Managing Users, Roles, and their Permissions

Avanan allows administrators to create custom roles to support their company's minimal permissions policy and provides a set of default roles in the Avanan Administrator Portal.

Note:

Only users assigned as Admin can add users, delete users and modify their permissions.

Default Roles

Avanan includes these default roles:

Role SaaS Applications SaaS Applications and Security Engines Policy Rules Custom Queries Events, Quarantine, and Exceptions Sensitive Data *
Admin View and connect or disconnect View and configure View and configure View, edit, and take actions View, edit, and take actions Cannot view (explicit permissions required)
Read-Only Cannot view Cannot view Cannot view View only View only Cannot view (explicit permissions required)
Operations Cannot view Cannot view Cannot view View and edit (no actions) View and take actions Cannot view (explicit permissions required)
User View and connect or disconnect View and configure View and configure View, edit, and take actions View, edit, and take actions Cannot view (explicit permissions required)
Note:

The User role has the same permissions as the Admin role, but it cannot access the User Management page. A user with this role cannot assign the Admin role itself or grant permissions to other users.

Custom Roles

Avanan allows administrators to create custom roles, so that different departments and individuals can view and perform only the actions permitted according to company policy.

Creating and Editing a Custom Role

To create a new custom role:

  1. Access the Avanan Administrator Portal.

  2. Go to System Settings > Roles.

  3. Click Add New Role or select an existing role to clone it.

  4. In the Name field, enter the desired name.

  5. In the Description field, enter the description.

  6. In the Permissions section, select the required permissions. See Custom Roles - Configurable Permissions.

  7. Click Save.

To edit a custom role:

  1. Go to System Settings > Roles.

  2. Select the existing role you want to edit and click the three-dot menu.

  3. In the Edit Role page, modify the required fields and permissions. See Custom Roles - Configurable Permissions.

  4. Click Save.

Custom Roles - Configurable Permissions

Avanan allows you to create custom roles by defining access permissions for various interface pages and managing access to additional features such as notifications and sensitive data.

Permissions for Interface Pages

Avanan allows you to configure access levels for various interface pages while defining a custom role using the following options:

  1. Hidden - Hides the page from the user.

  2. View - Allows the user to only view the page and export data, but cannot take actions on events, emails, or files etc.

  3. View and Actions - Allows the user to perform any available actions in the page.

Note:

Some actions are available from multiple interface pages. For example:

  • Users can quarantine an email from both User Interaction > Phishing Reports and Events page.

  • If a user has only View permission to the User Interaction > Phishing Reports, they cannot quarantine emails from that page.

  • If a user has View and Actions permission for Events page, they can quarantine emails from that page.

You can configure user access to the following sections in the interface:

Interface Page Description Available Settings
Overview Access to the Overview page Hidden, View, View and Actions
Events Access to the Events page Hidden, View, View and Actions
Entity Pages Access to entity pages, including details of emails, files, attachments, messages, and users.
  • Hidden

  • View only with detections (user can view sensitive data only when the system detects a malicious entity or a DLP leak)

  • View also without detections

Sensitive Data Access to sensitive data, including email bodies, downloading emails as EML files, shared files, sent messages, and viewing strings flagged as DLP violations.
Mail Explorer and Custom Queries Access to Mail Explorer and Custom Queries Hidden, View, View and Actions
User Interaction
Dashboard Access to the Dashboard page Hidden, View, View and Actions
Restore Requests Access to the Restore Requests page Hidden, View, View and Actions
Phishing Reports Access to the Phishing Reports page Hidden, View, View and Actions
Quarantined Items Access to the Quarantined Items page Hidden, View, View and Actions
Modified Attachments Access to the Modified Attachments page Hidden, View, View and Actions
Smart Banners Access to the Smart Banners page Hidden, View, View and Actions
Misdirected Emails Access to the Misdirected Emails Hidden, View, View and Actions
Analytics
Dashboard Access to the Dashboard page Hidden, View, View and Actions
Partner Risk Access to the Partner Risk page Hidden, View, View and Actions
Shadow IT Access to the Shadow IT page Hidden, View, View and Actions
Security Checkup Access to the Security Checkup page Hidden, View, View and Actions
Report Scheduler Access to the Report Scheduler page Hidden, View, View and Actions
Summary Report Access to the Summary Report page Hidden, View, View and Actions
Periodic Reports Access to the Periodic Reports page Hidden, View, View and Actions
Deliverability Access to the Deliverability page Hidden, View, View and Actions
Security Training
Dashboard Access to the Dashboard page
  • Hidden

  • View

  • View and export

  • View, export and import

Policy Access to the Policy page
  • Hidden

  • View

  • View and export

  • View, export and import

Leaked Credentials Access to the Leaked Credentials page Hidden, View, View and Actions
DMARC Access to the DMARC page Hidden, View, View and Actions
Policy Access to the Policy page Hidden, View, View and Actions
Security Settings
SaaS Applications Access to the SaaS Applications page Hidden, View, View and Actions
Security Engines Access to the Security Engines page Hidden, View, View and Actions
DLP Data Types Access to the DLP Data Types page Hidden, View, View and Actions
Security Exceptions Access to the Security Exceptions page Hidden, View, View and Actions
User Interaction Settings Access to the User Interaction Settings page Hidden, View, View and Actions
System Settings
Roles Access to the Roles page Hidden, View, View and Actions
Others - all other pages under System Settings Access to all other System Settings pages Hidden, View, View and Actions

Permissions for Notification Settings

Avanan allows you to configure the following settings in the Notifications section while defining a custom role:

Permission Description Available Settings
Overview User receives notifications from the system.
  • Receive

  • Do not receive

Events

User receives alerts from the system.

Note:

Even when this role is applied, the user receives email alerts for security events only when Send alerts to admins is selected in the policy.

  • Receive

  • Do not receive

Checkup report User receives scheduled Security Checkup reports.
  • Receive

  • Do not receive

Assigning Roles to Users

Avanan allows you to assign roles to individual users from the User Management page.

For more information, see User Management and Adding a New User.

Multiple Roles Assigned to a User

Each user can be assigned multiple roles. In this case, within Avanan, the user is granted the highest level of permissions from all assigned roles.

Example: A user is assigned two custom roles, Custom Role 1 and Custom Role 2. If Custom Role 1 allows performing actions on the Events page and Custom Role 2 hides the Events page, the user sees the Events page and can perform actions on it.