Entitlements

Understand entitlement-based access controls

Overview

An entitlement is an access control that permits a principal (client or end user) to access a particular application, API operation, or resource. The Intelligent Risk Platform uses entitlements to control access to applications (e.g. Risk Modeler), products (e.g. Data Vault), data (e.g. ESG, Location Intelligence), and models that are restricted by license.

Entitlement management ensures that Intelligent Risk Platform tenants only access the products and services in line with their contract terms. Licensing and entitlement management software provides a platform for these controls, in line with an organization’s authorizations, permissions, privileges, access management, and policies.

Currently, the Intelligent Risk Platform supports the following entitlements: RI-DATAVAULT, RI-EXPOSUREIQ, RI-RISKMODELER, RI-TREATYIQ, and RI-UNDERWRITEIQ.

To access and use API operations that are restricted by entitlement, a client application must belong to a group that has been assigned the appropriate entitlement to perform that operation. Entitlement-based access controls are frequently tied to role-based access controls. For details, see Groups.

IC-VPN entitlement

VPN for Data Bridge is a separately licensed product that enables Intelligent Risk Platform tenants to create and manage VPN connections to Data Bridge.

Tenant Data API operations are generally restricted to principals with the Admin or Data Bridge role. Operations for managing VPN connections require the IC-VPN entitlement.

CollectionOperationEntitlementRole
Tenant DataSearch Encryption KeysIC-VPNAdmin, Data Bridge Admin
Tenant DataCreate Encryption KeyIC-VPNAdmin, Data Bridge Admin
Tenant DataGet Encryption KeyIC-VPNAdmin, Data Bridge Admin
Tenant DataUpdate Encryption KeyIC-VPNAdmin, Data Bridge Admin
Tenant DataSearch VPN ConnectionsIC-VPNAdmin, Data Bridge Admin
Tenant DataCreate VPN ConnectionIC-VPNAdmin, Data Bridge Admin
Tenant DataGet VPN ConnectionIC-VPNAdmin, Data Bridge Admin
Tenant DataDelete VPN ConnectionIC-VPNAdmin, Data Bridge Admin
Tenant DataUpdate VPN ConnectionIC-VPNAdmin, Data Bridge Admin

RI-DATAVAULT entitlement

Data Vault is a separately licensed application that enables Intelligent Risk Platform tenants to manage archives of data servers and databases.

Admin Data API operations are generally restricted to principals with the Data Admin role. Operations for managing archives and snapshots require the RI-DATAVAULT entitlement.

CollectionOperationEntitlementRole
ArchivesCreate ArchiveRI-DATAVAULTData Admin
ArchivesDelete ArchiveRI-DATAVAULTData Admin
ArchivesGet ArchiveRI-DATAVAULTData Admin
ArchivesRestore ArchiveRI-DATAVAULTData Admin
ArchivesSearch ArchiveRI-DATAVAULTData Admin
ArchivesUpdate ArchiveRI-DATAVAULTData Admin
JobsGet Admin Data JobData Admin
JobsSearch Admin Data JobsData Admin
JobsUpdate Admin Data JobData Admin
SecurablesArchive SecurableRI-DATAVAULTData Admin
SecurablesDelete SecurableData Admin
SecurablesGet SecurableData Admin
SecurablesSearch SecurablesData Admin
SecurablesUpdate SecurableData Admin
SnapshotsCreate Archive from SnapshotRI-DATAVAULTData Admin
SnapshotsGet Database by SnapshotRI-DATAVAULTData Admin
SnapshotsGet Database by SnapshotRI-DATAVAULTData Admin
SnapshotsSearch Databases by SnapshotRI-DATAVAULTData Admin
SnapshotsSearch SnapshotsRI-DATAVAULTData Admin

RI-EXPOSUREIQ entitlement

Principals assigned the RI-EXPOSUREIQ entitlement may access operations and data available to licensed ExposureIQ tenants.

Principals with the RI-EXPOSUREIQ entitlement may also access the Data Bridge API.

RI-RISKMODELER entitlement

Principals assigned the RI-RISKMODELER entitlement may access operations and data available to licensed Risk Modeler tenants.

Principals with the RI-RISKMODELER entitlement may also access the Risk Modeler API and Data Bridge API.

The operations accessible to clients with the RI-RISKMODELER entitlement are generally in the Risk Data API.

RI-TREATYIQ entitlement

Principals assigned the RI-TREATYIQ entitlement may access operations and data available to licensed TreatyIQ tenants.

RI-UNDERWRITEIQ entitlement

Principals assigned the RI-UNDERWRITEIQ entitlement may access operations and data available to licensed TreatyIQ tenants.

Principals with the RI-UNDERWRITEIQ entitlement may also access the Risk Modeler API.