Access management involves establishing procedures for creating and managing user accounts, defining access permissions based on job roles or responsibilities, and monitoring user activity to ensure cyber risk with security policies. This includes managing user access, where user accounts are created and permissions are assigned based on job roles or responsibilities. It also includes implementing Role-Based Access Control (RBAC) which assigns permissions based on predefined roles, simplifying the management of user access. This article also includes steps to configure the Session management where you can configure the user session duration. You can manage DataBee user access to Controls Reports, explore and manage visibility of framework versions with Framework Coverage, and grant and revoke user access to RiskFlow features.
Users
Navigate to the top right corner of DataBee UI and click on the configuration icon. Select Access Management from the dropdown menu that appears. The "Access Management" configuration page will be displayed. Select the Users tab. A table with the following columns will be shown:
ID: the unique identifier for each user account.
FULL NAME: the name of the user associated with the account.
USERNAME: the username used to log in to the account.
LAST LOGIN: the date and time the user last logged in to the account.
CREATED: the date and time the user account was created.
ROLES: the user role assigned to the account, such as Administrator, Data Engineer, or a Security Analyst.
STATUS: the current state of the account, whether it is Active or Inactive. Inactive accounts are not permitted to log into DataBee but information related or linked to those accounts is retained by the system.
TYPE: identifies how the user account is managed and authenticated within the system.
ACTIONS: the available actions for each user account, including Edit, Revoke API Key, or Delete.
Just below the column headings, you will see a filter option. Here, you can type in the keyword you want to filter by, and it shows the user accounts that match your filter keyword.
Note:
Only users with administrative privileges can manage user accounts in DataBee.
.png?sv=2026-02-06&spr=https&st=2026-09-18T02%3A33%3A11Z&se=2026-09-18T02%3A49%3A11Z&sr=c&sp=r&sig=vyYZpmhpPkob80WDITUVhRa3%2Fb5elddN5a%2FPPOx%2FjAI%3D)
To create a new user account, click on the Create User Account button located below the table. This will take you to the "Create User" page.
When creating a new user account, select one of the following user types:
Federated:
Use the Federated option to perform just-in-time (JIT) user provisioning. Roles are assigned to federated users during their initial login attempt.
Enter the user's ‘Email Address’. The ‘Username’ field is automatically populated using the email address. Now select the appropriate ‘Roles’ from the drop-down list. Click the Submit button to create a new user account.

Local:
Use the Local option to create a user account that authenticates directly with DataBee. Upon account creation, the user receives an email at the specified address containing a one-time password (OTP) for use with DataBee.
Enter the user's ‘First Name’ and ‘Last Name’. Enter the user's ‘Email Address’ and the ‘Username’ field is automatically populated using the email address. Select the appropriate ‘Roles’ from the drop-down list. Click the Submit button to create a new user account.

Managing User Accounts
The ACTIONS column provides the following options for managing user accounts: Edit, Revoke API Key, Delete

Edit:
To edit an existing user account, click on the Edit icon located in the 'ACTIONS' column of the table. This will take you to the "User Details" page, where you can make the necessary changes and click on the Submit button.
.png?sv=2026-02-06&spr=https&st=2026-09-18T02%3A33%3A11Z&se=2026-09-18T02%3A49%3A11Z&sr=c&sp=r&sig=vyYZpmhpPkob80WDITUVhRa3%2Fb5elddN5a%2FPPOx%2FjAI%3D)
Revoke API Key:
Click on the Revoke API Key icon to deactivate the user's API key and prevent it from being used for authentication and API access.
Note:
This action does not prevent the user from accessing the web application, it simply revokes the existing API key the user may have created to access API endpoints with an API key.
Delete:
Click on the Delete icon to permanently remove the user account from the system.
Role-based Access Controls
Role-based access controls (RBAC) selectively allow users to use DataBee features based on what functions they perform for the enterprise. This allows enterprises to implement a policy of least privilege access.
DataBee Customer Roles
These roles are available in DataBee and can have multiple common industry job functions mapped onto them.
Security Analyst: Security Analysts can view all entities and data tied to their tenancy, but cannot edit the entities and campaigns generated from their data. There are two subtypes of security analysts in an organization: Cyber Risk Analysts and SOC Analysts, but for DataBee, they share a single role. Cyber Risk Analysts are responsible for measuring, proving, and ensuring that an organization's operations and procedures meet the company's regulatory and industry cyber risk standards. Measured on providing the necessary reporting and insights for organizations to enforce cyber risk standards. SOC Analysts are responsible for monitoring, analyzing, and responding to security issues detected and reported. They are measured on threat response remediation in both time to resolve and thoroughness of resolution.
Data Engineer: Data engineers can view all entities and data tied to their tenancy, and can edit the entities and campaigns generated from their data. They must be responsible for the data, platforms, and systems used by Threat Hunting, SOC, and Cyber Risk cybersecurity teams to effectively respond to security incidents. Measured on the ability to deliver solutions that improve cybersecurity teams' response to threats and incidents.
Administrator: Administrators manage their own instances of the analytics and data. They can configure their unique inputs and analytic results, and can edit the entities and campaigns generated from their data. This can be a Technical lead responsible for maintaining and configuring operating systems and platforms. Oversees the use of the DataBee product and has the widest authority within the system.
Controls: Controls users can only see the Controls section, but not other sections of UI.
Controls Admin: Controls Admin can access the Controls section, view content, request entitlements, and Policy Provisioner config page, but do not have access to other sections of the UI at this time.
Approver: Approvers can view and act on access review items assigned to them. They cannot create or manage campaigns, and only see their own assigned items.
Support Global Watcher: Support Global Watchers can manage Salesforce support tickets for their assigned tenant but do not have access to other tenant configurations.
RBAC Matrix
For each feature, a role can have the following permissions:
"r" for read (i.e., allow GET)
"w" for write (i.e., allow POST, PUT, and DELETE)
"r/w" both "r" and "w"
Primary Application
DataBee Web Application Permissions:
Features | Security Analyst | Data Engineer | Administrator | Controls | Controls Admin | Approver | Support Global Watcher |
|---|---|---|---|---|---|---|---|
DataBee Web Application Login | r/w | r/w | r/w | r/w | r/w | r/w | r/w |
Configuration | r/w | ||||||
Data Lake Configuration | r/w | ||||||
Policy Provisioner | r/w | r/w | |||||
License | r | ||||||
Notifications | r | r | r/w | ||||
Notes | r/w | r/w | r/w | ||||
User Account Preferences | r/w | r/w | r/w | r/w | r/w | r/w | r/w |
Manage/Lock User Accounts | r/w | ||||||
Searches | r/w | r/w | r/w | ||||
Data Feeds | r | r/w | r/w | ||||
Feed History | r | r | r | ||||
Feed Health Alert Settings | r | r/w | r/w | ||||
Dashboards | r/w | r/w | r/w | ||||
Entities | r/w | r/w | r/w | ||||
Content | r | r/w | r/w | r | r | ||
Rules | r | r/w | r/w | ||||
Suppress List | r/w | r/w | r/w | ||||
Chains | r/w | r/w | r/w | ||||
Data Health Alerts | r/w | r/w | r/w | ||||
Support Tickets | r/w | r/w | r/w | r/w | |||
Actions | r/w | r/w | |||||
Workflows | r/w | r/w | r/w | ||||
Connections | r/w | ||||||
Collections | r/w | r/w | r/w | ||||
Data Catalog | r | r | r | ||||
RiskFlow | r | r | r | ||||
Access Reviews | r | r | r/w | r | r/w | r/w | |
Campaign Dashboard | r | r | r | r | |||
User Manual/API Docs | r | r | r | r | r | r | r |
Session Management
Navigate to the top right corner of the DataBee UI and click on the configuration icon. Select Access Management from the dropdown menu that appears, and then click on Session Management. The "Session management" page will be displayed, where you can configure the user session duration. Enter the maximum idle time in seconds for web interface sessions and click on Submit.

Controls Reports
Navigate to the top right corner of the DataBee UI and click on the configuration icon. Select Access Management from the dropdown menu that appears, and then click on Controls Reports. This section is to manage DataBee user access to the Controls Reports. From the 'Select Report(s)' dropdown choose the report for which user need to be granted access or revoke access. The list of users who are authorized for that particular report are displayed in the table. To grant access to the users select the user and click on Grant Access button. To revoke the access select the user and click on Revoke Access button.
Under the ACTIONS column, click on the Edit Role icon to make changes. If you wish to delete the user access, click on the Revoke access icon.

When granting access to new users, set their Role as either Viewer or Publisher. Publisher role allows users to edit the report using our web editor. There are a limited number of Publisher seats available. A warning message will appear if you attempt to exceed the quota. Contact your DataBee Support representative if you need additional seats.
Select the GLOBAL READ check box to grant the user read-only access to all Controls Reports within the tenant, including existing reports and any Controls Reports created in the future.
.png?sv=2026-02-06&spr=https&st=2026-09-18T02%3A33%3A11Z&se=2026-09-18T02%3A49%3A11Z&sr=c&sp=r&sig=vyYZpmhpPkob80WDITUVhRa3%2Fb5elddN5a%2FPPOx%2FjAI%3D)
Framework Coverage
Refer to the Framework Coverage article for detailed information on how Dashboards and KPIs map to industry-standard compliance frameworks.
RiskFlow Access
See the RiskFlow Access article for information on how tenant administrators can grant and revoke user access to RiskFlow features.