Each role is associated with one or more entitlements. An entitlement specifies that a service (such as the Trellix IAM Web UI) or an application (such as a Central Management System appliance) can access a particular resource or feature to perform a particular action.
Note
Each application or service that integrates with Trellix IAM has its own set of entitlements.
Entitlement names take one of two forms:
<service>.<resource>.<action>
The Trellix IAM Web UI and Helix (previously known as the Threat Analytics Platform, or TAP) have entitlements that each represents an individual, fine-grained user access privilege. Thus the global roles for these products map to multiple entitlements.
Examples:
iam.apikeys.delete―The ability to delete any API key in the IAM organization.tap.alerts.add―The ability to add new alerts in Helix.
For more information, see Entitlements for the IAM Web UI roles and Entitlements for Helix roles.
<service>.role.<action>
Each role for a Trellix appliance maps to a single entitlement that represents multiple access privileges.
Examples:
cms.role.analyst―Analyst privileges on a Central Management System appliance.appliance.role.auditor―Auditor fallback privileges on all Trellix appliances.
For more information, see Entitlements for the appliance roles.