Skip to main content
For the list of built-in roles, see Built-in User Roles. xorlab defines the concepts of Roles, Permissions and Scopes:
  • A Permission denotes a specific action bound to a specific Scope. Example: Releasing an email from the quarantine.
  • A Scope limits a permission to a specific context. Example: Releasing an email is only allowed for a specific tenant.
  • A Role is a set of Scopes with Permissions. If needed, Roles can be arbitrarily composed and assigned to users.
Only roles can be assigned to users.

Create a new role

  1. Open the file xcc.yml in the Expert Editor.
  2. Add the name and permissions of the new role to roleToPermissionMappings. You can find all permissions below at Permissions-role matrix or Start from a built-in role.
    xcc.yml
Hint: You can query your current permissions as described here.
A custom role for SSQ users is not supported. It is required to use the built-in role xcc_quarantine_user. If you need to adjust the available permissions for your SSQ users, contact support@xorlab.com.

Start from a built-in role

Rather than assembling a role permission by permission, copy the full set of a built-in role and remove what you do not need. Each block below is the complete permission list of one built-in role, ready to paste into roleToPermissionMappings. Rename my_custom_role first — a custom role must not reuse a built-in role name.
xcc.yml
xcc.yml
xcc.yml
xcc.yml
xcc.yml
xcc.yml
xcc.yml
xcc.yml

Set the permission scope

Optional: you can restrict the permission scope with the following syntax. If you omit the scope, the permission will have global scope.
Examples: When you finish editing roleToPermissionMappings in xcc.yml, click Publish. The role mapping becomes active within about one minute.

Permissions-role matrix

This table shows whether a specific built-in role has a Permission or not and if so with what Scope.
  • Table entry global means that the role has unrestricted access for a specific permission.
  • Table entry tenant:primary means that the role has access for a specific permission but only within the bounds of the current user’s tenant.
  • Table entry based on <flag> means that the role has access only within the user’s own tenant, to the quarantined emails of their own addresses, and only where that flag is enabled for the quarantine in guarded_tenants.yml.
  • A missing table entry indicates that the role does not have that permission at all.
Show roles
Permissionxcc_adminxcc_admin_auditxcc_analystxcc_analyst_auditxcc_tenant_analystxcc_tenant_analyst_auditxcc_insightsxcc_monitorxcc_quarantine_user
config_service_readglobalglobal
Allows reading of configuration file from the config service in Expert Editor
config_service_writeglobal
Allows editing of a configuration file in the config service in Expert Editor
xcc_analyst_portalglobalglobalglobalglobalglobalglobal
Allows general access to the main analyst UI
xcc_api_key_createglobal
Allows creation of new API keys.
xcc_api_key_deleteglobal
Allows deletion of API keys.
xcc_api_key_fetchglobal
Allows listing API keys.
xcc_asset_fetchglobalglobalglobalglobaltenant:primarytenant:primarybased on canView
Allows retrieving analysis artifacts of messages, reported emails, and uploaded files
xcc_backup_info_fetchglobalglobal
Allows access to information about the current backup status
xcc_backup_triggerglobal
Allows manually triggering of a backup
xcc_campaign_addglobalglobaltenant:primary
Allows creation of a new campaign
xcc_campaign_archiveglobalglobaltenant:primary
Allows archiving of a campaign
xcc_campaign_fetchglobalglobalglobalglobaltenant:primarytenant:primary
Allows retrieval of the campaigns
xcc_campaign_removeglobalglobaltenant:primary
Allows removal of a campaign
xcc_campaign_updateglobalglobaltenant:primary
Allows update of existing campaigns
xcc_config_m365_credentialsglobal
Allows managing (setting or clearing) stored credentials for Microsoft 365 integrations
xcc_core_result_deleteglobal
Allows to delete a result from xcc
xcc_file_uploadglobalglobalglobal
Allows uploading files for analysis
xcc_incident_isolateglobalglobaltenant:primary
Allows isolation of one or multiple messages
xcc_incident_resolveglobalglobaltenant:primary
Allows resolving one or multiple incidents
xcc_loginglobalglobalglobalglobalglobalglobalglobal
Allows performing a login from the UI
xcc_mail_import_readglobalglobaltenant:primary
Allows reading of mail imports
xcc_mail_import_updateglobal
Allows updating/managing of mail imports
xcc_quarantine_archiveglobalglobaltenant:primarybased on canView
Allows archiving of a quarantined message.
xcc_quarantine_releaseglobalglobaltenant:primarybased on canRelease
Allows the release of one or more quarantined messages
xcc_quarantine_release_request_createglobalglobaltenant:primarybased on canRequestRelease
Allows creating a release request for one or more quarantined messages
xcc_quarantine_release_request_resolveglobalglobaltenant:primary
Allows resolving a message which has been requested to be released either by approving or denying the request.
xcc_result_detail_dana_screenshotsglobalglobalglobalglobaltenant:primarytenant:primarybased on canView
Allows viewing of screenshots and videos from the dynamic analysis (if available)
xcc_result_detail_fetchglobalglobalglobalglobaltenant:primarytenant:primarybased on canView
Allows view of the email details
xcc_result_detail_previewglobalglobalglobalglobaltenant:primarytenant:primarybased on canView
Allows viewing of email previews (if available)
xcc_result_detail_unlockglobalglobaltenant:primarybased on canUnlock
Allows unlocking of emails with encrypted attachments (Attachment Airlock)
xcc_result_list_fetchglobalglobalglobalglobaltenant:primarytenant:primarybased on canView
Allows view of search query results (e.g., the Messages overview)
xcc_result_query_checkglobalglobalglobalglobalglobalglobalglobal
Internal permission required for all roles
xcc_result_report_log_addglobalglobaltenant:primary
Allows to add a new message to the report log
xcc_result_report_log_fetchglobalglobalglobalglobaltenant:primarytenant:primary
Allows viewing of the case log
xcc_rule_list_addglobalglobaltenant:primary
Allows addition of entries on black- and whitelists
xcc_rule_list_fetchglobalglobalglobalglobaltenant:primarytenant:primary
Allows retrieval of black- and whitelists
xcc_rule_list_removeglobalglobaltenant:primary
Allows removal of entries of rule lists
xcc_rule_list_updateglobalglobaltenant:primary
Allows editing of black- and whitelists
xcc_search_addglobalglobaltenant:primary
Allows creation of a new saved query
xcc_search_fetchglobalglobalglobalglobaltenant:primarytenant:primary
Allows retrieval of the saved queries
xcc_search_removeglobalglobaltenant:primary
Allows removal of existing saved queries
xcc_search_updateglobalglobaltenant:primary
Allows update of existing saved queries
xcc_share_misclassificationglobalglobaltenant:primary
Allows submission of misclassification reports
xcc_sidebar_file_uploadglobalglobalglobalglobalglobalglobal
Allows access to the list of files uploaded using the File Upload menu item
xcc_sidebar_insightsglobal
Allows access to the Insights menu item
Note: To access the actual dashboards, the user must also have role xcc_insights
xcc_sidebar_messagesglobalglobalglobalglobalglobalglobal
Allows display of the Messages menu item
xcc_sidebar_monitorglobal
Allows access to Monitoring menu item
Note: To access the actual dashboards, the user must also have role xcc_monitor
xcc_sidebar_quarantinesglobalglobalglobalglobalglobalglobal
Allows display of the Quarantines menu item
xcc_sidebar_reportedglobalglobalglobalglobalglobalglobal
Allows display of the Reported menu item
xcc_sidebar_threat_intelligenceglobal
Allows access to the Threat Intelligence menu item
Note: To access the actual dashboards, the user must also have role xcc_insights
xcc_ssq_portalglobalglobalglobalglobalglobalglobalglobal
Allows access to the self-service user quarantine UI
xcc_topics_fetchglobalglobalglobalglobaltenant:primarytenant:primary
Allows viewing of the extracted topics from email (if available)
xcc_user_impersonateglobal
Allows impersonation of another user
xcc_user_settings_change_languageglobalglobalglobalglobalglobalglobalglobal
Allows the user to change their language
xcc_user_settings_change_quarantine_notificationglobalglobalglobalglobalglobalglobalglobal
Allows the user to change their quarantine notification settings
xcc_user_settings_change_themeglobalglobalglobalglobalglobalglobalglobal
Allows the user to change their settings (e.g., the theme)
xcc_user_tags_addglobalglobaltenant:primary
Allows adding of one or multiple tags for an analyzed message, reported incident, and uploaded file
xcc_user_tags_fetchglobalglobalglobalglobalglobalglobal
Allows retrieval of user tags attached to an analyzed message, reported incident, and uploaded file
xcc_user_tags_removeglobalglobaltenant:primary
Allows removal of one or multiple tags for an analyzed message, reported incident, and uploaded file