Skip to content

Available roles

Overview

Use this reference to look up the permissions you can assign when creating a role. You can create a role and assign any combination of the following permissions to it.

In the UI, to set up a role, navigate to Settings > Roles > Create role.

Organization

  • Turn on/off MFA
  • Data retention
  • Turn on/off prompt history logging
  • Turn on/off data retention
  • Enable/disable SIEM (Security Information and Event Management) integration
  • Update organization name
  • Update product name
  • Update logo
  • Update favicon
  • Update support email

Guardrails

  • Create guardrail package
  • Update guardrail package
  • Delete guardrail package
  • Turn on/off guardrail
  • Select block/audit mode
  • Customize response
  • Enforce guardrail use
  • Advanced configuration
  • Manage guardrail updates
  • View-only projects

Models

  • Add connection
  • Update connection
  • Delete connection
  • Create secret
  • Update secret
  • Delete secret

Projects

  • Create project
  • Update all projects
  • Delete all projects
  • Turn on/off provider
  • Update default provider
  • Create prompt template
  • Create API token
  • Revoke API token
  • Dashboard
  • Prompt history logs
  • Create fingerprints

Users

  • Invite user
  • Update user
  • Delete user
  • Block user
  • Unblock user
  • Reset user MFA (Multi-factor authentication)
  • Roles

Campaigns

  • View-only campaigns
  • Create campaign
  • Update campaign
  • Delete campaign

Reports

  • View-only reports
  • Create report
  • Cancel report
  • Update report
  • Delete report
  • Read report results

Attack types

  • Use agentic attacks
  • Use operational attacks
  • Use standard attacks
  • Use custom attacks

Remediations

  • Remediation access

API access

  • API access (Disabled by default for basic users)

Updated at: