This article explains how to create user accounts and manage role-based access control (RBAC) across the core tools in your SOCFortress stack: Graylog, Grafana, Wazuh, CoPilot, Shuffle, and Velociraptor. Each platform handles users and permissions slightly differently, but the overall goal is the same: give each person the access they need—nothing more, nothing less.
copilot.
velociraptor-ui.
Use the links below as your primary references for creating users and assigning roles in each platform. Replace domain placeholders (like ) with your actual internal domain.
https://copilot./user
https://copilot.soc.yourcompany.local/user
https://velociraptor-ui./app/index.html#/users
velociraptor-ui.soc.yourcompany.local
To keep things consistent across the stack, we recommend using a common set of roles and mirroring them in each tool as closely as possible.
For environments using internal or custom domains (for example, customer-facing stacks or MSSP multi-tenant deployments), ensure:
wazuh-ui
graylog01-ui
grafana
If you need help designing a consistent RBAC model across all tools or mapping your internal roles (e.g., Tier 1 / Tier 2 / Tier 3 analysts) into this stack, contact the SOCFortress team for guidance.
Was this article helpfu?
Thank you for voting
You are related to multiple companies. Please select the company you wish to login as.