Skip to main content
This reference lists every ContraForce role, what it allows, and who can hand it out.
ContraForce uses two kinds of roles. An organization role controls what someone can manage across your organization. A workspace role controls what they can do inside one customer workspace. Most people need both.

How roles work together

Organization roles

One per user, set in Settings → User Management. Controls users, groups, workspaces, billing, agents and content across the organization.

Workspace roles

One per user per workspace, set in the workspace’s IAM tab, directly or through a group. Controls incidents, Gamebooks, modules and settings in that workspace.
To work inside a workspace, a user needs a workspace role there. An Org Admin or Workspace Admin can open any workspace your organization manages to set it up, but the incident list and the actions inside a workspace still follow their workspace role. Everyone else can open only the workspaces where they hold a workspace role.

Organization roles

Content Admin and Content Operator are offered only when the Content Management Center is enabled for your organization.

What each organization role can do

Every other role sees, in the Workspaces list, only the workspaces where it holds a workspace role, because those are the ones it can open. To give someone a workspace, an Org Admin or Workspace Admin assigns them a workspace role there.
You can only grant what you hold. Only an Org Admin gives out a role above Member, workspace access or an API key. A User Admin manages people (who is in the organization) but not access (what they can do), much like the User Administrator role in Microsoft Entra ID.

Org Admin

  • Platform administrators responsible for ContraForce setup
  • Business owners who need full control
  • The people who decide who gets elevated access
  • Keep at least two Org Admins for continuity. ContraForce never lets the last working Org Admin be demoted, but removing users is not guarded the same way.
  • Limit the role to a few trusted people and review it quarterly.
  • Org Admin does not include workspace data: give yourself a workspace role where you need to work.

User Admin

  • Add new users to the organization as Member, without workspace access
  • Remove users and sync users from Microsoft Entra ID
  • Create, rename and delete groups, and remove members from groups
  • Add people to a group that does not give workspace access, or to one where they are an Owner of every workspace the group is assigned to
  • Import Entra groups whose members join as Member
  • Disable or delete service accounts and revoke their API keys
  • Change anyone’s organization role, including their own
  • Add users with a role above Member, or with a workspace assignment
  • Change or reactivate an existing user through Add Users
  • Create, change, re-key or re-enable service accounts
  • Make an Entra or SCIM group grant a role above Member
  • Open a workspace where they hold no workspace role

Workspace Admin

  • Add, onboard, bulk-import and remove customer workspaces
  • Assign users and groups to any workspace and set their workspace roles
  • Open any workspace your organization manages, even without a workspace role there
  • Subscribe or reactivate billing
  • Manage organization users, roles or groups
  • Use workspace profiles (Org Admin only)

Agent Admin

  • Deploy and configure agents and choose which workspaces they serve
  • Manage operating procedures
  • Create, change and delete organization webhooks and read their delivery logs
  • Delete an agent deployment (Org Admin only)
  • Manage users, roles or workspaces
  • Open a workspace where they hold no workspace role

Content Admin and Content Operator

These organization roles govern the Content Management Center: a Content Operator authors content; a Content Admin also governs it (approvals and repository settings). An Org Admin can do both. They are different from the Content Admin workspace role below, which manages analytic rules inside one workspace.

Member

  • Sees only the workspaces they are assigned to, with the access their workspace role gives
  • Default role for most team members; combine it with workspace roles

Workspace roles

What each workspace role can do

Org Admins and Workspace Admins can also manage any workspace’s users and groups without being its Owner. The last Owner of a workspace cannot be demoted.

Common role assignments


Best practices

Start people as Member with Incident Analyst or Workspace Reader, and raise access only when their work needs it.
Give day-to-day user management to User Admins. Keep role changes and API keys with a small group of Org Admins.
Assign groups like “SOC Tier 1” to workspaces with a fixed role. Remember that adding someone to such a group gives them that access, so only an Org Admin (or an Owner of every workspace the group covers) can add people to it.
Review Org Admins, API keys and workspace Owners every quarter.

Frequently asked questions

Every role above Member includes permissions a User Admin does not have, so changing roles, giving workspace access and creating API keys are reserved for Org Admins. A User Admin who tries sees “Only an organization Admin can…” and nothing is changed.
Yes. Each user has one role per workspace, and it can differ between workspaces.
Both work incidents and run Gamebooks. Only an Owner configures the workspace: modules, notifications, policies, approvers and its users.
Organization roles don’t include workspace data. Assign yourself a workspace role in that workspace’s IAM tab.
Not currently. Contact support if the predefined roles don’t fit your needs.

User Management

Add users, groups and roles

User & Group Management for Partners

Set up users and groups across customer workspaces

Service Accounts

API keys and their scopes

Content Management Center

Detection content and its permissions

Questions about roles and permissions? Contact us at support@contraforce.com.
Last modified on October 8, 2026