Skip to main content

Role-Based Access Control

K
Written by Karthek S

Overview

Role-Based Access Control (RBAC) lets you give users access to only the areas of the Right-Hand Cybersecurity platform they are responsible for, instead of granting full administrative access. This is called separation of duties.

Right-Hand Cybersecurity provides specialized roles for this purpose.

There are five roles in RBAC:

  • Employee - End users who have been added to the portal to receive training emails, phishing simulation emails, vishing simulation calls, and posters.

  • Admin - Users who have full access to everything in Right-Hand Cybersecurity.

  • People Manager - Users who have access to the My Team dashboard for the people who report to them.

  • Content Admin - Users who manage training modules, phishing templates, and AI generation.

  • IT Admin - Users who manage PhishArm, EQA, HRM, and SMTP/integrations setup.

Why it matters:

  • Protects sensitive employee and performance data by limiting who can see it.

  • Reduces the number of users with full administrative access.

  • Lets you delegate work to the right teams without over-provisioning access.

  • Improves accountability and collaboration across security, communications, learning, and IT teams.

At the two ends of the scale, Employees receive training and simulations, while Admins have full access to everything in the Right-Hand platform. The sections below explain the three roles in between - People Manager, Content Admin, and IT Admin.

What the People Manager role can do

The People Manager role provides visibility into the training and phishing performance of a manager's own team, without broad access to the rest of the administration portal.

A People Manager can review performance for the employees in their direct and indirect reporting hierarchy, such as:

  • Training assignment and completion status

  • Phishing simulation performance

  • Direct-report performance

  • Indirect-report performance

  • Team-level areas that require attention

A People Manager cannot see employees outside their reporting hierarchy, access account-wide administrative settings, integrations, or content management, or view organization-wide data (unless they hold another role that grants it). Phishing information can also be enabled or disabled for managers from the administration console.

Assign this role to team leads, department heads, executives, and other people managers responsible for reinforcing training completion and phishing resilience within their teams.

What the Content Admin role can do

The Content Admin role provides access to content management without broad access to the rest of the administration portal.

A Content Admin can create, review, and manage content such as:

  • Phishing templates

  • Phishing landing pages

  • Training content

  • Posters

  • Nudges

  • Other supported awareness content

A Content Admin cannot access employee information, workforce performance data, integrations, or unrelated administrative settings.

Assign this role to security awareness teams, learning and development teams, internal communications teams, and other stakeholders responsible for content.

What the IT Admin role can do

The IT Admin role provides access to supported third-party integrations and technical configuration areas without broad administrative access to the entire portal.

Depending on the modules and integrations enabled for your account, an IT Admin can manage:

  • SCIM integrations

  • Active Directory integrations

  • Google directory integrations

  • SAML and identity-provider configuration

  • Security tool integrations

  • Messaging platform integrations

  • Other supported third-party integration settings

An IT Admin cannot access content, employee information, or workforce performance data, and does not receive broad administrative access.

Assign this role to IT administrators, identity teams, infrastructure teams, and security engineering teams responsible for connecting Right-Hand Cybersecurity to your technology environment.

Prerequisites

Before you begin, make sure that:

  • You have administrator access with permission to manage users and roles.

  • The Content Admin and/or IT Admin role is enabled for your account.

  • You know which employees need each role.

  • For IT Admin assignments, the relevant integrations or modules are enabled, so the role has areas to manage.

Warning: Assigning, changing, or removing a role immediately ends the user's active session. The user must sign in again before the new permissions take effect. If the user is actively working in the platform, notify them before you change their role so they are not interrupted unexpectedly.

Note: The steps to assign Content Admin and IT Admin are identical. Only the role you select in each procedure differs.

Step-by-Step Instructions for role assignments

Option 1: Assign a role to one user

Use this method to update a single employee.

  1. Go to Company Management.

  2. Open Employees.

  3. Locate the employee you want to update.

  4. Select Update Role in the employee list, or click on Edit and then click on Update role in the employee's profile.

  5. Assign the role you need — Content Admin or IT Admin.

  6. Check the "I understand that the role change will impact employee access to certain features based on their roles." field.

  7. Select Proceed to save the settings.

Result: The employee's role is updated and takes effect the next time they sign in.

Option 2: Assign a role to multiple users

Use this method to assign a role to several employees at once, such as when onboarding a team.

  1. Go to Settings.

  2. Open User Access.

  3. Select the role you want to assign - Content Admin or IT Admin.

  4. Open the Users tab.

  5. Click Add user.

  6. Click the checkbox or enter the email addresses of employees who should receive the role.

  7. Check the "I understand that adding these users to the role will affect their access to certain features and permissions." field.

  8. Validate the users, then click Proceed to Save the configuration.

Result: Every selected employee is assigned the role. The change takes effect for each user the next time they sign in.

Task 1: Review the permissions a role grants

Use this to confirm exactly what a role gives access to before or after assigning it.

  1. Go to Settings.

  2. Open User Access.

  3. Select the role - Content Admin or IT Admin.

  4. Open Permissions.

Result: You see the specific platform capabilities available to users assigned to that role.

Menu path: Settings → User Access → Roles → Permissions

Validation / Expected Outcome

Confirm the role was assigned successfully:

  • The assigned role appears next to the employee in Company Management → Users

  • The employee is listed under Settings → User Access → Roles → Users.

  • After the affected user signs in again, they can access only the areas the role permits.

  • The Permissions page (Settings → User Access → Roles→ Permissions) reflects the capabilities you expect for the role.

Frequently Asked Questions

1. Why should we use these roles instead of making someone a full administrator?

The specialized roles support least-privilege access and separation of duties. For example:

  • Content teams can manage awareness content without accessing employee performance data.

  • IT teams can manage integrations without accessing unrelated program settings.

  • Managers can review their reporting hierarchy without accessing the full administration console.

This reduces unnecessary access and helps you maintain stronger governance.

2. What can a Content Admin access?

A Content Admin can access supported content-management capabilities, including:

  • Phishing templates

  • Landing pages

  • Training content

  • Posters

  • Nudges

  • Ally Content

  • Other awareness content

They do not receive broad access to employee data, integrations, or unrelated administrative settings.

3. Can a Content Admin see employee training or phishing results?

No. The Content Admin role is designed for content creation and management. It does not provide broad access to employee-level performance or workforce data.

4. What can an IT Admin access?

An IT Admin can manage supported third-party integrations and technical configurations, including:

  • SCIM

  • Active Directory

  • Google directory integrations

  • SAML

  • Security tool integrations

  • Messaging platforms

  • Other supported integration settings

The specific permissions available to the role can be reviewed in the platform.

5. Can an IT Admin manage campaigns or view employee performance?

The IT Admin role is intended for integrations and technical configuration. It does not provide broad access to content management, campaign administration, or employee-performance information unless those permissions are explicitly included in the role configuration.

6. Can one user have more than one role?

Yes, but role availability depends on your platform configuration. Review the user's responsibilities and assign only the roles required for that user's job function.

7. How can we see exactly what permissions each role has?

Go to Settings → User Access → Roles → Permissions. This page shows the capabilities available to users assigned to that role.

8. Can roles be assigned to multiple users at once?

Yes. You can assign roles in bulk through Settings → User Access → Roles → Users → Add User. This is useful when assigning access to an entire team or a selected group of employees.

9. Does RBAC replace the existing administrator role?

No. The existing administrator role remains available. The new roles provide more limited alternatives for customers that do not want to grant full platform access to every stakeholder.

10. Is there an additional charge for the new roles?

No.

Related articles:

Did this answer your question?