On This Page

Home / Identity and Access Management/ Access Control/ Permissions Model/Permissions

Permissions

Use Permissions to define and manage fine-grained access control across Cribl products and resources.


Cribl’s Permissions model provides fine-grained access control from the entire deployment down to individual resources.

Permissions are defined sets of access rights that you assign to Members and Teams. Members also inherit Permissions on lower-level objects like products and Worker Groups from the Permissions they are assigned on higher-level objects like Organizations and Workspaces.

Cribl.Cloud supports only the Permissions model. On-prem deployments support both the Permissions model and the legacy Roles and Policies model. Read more about when to use each access control model.

Quick Reference for Permissions

The following table summarizes each Permission and the objects it is available for. For details on specific access rights that each Permission grants for each object, refer to the linked sections within the table.

PermissionDescription
Object-Level Availability
OwnerBroadest access for Organizations and Workspaces in Cribl.Cloud. Includes all Admin access, plus exclusive access to actions like deleting Organizations.Organizations (Cribl.Cloud)
Workspaces (Cribl.Cloud)
AdminBroad access to manage settings and configurations (and Members if assigned at the Organization level), without access that is exclusive to the Owner at the Organization level.Organizations (Cribl.Cloud)
Global (on-prem)
Workspaces (Cribl.Cloud)
Products
Worker Groups/Edge Fleets
Billing ReaderLimited access to the Organization to view billing information only. Does not confer any Permissions on lower-level objects (Workspaces, products, Worker Groups and Edge Fleets, and resources).Organizations (Cribl.Cloud)
IAM AdminLimited access to manage Organization Members and SSO settings only. Does not confer any Permissions on lower-level objects (Workspaces, products, Worker Groups and Edge Fleets, and resources).Organizations (Cribl.Cloud)
User/MemberBasic login access with no automatic Permissions on lower-level objects. Serves as a flexible starting point, but Owners or Admins must manually assign specific Permissions on lower-level objects.Organizations (Cribl.Cloud)
Global (on-prem)
Workspaces (Cribl.Cloud)
Cribl Stream and Edge
Cribl Search
Worker Groups/Edge Fleets
MaintainerLimited access to manage and modify resources and configurations within a Worker Group/Edge Fleet or product, without administrative access to manage Members or Global Settings.Stream Projects
Search Dataset Providers and Datasets
Search Dashboards
Search Notebooks
EditorLimited access to create, modify, and delete most resources and configurations, without access to modify Members or Global Settings.Cribl Stream and Edge
Cribl Search
Worker Groups/Edge Fleets
Stream Projects
CollectLimited access to run collection jobs on a Worker Group or Edge Fleet, without access to modify configurations or resources or perform administrative tasks.Worker Groups/Edge Fleets
Read OnlyLimited access to view Members, Groups, settings, Leader commits, and monitoring pages. Does not allow configuration changes or administrative actions.Cribl Stream and Edge
Cribl Search
Worker Groups/Edge Fleets
Stream Projects
Search Dataset Providers and Datasets
Search Dashboards
Search Notebooks

No Access Permission

The No Access Permission is available for all objects except Organizations. No Access explicitly blocks all access for a Member on the object and all lower-level objects. This allows you to enforce least privilege and ensure that only explicitly assigned Members have access.

By default, when you invite a new Member, they receive the User Permission at the Organization level (Cribl.Cloud) or at the Global level (on-prem). If you do not grant any Permissions on lower-level objects, the Member can log in but has the No Access Permission by default on all lower-level objects (Workspaces, products, Worker Groups/Edge Fleets, and resources). You must explicitly assign Permissions to the Member on lower-level objects to allow access.

No Permissions on lower-level objects are inherited from the No Access Permission. In addition, unless an Owner or Admin changes a Member’s No Access Permission on the Organization (Cribl.Cloud) or Global level (on-prem), they cannot assign the Member any Permissions on lower-level objects.

User Permission

User is the most flexible Permission. When a Member has the User Permission on an object, you can assign them any available Permission on the next lower-level object. This makes User ideal for Members who need varying access across different Products or Worker Groups and Edge Fleets.

For example, in Cribl.Cloud, if a Member has the User Permission at the Organization level, you can assign them the Member Permission at the Workspace level. This in turn allows you to assign the Member any of the available Permissions on individual Cribl products. If you assign the User Permission on Cribl Stream (that is, at the product level), you can then assign the Member any of the available Permissions on individual Worker Groups.

Exception: Members cannot be assigned the Maintainer Permission on Cribl Stream Projects if they have the User Permission on the Organization, Product, or Worker Group/Edge Fleet or the Member Permission on the Workspace. The Maintainer Permission on Cribl Stream Projects requires Admin or Editor on higher-level objects.

Initial Permissions

On Cribl.Cloud, the first user to deploy Cribl is assigned the Admin Permission on the Organization.

In on-prem Distributed deployments at the correct plan/license tier, the first user to deploy Cribl is assigned the Admin Permission at the Global level.

With the Admin Permission, you can assign Permissions to other Members and Teams.

In on-prem Single-instance deployments and Distributed deployments at other license tiers, Cribl bypasses the Permissions model and assigns all users implicit Admin Permissions.

Organization Permissions (Cribl.Cloud)

Organizations and Organization-level Permissions are available only on Cribl.Cloud. In on-prem deployments, use Global Permissions to manage access at the deployment level.

The following table describes the access that you can grant on Organizations for each Permission:

Access DescriptionUserIAM AdminBilling ReaderAdminOwner
Log into the system
View the credit consumption dashboards in the FinOps Center
Update own Member profile
View Worker Groups/Edge Fleets and resources to which you have access
View, invite, update, and delete Organization Members
View and modify SSO settings
Manage Connected Environments
View and modify Global Settings
Download invoices
Manage access control lists
Manage API Credentials
View and execute Leader commits
View, provision, update, and delete Worker Groups/Edge Fleets
Create and manage secret stores, secret folders, and global secrets
Reload secret folders
View data Sources and trust policies
Create and delete Lakehouses
Link and unlink Lakehouses with Datasets
View Organization details
Send Cloud Identity event logs to Cribl Stream
Download Cloud Identity event logs
Update Organization details
Add and delete Workspaces
Delete Organization

Inheritance for Organization Permissions

The following diagram depicts the Permissions that Members automatically inherit on lower-level objects based on their Organization Permissions on Cribl.Cloud:

Owner or Admin on Organization
└── Admin on Workspaces
    └── Admin on Cribl Stream and Edge
        └── Admin on Worker Groups and Edge Fleets
            └── Maintainer on Resources
    └── Admin on Cribl Search and Lake
        └── Maintainer on Resources

Billing Reader on Organization
└── No access on lower-level objects

IAM Admin on Organization
└── No access on lower-level objects

User on Organization
└── No inherited Permissions on lower-level objects; Permissions must be assigned

Global Permissions (On-Prem)

Global Permissions in on-prem deployments describe access rights at the deployment level, similar to Organization Permissions on Cribl.Cloud.

The following table describes the access that each Global Permission grants in on-prem deployments:

Access DescriptionUserAdmin
Log into the system
Create, view, update, and delete all Members

Inheritance for Global Permissions (On-Prem)

The following diagram depicts the Permissions that Members automatically inherit on lower-level objects based on their on-prem Global Permissions:

Admin on Global
└── Admin on Products
    └── Editor on Worker Groups and Edge Fleets
        └── Maintainer on Resources

User on Global
└── No inherited Permissions on lower-level objects; Permissions must be assigned

Workspace Permissions (Cribl.Cloud)

The following table describes the access that you can grant on Workspaces for each Permission:

Access DescriptionMemberAdminOwner
Log into the system
View Workspace Members
View Workspace details
Create and manage secret stores, secret folders, and global secrets
Reload secret folders
View default data Sources and trust policies
View and manage access control lists

When using the Cribl management plane API or SDK to create new API Credentials, the user Role on Workspaces is equivalent to Member.

Users must have the Owner, Admin, or IAM Admin Permission on the Organization to invite, update, or delete Members. Even Members with the Admin or Owner Permission on a Workspace in Cribl.Cloud must also have Owner, Admin, or IAM Admin on the Organization to invite, update, or delete Members.

If you have multiple Workspaces on Cribl.Cloud, you can manage Permissions independently for each of them. Permissions are scoped to each Workspace and do not carry over to other Workspaces. For example, a user can be an Admin in Workspace A and a Member in Workspace B. This allows granular control over segmented environments within your Organization (such as production, staging, and dev).

Inheritance for Workspace Permissions (Cribl.Cloud)

The Permission a Member has on the Organization automatically determines their Permissions on Workspaces as follows:

Organization   ──►   Workspace
------------         ---------
Owner          ──►   Admin
Admin          ──►   Admin
Billing Reader ──►   No Access
IAM Admin      ──►   No Access
User           ──►   No Access (configurable)

The following diagram depicts the Permissions that Members automatically inherit on lower-level objects based on their Workspace Permissions on Cribl.Cloud:

Owner or Admin on Workspace (Cribl.Cloud)
└── Admin on Cribl Stream and Edge
    └── Admin on Worker Groups and Edge Fleets
        └── Maintainer on Resources
└── Admin on Cribl Search and Lake
    └── Maintainer on Resources

Member on Workspace (Cribl.Cloud)
└── No inherited Permissions on lower-level objects; Permissions must be assigned

Product Permissions

Product Permissions grant access to particular actions and resources in Cribl Stream, Edge, Search, and Lake. Each product has different Permissions.

Cribl Stream and Edge Permissions

The following table describes the access that you can grant on Cribl Stream and Edge:

Access DescriptionUserRead OnlyEditorAdmin
Log in to the system
View Members, Worker Groups/Edge Fleets, settings, Leader commits, and legacy Local Users and Roles
View all Worker Groups/Edge Fleets
View all Monitoring pages
Add, update, restart Worker Groups/Edge Fleets
Create, view, update, and delete all Worker Groups/Edge Fleets and resources
Manage Worker Group/Edge Fleet Mappings
(Cribl.Cloud only) Create and manage secret folders and global secrets
(Cribl.Cloud only) Reload secret folders
Manage Notifications and Notification Targets

Inheritance for Cribl Stream and Edge Permissions

The Permissions a Member has on the Organization and Workspace (Cribl.Cloud) or at the Global level (on-prem) automatically determine their Permission on Cribl Stream and Edge as follows:

Cribl.Cloud:
Organization   +   Workspace   ──►   Cribl Stream and Edge
------------       ---------         ---------------------
Owner          +   Admin       ──►   Admin
Admin          +   Admin       ──►   Admin
Billing Reader +   No Access   ──►   No Access
IAM Admin      +   No Access   ──►   No Access
User           +   Owner       ──►   Admin
User           +   Admin       ──►   Admin
User           +   Member      ──►   No Access (configurable)

On-Prem:
Global   ──►   Cribl Stream and Edge
------         ---------------------
Admin    ──►   Admin
User     ──►   No Access (configurable)

The following diagram depicts the Permissions that Members automatically inherit on lower-level objects based on their Cribl Stream and Edge Permissions:

Admin on Cribl Stream and Edge
└── Admin on Worker Groups and Edge Fleets
    └── Maintainer on Cribl Stream and Edge Resources

Editor on Cribl Stream and Edge
└── Editor on Worker Groups and Edge Fleets
    └── Maintainer on Cribl Stream and Edge Resources

Read Only on Cribl Stream and Edge
└── Read Only on Worker Groups and Edge Fleets
    └── Read Only on Cribl Stream and Edge Resources

User on Cribl Stream and Edge
└── No inherited Permissions on lower-level objects; Permissions must be assigned

Cribl Search Permissions

The following table describes the access that you can grant on Cribl Search.

For details on individual Datasets, Dataset Providers, Dashboards, and Notebooks, see the resource Permissions.

For details on specific operators, functions, and commands, see the Cribl Search Language Reference (for example, send).

Access DescriptionUserEditorAdmin
Add and resize lakehouse engines
Resize the federated engine
Add new Datasets and Dataset Providers
Access existing Datasets or Dataset ProvidersOnly if sharedOwn or shared
Add or modify Datatype rules and Dataset rules
Add new Dashboards and Notebooks
Access existing Dashboards or NotebooksOnly if sharedOwn or shared
See search historyOwn or sharedOwn or shared
View, add, and modify lookups, Parsers, regexes,
Grok patterns, saved or scheduled searches, and custom Datatypes
View, add, use, import, modify, and export Packs
Export results (export operator)Only to lookups
Manage Members, usage groups and limits

Inheritance for Cribl Search Permissions

The Permissions a Member has on the Organization and Workspace automatically determine their Permission on Cribl Search as follows:

Organization   +   Workspace   ──►   Cribl Search
------------       ---------         ------------
Owner          +   Admin       ──►   Admin
Admin          +   Admin       ──►   Admin
Billing Reader +   No Access   ──►   No Access
IAM Admin      +   No Access   ──►   No Access
User           +   Owner       ──►   Admin
User           +   Admin       ──►   Admin
User           +   Member      ──►   No Access (configurable)

The following diagram depicts the Permissions that Members automatically inherit on lower-level objects based on their Cribl Search Permissions:

Admin on Cribl Search
└── Maintainer on Cribl Search Resources

Editor on Cribl Search
└── No inherited Permissions on Cribl Search Resources

User on Cribl Search
└── No inherited Permissions on Cribl Search Resources

Members with the Editor and User Permissions on Cribl Search do not inherit Permissions on Cribl Search Resources. Instead, they gain resource-level Permissions on the individual resources that they create or when another Member shares a resource with them. See the resource-level sections for Dataset Providers and Datasets, Dashboards, and Notebooks for details.

Cribl Lake Permissions

The following table describes the access that you can grant on Cribl Lake:

Access DescriptionRead OnlyEditorAdmin
Read Lake Datasets
Read Lakehouses
Search a Lake Dataset directly from the Dataset table

Also requires User, Editor, or Admin on Cribl Search and Read Only or Maintainer on the Cribl Search Dataset
View the Connected to column in the Dataset table, which lists the Cribl Lake Collectors and Destinations that each Lake Dataset is connected with

Also requires Read Only, Editor, or Admin on Cribl Stream
Create and edit Lake Datasets
Delete Lake Datasets
Create and delete Lakehouses
Assign and unassign Lake Datasets to Lakehouses

Inheritance for Cribl Lake Permissions

The Permissions a Member has on the Organization and Workspace automatically determine their Permission on Cribl Lake as follows:

Organization   +   Workspace   ──►   Cribl Lake
------------       ---------         ----------
Owner          +   Admin       ──►   Admin
Admin          +   Admin       ──►   Admin
Billing Reader +   No Access   ──►   No Access
IAM Admin      +   No Access   ──►   No Access
User           +   Owner       ──►   Admin
User           +   Admin       ──►   Admin
User           +   Member      ──►   No Access (configurable)

The following diagram depicts the Permissions that Members automatically inherit on lower-level objects based on their Cribl Lake Permissions:

Admin on Cribl Lake
└── Maintainer on Cribl Lake Resources

Editor on Cribl Lake
└── Maintainer on Cribl Lake Resources

Read Only on Cribl Lake
└── No inherited Permissions on lower-level objects; Permissions must be assigned

Worker Group and Edge Fleet Permissions

The following table describes the access that you can grant on Worker Groups and Edge Fleets:

Access DescriptionUserRead OnlyCollectEditorAdmin
Be assigned to resources within the Worker Group/Edge Fleet
View all Worker Group/Edge Fleet Settings, encryption keys, certificates, secrets, scripts.
View all Sources, Destinations, Pipelines, Packs, Apps, Routes, QuickConnect connections, Knowledge Objects, Notifications, and Notification Targets
View all Edge Subfleets and their Settings, and Stream Projects and Subscriptions
Run Collection jobs on the Worker Group/Edge Fleet
Create, view, update, and delete all Worker Group/Edge Fleet encryption keys, certificates, secrets, scripts, Sources, Destinations, Pipelines, Packs, Apps, Routes, QuickConnect connections, Knowledge Objects, and Notifications and Notification targets
Commit configuration changes
Create, view, update, and delete all Worker Group/Edge Fleet access management (Members’ Permissions), Settings, encryption keys, key management system (KMS) settings, certificates, secrets, scripts
Create, view, update, and delete all Sources, Destinations, Pipelines, Packs, Apps, Routes, QuickConnect connections, Knowledge Objects, Notifications and Notification targets, Stream Projects/Subscriptions, and can run tests on Sources and Destinations
Restart Worker/Edge Nodes
Update Edge Nodes
(Fleet admin only)
Commit and deploy configuration changes
On Edge, CRUD capabilities on Subfleet Settings and access management identical to those on the parent Fleet

Inheritance for Worker Group and Edge Fleet Permissions

The Permissions a Member has on the Workspace and products (Cribl.Cloud) or at the Global level and on products (on-prem) automatically determine their Permission on Worker Groups and Edge Fleets as follows:

Cribl.Cloud:
Workspace   +   Cribl Stream and Edge   ──►   Worker Group/Edge Fleet
---------       ---------------------         -----------------------
Owner       +   Admin                   ──►   Admin
Admin       +   Admin                   ──►   Admin
Member      +   Admin                   ──►   Admin
Member      +   Editor                  ──►   Editor
Member      +   Read Only               ──►   Read Only
Member      +   User                    ──►   No Access (configurable)

On-Prem:
Global   +   Cribl Stream and Edge   ──►   Worker Group/Edge Fleet
------       ---------------------         -----------------------
Admin    +   Admin                   ──►   Admin
User     +   Admin                   ──►   Admin
User     +   Editor                  ──►   Editor
User     +   Read Only               ──►   Read Only
User     +   User                    ──►   No Access (configurable)

The following diagram depicts the Permissions that Members automatically inherit on lower-level objects based on their Worker Group/Edge Fleet Permissions:

Admin on a Worker Group or Edge Fleet
└── Maintainer on Resources

Editor on a Worker Group or Edge Fleet
└── Maintainer on Resources

Collect on a Worker Group or Edge Fleet
└── No access on lower-level objects

Read Only on a Worker Group or Edge Fleet
└── Read Only on Resources

User on a Worker Group or Edge Fleet
└── No inherited Permissions on lower-level objects; Permissions must be assigned

Resource Permissions

Certain Cribl products provide Permission-based access to particular resources.

Stream Projects

You must use the Permissions model to manage access to Stream Projects and Subscriptions. Cribl does not support the legacy Roles and Policies model for Stream Projects.

The following table describes the access that you can share on Stream Projects for each Permission:

Access DescriptionRead OnlyEditorMaintainer
View Project and Subscription settings and connections among the Project’s Subscriptions, Packs, and Destinations
Configure connections among the Project’s Subscriptions, Packs, and Destinations
Create, modify, and delete Pipelines within the Project
Modify Project settings
Delete the Project

Inheritance for Stream Projects

The Permissions a Member has on higher-level objects automatically determine their Permission on Stream Projects as follows:

Cribl.Cloud:
Organization   +   Workspace   +   Cribl Stream/Edge   ──►   Stream Projects
------------       ---------       -----------------         ---------------
Owner          +   Admin       +   Admin               ──►   Maintainer
Admin          +   Admin       +   Admin               ──►   Maintainer
Billing Reader +   No Access   +   No Access           ──►   No Access
IAM Admin      +   No Access   +   No Access           ──►   No Access
User           +   Owner       +   Admin               ──►   Editor
User           +   Admin       +   Admin               ──►   Editor
User           +   Member      +   Admin               ──►   Editor
User           +   Member      +   Editor              ──►   Editor
User           +   Member      +   Read Only           ──►   Read Only
User           +   Member      +   User                ──►   No Access (configurable)

On-Prem:
Global   +   Cribl Stream/Edge   +   Worker Group/Fleet   ──►   Stream Projects
------       -----------------       ------------------         ---------------
Admin    +   Admin               +   Admin                ──►   Maintainer
User     +   Admin               +   Admin                ──►   Editor
User     +   Admin               +   Editor               ──►   Editor
User     +   Admin               +   Collect              ──►   No Access
User     +   Admin               +   Read Only            ──►   Read Only
User     +   Editor              +   Editor               ──►   Editor
User     +   Editor              +   Collect              ──►   No Access
User     +   Editor              +   Read Only            ──►   Read Only
User     +   Read Only           +   Read Only            ──►   Read Only
User     +   User                +   Collect              ──►   No Access
User     +   User                +   User                 ──►   No Access (configurable)

The Maintainer Permission on Stream Projects is not available for Members who have the User Permission on any higher-level object.

Cribl Search Dataset Providers and Datasets

The following table describes the access that you can share on individual Dataset Providers and Datasets (both Cribl-hosted and federated).

Access DescriptionRead OnlyMaintainer
View the Dataset Provider/Dataset configuration and settings
Search and export the Dataset
Modify and delete the Dataset Provider/Dataset
Assign Datatypes
Share and revoke access to the Dataset Provider/Dataset for Members and Teams
Unhide Dataset Provider credentialsSearch Admin onlySearch Admin only

The Member who creates a Dataset Provider or Dataset becomes its Maintainer by default.

Inheritance for Cribl Search Dataset Providers and Datasets Permissions

The Permissions a Member has on higher-level objects automatically determine their Permission on Cribl Search Dataset Providers and Datasets as follows:

Organization   +  Workspace  +  Cribl Search   ──►   Dataset Providers/Datasets
------------      ---------     ------------         --------------------------
Owner          +  Admin      +  Admin          ──►   Maintainer
Admin          +  Admin      +  Admin          ──►   Maintainer
Billing Reader +  No Access  +  No Access      ──►   No Access
IAM Admin      +  No Access  +  No Access      ──►   No Access
User           +  Owner      +  Admin          ──►   Maintainer
User           +  Admin      +  Admin          ──►   Maintainer
User           +  Member     +  Admin          ──►   Maintainer
User           +  Member     +  Editor         ──►   No Access (configurable)
User           +  Member     +  User           ──►   No Access (configurable)

Cribl Search Dashboards

The following table describes the access that you can share on individual Search Dashboards.

Access DescriptionRead OnlyMaintainer
View the Dashboard and settings
View the Dashboard’s queries and widgets
Export and forward data from the Dashboard
Export and forward data from Dashboard widgets

Also requires Read Only or Maintainer on the Cribl Search Dataset
Clone the Dashboard
Create, modify, and delete a Dashboard
Edit the Dashboard’s queries and widgets
Share and revoke access to the Dashboard for Members and Teams

The Member who creates a Dashboard becomes its Maintainer by default.

Inheritance for Cribl Search Dashboards Permissions

The Permissions a Member has on higher-level objects automatically determine their Permission on Cribl Search Dashboards as follows:

Organization   +  Workspace  +  Cribl Search   ──►   Dashboards
------------      ---------     ------------         ----------
Owner          +  Admin      +  Admin          ──►   Maintainer
Admin          +  Admin      +  Admin          ──►   Maintainer
Billing Reader +  No Access  +  No Access      ──►   No Access
IAM Admin      +  No Access  +  No Access      ──►   No Access
User           +  Owner      +  Admin          ──►   Maintainer
User           +  Admin      +  Admin          ──►   Maintainer
User           +  Member     +  Admin          ──►   Maintainer
User           +  Member     +  Editor         ──►   No Access (configurable)
User           +  Member     +  User           ──►   No Access (configurable)

Cribl Search Notebooks

The following table describes the access that you can share on Search Notebooks.

Access DescriptionRead OnlyMaintainer
View the Notebook
View Results
Export Results
Open in Cribl Search
Create Notebooks
Share Notebooks
Lock or unlock Notebooks
Delete Notebooks
Rerun cells
Add cells
Edit cells
Delete cells

The Member who creates a Notebook becomes its Maintainer by default.

Inheritance for Cribl Search Notebooks

The Permissions a Member has on higher-level objects automatically determine their Permission on Cribl Search Notebooks as follows:

Organization   +  Workspace  +  Cribl Search   ──►   Notebooks
------------      ---------     ------------         ---------
Owner          +  Admin      +  Admin          ──►   Maintainer
Admin          +  Admin      +  Admin          ──►   Maintainer
Billing Reader +  No Access  +  No Access      ──►   No Access
IAM Admin      +  No Access  +  No Access      ──►   No Access
User           +  Owner      +  Admin          ──►   Maintainer
User           +  Admin      +  Admin          ──►   Maintainer
User           +  Member     +  Admin          ──►   Maintainer
User           +  Member     +  Editor         ──►   No Access (configurable)
User           +  Member     +  User           ──►   No Access (configurable)

Cribl Search Editors and Users have No Access on existing Notebooks by default. Other Members can share Notebooks that they have the Maintainer Permission on, assigning either the Read Only or Maintainer Permission on each Notebook to each Member they share it with.