About entitlements

Prev Next

Each role is associated with one or more entitlements. An entitlement specifies that a service (such as the Trellix IAM Web UI) or an application (such as a Central Management System appliance) can access a particular resource or feature to perform a particular action.

Note

Each application or service that integrates with Trellix IAM has its own set of entitlements.

Entitlement names take one of two forms:

<service>.<resource>.<action>

The Trellix IAM Web UI and Helix (previously known as the Threat Analytics Platform, or TAP) have entitlements that each represents an individual, fine-grained user access privilege. Thus the global roles for these products map to multiple entitlements.

Examples:

  • iam.apikeys.delete―The ability to delete any API key in the IAM organization.

  • tap.alerts.add―The ability to add new alerts in Helix.

For more information, see Entitlements for the IAM Web UI roles and Entitlements for Helix roles.

<service>.role.<action>

Each role for a Trellix appliance maps to a single entitlement that represents multiple access privileges.

Examples:

  • cms.role.analyst―Analyst privileges on a Central Management System appliance.

  • appliance.role.auditor―Auditor fallback privileges on all Trellix appliances.

For more information, see Entitlements for the appliance roles.