Capsule supports four user roles: Owner, Admin, Viewer, and Legal Discovery. Each role grants a different level of access - from full administrative control to read-only investigation. Roles are assigned per tenant from the user-management settings.
Capsule's role model lets security teams investigate findings and detections without exposing private end-user content. Roles control two things: which actions a user can take (connecting integrations, configuring policies, managing users, taking responses) and whether private conversation content is visible.
| Role | Manage integrations | Manage users & settings | View security findings | View private conversation content |
|---|---|---|---|---|
| Owner | ✅ | ✅ | ✅ | All sessions |
| Admin | ✅ | ❌ | ✅ | Flagged sessions only |
| Viewer | ❌ | ❌ | ✅ | Always hidden |
| Legal Discovery | ❌ | ❌ | ✅ | All sessions |
Full administrative access. Owners manage users, configure integrations and policies, and view every session - including private conversation content. Use this role for platform owners.
Access to all security findings and detections, with privileged visibility into flagged sessions - those with an active policy violation, issue, or detection. Private conversation content remains hidden on sessions that have not been flagged.
Admins can also manage the Integration center: connect a new platform, apply configuration, test a connection, trigger a sync, enable or disable an integration, and remove one. They cannot manage users, roles, policies, or the remaining tenant settings - those stay with Owners. This is the recommended role for SOC analysts and security investigators who own platform onboarding.
Read-only access to dashboards, posture, agent inventory, and aggregated metrics. Conversation content is always hidden. Use this role for stakeholders who need awareness without operational responsibilities.
Read-only access with full visibility into all session content - private conversation messages and tool input/output across every session, not just flagged ones. Legal Discovery users cannot manage users, configure integrations or policies, or take response actions. Use this role for legal and e-discovery reviewers who must read complete session content for investigations or legal holds without gaining operational control.
- Sign in as an Owner.
- Go to Settings → Users.
- Click Add user, enter the email and name, then pick a role.
- To change an existing role, open the user's row and click Edit.
Only Owners can assign or change roles.
When a user without permission opens a session, conversation messages and tool input/output are replaced with a Hidden - contact a system owner for access. placeholder.
Identity fields - user email and user IDs - remain visible so investigations can still attribute activity to the right person.