For MSSPs
Team Access lets an admin create a team, restrict it to a set of profiles, and add analysts to it - everyone on the team is limited to that same set. You configure access once and reuse it.
This is the scalable way to apply per-profile restriction when several analysts share the same scope. To restrict a single analyst, use Managing Per-Profile Access for Analysts instead.
A profile is an isolated customer within your organization - its own data, sources, and context. MSSPs typically use one profile per end customer.
How team access works
- Admins always have access to all profiles. This cannot be restricted.
- A team is scoped to an allow-list of profiles. Analysts added to the team see only those profiles, and nothing else.
- Adding an analyst to a team grants the team's profiles instantly; removing them revokes that team's access.
- An analyst's total access is the union of every team they belong to, plus any profiles granted to them directly. (See the note under Removing access.)
- Team Access works on its own - you don't need to enable per-profile enforcement first. Adding an analyst to a team restricts them to that team's profiles by itself.
Part 1: Create a team and scope it to profiles
- Go to Settings → Team Management.
- Click Create Team.
- Name the team and select the profiles it should be scoped to.
- Save.
The team now has an explicit list of profiles. Anyone you add sees only these.
Part 2: Add analysts to the team
You can add existing users or invite new ones:
- Existing users: Settings → Team Management → click the team → add members (select all, or pick individuals) → save.
- New users: Settings → Add User → enter name and email → select an existing team, or create one and select its profiles.
Each analyst added inherits the team's profile access immediately - no per-analyst setup.
Managing a team
Open Settings → Team Management and click the team to:
- Update profiles - remove one with the X, or add via the dropdown
- Add or remove members - select all or individual analysts
- Rename the team
- Delete the team - use Delete team at the top right
Alternate path per user: Settings → User Management → user → ⋮ → Manage Teams to deselect a team, or open Team Management for the full view.
What the analyst sees
Once an analyst is on a team, they see investigations only for that team's profiles (combined with any other teams or direct grants they have). An analyst with no profiles granted - through a team or directly - sees an empty Investigations list until an admin grants access.
Removing access
⚠️ Because access is the union of a user's teams and any direct grants, removing an analyst from a team does not remove access they were granted directly to the same profile. To fully remove an analyst's access to a profile, remove it in both places - the team and any direct grant.
Team Access vs. Per-Profile Access
| Use Team Access | Use Per-Profile Access | |
| Best for | Groups of analysts sharing a scope | A single analyst |
| Set restriction | Once per team | Once per analyst |
| Adding people | Add to the team | Grant profiles individually |
| Availability | MSSPs | MSSPs |
Both restrict analysts to only the profiles they've been granted. Team Access does this on its own and doesn't require per-profile enforcement to be enabled.
Best practices
- Group by responsibility - create a team per book of business (e.g. a set of end customers) and add the analysts who own it.
- Grant the minimum necessary - scope each team to only the profiles its analysts need.
- Assign on onboarding - add new analysts to their team as part of setup, so they aren't left without access.
- Remember new profiles need granting - profiles created later aren't added to a team automatically.
- Review after team changes - when responsibilities shift, update team membership and scope to keep access aligned.
- Keep admins few - admins always see everything, so reserve the admin role for users who need full visibility.