This is the multi-page printable view of this section. Click here to print.

Return to the regular view of this page.

User Roles

    Roles and access control

    Role-Based Access Control (RBAC) controls which areas of the SamurAI Portal a user can view and which actions they can perform.

    Each SamurAI Portal user is assigned one role. The role determines the permissions available to that user, such as whether they can view security incidents, manage telemetry, create or update tickets or administer users.

    RBAC helps your organization apply the principle of least privilege by ensuring users have access only to the information and actions required for their responsibilities.

    Regional role availability

    RBAC is available in the SamurAI Portal for tenants in Japan and Europe.

    Japan and Europe operate separate platforms with different role catalogues. The roles reflect the capabilities and operational requirements of each regional portal.

    Available roles and their associated permissions may vary by region. Refer to the applicable regional role catalogue below when choosing a role for a user.

    Who can manage roles?

    Users assigned the Tenant Administrator role can:

    • View users in the tenant
    • Invite new users
    • Assign and change user roles
    • View available roles and their associated permissions
    • Manage tenant-level administrative activities available within the SamurAI Portal

    Users with other roles can access only the portal functions permitted by their assigned role.

    Important information

    Existing tenants

    When RBAC is enabled for an existing SamurAI tenant, all existing portal users are initially assigned the Tenant Administrator role.

    This approach ensures that existing users retain access during the rollout. Your organization must review its current user population and change each user to the most appropriate role as soon as possible.

    NTT recommends reviewing user access with the individuals responsible for security operations, IT operations, service ownership, and access governance.

    New tenants

    For a new SamurAI tenant, the first registered portal user is assigned the Tenant Administrator role.

    That user is responsible for inviting additional users and assigning appropriate roles.

    Tenant Administrator coverage

    Your organization should maintain at least two active Tenant Administrators wherever possible, providing a primary administrator and a backup.

    This reduces the risk of losing administrative access when an administrator is unavailable, changes role, leaves the organization, or cannot access their account.

    Keep the number of Tenant Administrators limited to those who need to manage the portal and user access. Assign additional administrators only where there is a clear administrative or coverage requirement.

    View roles

    To view the roles configured for your SamurAI tenant:

    1. Log in to the SamurAI Portal.
    2. From the main menu, select Admin > Roles.
    3. Select a role to view its permissions.

    The Roles page displays the roles available to your tenant, a short description of each role, its category, and the number of permissions assigned.

    When viewing a role, permissions are grouped by SamurAI Portal feature and, where applicable, by component. A check mark indicates that the role has the corresponding permission.

    Permission actions

    Depending on the feature and component, permissions can include:

    • Read — View information or access a portal feature
    • Create — Create new records or configurations
    • Update — Modify existing records or configurations
    • Delete — Delete records or configurations
    • Upload — Upload files or evidence where supported
    • Close — Close tickets or security incidents where supported
    • Enroll — Enroll endpoints where supported
    • Assign role — Assign a role to portal users
    • Invite — Invite new users

    An action applies to the feature and component against which it is listed. Permission to perform an action in one feature does not automatically grant the same action in another.

    Understand Core permissions

    Core refers to the main information or functionality of a feature. The actions shown against Core apply to that feature’s primary records or functions.

    For example, under General tickets, Core permissions control actions on the ticket itself, such as reading, creating, updating, or closing it.

    Supporting components, such as attachments, and communication channels, have their own permissions where listed.

    Core is not an additional permission level and does not automatically grant access to every component within a feature.

    Permissions used across portal views

    Some permissions provide access to information used in several areas of the SamurAI Portal.

    For example:

    • Events permissions support views that use telemetry event data, including relevant dashboards and event graphs within integrations.
    • Alerts permissions support views that display alert data, including relevant dashboards.
    • Security Incidents permissions support incident views and dashboards that use incident data, including MDR metrics.

    Dashboards are therefore not necessarily listed as separate features in the permissions table. Access to their information depends on permissions for the underlying data.

    Permission to view an integration’s configuration does not, by itself, grant permission to view its event data. These are separate permissions.

    The predefined roles include the permissions required for their intended responsibilities.

    Available roles

    The following descriptions summarise the intended use of each role. They are not exhaustive permission lists.

    Japan

    The following roles are available to tenants in Japan:

    RoleIntended usersTypical access
    Tenant AdministratorDesignated personnel responsible for portal and access administrationBroad access to supported SamurAI Portal capabilities, including user management and role assignment
    ViewerUsers who require visibility of service information without making changesRead-only access to permitted portal features and information
    TAMTechnical Account Managers or users responsible for reviewing service information and coordinating activitiesAccess supporting service review, incidents, tickets, reporting, and operational coordination
    SecuritySecurity operations, security engineering, or incident-response usersAccess supporting security monitoring, incidents, alerts, analysis, tickets, and permitted security administration activities
    ITIT operations, infrastructure, network, or telemetry ownersAccess supporting telemetry, integrations, collectors, monitoring, related operational tickets, and permitted IT administration activities

    Europe

    The following roles are available to tenants in Europe:

    RoleIntended usersTypical access
    Tenant AdministratorDesignated personnel responsible for portal and access administrationBroad access to supported SamurAI Portal capabilities, including user management and role assignment
    Security AdministratorUsers who require broad security operational and integration-management capabilities without administering user accessAccess to incidents, tickets, alerts, and permitted telemetry/search, plus management of integrations and collectors; excludes user and role management
    Security AnalystSecurity operations or incident response users who investigate and manage security findingsAccess to security incidents, general tickets; read-only access to integration and collector configuration
    IT TechnicianSystem and administrators responsible for setting up and troubleshooting data-source integrationsManagement of integrations and collectors, permitted telemetry and diagnostic functions
    Help Desk AnalystUsers who need to view and interact with tickets without accessing telemetryAccess to authorised tickets and their permitted workflow actions; excludes telemetry access and integration configuration
    ViewerUsers who require visibility of service information without making changesRead-only access to permitted portal features and information

    Choose the appropriate role

    Select a role based on the user’s responsibilities and the roles available.

    Japan

    User responsibilityRecommended role
    Administers the SamurAI Portal, including user access and role assignmentTenant Administrator
    Reviews permitted portal information without making changesViewer
    Coordinates service delivery, reviews service information, and works with NTT on customer activitiesTAM
    Investigates alerts and incidents, performs security analysis, or manages permitted security-related activitiesSecurity
    Maintains integrations, collectors, telemetry sources, and related IT operational activitiesIT

    Europe

    User responsibilityRecommended role
    Administers the SamurAI Portal, including user access and role assignmentTenant Administrator
    Performs security operational activities and manages integrations or collectors, without managing users or rolesSecurity Administrator
    Investigates incidents, reviews alerts, and searches permitted security data without changing integrations or collectorsSecurity Analyst
    Sets up and troubleshoots integrations and collectors, and manages related support ticketsIT Technician
    Views and interacts with authorised tickets without requiring telemetry accessHelp Desk Analyst
    Reviews permitted portal information without making changesViewer

    Assign the lowest-privilege role that allows a user to perform their responsibilities.

    For example, an engineer responsible for maintaining telemetry integrations should normally receive IT in Japan or IT Technician in Europe, rather than Tenant Administrator.

    For tenants in Europe, a user who investigates incidents but does not need to change integrations should normally receive Security Analyst, rather than Security Administrator.

    A user who only handles tickets and does not require telemetry access should receive Help Desk Analyst in Europe.

    A stakeholder who only needs to review permitted service information should normally receive Viewer in Japan or Europe.

    Review access before assigning roles

    Before assigning or changing a user’s role, review:

    • The user’s current responsibilities
    • The roles available to the tenant and the services the user needs to access
    • Whether the user needs to manage users or assign roles
    • Whether the user needs to configure integrations or collectors
    • Whether the user needs telemetry search, troubleshooting information, or only ticket access
    • Whether the user needs access to security incidents, alerts, reports, or evidence
    • Whether the user needs to create, update, close, or delete records
    • Whether the user needs to export information or perform response actions
    • Whether the user still requires SamurAI Portal access
    • Your organization’s internal access-control and approval requirements

    Review role assignments regularly and when a user changes responsibilities, changes team, stops supporting a service, or leaves your organization.

    Next steps

    • To view, invite, and manage users, see User Management.
    • To understand the capabilities available in the SamurAI Portal, see SamurAI Portal User Guide.
    • To request assistance, raise a request with the SamurAI SOC through the SamurAI Portal.