Skip to content
Docs
foxborne.comRequest a pilot

Roles and permissions

Foxborne has five fixed roles, from admin to auditor. Each carries a fixed set of permissions, so an audit can reason about who could import, edit, approve, export or read the audit log.

ReferenceMarkdown
On this page7

Each person in Foxborne holds one of five roles: admin, investigator, reviewer, viewer or auditor. The permissions of each role are fixed, so an audit can reason about them.

The five roles#

RoleWhat it doesSCIM group
AdminRuns the deployment: sources, hosting, access, retention and rules.foxborne-admins
InvestigatorImports runs, opens incidents, annotates evidence and writes reports.foxborne-investigators
ReviewerReads everything an investigator can, comments and approves reports.foxborne-reviewers
ViewerReads approved reports and their evidence. Cannot import or edit.foxborne-viewers
AuditorReads the audit log, exports and the evidence chain. Cannot edit.foxborne-auditors

The descriptions are the ones on the Roles tab under Access. Its Roles table gives each role's name, What it is for and the number of People who hold it.

Permissions#

The Permissions panel on the same tab carries the subtitle Fixed per role, so an audit can reason about them. A blank cell means the role does not hold the permission.

PermissionAdminInvestigatorReviewerViewerAuditor
Import runs and filesYesYes
Open and edit incidentsYesYes
Inspect original evidenceYesYesYesYesYes
Comment on reportsYesYesYes
Approve reportsYesYes
Export case filesYesYesYesYes
Read and download reportsYesYesYesYesYes
Save, schedule and generate reportsYesYesYes
Manage sources and collectorsYes
Change detection rulesYes
Save a parser for a new log formatYes
Read the audit logYesYes
Manage hosting, keys and accessYes

Who approves reports#

  • Admins and reviewers hold Approve reports. Investigators write reports but cannot approve them.
  • A request for review is recorded in the audit log as Requested review, with the reviewer's name.
  • On the incident's Report tab, Approve report appears in the Report panel while the report is In review, for the reviewer named on that incident.
  • The report's status chip reads Draft, In review or Approved. Viewers read approved reports and their evidence.

Who reads the audit log#

  • Admins and auditors hold Read the audit log. The Audit log page gives them Verify chain and Export as well.
  • An auditor reads the audit log, exports and the evidence chain, and cannot edit.
  • Auditors also hold Inspect original evidence and Export case files, so they can check a report against its sources.

Evidence marked EXPT#

All five roles hold Inspect original evidence. Evidence marked EXPT also needs US person status: it opens only for users whose identity provider asserts it. See Export-controlled evidence.

Where roles are set#

WhereHow
Invite someoneChoose the Role when you invite. The list starts at Investigator.
Change roleFrom the person's row on Members. It takes effect on their next request.
SCIMMembership of the matching Foxborne group in your identity provider.

Change role writes Changed role to the audit log, with the person and the new role. An invitation writes Invited user, with the role as its detail.