By default, every analyst can access all of your profiles. Per-profile access lets an admin restrict each analyst to only the profiles they've been granted, so analysts work only within their assigned scope.
This is useful when different analysts are responsible for different customers or investigation scopes and you need clear data separation between them.
A profile is an isolated scope within your organization - its own data, sources, and context. MSSPs typically use one profile per end customer.
Setting it up has two parts: turning on enforcement for a profile, and granting each analyst their profiles.
How per-profile access works
- Admins always have access to all profiles - this cannot be restricted.
- Analysts are limited to the profiles granted to them once enforcement is enabled. With enforcement on and no profiles granted, an analyst sees no investigations.
- Access is allow-list only: a profile is visible if it's been granted, and nothing else.
Part 1 - Enable enforcement
- Open the Profiles list.
- On the relevant profile's row, open the ⋮ actions menu.
- Select Per-profile access.
- In the enforcement dialog, switch the toggle to Enforced.
- Click Update enforcement.
⚠️ Enabling is safe for existing access. Each analyst's current access is backfilled when you enable, so no one loses access at the moment you turn it on. Only profiles created after enabling must be granted explicitly.
To turn it off later, use the same menu, switch the toggle to Not enforced, and click Update enforcement. Analysts can then see all profiles again, and existing grants are kept so you can re-enable without reconfiguring.
Part 2 - Grant profiles to an analyst
- Go to Settings → User Management to open the Users list.
- On the analyst's row, open the ⋮ menu and select Manage profile access.
- In the dialog, use the search box or Select all, and tick the profiles this analyst should have access to.
- The dialog shows a running count of how many profiles are selected.
- Save. A confirmation appears: Access updated - profile access successfully updated.
The selection you save becomes the analyst's complete access list - saving replaces any previous selection. To change access later, reopen the same dialog and adjust the selection.
What the analyst sees
Once enforcement is on and profiles are assigned, the analyst sees investigations only for their granted profiles. An analyst with no profiles granted sees an empty Investigations list until an admin grants access.
Roles and access at a glance
| Role | Actions | Profile access |
|---|---|---|
| Admin | Full administrative actions, including enforcement and granting access | All profiles - unrestricted |
| Analyst | Investigation actions within scope | All profiles by default; limited to granted profiles once enforcement is enabled |
Roles govern what a user can do; per-profile access governs which profiles they can see.
Best practices
- Grant the minimum necessary - give each analyst only the profiles they're responsible for.
- Remember new profiles need granting - once enforcement is on, profiles created later aren't granted automatically.
- Assign on onboarding - make profile granting part of new-analyst setup, so they aren't left without access.
- Keep admins few - since admins always see everything, reserve the admin role for users who need full visibility.
Review after team changes - audit grants periodically to keep access aligned with responsibilities.