Skip to content
Last updated

Capsule supports four user roles: Owner, Admin, Viewer, and Legal Discovery. Each role grants a different level of access - from full administrative control to read-only investigation. Roles are assigned per tenant from the user-management settings.

Overview

Capsule's role model lets security teams investigate findings and detections without exposing private end-user content. Roles control two things: which actions a user can take (connecting integrations, configuring policies, managing users, taking responses) and whether private conversation content is visible.

Roles

RoleManage integrationsManage users & settingsView security findingsView private conversation content
OwnerAll sessions
AdminFlagged sessions only
ViewerAlways hidden
Legal DiscoveryAll sessions

Owner

Full administrative access. Owners manage users, configure integrations and policies, and view every session - including private conversation content. Use this role for platform owners.

Admin

Access to all security findings and detections, with privileged visibility into flagged sessions - those with an active policy violation, issue, or detection. Private conversation content remains hidden on sessions that have not been flagged.

Admins can also manage the Integration center: connect a new platform, apply configuration, test a connection, trigger a sync, enable or disable an integration, and remove one. They cannot manage users, roles, policies, or the remaining tenant settings - those stay with Owners. This is the recommended role for SOC analysts and security investigators who own platform onboarding.

Viewer

Read-only access to dashboards, posture, agent inventory, and aggregated metrics. Conversation content is always hidden. Use this role for stakeholders who need awareness without operational responsibilities.

Read-only access with full visibility into all session content - private conversation messages and tool input/output across every session, not just flagged ones. Legal Discovery users cannot manage users, configure integrations or policies, or take response actions. Use this role for legal and e-discovery reviewers who must read complete session content for investigations or legal holds without gaining operational control.

How to assign a role

  1. Sign in as an Owner.
  2. Go to Settings → Users.
  3. Click Add user, enter the email and name, then pick a role.
  4. To change an existing role, open the user's row and click Edit.

Only Owners can assign or change roles.

Redaction behavior

When a user without permission opens a session, conversation messages and tool input/output are replaced with a Hidden - contact a system owner for access. placeholder.

Identity fields - user email and user IDs - remain visible so investigations can still attribute activity to the right person.