Skip to main content
Version: Atlas v5.1

Atlas Capabilities & Permissions

Atlas leverages 4 built-in Splunk Roles that automatically assign Splunk permissions in order to use features effectively. This page breaks down the capabilities and feature access associated with each Atlas role.

Role Overview

Atlas provides a role-based access control system with four distinct roles that determine what users can access and modify within the platform:

RoleDescription
No AccessNo Atlas feature access. Does not count as a License Seat.
Atlas ViewerRead-focused access to Atlas features. Can review dashboards, reports, and metrics, and has limited Search Hub action access based on ownership and Splunk permissions. Does not count as a License Seat.
Atlas CreatorAll Viewer permissions plus the ability to create and modify content within supported Atlas features. Cannot perform Atlas administrative functions or manage users.
Atlas AdminFull access to Atlas features, including administrative functions, configuration settings, and the ability to assign roles to other users.

In a Seat-based license, only Atlas Creators and Atlas Admins consume seats when given access to Atlas. Atlas Viewers do not consume seats.

Role Capability Matrix

The following table outlines the key Splunk capabilities assigned to each Atlas role, which enable core functionality across the platform:

CapabilityNo AccessAtlas ViewerAtlas CreatorAtlas AdminUsed For
edit_log_alert_eventAtlas logs
list_deployment_serverForwarder Awareness
_internal index accessMost Atlas Features
_audit index accessData Hub, Search Library, Data Utilization, PCA
schedule_searchSearch Hub, Scheduling Assistant
dispatch_rest_to_indexersSearch Hub, App Awareness, Scheduling Assistant
list_search_head_clusteringApp Awareness
list_dist_peerData Hub, Data Management inventory, server selection
_introspection index accessSearch Hub, Migration Helper, Scheduling Assistant
edit_userUser role assignment
admin_all_objectsAccess to all Knowledge Objects (Search Hub)

Atlas feature access still depends on underlying Splunk permissions. Atlas roles determine which Atlas controls are available, while Splunk read and write access determine which searches, knowledge objects, or data a user can actually inspect or modify.

Permissions By Feature

Atlas Configurations

ActionNo AccessAtlas ViewerAtlas CreatorAtlas Admin
View Settings, license, and target information
View user settingsSelf onlySelf only
Manage Atlas configuration, licenses, users, and targets
View Activity Monitor

Data Hub

ActionNo AccessAtlas ViewerAtlas CreatorAtlas Admin
Access App
View datasets, definitions, and utilization
Edit Data Definitions and use bulk actions, including Email Report

Search Hub

ActionNo AccessAtlas ViewerAtlas CreatorAtlas Admin
Access App
View governance results and use Fix Search on owned searches
View searches with Splunk read access
Edit searches with Splunk write access
Use standard bulk actions, including Ignore, Reschedule, and Email Report
Auto-Balance searches and delete eligible local saved searches
Create and manage Search Governance rules
Configure Search Hub and governance automation

Atlas roles determine which Search Hub controls are available. Splunk read and write permissions determine which searches Atlas Creators and Atlas Admins can view or edit; Atlas Viewers are limited to searches they own and supported actions on those searches.

Premium Features

STIG Compliance

ActionNo AccessAtlas ViewerAtlas CreatorAtlas Admin
Access App
View Systems
Create/Edit/Delete Systems
Edit Target Information
Update Vulnerability
Create Target/STIG Library

License Considerations

  • Enterprise License: All Splunk users automatically have access to Atlas with the Atlas Viewer role. Users can be assigned higher roles without seat-based license limits applying.

  • Seat-based License: Users explicitly assigned Atlas Creator or Atlas Admin, and given access, count against the total seat limit. Atlas Viewers do not count against the seat limit. Users without an assigned Atlas role default to No Access. Users with Creator or Admin roles, but not given access are interpreted as Atlas Viewers.