Enable SOAR access
This document is for Google Security Operations admins who want to provide users with access to SOAR features in Google SecOps (such as managing cases).
Before you begin
These procedures are based on the assumption that you have already onboarded to the Google SecOps platform, enabled the Chronicle API, and started working with IAM permissions. The following procedures may vary slightly, depending on whether you configured a Cloud Identity provider or a third-party identity provider.
Enable access
Define either a predefined role or a custom role. The custom role must contain the following minimum baseline permissions:
chronicle.dataAccessScopes.listchronicle.preferenceSets.getchronicle.preferenceSets.updatechronicle.instances.getchronicle.socRoles.getchronicle.userNotifications.getchronicle.userLocalizations.getchronicle.moduleSettings.rebrandingchronicle.integrations.getchronicle.legacySoarAdvancedReports.getchronicle.environmentGroups.getchronicle.moduleSettingsProperties.getchronicle.legacySoarUsers.get
For more information about baseline permissions and mapping to specific SOAR actions, see Required permissions for every role.
If you're using the Cloud Identity provider, map user email groups into the email group mapping page.
If you're using a third-party identity provider, map IdP groups into the IdP group mapping page.
You can choose the control access parameters that meet your needs. For more information, see SOAR access overview.
Need more help? Get answers from Community members and Google SecOps professionals.