Role Types
Permission Roles
Grant one or more capabilities. Every authorization decision in ThreatLab — server actions, API routes, and UI elements — is gated on a specific capability drawn from a permission role. A user can hold multiple permission roles; their effective capabilities are the combined set.
Title Roles
Display-only labels such as SOC Lead, Instructor, or Engineer. Title roles appear next to your name in the platform but carry no permissions and are never checked during authorization.
System Roles
Two roles are built into ThreatLab and cannot be modified or deleted:
Additional title roles — such as Engineer and Instructor — are pre-configured on every ThreatLab instance for cosmetic use.
Capabilities Reference
The table below lists every capability in ThreatLab, its display label, and what it authorises you to do:Checking Your Own Capabilities
You do not need to memorise which roles you hold. ThreatLab surfaces your permissions in two practical ways:- Gated Actions
Contact your ThreatLab administrator to have roles assigned to your account. Administrators manage role assignments under Admin > Users.