Skip to content

Permissions

This page lists every action that authorization in LogCraft governs, and who can perform it. Use it when you need to verify whether a specific role or access level can perform a specific action.

  • To choose a global role for a user, see Team.
  • To choose an access level for a workspace member, see Members.

How authorization works

Authorization in LogCraft is a two-layer model:

  • Global role: the system-wide role assigned to a user at creation.
  • Workspace access level: the per-workspace role assigned when a user is added to a workspace.

Both layers apply to workspace-scoped actions: the user must satisfy the minimum global role and the minimum access level required by the action.

Workspaces

ActionRolesAccess level
List the workspaces the user can seeAdmin, Operator, Membern/a
View a workspaceAdmin, Operator, MemberMaintainer, Collaborator, Contributor, Observer
Edit workspace settingsAdmin, Operator, MemberMaintainer
Create a workspaceAdmin, Operatorn/a
Delete a workspaceAdmin, Operatorn/a

Detection content

The same rules govern Security Assets and Use Cases.

ActionRolesAccess level
View Security Assets and Use CasesAdmin, Operator, MemberMaintainer, Collaborator, Contributor, Observer
Create or edit a Security Asset or a Use CaseAdmin, Operator, MemberMaintainer, Collaborator, Contributor
Delete a Security Asset or a Use CaseAdmin, Operator, MemberMaintainer, Collaborator

Posture Management

These rules cover the Security Posture, MITRE ATT&CK, and Detection Opportunities views.

ActionRolesAccess level
Open Posture Management viewsAdmin, Operator, MemberMaintainer, Collaborator, Contributor, Observer
Set or change MITRE ATT&CK objectivesAdmin, Operator, MemberMaintainer, Collaborator, Contributor

Team and users

ActionRolesAccess level
View user informationAdmin, Operator, Membern/a
Create a userAdmin, Operatorn/a
Edit a user or workspace membershipAdmin, Operatorn/a
Remove a userAdmin, Operatorn/a

Server administration

These actions are performed outside any workspace and are reserved for the Admin role.

ActionRoles
View license detailsAdmin
Install or update the licenseAdmin
View audit logsAdmin