To add a new user to the Chronicle SOAR platform:

  1. Navigate to Settings > Organization > User Management.
    Click on the  icon on the top right of the screen. The Add User dialog box opens.

  2. Fill out the relevant information and select from the drop-down list the User Type, License Type, Advanced Reports Access, SOC Role, Login ID, Permissions Group, and Environments.

    Everything in the drop-down list can be edited after user creation.

    Note that the Login ID field should contain an email address for internal issues. If you edit the Login ID field the user is on pending status until they relog in with their new credentials.

    If you are configuring new users for SAML authentication, make sure to select the required SAML provider in the User Type field and to fill out the Login ID field according to the SAML specifications. The Email field for SAML/LDAP users is for notification purposes.

    If you've selected a Permission group which has edit permissions to All Environments this will appear here. To change this at Permission group level, select None for All Environments in the Permissions screen. Once you do that, you can select one to several environments for the user to have access to.
  3. Click Add. The new user appears in the list of Users.
  4. An email invitation is sent automatically to the user. For internal users, the status remains as “Pending” until they accept the email invitation to join Chronicle SOAR and create a password.
    The password link is valid for 3 days for an internal user. After that period, the Admin can click Send Invitation in the User Management screen to send the user a new link.
    For SAML users the status remains as “Pending” until the first time they login. They can log in directly to the platform; they don't necessarily need to log in through the mail invitation. 
  5. Click on the picture icon to upload a PNG file up to 400kb for this new User.