Skip to main content
Skip table of contents

User Roles and Permissions Matrix

HYAS Protect provides six distinct permission roles, each tailored to specific levels of access and responsibilities. These roles are designed to ensure users have the appropriate permissions for their tasks while maintaining a secure and efficient operational structure. Below is a brief overview of each role, followed by a detailed matrix outlining their specific capabilities and limitations.

The Partner Admin role holds the highest level of authority within the system. This role has unrestricted access to all features, including creating, editing, and managing MSSP accounts and performing actions across all child organizations. Partner Admins act as the ultimate administrators, overseeing all aspects of the system.

The MSSP Admin role is next in the hierarchy. It inherits most permissions from the Partner Admin but has certain limitations. For instance, MSSP Admins cannot create or manage other MSSP accounts. However, they maintain full access and control within their assigned MSSP scope, enabling them to manage child organizations and user accounts as necessary.

The MSSP Analyst role is more operational in nature. This role is limited to viewing and acting within assigned MSSPs. MSSP Analysts cannot manage accounts, policies, or configurations, focusing instead on day-to-day tasks like monitoring logs and alerts.

The Org Admin role operates at the organization level, with full access within the assigned organization. Unlike MSSP roles, Org Admins do not have visibility or access to MSSP-level accounts or settings. They are responsible for managing their specific organization’s configurations and users.

The Protect Analyst role is designed for limited access. Analysts can view logs, reports, and activity data within the Protect environment but are unable to make configuration changes or manage policies. Their primary responsibility is to analyze and monitor system activity.

Finally, the Protect Executive role is tailored for high-level access, limited to reports and summaries. This role is meant for executive decision-making and does not include, detailed configurations, or operational tasks.

Permission

Partner Admin

MSSP Admin

MSSP Analyst

(Org) Admin

Protect Analyst

Protect Executive

Create, Edit MSSPs

βœ…

πŸ›‘

πŸ›‘

πŸ›‘

πŸ›‘

πŸ›‘

Configure Policy Inheritance

βœ…

πŸ›‘

πŸ›‘

πŸ›‘

πŸ›‘

πŸ›‘

View Child Orgs

βœ…

βœ…

βœ…

πŸ›‘

πŸ›‘

πŸ›‘

Create, Edit Child Orgs

βœ…

βœ…

πŸ›‘

πŸ›‘

πŸ›‘

πŸ›‘

Manage User Accounts

βœ…

βœ…

πŸ›‘

βœ…

πŸ›‘

πŸ›‘

View Blocking Mode

βœ…

βœ…

πŸ›‘ - UI

βœ… - API

βœ…

πŸ›‘ - UI

βœ… - API

πŸ›‘ - UI

βœ… - API

Set Blocking Mode

βœ…

βœ…

πŸ›‘

βœ…

πŸ›‘

πŸ›‘

View Notification Emails

βœ…

βœ…

βœ…

βœ…

βœ…

βœ…

Set Notification Emails

βœ…

βœ…

πŸ›‘

βœ…

πŸ›‘

πŸ›‘

View Source Networks

βœ…

βœ…

πŸ›‘ - UI

βœ… - API

βœ…

πŸ›‘ - UI

βœ… - API

πŸ›‘ - UI

βœ… - API

Change Source Networks

βœ…

βœ…

πŸ›‘

βœ…

πŸ›‘

πŸ›‘

View SentinelOne Config

βœ…

βœ…

πŸ›‘ - UI

βœ… - API

βœ…

πŸ›‘ - UI

βœ… - API

πŸ›‘ - UI

βœ… - API

Set SentinelOne Config

βœ…

βœ…

πŸ›‘

βœ…

πŸ›‘

πŸ›‘

View Logs

βœ…

βœ…

βœ…

βœ…

βœ…

βœ…

Block from Log View

βœ…

βœ…

πŸ›‘

βœ…

πŸ›‘

πŸ›‘

Allow from Log View

βœ…

βœ…

πŸ›‘

βœ…

πŸ›‘

πŸ›‘

Block from Flyout

βœ…

βœ…

βœ…

βœ…

βœ…

πŸ›‘

Allow from Flyout

βœ…

βœ…

βœ…

βœ…

βœ…

πŸ›‘

Add Tag from Flyout

βœ…

βœ…

βœ…

βœ…

βœ…

πŸ›‘

Add Note from Flyout

βœ…

βœ…

βœ…

βœ…

βœ…

πŸ›‘

View Category

βœ…

βœ…

βœ…

βœ…

βœ…

βœ…

Block/ Unblock Category

βœ…

βœ…

πŸ›‘

βœ…

πŸ›‘

πŸ›‘

View policy

βœ…

βœ…

βœ…

βœ…

βœ…

βœ…

Create, Edit, Delete Policy

βœ…

βœ…

πŸ›‘

βœ…

πŸ›‘

πŸ›‘

View List

βœ…

βœ…

βœ…

βœ…

βœ…

βœ…

Create, Edit, Delete Lists

βœ…

βœ…

πŸ›‘

βœ…

πŸ›‘

πŸ›‘

View Policy Rule

βœ…

βœ…

βœ…

βœ…

βœ…

βœ…

Create, Edit, Delete Policies

βœ…

βœ…

πŸ›‘

βœ…

πŸ›‘

πŸ›‘

Delete alert

βœ…

βœ…

βœ…

βœ…

βœ…

βœ…

Acknowledge Alert

βœ…

βœ…

βœ…

βœ…

βœ…

βœ…

Configure Timezone

βœ…

βœ…

βœ…

βœ…

βœ…

βœ…

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.