Atlas Capabilities & Permissions
Atlas leverages 4 built-in Splunk Roles that automatically assign Splunk permissions in order to use features effectively. This page breaks down the capabilities and feature access associated with each Atlas role.
Role Overview
Atlas provides a role-based access control system with four distinct roles that determine what users can access and modify within the platform:
| Role | Description |
|---|---|
| No Access | No Atlas feature access. Does not count as a License Seat. |
| Atlas Viewer | Read-focused access to Atlas features. Can review dashboards, reports, and metrics, and has limited Search Hub action access based on ownership and Splunk permissions. Does not count as a License Seat. |
| Atlas Creator | All Viewer permissions plus the ability to create and modify content within supported Atlas features. Cannot perform Atlas administrative functions or manage users. |
| Atlas Admin | Full access to Atlas features, including administrative functions, configuration settings, and the ability to assign roles to other users. |
In a Seat-based license, only Atlas Creators and Atlas Admins consume seats when given access to Atlas. Atlas Viewers do not consume seats.
Role Capability Matrix
The following table outlines the key Splunk capabilities assigned to each Atlas role, which enable core functionality across the platform:
| Capability | No Access | Atlas Viewer | Atlas Creator | Atlas Admin | Used For |
|---|---|---|---|---|---|
edit_log_alert_event | ✓ | ✓ | ✓ | Atlas logs | |
list_deployment_server | ✓ | ✓ | ✓ | Forwarder Awareness | |
_internal index access | ✓ | ✓ | ✓ | Most Atlas Features | |
_audit index access | ✓ | ✓ | ✓ | Data Hub, Search Library, Data Utilization, PCA | |
schedule_search | ✓ | ✓ | Search Hub, Scheduling Assistant | ||
dispatch_rest_to_indexers | ✓ | ✓ | Search Hub, App Awareness, Scheduling Assistant | ||
list_search_head_clustering | ✓ | ✓ | App Awareness | ||
list_dist_peer | ✓ | ✓ | Data Hub, Data Management inventory, server selection | ||
_introspection index access | ✓ | ✓ | Search Hub, Migration Helper, Scheduling Assistant | ||
edit_user | ✓ | User role assignment | |||
admin_all_objects | ✓ | Access to all Knowledge Objects (Search Hub) |
Atlas feature access still depends on underlying Splunk permissions. Atlas roles determine which Atlas controls are available, while Splunk read and write access determine which searches, knowledge objects, or data a user can actually inspect or modify.
Permissions By Feature
Atlas Configurations
| Action | No Access | Atlas Viewer | Atlas Creator | Atlas Admin |
|---|---|---|---|---|
| View Settings, license, and target information | ✓ | ✓ | ✓ | |
| View user settings | Self only | Self only | ✓ | |
| Manage Atlas configuration, licenses, users, and targets | ✓ | |||
| View Activity Monitor | ✓ | ✓ | ✓ |
Data Hub
| Action | No Access | Atlas Viewer | Atlas Creator | Atlas Admin |
|---|---|---|---|---|
| Access App | ✓ | ✓ | ✓ | |
| View datasets, definitions, and utilization | ✓ | ✓ | ✓ | |
| Edit Data Definitions and use bulk actions, including Email Report | ✓ | ✓ |
Search Hub
| Action | No Access | Atlas Viewer | Atlas Creator | Atlas Admin |
|---|---|---|---|---|
| Access App | ✓ | ✓ | ✓ | |
| View governance results and use Fix Search on owned searches | ✓ | ✓ | ✓ | |
| View searches with Splunk read access | ✓ | ✓ | ||
| Edit searches with Splunk write access | ✓ | ✓ | ||
| Use standard bulk actions, including Ignore, Reschedule, and Email Report | ✓ | ✓ | ||
| Auto-Balance searches and delete eligible local saved searches | ✓ | |||
| Create and manage Search Governance rules | ✓ | ✓ | ||
| Configure Search Hub and governance automation | ✓ |
Atlas roles determine which Search Hub controls are available. Splunk read and write permissions determine which searches Atlas Creators and Atlas Admins can view or edit; Atlas Viewers are limited to searches they own and supported actions on those searches.
Premium Features
STIG Compliance
| Action | No Access | Atlas Viewer | Atlas Creator | Atlas Admin |
|---|---|---|---|---|
| Access App | ✓ | ✓ | ✓ | |
| View Systems | ✓ | ✓ | ✓ | |
| Create/Edit/Delete Systems | ✓ | |||
| Edit Target Information | ✓ | ✓ | ||
| Update Vulnerability | ✓ | ✓ | ||
| Create Target/STIG Library | ✓ | ✓ |
License Considerations
-
Enterprise License: All Splunk users automatically have access to Atlas with the Atlas Viewer role. Users can be assigned higher roles without seat-based license limits applying.
-
Seat-based License: Users explicitly assigned Atlas Creator or Atlas Admin, and given access, count against the total seat limit. Atlas Viewers do not count against the seat limit. Users without an assigned Atlas role default to No Access. Users with Creator or Admin roles, but not given access are interpreted as Atlas Viewers.