Role-Based Access Control (RBAC)

Sublime's built-in and custom roles make it easy to give your team the perfect amount of access.

Managing Roles

When you create a new user from the Admin > Account page, you'll have the option to select a role.

To change an existing user's role, select the user in the Users table, select Actions > Edit, and update the user's role.

Roles

RoleDescription
AdminAll Sublime features, including the ability to create custom roles.
EngineerBuild detection rules, Backtest, Hunt, investigate and remediate flagged and user reported messages, view system error notifications, and more.
AnalystInvestigate and remediate flagged and user reported messages, view system error notifications. Cannot create or modify rules, Search, Backtest, or Hunt.
CustomAnyone with the Admin role can create a custom role with granular permissions.

The below table enumerates the Sublime Platform permissions and denotes which role contains it. A green check ✅ denotes that the permission is included in the role. A green check with an asterisk ✅* denotes that the role has the listed permission, but can only operate on resources that the current user has created themselves (e.g. an Engineer can only read API keys that were created by themselves, whereas an Admin can read API keys regardless of which user they were created by).

CategoryPermissionAdminEngineerAnalyst
Audit Logmanage_audit_log✅
Audit Logread_audit_log✅
IP Allowlistmanage_ip_allowlist✅
IP Allowlistread_ip_allowlist✅✅✅
MDM Retentionupdate_full_message_retention✅
Mailbox Auto-Activationread_auto_activate✅✅✅
Mailbox Auto-Activationupdate_auto_activate✅
Abuse Mailbox Settingsmanage_abuse_mailbox✅✅
Abuse Mailbox Settingsread_abuse_mailbox✅✅✅
API Keyscreate_api_keys✅✅*✅*
API Keysread_api_keys✅✅*✅*
API Keysdelete_api_keys✅✅*✅*
API Keysset_external_api_keys✅✅*
API Keysread_external_api_keys✅✅*
Userscreate_users✅
Usersread_users✅✅✅
Usersupdate_users✅
Usersdelete_users✅
Usersinvite_users✅
Message Sourcescreate_message_sources✅
Message Sourcesread_message_sources✅✅✅
Message Sourcesupdate_message_sources✅
Message Sourcesdelete_message_sources✅
Mailboxesread_mailboxes✅✅✅
Mailboxesactivate_mailbox✅
Mailboxesdeactivate_mailbox✅
Detection Rulescreate_rules✅✅
Detection Rulesread_rules✅✅✅
Detection Rulesupdate_rules✅✅
Detection Rulesdelete_rules✅✅
Detection Rulesassociate_rules_to_actions✅✅
DLP Rulescreate_dlp_rules✅✅
DLP Rulesread_dlp_rules✅✅✅
DLP Rulesupdate_dlp_rules✅✅
DLP Rulesdelete_dlp_rules✅✅
DLP Rulesassociate_dlp_rules_to_actions✅✅
DLPmanage_dlp✅
DLPmanage_dlp_alerts✅
Automationscreate_automations✅✅
Automationsread_automations✅✅✅
Automationsupdate_automations✅✅
Automationsdelete_automations✅✅
Automationsassociate_automations_to_actions✅✅
Listscreate_lists✅✅
Listsread_lists✅✅✅
Listsupdate_lists✅✅✅
Listsdelete_lists✅✅
Listsupdate_system_list_overrides✅✅
Actionscreate_actions✅✅
Actionsread_actions✅✅✅
Actionsupdate_actions✅✅
Actionsdelete_actions✅✅
Actionsupload_logo_image✅
Actionsuse_crowdstrike_sandbox✅
Feedscreate_feeds✅✅
Feedsread_feeds✅✅✅
Feedsupdate_feeds✅✅
Feedsdelete_feeds✅✅
Backtestbacktest✅✅
Hunthunt✅✅
Huntprivate_hunt✅
Searchsearch✅✅
Investigationaccess_unflagged_message_contents✅✅
Investigationaccess_dlp_flagged_message_contents✅✅
Investigationaccess_flagged_message_contents✅✅✅
Investigationaccess_user_reported_message_contents✅✅✅
Investigationcreate_email_bomb✅✅
Investigationread_email_bomb✅✅✅
Remediationperform_actions✅✅✅
Error Logaccess_error_logs✅✅✅
URL Defenseread_url_defense_settings✅
URL Defensemanage_url_defense_settings✅
Content viewing settingmanage_view_contents_requirements✅
OIDC settingmanage_oidc✅
OIDC settingread_oidc✅✅✅
SCIMread_scim_resources✅✅✅
Provider groupread_provider_groups✅✅✅
Provider groupupdate_provider_groups✅✅✅
Exclusionscreate_exclusions✅
Exclusionsread_exclusions✅✅✅
Exclusionsupdate_exclusions✅
Exclusionsdelete_exclusions✅
Historical ingestionstart_historical_ingestion_jobs✅
Historical ingestionabandon_historical_ingestion_jobs✅
Historical ingestionread_historical_ingestion_jobs✅✅✅
Rolesread_roles✅✅✅
Rolesset_delegated_user_default_role✅
Rolescan_access_child_orgs✅
Telemetrymanage_telemetry✅
Deletiondelete_org✅
Polling settingmanage_message_polling✅
Overview Reportread_org_stats✅✅✅
Overview Reportread_remediation_stats✅✅✅
Link Analysis clicksread_link_clicks✅
S3 exportmanage_message_export✅
Setup guidemanage_account_setup_guide✅
Message creationcreate_new_message✅✅✅
Quarantine Digestsread_quarantine_digest_configs✅✅✅
Quarantine Digestsmanage_quarantine_digest_configs✅
Quarantine Digestsread_quarantine_digest_release_requests✅✅✅
Quarantine Digestsmanage_quarantine_digest_release_requests✅✅✅
ASAmanage_asa✅✅
ADÉread_ade✅✅✅
ADÉmanage_ade✅✅✅
Inline Protectionmanage_inline_processing✅
Inline Protectionmanage_inline_alerts✅
Inline Protectionwrite_inline_message_meta✅
Inline Protectionread_message_sources_inline_message_meta✅
Graymail User Preferencesmanage_folder_routing✅
Phishing Simulations (Beta)manage_phishing_sims✅
Phishing Simulations (Beta)read_phishing_sims✅
📘

API Key Permissions

API keys reflect the RBAC permissions of the creating user at the time the key was generated.

Custom roles

You can create an unlimited number of custom roles within your organization by heading to Admin > Account and clicking Create Role.

Multi-tenant custom roles

For multi-tenant instances, custom roles can only be created or managed by the parent org. While Admins can assign custom roles to team members on any child org, they can't create new roles or edit the permissions on existing roles via the child org.

Team members who have access to the parent org will inherit their existing role when they log into the child org for the first time. Admins can change their role afterwards if they want that team member to have a different role on a specific child org.

All custom roles created by the parent org are available to all of the child orgs, so we recommend that custom role names don't include child org information, such as business names. You can alternatively limit anyone with a custom role from seeing available roles by withholding the read_roles permission.

Additionally, multi-tenant environments include permissions that control user propagation and cross-org access. The set_delegated_user_default_role permission defines the default role assigned when users are automatically propagated to child orgs, while can_access_child_orgs controls whether a user can access child and descendant orgs. Users without the can_access_child_orgs permission will still appear in child orgs but will be shown in a disabled state indicating they cannot access the org.