Organizations that operate multiple business units often require granular control over user account access—for example, when managing dedicated teams across different countries. The Lumu Enterprise Management Portal is designed to meet these needs, allowing you to create and manage user accounts and roles efficiently. This article will guide you through the necessary procedures.
To create users and assign user roles, head to the Accounts section inside the Settings submenu on the Lumu Enterprise Management Portal’s side panel.
A tenant is the way the Lumu Enterprise Management Portal displays all the security and visibility options available for a client organization. If you are monitoring the cybersecurity state of three different business units, you should create a tenant for each at the very least, for example.
Once the user is created, you will be able to access it from the Accounts section and edit what you need. The button to save changes will be enabled whenever the user's information or access is modified.
You can also configure other account settings such as report frequency and two-factor authentication.
As mentioned above, you can assign different roles to your users based on the access level you wish to provide them with. Let’s take a look at each of them.
|
|
Create Tenants
|
Assign Endpoints
|
Accounts Management
|
Edit/delete tenants
|
Configure Collectors
|
Create /edit Labels
|
Operate Incidents
|
|
Admin
|
✅
|
✅
|
✅
|
✅
|
✅
|
✅
|
✅
|
|
Supervisor
|
❌
|
❌
|
❌
|
❌
|
✅
|
✅
|
✅
|
|
Analyst
|
❌
|
❌
|
❌
|
❌
|
❌
|
❌
|
✅
|
This is the highest authority level. It can modify every configurable aspect of the organization on the Lumu Enterprise Management Portal, as well as make every possible decision regarding tenants and incidents. This role should be assigned to the people with the highest rank on the team, since they should be able to assign roles to other accounts and self-manage all aspects of the Lumu Enterprise Management Portal operation.
The supervisor is an intermediate role and has considerably fewer permissions than the Admin role. This role can only access the tenants that have been assigned to the user and change settings pertaining to said tenants. It should be assigned to team supervisors and leaders that need to configure collectors and be aware of the cybersecurity state of assigned tenants
This is the role with least permissions and is designed to only monitor the incidents of assigned tenants. It cannot change settings or make any changes to either tenants nor the organization as a whole. This role is reserved for analysts who only need visibility to operate the incidents of assigned tenants