About roles

Prev Next

Role-based access controls determine what users can see and do on OIDC clients in the IAM organization. A role associates a product-specific job function with the product-specific access privileges needed to perform that job. On an Email Security — Server appliance, for example, the Analyst role grants users the privileges necessary to perform email malware analysis tasks.

User accounts can be assigned roles for more than one product type, and they typically are. A user can be assigned multiple roles for accessing the Trellix Web UI or Helix Web UI. For access to Trellix appliances, a user can only be assigned a single role for each product type in the IAM organization.

Global roles

Trellix IAM provides a comprehensive set of system-defined roles, called global roles, for granting user access to its own Web UI and also to the products that integrate with IAM: Helix Enterprise and supported Trellix products.

Global roles grant product-specific user access permissions that are geared toward a job function pertaining to that product.

The IAM global roles and the permissions they grant are described in IAM entitlements.

Global roles are created automatically when Trellix creates an IAM organization, and they cannot be modified or deleted.

Custom roles

For the IAM Web UI roles and Helix Enterprise, if none of the global roles match your workflow needs, a Trellix IAM administrator can create custom roles for the IAM organization. For more information, see Creating a custom role.

Trellix IAM does not support custom roles for Trellix appliances.

Fallback roles

The IAM roles for Trellix appliances include six roles that grant access privileges needed to perform a specific job function: Admin, Analyst, Auditor, Monitor, Operator, or Reject.

These job-specific roles are product-agnostic rather than product-specific. Each role grants job-specific access privileges for all supported Trellix appliance types: Central Management System, Endpoint Security (HX), Email Security — Server, and Network Security. The roles act as "fallback roles" because a Trellix appliance will apply a fallback role only for users that are not assigned any appliance-specfic roles.

For details, see Entitlements for fallback roles for all appliances.