Skip to content

User Roles

In AIR, the Global Admin has full control over managing 118 specific privileges, allowing the creation of highly customized user roles. This granular access control ensures that each user or group has permissions tailored to their specific needs, such as handling evidence acquisition, interACT sessions, or audit log management.

A useful feature within this setup is the tooltips provided alongside each privilege. These tooltips highlight any dependencies that may exist between privileges, helping administrators configure roles accurately without unintentionally restricting necessary functions.

For example, an admin could create a role that enables a user to access interACT for remote evidence collection while restricting access to audit logs or system-wide settings. The tooltips ensure that admins are aware of any required privileges to avoid misconfigurations.

This approach provides both flexibility and clarity, empowering admins to manage user roles effectively.

The tables below show the default privileges assigned to each built-in role. These can be customized by creating new roles with specific privilege combinations.


PrivilegeOrg AdminL1/L2L3/L4MaintenanceResponder
View Backup❌❌❌✅❌
Backup Now❌❌❌✅❌
Delete Backup❌❌❌❌❌
Download Backup❌❌❌❌❌
PrivilegeOrg AdminL1/L2L3/L4MaintenanceResponder
View License Key❌❌❌✅❌
Update License Key❌❌❌✅❌
PrivilegeOrg AdminL1/L2L3/L4MaintenanceResponder
Create Organization❌❌❌❌❌
Delete Organization❌❌❌❌❌
PrivilegeOrg AdminL1/L2L3/L4MaintenanceResponder
Save Settings❌❌❌✅❌
PrivilegeOrg AdminL1/L2L3/L4MaintenanceResponder
Download Server Logs❌❌❌❌❌

PrivilegeOrg AdminL1/L2L3/L4MaintenanceResponder
View Acquisition Profile✅✅✅❌✅
Create Acquisition Profile✅✅✅❌✅
Update Acquisition Profile✅✅✅❌✅
Delete Acquisition Profile✅❌✅❌✅
PrivilegeOrg AdminL1/L2L3/L4MaintenanceResponder
View Auditlog✅❌❌❌❌
PrivilegeOrg AdminL1/L2L3/L4MaintenanceResponder
Create Auto Asset Tag✅❌❌❌✅
Update Auto Asset Tag✅❌❌❌✅
View Auto Asset Tag✅❌❌❌✅
Delete Auto Asset Tag✅❌❌❌✅
Assign Auto Asset Tagging Task✅❌❌❌✅
PrivilegeOrg AdminL1/L2L3/L4MaintenanceResponder
View Automation Hub✅✅✅❌✅
Manage Automation Hub✅❌✅❌✅
PrivilegeOrg AdminL1/L2L3/L4MaintenanceResponder
View Case✅✅✅❌✅
Create Case✅✅✅❌✅
Manage Case✅✅✅❌✅
Update Case Status✅✅✅❌❌
Change Owner Case✅✅✅❌✅
PrivilegeOrg AdminL1/L2L3/L4MaintenanceResponder
View Cloud Acquisition Profile❌❌❌❌❌
Create Cloud Acquisition Profile❌❌❌❌❌
Update Cloud Acquisition Profile❌❌❌❌❌
Delete Cloud Acquisition Profile❌❌❌❌❌
PrivilegeOrg AdminL1/L2L3/L4MaintenanceResponder
View Cloud Asset Account❌❌❌❌❌
Create Cloud Asset Account❌❌❌❌❌
Delete Cloud Asset Account❌❌❌❌❌
Sync Cloud Asset Account❌❌❌❌❌
PrivilegeOrg AdminL1/L2L3/L4MaintenanceResponder
Manage Cloud Account✅❌❌❌✅
Deploy Responder to Cloud✅❌❌❌✅
PrivilegeOrg AdminL1/L2L3/L4MaintenanceResponder
Create Asset✅❌✅❌✅
Edit Asset Label✅❌❌❌✅
Delete Asset✅❌❌✅✅
View Asset✅✅✅✅✅
Sync LDAP✅❌❌✅✅
Download Asset Logs✅❌❌✅✅
Import Off-Network Asset✅❌✅❌✅
Import PPC to Existing Asset✅❌✅❌✅
Update Asset Connection Route✅❌✅✅✅
Update Asset Maintenance Mode❌❌❌❌❌
PrivilegeOrg AdminL1/L2L3/L4MaintenanceResponder
Create Asset Tag✅✅✅✅✅
Update Asset Tags✅❌❌✅✅
Delete Asset Tag✅❌❌✅✅
Delete All Asset Tags✅❌❌✅✅
Remove Tags from Asset✅❌❌✅✅
Add Tags to Assets✅✅✅✅✅
PrivilegeOrg AdminL1/L2L3/L4MaintenanceResponder
Create Event Subscriptions✅❌❌❌✅
Update Event Subscriptions✅❌❌❌✅
View Event Subscriptions✅❌❌❌✅
Delete Event Subscriptions✅❌❌❌✅
PrivilegeOrg AdminL1/L2L3/L4MaintenanceResponder
View Evidence Repository✅✅✅✅✅
Create Evidence Repository✅❌❌✅✅
Update Evidence Repository✅❌❌✅✅
Delete Evidence Repository✅❌❌✅✅
View Case Report✅✅✅❌✅
PrivilegeOrg AdminL1/L2L3/L4MaintenanceResponder
View Full Text Search Profile✅✅✅❌✅
Create Full Text Search Profile✅✅✅❌✅
Update Full Text Search Profile✅✅✅❌✅
Delete Full Text Search Profile✅❌✅❌✅
PrivilegeOrg AdminL1/L2L3/L4MaintenanceResponder
View Disk Image Acquisition Profile❌❌❌❌❌
Create Disk Image Acquisition Profile❌❌❌❌❌
Update Disk Image Acquisition Profile❌❌❌❌❌
Delete Disk Image Acquisition Profile❌❌❌❌❌
PrivilegeOrg AdminL1/L2L3/L4MaintenanceResponder
View interACT Library✅✅✅❌✅
Modify interACT Library✅❌✅❌✅
PrivilegeOrg AdminL1/L2L3/L4MaintenanceResponder
Enumerate✅✅✅❌✅
Read Content✅❌✅❌✅
Write and Execute✅❌✅❌✅
PrivilegeOrg AdminL1/L2L3/L4MaintenanceResponder
View Notification✅✅✅✅✅
Delete All Notifications✅❌❌✅✅
Mark All as Read Notification✅✅✅✅✅
PrivilegeOrg AdminL1/L2L3/L4MaintenanceResponder
View Organization✅❌❌❌❌
Update Organization✅❌❌❌❌
PrivilegeOrg AdminL1/L2L3/L4MaintenanceResponder
Update Deployment Token✅❌❌❌❌
PrivilegeOrg AdminL1/L2L3/L4MaintenanceResponder
View Policy✅✅✅✅✅
Create Policy✅❌❌✅✅
Update Policy✅❌❌✅✅
Delete Policy✅❌❌✅✅
Override Policy✅❌✅✅✅
PrivilegeOrg AdminL1/L2L3/L4MaintenanceResponder
Manage Relay Server✅❌❌❌✅
PrivilegeOrg AdminL1/L2L3/L4MaintenanceResponder
View Task✅✅✅✅✅
Delete Task✅✅✅❌✅
Cancel Task✅✅✅❌✅
Update Task✅❌❌❌✅
Schedule Task✅❌✅❌✅
Update Scheduled Task✅❌✅❌✅
PrivilegeOrg AdminL1/L2L3/L4MaintenanceResponder
Assign Hunt/Triage Task✅✅✅❌✅
Assign Acquire Evidence Task✅✅✅❌✅
Assign Full Text Search Task✅❌❌❌❌
Assign Disk Image Acquisition Task❌❌❌❌❌
Assign Reboot Task✅❌✅✅❌
Assign Shutdown Task✅❌❌✅❌
Assign Log Retrieval Task✅❌❌✅✅
Assign Version Update Task✅❌✅✅✅
Assign Isolation Task✅❌✅✅✅
PrivilegeOrg AdminL1/L2L3/L4MaintenanceResponder
Delete Task Assignment✅✅✅✅✅
Cancel Task Assignment✅✅✅✅✅
PrivilegeOrg AdminL1/L2L3/L4MaintenanceResponder
View Hunt/Triage✅✅✅❌✅
Create Hunt/Triage✅✅✅❌✅
Update Hunt/Triage✅✅✅❌✅
Delete Hunt/Triage✅✅✅❌✅
PrivilegeOrg AdminL1/L2L3/L4MaintenanceResponder
View User✅✅✅❌✅
Create User✅❌❌❌❌
Delete User✅❌❌❌❌
Update User✅❌❌❌❌
PrivilegeOrg AdminL1/L2L3/L4MaintenanceResponder
View Role✅❌❌❌❌
PrivilegeOrg AdminL1/L2L3/L4MaintenanceResponder
Update 2FA Settings✅❌❌❌❌
PrivilegeOrg AdminL1/L2L3/L4MaintenanceResponder
View Webhook✅❌❌❌✅
Create Webhook✅❌❌❌✅
Update Webhook✅❌❌❌✅
Delete Webhook✅❌❌❌✅