Admins
Oblique organizations include three default roles:
- Organization owner: Owns the Oblique organization, can perform all actions in Oblique, and receives all communications. Each Oblique organization has one owner.
- Admin: Manages the organization, including managing integrations, users, attributes, accounts, groups, resources, and entitlements, and creating Oblique API keys.
- Member: Member of the organization. Members can become members of groups and have entitlements granting them access.
Objects can also have owners. Object owners are users or groups who can make or approve changes to an object, such as an attribute-based group, team group, or reporting group. By default, Oblique admins are owners of all groups in Oblique.
Although admins can create Oblique API keys, the organization owns these keys, not the individual admin. When you remove an admin, the API keys remain valid.
By default, the organization owner receives all communications about Oblique, including billing and security notifications.
Add an admin
Section titled “Add an admin”Navigate to the admins page.
- Under Admins, select Add admin.
- Search for and select the user you wish to add as an Oblique admin.
- Select Add admins.
Remove an admin
Section titled “Remove an admin”Navigate to the Admins page.
- Under Admins, locate the user to be removed. If you have a lot of admins, use the search bar to more easily find them.
- For the selected user, in the More menu, select Remove admin….
- Confirm you want to remove the admin, and select Remove admin.
Change the organization owner
Section titled “Change the organization owner”Navigate to the Admins page.
- Under Organization owner, select Change owner.
- Search for and select the user you wish to make the new owner.
- Select Update owner.
Verify ownership of an Oblique organization
Section titled “Verify ownership of an Oblique organization”Oblique requires you to show control of your organization’s domain when requesting help from our support team for certain issues, such as claiming ownership of your organization’s Oblique tenant. Our support team will ask you to do one of the following:
- Respond to a confirmation email sent to an address at your organization, such as to the existing owner
- Set a DNS TXT record for your domain
Permission matrix
Section titled “Permission matrix”By default, all members of an organization can make change requests but cannot make changes unilaterally. Members who are the owners of affected objects can approve requests for those objects, including their own requests. Admins can make or approve any change.
Users and resources cannot be directly added to Oblique. Instead, they are automatically imported when they are discovered in and synced from an integration.
| Target | Action | Description | Is a request | Admin | Object owner | User |
|---|---|---|---|---|---|---|
User | CREATE | Import a user. | NO | NO | n/a | NO |
Team | CREATE | Create a team group. | YES | YES | n/a | REQUEST |
Team | UPDATE | Update a team group’s description. | Coming soon | YES | YES | NO |
Team | DELETE | Delete a team group. | YES | YES | YES | REQUEST |
TeamMember | CREATE | Add a user to a team group. | YES | YES | YES | REQUEST |
TeamMember | DELETE | Remove a user from a team group. | YES | YES | YES | REQUEST |
TeamOwner | CREATE | Add an owner to a team group. | YES | YES | YES | REQUEST |
TeamOwner | DELETE | Remove an owner from a team group. | YES | YES | YES | REQUEST |
Group | CREATE | Create an attribute-based group. | NO | YES | n/a | NO |
| Create a reporting group. | NO | YES | n/a | YES | ||
Group | DELETE | Delete an attribute-based group or reporting group. | NO | YES | YES | NO |
GroupOwner | CREATE | Add an owner to an attribute-based group or reporting group. | YES | YES | YES | REQUEST |
GroupOwner | DELETE | Remove an owner from an attribute-based group or reporting group. | YES | YES | YES | REQUEST |
Resource | CREATE | Import a resource. | NO | NO | n/a | NO |
Entitlement | CREATE | Create an entitlement for a resource. | YES | YES | n/a | Coming soon |
Entitlement | UPDATE | Edit an entitlement for a resource. | YES | YES | n/a | Coming soon |
Entitlement | DELETE | Revoke an entitlement for a resource. | YES | YES | n/a | Coming soon |
AccessReview | CREATE | Start an access review. | NO | YES | n/a | NO |
AccessReview | UPDATE | Confirm a review’s scope, complete a review, or re-open a review. | NO | YES | n/a | NO |
AccessReview | DELETE | Delete a review. | NO | YES | n/a | NO |
AccessReviewApp | CREATE | Add an app to a review’s scope. | NO | YES | n/a | NO |
AccessReviewApp | DELETE | Remove an app from a review’s scope. | NO | YES | n/a | NO |
AccessReviewAccount | CREATE | Add an account to an app in a review. | NO | YES | n/a | NO |
AccessReviewAccount | DELETE | Remove an account from an app in a review. | NO | YES | n/a | NO |
AccessReviewDecision | UPDATE | Record, change, or clear a decision on an account. | NO | YES | n/a | NO |
AccessReviewScreenshot | CREATE | Attach a screenshot to capture accounts in an app for a review. | NO | YES | n/a | NO |
AccessReviewScreenshot | DELETE | Remove a screenshot capturing accounts for an app in a review. | NO | YES | n/a | NO |
AccessReviewRemediationEvidence | CREATE | Add remediation evidence for an app in a review. | NO | YES | n/a | NO |
AccessReviewRemediationEvidence | DELETE | Remove remediation evidence from an app in a review. | NO | YES | n/a | NO |
Integration | CREATE | Add an integration. | NO | YES | n/a | NO |
Integration | UPDATE | Update an integration’s settings, including approvals from Slack. | NO | YES | n/a | NO |
ServiceAccount | CREATE | Create an API key. | NO | YES | n/a | NO |
ServiceAccount | DELETE | Revoke an API key. | NO | YES | n/a | NO |
Admin | CREATE | Add an admin. | NO | YES | n/a | NO |
Admin | DELETE | Remove an admin. | NO | YES | n/a | NO |
Owner | UPDATE | Change the organization owner. | NO | YES | n/a | NO |
Only admins can view recommendations and open requests from them.
Only admins can run access reviews.