ContraForce uses two kinds of roles. An organization role controls what someone can manage across your organization. A workspace role controls what they can do inside one customer workspace. Most people need both.
How roles work together
Organization roles
One per user, set in Settings → User Management. Controls users, groups, workspaces, billing, agents and content across the organization.
Workspace roles
One per user per workspace, set in the workspace’s IAM tab, directly or through a group. Controls incidents, Gamebooks, modules and settings in that workspace.
Organization roles
Content Admin and Content Operator are offered only when the Content Management Center is enabled for your organization.
What each organization role can do
Every other role sees, in the Workspaces list, only the workspaces where it holds a workspace role, because those are the ones it can open. To give someone a workspace, an Org Admin or Workspace Admin assigns them a workspace role there.
You can only grant what you hold. Only an Org Admin gives out a role above Member, workspace access or an API key. A User Admin manages people (who is in the organization) but not access (what they can do), much like the User Administrator role in Microsoft Entra ID.
Org Admin
Use cases
Use cases
- Platform administrators responsible for ContraForce setup
- Business owners who need full control
- The people who decide who gets elevated access
Assignment guidelines
Assignment guidelines
- Keep at least two Org Admins for continuity. ContraForce never lets the last working Org Admin be demoted, but removing users is not guarded the same way.
- Limit the role to a few trusted people and review it quarterly.
- Org Admin does not include workspace data: give yourself a workspace role where you need to work.
User Admin
Can
Can
- Add new users to the organization as Member, without workspace access
- Remove users and sync users from Microsoft Entra ID
- Create, rename and delete groups, and remove members from groups
- Add people to a group that does not give workspace access, or to one where they are an Owner of every workspace the group is assigned to
- Import Entra groups whose members join as Member
- Disable or delete service accounts and revoke their API keys
Cannot
Cannot
- Change anyone’s organization role, including their own
- Add users with a role above Member, or with a workspace assignment
- Change or reactivate an existing user through Add Users
- Create, change, re-key or re-enable service accounts
- Make an Entra or SCIM group grant a role above Member
- Open a workspace where they hold no workspace role
Workspace Admin
Can
Can
- Add, onboard, bulk-import and remove customer workspaces
- Assign users and groups to any workspace and set their workspace roles
- Open any workspace your organization manages, even without a workspace role there
- Subscribe or reactivate billing
Cannot
Cannot
- Manage organization users, roles or groups
- Use workspace profiles (Org Admin only)
Agent Admin
Can
Can
- Deploy and configure agents and choose which workspaces they serve
- Manage operating procedures
- Create, change and delete organization webhooks and read their delivery logs
Cannot
Cannot
- Delete an agent deployment (Org Admin only)
- Manage users, roles or workspaces
- Open a workspace where they hold no workspace role
Content Admin and Content Operator
Details
Details
These organization roles govern the Content Management Center: a Content Operator authors content; a Content Admin also governs it (approvals and repository settings). An Org Admin can do both. They are different from the Content Admin workspace role below, which manages analytic rules inside one workspace.
Member
Details
Details
- Sees only the workspaces they are assigned to, with the access their workspace role gives
- Default role for most team members; combine it with workspace roles
Workspace roles
What each workspace role can do
- Incidents
- Response
- Configuration
- Administration
Org Admins and Workspace Admins can also manage any workspace’s users and groups without being its Owner. The last Owner of a workspace cannot be demoted.
Common role assignments
Best practices
Apply least privilege
Apply least privilege
Start people as Member with Incident Analyst or Workspace Reader, and raise access only when their work needs it.
Separate people management from access
Separate people management from access
Give day-to-day user management to User Admins. Keep role changes and API keys with a small group of Org Admins.
Use groups for consistent workspace access
Use groups for consistent workspace access
Assign groups like “SOC Tier 1” to workspaces with a fixed role. Remember that adding someone to such a group gives them that access, so only an Org Admin (or an Owner of every workspace the group covers) can add people to it.
Review regularly
Review regularly
Review Org Admins, API keys and workspace Owners every quarter.
Frequently asked questions
Why can't a User Admin change roles?
Why can't a User Admin change roles?
Every role above Member includes permissions a User Admin does not have, so changing roles, giving workspace access and creating API keys are reserved for Org Admins. A User Admin who tries sees “Only an organization Admin can…” and nothing is changed.
Can a user have different roles in different workspaces?
Can a user have different roles in different workspaces?
Yes. Each user has one role per workspace, and it can differ between workspaces.
What's the difference between Owner and Incident Responder?
What's the difference between Owner and Incident Responder?
Both work incidents and run Gamebooks. Only an Owner configures the workspace: modules, notifications, policies, approvers and its users.
Why can't I see a workspace's incidents as an Org Admin?
Why can't I see a workspace's incidents as an Org Admin?
Organization roles don’t include workspace data. Assign yourself a workspace role in that workspace’s IAM tab.
Can I create custom roles?
Can I create custom roles?
Not currently. Contact support if the predefined roles don’t fit your needs.
Related guides
User Management
Add users, groups and roles
User & Group Management for Partners
Set up users and groups across customer workspaces
Service Accounts
API keys and their scopes
Content Management Center
Detection content and its permissions
Questions about roles and permissions? Contact us at support@contraforce.com.