Note

At least these rights are available in Workbench. However, this list can change at any time and may not be accurate at any given viewing.

Any user can be designated assignable by selecting a checkbox in the User profile. After a user is assignable:

  • Their name appears in the Assign to menus.

  • Their initials are visible to other Expel users after an alert or action is assigned to them.

Feature

Action

Organization Admin

Organization Analyst

Assign

assign to customer user

AYesIcon.png
AYesIcon.png

Assemblers

view page

AYesIcon.png
AYesIcon.png

create/edit/delete

AYesIcon.png
 

BOLO

view page

API only

API only

Customer context

view page

AYesIcon.png
AYesIcon.png

Customer configuration [1]

view/edit

AYesIcon.png
 

Hunting

view hunts (org specific with hunting service)

AYesIcon.png
AYesIcon.png

Investigative actions

pivot to console

API only

API only

Investigation findings

create/edit/delete

AYesIcon.png
AYesIcon.png

Investigation remediations

credit/edit/delete

AYesIcon.png
AYesIcon.png

Timeline

upload CSV

AYesIcon.png
AYesIcon.png

add/edit timeline event

AYesIcon.png
AYesIcon.png

My profile

edit notifications

AYesIcon.png
AYesIcon.png

change password

AYesIcon.png
AYesIcon.png

reset Google Auth

AYesIcon.png
AYesIcon.png

edit user

AYesIcon.png
AYesIcon.png

"assignable" checkbox

AYesIcon.png
 

"locked" checkbox

AYesIcon.png
 

Navigation bar

change organizations

Multi-org only

Multi-org only

Organizations list

view page

Multi-org only

Multi-org only

edit

Multi-org only

 

My organization

view page

AYesIcon.png
AYesIcon.png

configure/edit PagerDuty integration

AYesIcon.png
 

show PagerDuty service key

AYesIcon.png
AYesIcon.png

configure/edit Ticketing integration

AYesIcon.png
 

edit notifications

AYesIcon.png
AYesIcon.png

Resilience

view all recommendations

AYesIcon.png
AYesIcon.png

show/hide recommendations

AYesIcon.png
AYesIcon.png

Security devices

view page

AYesIcon.png
AYesIcon.png

create

AYesIcon.png
 

edit

AYesIcon.png
 

delete

AYesIcon.png
 

Workbench Integrations (PD, ticketing, and so on)

configure/edit

AYesIcon.png
 

test connection

AYesIcon.png
 

Users

view page

AYesIcon.png
AYesIcon.png

"assignable" checkbox

AYesIcon.png
 

change own role

AYesIcon.png
 

change username

AYesIcon.png
 

create/delete

AYesIcon.png
 

edit

AYesIcon.png
 

lock other users ("locked" checkbox)

AYesIcon.png
 

resend enrollment email

AYesIcon.png
 

[1] Customer configuration defaults can only be created by expel_admin but overrides can be set per customer by org_admin. However, each configuration has internal write and visibility properties that can further change who can view or edit the setting to SYSTEM, EXPEL, or ORGANIZATION.