Getting Started with Role Based Access Control
Learn how to control user access and permissions in LogScale
New to RBAC?
Begin with RBAC concepts, understand permission scopes and hierarchy, learn how users, groups, and roles work together, and build a strong foundation before configuring access controls. Perfect for those new to role-based access control.
- What is RBAC?
- Permission Scopes and Hierarchy
- Users, Groups, and Roles
- Authorization Model
Ready to Configure RBAC?
You understand RBAC concepts and are ready to configure access controls. Jump into creating roles, managing groups, assigning permissions, and implementing best practices for real-world scenarios.
- Creating Roles and Groups
- Assigning Permissions
- Identity Provider Integration
- Troubleshooting Access Issues
Workflow 1: New to RBAC?
Learn the fundamentals of role-based access control step by step. Understanding these concepts makes configuring permissions intuitive and secure.
Understanding the Foundation
Grasp the RBAC model and how authorization works in LogScale
What is RBAC?
conceptbeginnerUnderstand the difference between authentication (who you are) and authorization (what you can do). Learn about the four permission scopes: Cluster, Organization, Repository/View, and Asset.
The Building Blocks
guideintermediateUnderstand Users (individual people), Groups (collections of users), Roles (named sets of permissions), and Permissions (specific capabilities).
Understand Permission Levels
Learn about cluster, orgnaization, and repository permissions and the differences between them
Organization and Cluster Permissions
guideintermediateLearn how organization-level and cluster-level permissions work. Cluster permissions apply only to self-hosted environments.
Repository and View Permissions
guideintermediateUnderstand repository and view permissions. Learn about the four permission levels and how permissions are NOT inherited between scopes.
Permission Strategy Patterns
guideintermediateApply the principle of least privilege, choose between group-based versus direct assignment strategies, establish role naming conventions, and plan for multi-tenant scenarios.
How Asset Permissions Work
Learn how to share dashboards, queries, alerts, and other assets
Troubleshooting and Reference
Resources to diagnose and fix permission issues
Permissions by Functionality
guideintermediateReference guide showing which permissions are needed for specific LogScale functionality.
Permissions by Name
guideintermediateAlphabetical reference of all available permissions and what they grant access to.
Audit Log for User Activity
troubleshootingintermediateUse the humio-audit repository to track user actions, role changes, group modifications, and permission grants. Essential for security auditing and troubleshooting access issues.
Workflow 2: Ready to Configure RBAC?
Implement role-based access control in this logical progression from creating components to troubleshooting issues.
RBAC Quick Start
Get a rapid overview and jump into configuration
RBAC Overview
conceptintermediateQuick reference: permission scopes, default roles, and the relationship between users, groups, and roles.
RBAC Building Blocks
guideintermediateUnderstand users, groups, roles, and permissions before you configure them.
Permission Strategy Patterns
guideintermediateApply the principle of least privilege, choose group-based versus direct assignment, establish role naming conventions, and plan for multi-tenant scenarios.
Creating Roles
Build custom and default roles with specific permissions
Manage Roles
guideintermediateCreate custom roles, and assign granular permissions.
Edit Role Permissions
guideintermediateModify permissions for existing roles to match your organization's needs.
Default Roles
guideintermediateLearn about Reader, Admin, Member, and Deleter default roles and their predefined permissions.
Managing Groups
Create and manage groups for organizing users, and connect roles to groups with default permissions and exceptions
Manage Groups
guideintermediateCreate groups manually, configure group properties, and establish naming conventions.
Add Users to Groups
guideintermediateManually add users to groups to grant them the group's permissions.
Query Prefix
guideintermediateAutomatically prepend filters to user queries based on group membership to restrict data access.
Repository Exceptions
guideintermediateCreate exceptions where a group has different roles in specific repositories.
Managing Users
Add and configure user accounts, and directly assign roles to individual users when needed
Manage Users
guideintermediateAdd users manually, configure auto-creation settings, and edit user properties.
Assign Roles to Users
guideintermediateDirectly assign roles to individual users when group-based assignment is not appropriate. Understand when to use direct assignment versus group membership.
Aggregate Permissions
guideintermediateView all permissions a user has across multiple assigned roles to understand their total access.
Sharing Assets
Grant access to dashboards, queries, alerts, and actions
Identity Provider Integration
Automate user and group management
Group Memberships
guideintermediateUnderstand how group membership works with manual assignment and identity provider synchronization.
Group Synchronization
guideintermediateAutomate group membership based on identity provider group membership. Configure one-to-many group mapping strategies for SAML and LDAP.
Reference and Troubleshooting
Find permissions and diagnose issues
Repository and View Permissions
guideintermediateComplete reference of all repository and view permissions with descriptions.
Organization Permissions
guideintermediateComplete reference of all organization-level permissions with descriptions.
Cluster Permissions
guideintermediateFor self-hosted: Complete reference of all cluster-level permissions with descriptions.
Permissions by Functionality
guideintermediateFind which permissions are needed for specific LogScale features and functionality.
Permissions by Name
guideintermediateAlphabetical reference of all available permissions and what they control.
Audit Log for User Activity
troubleshootingintermediateUse the humio-audit repository to track user actions, role changes, group modifications, and permission grants. Essential for security auditing and troubleshooting access issues.