Hey folks, been running our Falcon instance for about a year now. We're growing fast and I'm getting swamped with routine tasks—approving sensor updates, managing host groups, handling policy exceptions for dev teams.
I need to hand off some of this day-to-day work to a couple of trusted team leads, but I'm nervous about giving them full Administrator access. I've seen what happens when too many people have the "keys to the kingdom" in other tools.
Specifically, I'm looking for a way to let someone:
* Approve software runs for a specific application control policy.
* Manage host groups for their department's machines.
* Maybe view detection events for their own groups.
Has anyone set up a granular role-based access system successfully? I've poked around in the Falcon console and see the custom roles, but I'm unsure how to map real-world tasks to those permissions cleanly. Any gotchas or best practices you've learned?