User roles and permissions.
Liberty91 has four user roles: Viewer, Analyst, Admin, and Owner. Each role builds on the one before it, adding more capability. Viewers read, Analysts do the day-to-day intelligence work, Admins manage users and templates, and Owners control the subscription. The first user on an account is the Owner. You assign a role when you invite a member, and you can change it later from the Members area of your Organization Profile.
The four roles
Viewer
Viewers have read-only access. They can see Events, Threat Events, entity cards in the Threat Library, reports, and dashboards, but they cannot generate reports or act on Enrichment Opportunities, and they cannot change any data.
Analyst
Analyst is the most common role. Analysts can use all of the analysis features of the platform. They can generate reports, modify Organizations by uploading or removing Documents and Stakeholders, set up Alerts, and edit and send reports.
Analysts also hold the tradecraft judgements the automatic pipeline will not make on its own. They set a Threat Event's verification stage to verified, disputed, or rejected, and they discredit a source that has been caught out. Both stick: once an analyst has made the call, automatic processing does not overwrite it.
Admin
Admins can do everything an Analyst can do. On top of that, they can invite, change, and remove other users, and they can change the email templates and report templates that go out to Users and Stakeholders.
Owner
Owners can do everything an Admin can do, plus make subscription changes for the account. The first user on an account is the Owner.
Permission matrix
The table below lists each capability against the role that has it. A check means the role has the capability, a dash means it does not.
| Capability | Viewer | Analyst | Admin | Owner |
|---|---|---|---|---|
| View Events, Threat Library entries, reports, and dashboards | ✓ | ✓ | ✓ | ✓ |
| Run analysis on the platform | ✓ | ✓ | ✓ | ✓ |
| Generate reports | ✗ | ✓ | ✓ | ✓ |
| Upload or remove Documents and Stakeholders | ✗ | ✓ | ✓ | ✓ |
| Set up Alerts | ✗ | ✓ | ✓ | ✓ |
| Edit and send reports | ✗ | ✓ | ✓ | ✓ |
| Verify, dispute, or reject a Threat Event | ✗ | ✓ | ✓ | ✓ |
| Discredit a source | ✗ | ✓ | ✓ | ✓ |
| Invite, change, or remove users | ✗ | ✗ | ✓ | ✓ |
| Change email and report templates | ✗ | ✗ | ✓ | ✓ |
| Make subscription changes | ✗ | ✗ | ✗ | ✓ |
Viewers can run and view analysis, but they cannot save the results as reports. If a team member needs to produce intelligence products, give them at least the Analyst role.
Managing roles
You invite members and set or change their roles from the Members area of your Organization Profile, reached through your avatar in the top-right corner. For the step-by-step walkthrough of inviting a member and choosing a role, see Users and roles.
Frequently asked questions
What are the four Liberty91 roles?
Viewer, Analyst, Admin, and Owner. Each builds on the one before it: Viewers read, Analysts do the day-to-day intelligence work, Admins manage users and templates, and Owners control the subscription.
Who can verify, dispute, or reject a Threat Event?
Analysts and above. Those verification stages are deliberate analyst judgements, and once set the automatic pipeline never overwrites them.
Can a Viewer generate a report?
No. Viewers can run and view analysis but cannot save the results as reports. Anyone who needs to produce intelligence products needs at least the Analyst role.