Files
prowler/docs/user-guide/tutorials/prowler-app-rbac.mdx

269 lines
12 KiB
Plaintext
Raw Permalink Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
---
title: 'Managing Users and Role-Based Access Control (RBAC)'
sidebarTitle: 'Users & RBAC'
---
import { VersionBadge } from "/snippets/version-badge.mdx"
import { AppliesTo } from "/snippets/applies-to.mdx"
<VersionBadge version="5.1.0" />
<AppliesTo />
**Prowler Cloud** supports multiple users within a single tenant, enabling seamless collaboration by allowing team members to easily share insights and manage security findings.
[Roles](#roles) help you control user permissions, determining what actions each user can perform and the data they can access within Prowler. By default, each account includes an immutable **admin** role, ensuring that your account always retains administrative access.
<Note>
If the account is created without an invitation, a new tenant will be provisioned for it. However, if the account is created through an invitation, the user will join the inviters tenant.
</Note>
## Organization
To get to User-Invitation Management we will focus on the Organization section.
<Note>
**Only users that have the _Invite and Manage Users_ or _admin_ permission can access this section.**
</Note>
<img src="/images/prowler-app/rbac/organization.png" alt="Organization tab" width="400" />
### Users
#### Editing a User
Follow these steps to edit a user of your account:
1. Navigate to **Users** from the side menu.
2. Click the edit button of the user you want to modify.
<img src="/images/prowler-app/rbac/user_edit.png" alt="Edit User" width="700" />
3. Edit the user fields you need and save your changes.
<img src="/images/prowler-app/rbac/user_edit_details.png" alt="Edit User Details" width="700" />
<Note>
Users can edit their own account details. Editing another user's account details requires the **Invite and Manage Users** or **admin** permission.
</Note>
#### Removing a User
Follow these steps to remove a user of your account:
1. Navigate to **Users** from the side menu.
2. Click the delete button of your current user.
> **Note: Each user can only delete their own account, regardless of their permissions. For this reason, the delete button is only shown on your own row and not on other users' rows.**
Deleting a user removes the **entire user account** from Prowler, not just its membership in your organization. Because a single account can belong to more than one tenant, allowing one administrator to delete it outright could affect organizations they don't manage and irreversibly remove another person's identity. To keep this destructive action under the control of the account owner, the API only permits a user to delete themselves (it rejects any other target with a `400` response), and the UI mirrors this by showing the delete button exclusively on your own row.
To remove **another** user from your organization, use the [_Expel from organization_](/user-guide/tutorials/prowler-app-multi-tenant#expelling-a-user-from-an-organization) action instead. Expelling removes the user's membership, role grants, and active sessions for your tenant only, and deletes the underlying account just for that user if your organization was their last remaining membership. This action is reserved for tenant **owners**.
<img src="/images/prowler-app/rbac/user_remove.png" alt="Remove User" width="700" />
### Invitations
#### Inviting Users
<Note>
Please be aware that at this time, an email address can only be associated with a single Prowler account_.
</Note>
Follow these steps to invite a user to your account:
1. Navigate to **Users** from the side menu.
2. Click the **Invite User** button on the top right-hand corner of the screen.
<img src="/images/prowler-app/rbac/invite.png" alt="Invite User" width="700" />
3. In the Invite User screen, enter the email address of the user you want to invite.
4. Pick a Role for the user. You can also change the roles for users and pending invites later. To learn more about the roles and what they can do, see [Roles](#roles).
<img src="/images/prowler-app/rbac/invitation_info.png" alt="Invitation info" width="700" />
5. Click the **Send Invitation** button to send the invitation to the user.
6. After clicking you will see a summary of the status of the invitation. You could access this view again from the invitation menu.
<img src="/images/prowler-app/rbac/invitation_details.png" alt="Invitation details" width="700" />
<img src="/images/prowler-app/rbac/invitation_details_1.png" alt="Invitation button" width="700" />
7. To allow the user to join your Prowler account you will need to share the link with the user. They will only need to access this URL and follow the steps to create a user and complete their registration. **Note: Invitations will expire after 7 days.**
<img src="/images/prowler-app/rbac/invitation_sign-up.png" alt="Invitation sign-up" width="700" />
<Note>
If you are a [Prowler Cloud](https://cloud.prowler.com/sign-in) user, the invited user will receive an email with the link to accept the invitation.
</Note>
#### Editing Invitation
Follow these steps to edit an invitation:
1. Navigate to **Invitations** from the side menu.
2. Click the edit button of the invitation and modify the email, the role or both. **Note: Editing an invitation will not reset its expiration time.**
<img src="/images/prowler-app/rbac/invitation_edit.png" alt="Invitation edit" width="700" />
<img src="/images/prowler-app/rbac/invitation_edit_1.png" alt="Invitation edit details" width="700" />
#### Cancelling Invitation
Follow these steps to cancel an invitation:
1. Navigate to **Invitations** from the side menu.
2. Click the revoke button of the invitation.
<img src="/images/prowler-app/rbac/invitation_revoke.png" alt="Invitation revoke" width="700" />
#### Sending an Invitation Again
To resend the invitation to the user, it is necessary to explicitly **delete the previous invitation and create a new one**.
## Managing Groups and Roles
Roles combine administrative permissions with provider visibility. Administrative permissions control the actions a role can perform. Provider Groups and Unlimited Visibility control the providers, resources, findings, scans, compliance results, and integrations the role can access.
<Note>
**Only users that have the _Manage Account_ or _admin_ permission can access this section.**
</Note>
### Provider Groups
Provider Groups limit visibility to selected providers. Assigning one or more Provider Groups to a role grants access to the providers in those groups and their resources, findings, scans, and compliance results.
New roles have no provider visibility by default. Assign at least one Provider Group or enable **Unlimited Visibility** before assigning the role to users who need access to provider data.
**Unlimited Visibility** grants organization-wide visibility across every provider, regardless of the Provider Groups assigned to the role. It does not grant administrative permissions.
#### Integration Visibility
<VersionBadge version="5.36.0" />
Integrations follow the visibility of the providers attached to them: a role can see an integration when it can access at least one of its providers, and only the providers visible to that role are listed on the integration. Editing or deleting an integration attached to providers outside the visibility of the role is not allowed. Integrations that are not attached to any provider, such as Jira, are tenant-wide and remain available to every role with the **Manage Integrations** permission.
#### Creating a Provider Group
Follow these steps to create a provider group in your account:
1. Click **Providers** in the side menu.
2. Select the **Provider Groups** tab.
3. Enter a group name in the **Create a new provider group** form.
4. Select the providers that the group controls. Optionally, select the roles that should use the group.
5. Click **Create Group**.
<img src="/images/prowler-app/rbac/provider_group.png" alt="Create a Provider Group" width="700" />
#### Editing a Provider Group
Follow these steps to edit a provider group on your account:
1. Click **Providers** in the side menu and select the **Provider Groups** tab.
2. Open the actions menu for the Provider Group and click **Edit Provider Group**.
<img src="/images/prowler-app/rbac/provider_group_edit.png" alt="Edit Provider Group action" width="300" />
3. Update the group name, providers, or roles, and save the changes.
<img src="/images/prowler-app/rbac/provider_group_edit_1.png" alt="Edit Provider Group form" width="700" />
#### Removing a Provider Group
Follow these steps to remove a provider group from your account:
1. Click **Providers** in the side menu and select the **Provider Groups** tab.
2. Open the actions menu for the Provider Group and click **Delete Provider Group**.
3. Confirm the deletion.
<img src="/images/prowler-app/rbac/provider_group_remove.png" alt="Delete Provider Group confirmation" width="700" />
### Roles
#### Creating a Role
Follow these steps to create a role for your account:
1. Navigate to **Roles** from the side menu.
2. Click **Add Role**.
3. Enter the role name and select the required administrative permissions.
4. Configure **Visibility**:
- To grant organization-wide visibility, select **Enable Unlimited Visibility for this role**.
- To limit visibility, leave Unlimited Visibility cleared and select one or more Provider Groups.
<img src="/images/prowler-app/rbac/role_create_1.png" alt="Role parameters" width="700" />
5. Click **Add Role**.
<Note>
To grant read-only access across the organization, enable **Unlimited Visibility** without selecting administrative permissions. Then, assign the role from the **Users** page.
</Note>
#### Editing a Role
Follow these steps to edit a role on your account:
1. Navigate to **Roles** from the side menu.
2. Open the actions menu for the role and click **Edit Role**.
3. Update the role name, administrative permissions, Unlimited Visibility setting, or Provider Groups.
4. Save the changes.
#### Removing a Role
Follow these steps to remove a role from your account:
1. Navigate to **Roles** from the side menu.
2. Open the actions menu for the role and click **Delete Role**.
3. Confirm the deletion.
## RBAC Administrative Permissions
Assign administrative permissions by selecting from the following options:
| Permission | Scope | Description |
|------------|-------|-------------|
| Invite and Manage Users | All | Invite new users and manage existing ones. |
| Manage Account | All | Adjust account settings, delete users and read/manage users permissions. |
| Manage Scans | All | Run and review scans, and manage [Scan Configuration](/user-guide/tutorials/prowler-app-scan-configuration) settings. |
| Manage Providers | All | Add or modify connected providers, and attach or detach providers from a [Scan Configuration](/user-guide/tutorials/prowler-app-scan-configuration) (in addition to Manage Scans). |
| Manage Integrations | All | Add or modify the Prowler Integrations. |
| Manage Ingestions | Prowler Cloud | Allow or deny the ability to submit findings ingestion batches via the API. |
| Manage Billing | Prowler Cloud | Access and manage billing settings and subscription information. |
| Manage Alerts | Prowler Cloud | Create, edit, and delete alert rules and recipients. |
<Note>
The **Scope** column indicates where each permission applies. **All** means the permission is available in both Prowler Cloud and Self-Managed deployments. **Prowler Cloud** indicates permissions that are specific to [Prowler Cloud](https://cloud.prowler.com/sign-in).
</Note>
To grant all administrative permissions, select the **Grant all admin permissions** option.
### Prowler Cloud exclusive permissions
The following permissions are available exclusively in **Prowler Cloud**:
**Manage Ingestions:** Submit and manage findings ingestion jobs via the API. Required to upload OCSF scan results using the `--push-to-cloud` CLI flag or the ingestion endpoints. See [Import Findings](/user-guide/tutorials/prowler-import-findings) for details.
**Manage Billing:** Access and manage billing settings, subscription plans, and payment methods.
**Manage Alerts:** Create, edit, and delete alert rules and recipients used to deliver scan-result digests via email.