How it works (mental model)
- Alerts in Incident Management can be tagged (e.g.,
Network,Endpoint,O365,CustomerA). - An admin assigns one or more tags to a user (or role).
- When Tag RBAC is enabled, that user only sees alerts matching their assigned tags.
Key rule: A user with no tags assigned has no restrictions — they can see all alerts. Tag RBAC only restricts visibility once you assign specific tags to a user.
Access rules summary
Enabling Tag RBAC
- Navigate to Settings → Tag RBAC Settings (admin only).
- Toggle Enable Tag RBAC to On.
- Configure how untagged alerts should be handled (see below).
- Click Save Settings.
Until Tag RBAC is enabled, tag assignments on users have no effect — all users can see all alerts.
Untagged alert behavior
When Tag RBAC is enabled, you need to decide what happens to alerts that don’t have any tags. There are three options:When to use “Default Tag”
This is useful when you want a catch-all group. For example:- Create a tag called
GeneralorTriage. - Set it as the default tag.
- Assign
Generalto your triage team. - Now untagged alerts land in their queue automatically without needing to tag every single alert.
Assigning tags to users
- Navigate to the Users page.
- Select the user you want to configure.
- In the user detail panel, find the Assign Tags section.
- Use the multi-select dropdown to choose one or more tags.
- Click Save.
Tags must already exist in the system (created via alert tagging in Incident Management). You cannot create new tags from the assignment panel.
Assigning tags to roles
Instead of assigning tags per-user, you can assign tags at the role level. This is useful when all users with a particular role should have the same alert visibility.- Role-level tags apply to every user with that role.
- User-level tags override or extend role-level tags for individual users.
- If a user has both role-level and user-level tags, they see alerts matching any of their combined tags.
Checking effective access
You can verify what a user actually has access to by viewing their effective access, which combines:- Their role’s tag assignments
- Their personal tag assignments
- Customer access restrictions (if applicable)
Common scenarios
MSSP with multiple customers
Each analyst only sees alerts tagged with their customer. The senior analyst sees both.
SOC with specialized teams
Alerts are tagged by source, and each team only sees their relevant alerts.
