EDRF uses role-based access control inherited from both Trellix EDR (EDR workspace) and Endpoint Security (HX) (Forensics workspace). Before deployment, ensure that users have the correct roles to perform their responsibilities.
Note
Roles are predefined permissions within EDRF that control what a user can access and perform. Personas describe user types and the tasks they typically carry out.
Before you begin
To assign a role in ePO, first create a user, then assign the role to that user.
For Trellix ePO - SaaS users: See Assign roles to users for details.
For Trellix ePO - On-prem users: See User account and Add or edit a permission set for details.
EDR workspace roles
EDR Administrator — Configure EDRF, manage collectors, perform investigations, and take endpoint actions.
SOC Analyst L2 — Investigate threats, run real-time and historical searches, and take remediation actions.
SOC Analyst L1 — Monitor threats and perform real-time or historical searches.
Account Administrator — Assign granular roles such as:
Configure endpoint policies
Configure tenant settings and data sources
Execute targeted remediation (single device)
Triage and scope investigations
Forensics workspace roles
HX API Admin — Configure API access and manage integrations.
HX Analyst SR (Senior Analyst) — Conduct deep investigations and lead incident response activities.
HX Investigator — Perform endpoint investigations and forensic data analysis.
HX Analyst — Review alerts, monitor threats, and support incident triage.
HX Operator — Execute approved remediation and containment actions.
HX Monitor — Monitor dashboards and system health without making changes.
HX Auditor — Review system activity, audit logs, and compliance reports.
HX Reject — Role with no permissions; used to explicitly deny system access.