1. The Transition to Role-Based Logic
To ensure maximum platform stability and enforce security best practices, COGNNA has transitioned from granular, individual user permissions to a streamlined, predefined Role-Based logic.
- Principle of Least Privilege: During this transition, user permissions are mapped to their closest predefined role. We ensure no user loses their core functional capabilities, but permissions are "rounded down" where appropriate to enforce the principle of least privilege.
- Predefined Roles Prioritized: To guarantee consistent security baselines across all organizations, the system currently utilizes strict predefined roles rather than highly customized granular checklists.
2. Platform Hierarchy Model
The system enforces a hierarchical inheritance model to ensure data isolation. Users belong to exactly one tenant. MSSP users access Client Tenants via Delegated Administration rather than holding separate accounts in every tenant.

3. Predefined Roles
The platform includes four immutable roles. The permissions for these roles are standard across all tenants.
- Administrator: Full access to all features, user management, and integrations. (Best for: Systems Administrators, Partner/Product Support).
- Responder: Investigates detections and hunts threats, with the critical privilege to take remote response actions on assets. Cannot manage users. (Best for: Incident Response, SecOps).
- Analyst: Investigates detections and recommends actions. Cannot take remote response actions or manage users. (Best for: Security Analysts).
- Auditor: Read-only access. Can create searches and reports but cannot modify data. (Best for: Customer Success Managers).
4. Managing User Roles (UI Updates)
The interface for managing user access has been updated to reflect the new role-based architecture.
Creating and Editing Users
When Administrators navigate to Settings > Manage Users to add a new user or edit an existing one (via the pen icon), they will experience a streamlined workflow:
- Role Dropdown: The legacy 'User Permissions' checklist has been entirely removed. It is replaced by a mandatory Role dropdown menu containing the four predefined roles. Role changes apply instantly to the user's capabilities.
- Permissions Matrix Link: Next to the Role dropdown, Administrators can click "View Role Permissions Matrix" to open a detailed PDF in a new tab, outlining exact privileges before making an assignment.
Viewing Your Assigned Role
All users can verify their current access level by navigating to Settings > My Profile. Your profile now displays your assigned Role alongside your standard user information, as well as a link to view the Permissions Matrix.
5. System Safeguards and Governance
To maintain a secure environment, the platform enforces strict governance rules regarding role assignments and privilege management:
- Privilege Escalation Boundaries (Ceiling Logic): Administrators cannot assign a role with privileges higher than their own, nor can they elevate their own privileges.
- High-Risk Awareness: When an Administrator promotes a user to a higher-privilege role, the system will prompt a confirmation to highlight the security implications of the escalation.
- (Upcoming) Bulk Editing: Future updates will allow Tenant Administrators to select multiple users and apply a "Change Role" action simultaneously to streamline organizational restructuring.
- (Upcoming) Custom Roles: Administrators will have the ability to build Custom Roles to tailor granular access to their team's specific operational needs.
6. Detailed Permission Matrix
The following matrix defines the baseline access rights for the four predefined roles based on the platform's supported user permissions.
Permission Key
- Full Access: View/Access, Edit, Add, Delete
- View only: View/Access only
- None: No access granted


