RBAC Considerations for AI SOC
ai soc relies on hero ai , orchestration components , and the ai alert analysis panel on case management records access depends both on widget level options (who can see generate plan , automation, and so on) and on platform role based access control (rbac) for turbine components and orchestration administrators should align account rbac mode with the permissions below so analysts can generate plans and use automation (for example create a triage rule , ai soc case hero ai analysis ) as intended at a glance rbac mode what analysts typically need for full ai soc usage enhanced rbac read and execute permissions on components required for plan steps and automation (grant per component or role as your organization defines) legacy rbac orchestrator level permissions are required for users to use ai soc features that depend on components and orchestration enhanced rbac in enhanced rbac , grant analysts (and other roles that generate or run plans) read and execute access to the components hero ai selects when building or running investigation steps without execute permission on the relevant components, tools may not appear or populate in the plan workflow (for example in the automation area after generate plan ), and users may be unable to complete actions that depend on those components administrator actions identify which components your organization uses for ai soc (installed connectors, hero ai analysis components, marketplace items) assign read and execute on those components to the roles that should run plans and automation keep case management widget permissions aligned so the same roles can use the ai analysis / ai alert analysis features you expect see getting started β permissions configuration docid\ p7qjquayekczhpxeppwcp legacy rbac in legacy rbac , orchestrator level permissions are required for users to use ai soc in line with component backed plan and automation behavior analyst or viewer roles that do not include orchestration rights at that level may see incomplete behavior (for example plans that do not surface the ai soc case hero ai analysis tool or options to create triage rules from a generated plan) even when case management widget options look correct administrator actions confirm whether your account uses legacy or enhanced rbac for legacy rbac , ensure users who need full ai soc analyst workflows have the appropriate orchestrator access, or migrate to enhanced rbac and apply read / execute on components as described above widget rbac (case management) the ai analysis widget on the case management form layout controls which roles can see each section of ai alert analysis (summary, plan, automation, marketplace, and so on) this is separate from component permissions but must be configured together users need both widget access and component / orchestration permissions for end to end flows see getting started β permissions configuration docid\ p7qjquayekczhpxeppwcp and case management (case) β ai alert analysis configuration (rbac) docid\ sdpesft6lsyz0zfrn hok