The following Trellix IAM global roles are provided for each of the supported Trellix appliance types.
Admin―This is a "super user" role for each appliance type. The primary function of this role is to configure the system.
Analyst―This role focuses on the detection of appliance-specific malware type and taking appropriate action, including setting up alerts and reports.
Auditor―This role reviews audit logs for the appliance type and performs forensic analysis to trace how events occurred.
Monitor―This role has read-only access to some of the Admin role capabilities for the appliance type, and it has access to some appliance-specific malware analysis functions.
Operator―This role has a subset of the Admin role capabilities for the appliance type. Its primary function is configuring and monitoring the system.
Org Admin―This is a "super user" role for all appliance types. The primary function of this role is to configure the system.
Reject―This role is denied access of any kind to the appliance type.
The following Trellix IAM global roles are provided for HX Series appliances only:
API Admin―This role grants basic and extended API authorization for HX Series appliance features. The extended authorization allows a user to maintain custom policy channels and to contain hosts.
API Analyst―This role grants only basic API authorization for HX Series appliance features.
Analyst SR―This role is the same as the Analyst role, except the Analyst SR role can also request file acquisitions. An Analyst SR cannot approve containment requests or stop containment of host endpoints.
FE Services―This role is for a FireEye as a Service (FAAS) analyst on HX Series appliances that have an MD_ACCESS license. The role does allow the user to create additional FE Services users unless an MD_ACCESS license is installed.
Investigator―This role is the same as the Analyst SR role for HX Series appliances, but the Investigator can also stop containment of host endpoints.