Security Analyst Role
Learn the various permissions available to the security analyst role in Nightfall.
Last updated
Learn the various permissions available to the security analyst role in Nightfall.
Last updated
The Security Analyst role allows users to view Dashboard, generate reports from Dashboards, view DLP violations, view exfiltration and posture management events, and view detectors.
The Nightfall app view for a user with this role is as shown in the following image.
A user with Security Analyst Role has the following permissions
With the Dashboard and Reporting permissions, users to view data on the Dashboard, apply filters to the dashboard data, and also generate reports from the Dashboard data.
With the DLP Violations permission, users can take appropriate actions on the DLP violations. They can also share the violation data and export it as a CSV file.
With the Content Preview permission, users can preview the content of the DLP Violations page. The sensitive data is redacted.
The main point of difference between the Security analyst role and the Security events manager role is that users with the Security analyst role can view redacted content of DLP violations page.However, content is not redacted for the Security Events manager role.
With the Exfiltration permission, users can filter event data, share event data, view historic events data, and take actions on Posture management, Exfiltration, and encryption events.
With the Detectors permission, users can view all the detectors, view detectors that belong to a specific category, filter the list of detectors, search a detector, and copy the UUID of a detector.