Article

    help.nightfall.ai / nightfall_settings / role_based_access_control / security_events_manager.md

    4 min read
    Last updated 1 month ago

    For the complete documentation index, see llms.txt. Markdown versions of documentation pages are available by appending .md to page URLs; this page is available as Markdown.

    Security Events Manager Role

    The Security Events Manager role allows users to view Dashboard, generate reports from Dashboards, view DLP violations, view exfiltration and posture management events, and view detectors.

    The Nightfall app view for a user with this role is as shown in the following image.

    <figure><!--kb:media-unavailable--><figcaption></figcaption></figure>

    Permissions Associated with Security Events Manager Role

    A user with Security Events Manager Role has the following permissions.

    View Dashboard and Create Reports

    With the Dashboard and Reporting permissions, users to view data on the Dashboard, apply filters to the dashboard data, and also generate reports from the Dashboard data.

    <figure><!--kb:media-unavailable--><figcaption></figcaption></figure>

    Take Actions on DLP Violations

    With the DLP Violations permission, users can take appropriate actions on the DLP violations. They can also share the violation data and export it as a CSV file.

    <figure><!--kb:media-unavailable--><figcaption></figcaption></figure>

    View the DLP Violations Content

    With the Content Preview permission, users can preview the content of the DLP Violations page. The sensitive data is not redacted for this role.

    <figure><!--kb:media-unavailable--><figcaption></figcaption></figure>

    {% hint style="info" %}

    1. The main point of difference between the Security analyst role and the Security events manager role is that users with the Security analyst role can view redacted content of DLP violations page.However, content is not redacted for the Security Events manager role.
    2. The common feature between a user with Security analyst role and a user with Security events manager role is that the download button on the Events detail view page is active for both. However, they cannot downlaod files containing sensitive data. {% endhint %}

    Exfiltration/Posture Management and Encryption Events

    With the Exfiltration permission, users can filter event data, share event data, view historic events data, and take actions on Posture management, Exfiltration, and encryption events.

    <figure><!--kb:media-unavailable--><figcaption></figcaption></figure>

    View Detectors

    With the Detectors permission, users can view all the detectors, view detectors that belong to a specific category, filter the list of detectors, search a detector, and copy the UUID of a detector.

    <figure><!--kb:media-unavailable--><figcaption></figcaption></figure>

    Agent Instructions

    This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

    Querying This Documentation

    If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

    Perform an HTTP GET request on the current page URL with the ask query parameter, and the optional goal query parameter:

    GET https://help.nightfall.ai/nightfall_settings/role_based_access_control/security_events_manager.md?ask=<question>&goal=<endgoal>
    

    ask is the immediate question: it should be specific, self-contained, and written in natural language. goal is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

    The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

    Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.