access Control

RBAC permissions allow control of view and edit permissions for each individual dashboard. An administrator or a dashboard creator can assign multiple user roles to any dashboard they create or edit, and can define which type of access should be granted to each of those user roles for that specific dashboard.

Tip

For user roles that are assigned URBA view-level access to the Dashboards service (see User Roles above), RBAC permissions to edit or delete individual dashboards cannot be assigned. For example, if the Developer user role is assigned read-only access in the URBA settings, you cannot grant any edit or delete permissions to the Developer role in an individual dashboard. If you try to assign such permissions, an error message is displayed.

The following levels of permissions are available, depending on the limitations of the user role.

  • Can View – Users with roles assigned to this permission can view but not modify the dashboard. All options for editing the dashboard are hidden. Users whose role is not included in this permission cannot see or access the dashboard.

  • Can View and Edit – Users with roles assigned to this permission can view and modify the dashboard but cannot delete it. All editing options are available to users whose role is included in this permission.

  • Can View, Edit and Delete – Users with roles assigned to this permission can view, edit, or delete the dashboard. All editing options are availabel to users whose role is included in this permission, and they can also delete the dashboard. Users with the Administrator role have this full access to all dashboards. Dashboard creators also have this full access for any dashboards they create.

For information about defining or editing RBAC permissions on a specific dashboard, see Create a Dashboard or Edit Dashboard Details.

Note

Dashboards with no RBAC permissions assigned are visible to all Dashboards users. Users in the Administrator role always retain full access to all dashboards regardless of the RBAC permissions defined for a specific dashboard.