Skip to main content
Applies to BloodHound Enterprise and CE

Purpose

This article provides a summary of assignable roles that are available when creating new users in BloodHound.

Creating users

Users are created through Settings Administration Manage Users, and clicking the button Create User. The following properties must be set on each user:

User Role Definitions

BloodHound offers multiple roles for access control. Each user must be assigned one role. In BloodHound Enterprise, Environment Targeted Access Control (ETAC) can further limit which environments User and Read-only roles can access. ETAC does not change the baseline permissions in the role matrix below. Instead, it limits which environments those permissions apply to. For OpenGraph extensions, BloodHound separates read and write permissions. Users without permission to upload or delete extension schemas can still view extension content that their role allows, but the Upload and Delete extension buttons remain disabled.
Scroll right to view the full table of permissions for each role.