All Helix Enterprise entitlements

Prev Next

The table in this section lists all of the Helix Enterprise (formerly known as TAP) entitlements for each role. You can create custom roles and add entitlements to them as needed for granular control and security. For information about creating a custom role, see Creating a custom role.

For example, a user with a custom role that grants the tap.dashboards.read entitlement but not the tap.dashboards.edit entitlement can view individual dashboards, but cannot edit them.

If a user lacks the entitlements to view data or perform actions in the Helix Web UI, the data or action will not be available or an error message will be returned.

The following roles are available:

  • FaaS analyst role: FaaS Analyst access allows the user to manage hidden content within a Helix Enterprise instance.

  • TAP analyst limited role: TAP Analyst access allows the user to view data and perform all actions within Helix Enterprise, except for assigning and editing user permissions.

  • TAP analyst role: TAP Analyst Limited access allows the user to view data and perform all actions within Helix Enterprise, except for assigning or editing user permissions and executing regex searches.

  • TAP Cloud Collector role: TAP Cloud Collector access gives the user limited access to view data and perform actions in Helix Enterprise related to Cloud Collector sensors.

  • TAP content limited role: TAP Content Limited prevents the user from viewing data or performing actions within Helix Enterprise. You can temporarily disable a user's access to Helix Enterprise by assigning the TAP Content Limited role instead of deleting the user account. Depending on the circumstances, this might be preferable for auditing purposes.

  • TAP federated analyst role: TAP Federated Analyst access allows the user to view data and perform all actions within Helix Enterprise, except for assigning and editing user permissions. It also gives the user the federated view and the ability to take actions on behalf of child organizations.

  • TAP federated analyst limited role: TAP Federated Analyst Limited access allows the user to view data and perform all actions within Helix Enterprise, except for assigning or editing user permissions and executing regex searches. It also gives the user the federated view and the ability to take actions on behalf of child organizations.

  • TAP federated organization administrator role: TAP Federated Organization Administrator access gives the user full access to view data and perform all actions in Helix Enterprise. It also gives the user the federated view and the ability to take actions on behalf of child organizations.

  • TAP organization administrator role: TAP Organization Administrator access gives the user full access to view data and perform all actions in Helix Enterprise.

Note

These are global roles, and they cannot be modified or deleted.

Viewing roles and entitlements

To view the entitlements assigned to the role, filter the list of roles to show only Helix Enterprise (TAP) roles, select a role, and then drill down to its component entitlements. To view each role, you must have IAM Admin or IAM User access to the Trellix IAM Web UI.

To view the entitlements associated with the FaaS and TAP roles:
  1. Log in to the Trellix IAM Web UI.

  2. Select Organization Settings > Roles. The Roles page lists the IAM global roles and custom roles in your IAM organization.

  3. Filter the list on the Name column, specifying the match string FAAS or TAP.

  4. Click the role in the Name column. The Assigned Entitlements panel lists the entitlements assigned to the role.

If a user lacks the entitlements to view data or perform actions in the Helix Enterprise Web UI, the data or action will not be available or an error message will be returned.

Note

The TAP Content Limited role has no entitlements.