RBAC Considerations for AI SOC
ai soc relies on hero ai , orchestration components , and the ai alert analysis panel on case management records access depends both on widget level options (who can see generate plan , automation, and so on) and on platform role based access control (rbac) for turbine components and orchestration administrators should align account rbac mode with the permissions below so analysts can generate plans, use re investigate , and use automation (for example create a triage rule , ai soc case hero ai analysis ) as intended at a glance rbac mode what analysts typically need for full ai soc usage enhanced rbac read and execute permissions on components required for plan steps and automation (grant per component or role as your organization defines) legacy rbac orchestrator level permissions are required for users to use ai soc features that depend on components and orchestration enhanced rbac in enhanced rbac , grant analysts (and other roles that generate or run plans) read and execute access to the components hero ai selects when building or running investigation steps without execute permission on the relevant components, tools may not appear or populate in the plan workflow (for example in the automation area after generate plan ), and users may be unable to complete actions that depend on those components administrator actions identify which components your organization uses for ai soc (installed connectors, hero ai analysis components, marketplace items) assign read and execute on those components to the roles that should run plans and automation keep case management widget permissions aligned so the same roles can use the ai analysis / ai alert analysis features you expect see getting started docid\ p7qjquayekczhpxeppwcp legacy rbac in legacy rbac , orchestrator level permissions are required for users to use ai soc in line with component backed plan and automation behavior analyst or viewer roles that do not include orchestration rights at that level may see incomplete behavior (for example plans that do not surface the ai soc case hero ai analysis tool or options to create triage rules from a generated plan) even when case management widget options look correct administrator actions confirm whether your account uses legacy or enhanced rbac for legacy rbac , ensure users who need full ai soc analyst workflows have the appropriate orchestrator access, or migrate to enhanced rbac and apply read / execute on components as described above widget rbac (case management) the ai analysis widget on the case management form layout controls which roles can see each section of ai alert analysis (summary, plan, automation, marketplace, and so on) this is separate from component permissions but must be configured together users need both widget access and component / orchestration permissions for end to end flows see getting started docid\ p7qjquayekczhpxeppwcp and case management (case) docid\ sdpesft6lsyz0zfrn hok trigger analysis agent and routing rules when signal routing rules run ai soc trigger analysis agent via routing rule , investigation executes as a playbook run using a pat token stored in an asset—not as the analyst who later opens the record one time administrator setup configure a pat token (personal access token) in an asset referenced by ai soc trigger analysis agent via routing rule the platform calls the ai soc trigger analysis agent over http using that token component execute permissions for the pat user apply while the agent runs reviewer vs runner role permissions agent run (routing rule / pat user) determines which components ai soc trigger analysis agent can execute analyst reviewing the signal may differ from the pat user; can review verdict, progress, and stored inputs/outputs on the record create a playbook uses the reviewing user's component access—playbook creation can fail if that user cannot access components the agent ran component inputs and outputs from trigger analysis agent runs are stored as attachments on the record so analysts can inspect results even when they lack permission to open the underlying playbook run only components with visible to hero ai enabled are available to the ai soc trigger analysis agent review which components are hero visible before using re investigate or routing rule analysis in production see building routing rule playbooks docid\ veifyg4oywkq3dcmmwjxi and getting started docid\ p7qjquayekczhpxeppwcp