Skip to main content

Role-Based Access Control (RBAC)

KoreShield provides a built-in RBAC system for managing who can access what within your deployment. RBAC is managed through the dashboard for hosted customers.

Built-in Roles

RoleDescription
ownerFull access, can manage all resources
adminAdministrative access, can manage users and config
editorCan modify rules, policies, and configurations
viewerRead-only access to dashboards and reports
security_analystAccess to security events, alerts, and analytics

Permission Categories

Permissions are organized by category:

  • security: view threats, manage rules, configure detection
  • management: manage users, roles, API keys
  • analytics: view dashboards, run reports
  • system: server configuration, provider management

User Statuses

  • active: user can log in and access resources
  • inactive: user account is disabled
  • pending: user has been invited but has not accepted