Overview
Hearth uses roles to control what each member of your workspace can see and do. This guide explains the built-in roles, what each one is for, and how to assign them.
Every member of a Hearth workspace has a role. A role is a bundle of permissions that decides which parts of Hearth a member can open, and which actions they can take. Hearth offers six built-in roles (four general-purpose roles and two billing-scoped roles) and you can also create custom roles tailored to your team.
If you are a Blumira customer, your role is automatically assigned in Hearth.
The built-in roles
Hearth includes the following built-in role options:
| Role | Who it's for | What it can do |
|---|---|---|
| Owner | The person ultimately responsible for the workspace | Everything an Administrator can do, plus transfer ownership and permanently delete the workspace. |
| Administrator | Team leads and workspace admins | Manage members, roles, integrations, billing, and settings; use every response action; author dashboards, schedules, and briefings; delete artifacts. Cannot transfer ownership or delete the workspace. |
| Analyst | Day-to-day SecOps analysts and responders | View everything; ask Hestia questions; launch investigations and briefings; build dashboards, schedules, and action plans; triage findings; take lower-risk response actions; manage uploads and contacts. Cannot manage members, roles, integrations, or billing, and cannot take the highest-risk actions. |
| Viewer | Stakeholders who need visibility, not control | View artifacts, exposure, dashboards, and the audit trail; export and download reports; pin items to a watchlist. |
| Billing | Whoever handles invoices and payment for the workspace | Manage billing and view usage and cost — the billing and usage pages, the card on file, plans, and credits. No access to the security features, investigations, or settings. |
| Usage & Billing (read-only) | Finance or stakeholders who need to see spend but not change it | Everything a Viewer can see, plus read-only access to the billing and usage pages (usage, cost, invoices). Cannot change billing, prompt Hestia, or take any response action. |
Note: Hearth's roles are specific to Hearth and are not the same as Blumira's user roles.
Assigning a role to a member
- Navigate to Account > Org admin.
- Find the tenant member you want to change or invite a new one.
- Click Edit role.
- Select the role or roles the member needs.
- Click Save.
Customizing roles
If a team member needs a set of permissions that is not already built into one of the Hearth roles, an Administrator can create a new role that grants a custom set of permissions from Hearth's permission catalog. For example, a "reporting" role that can build and export dashboards but nothing else.
The Roles page is where you can create custom Hearth roles and edit the permissions of existing custom roles. To create a new role, do the following:
- Navigate to Roles.
- Next to Add a role, click Add.
- In the Role Name box, type a name for the role.
- In the Description box, type a description that helps identify the role’s purpose.
- In the Permissions table, click the check box next to each permission you want to allow for the custom role.
- Click Add role.