Understand EDRF roles

Prev Next

EDRF uses role-based access control inherited from both Trellix EDR (EDR workspace) and Endpoint Security (HX) (Forensics workspace). Before deployment, ensure that users have the correct roles to perform their responsibilities.

Note

Roles are predefined permissions within EDRF that control what a user can access and perform. Personas describe user types and the tasks they typically carry out.

Before you begin

To assign a role in ePO, first create a user, then assign the role to that user.

EDR workspace roles

  • EDR Administrator — Configure EDRF, manage collectors, perform investigations, and take endpoint actions.

  • SOC Analyst L2 — Investigate threats, run real-time and historical searches, and take remediation actions.

  • SOC Analyst L1 — Monitor threats and perform real-time or historical searches.

  • Account Administrator — Assign granular roles such as:

    • Configure endpoint policies

    • Configure tenant settings and data sources

    • Execute targeted remediation (single device)

    • Triage and scope investigations

Forensics workspace roles

  • HX API Admin — Configure API access and manage integrations.

  • HX Analyst SR (Senior Analyst) — Conduct deep investigations and lead incident response activities.

  • HX Investigator — Perform endpoint investigations and forensic data analysis.

  • HX Analyst — Review alerts, monitor threats, and support incident triage.

  • HX Operator — Execute approved remediation and containment actions.

  • HX Monitor — Monitor dashboards and system health without making changes.

  • HX Auditor — Review system activity, audit logs, and compliance reports.

  • HX Reject — Role with no permissions; used to explicitly deny system access.