Skip to content

Platform Administrators & Role-Based Access Control (RBAC)

1. Executive Summary & Value Proposition

Large organizations, distributed security teams, and compliance auditors require distinct platform access permissions based on operational duties. Granting blanket super-admin privileges creates significant insider risk and violates the Principle of Least Privilege. SimuPhish’s Role-Based Access Control (RBAC) (Main Navigation > Settings > Role Management or User Management) allows organizations to provision and manage multiple administrators, assigning distinct operational roles—including Super Admin, Admin, and Sub-Admin—with tailored permissions across campaign execution, template editing, employee roster management, and compliance reporting.


2. The Threat Landscape & The Real-World Problem Solved

  • Excessive Privilege Exposure: When all team members share full administrative credentials, accidental configuration changes or malicious insider actions can compromise organization-wide security programs.
  • Auditor Scrutiny (SOC 2 & ISO 27001): Compliance frameworks strictly require documented role separation ensuring that team members only access data necessary for their specific role.
  • Decentralized Multi-Department Management: Divisional security coordinators (e.g., European division, APAC branch) need to manage local awareness drills without modifying global corporate policies.

3. How It Works (The User Journey)

graph TD
    A[Primary Tenant Administrator] --> B[Settings > Role Management]
    B --> C[Add Sub-Admin Workflow]
    C --> D1[Assign Identity: Name, Corporate Email]
    C --> D2[Select RBAC Role: Super Admin, Admin, Sub-Admin]
    C --> D3[Configure Granular Permission Scopes]
    D3 --> E1[Campaign Management: Create, Launch, Stop]
    D3 --> E2[Threat Forge: Create & Edit Templates]
    D3 --> E3[User Directory: Sync & Edit Employee Lists]
    D3 --> E4[Reporting & Compliance: View & Export Posture Data]
    D3 --> E5[Settings & Delivery: Configure SMTP & Integrations]

The Administrator Experience

  1. Navigating to Role Management: Go to Main Navigation > Settings and click the Role Management tab.
  2. Sub-Admins Overview Table:
  3. View all provisioned platform administrators, displaying Name, Email, Assigned Role, Status (Active/Inactive), and Last Login.
  4. Toggle administrator status instantly between Active and Inactive without deleting their account.
  5. Use search and filter bars to locate specific administrator profiles quickly.
  6. Adding a New Administrator ("Add Sub-Admin"):
  7. Click Add Sub-Admin to launch the provisioning drawer.
  8. Enter the administrator's Full Name, Corporate Email Address, and Phone Number.
  9. Selecting Roles & Permission Tiers:
  10. Super Admin: Full, unrestricted control over the entire tenant, including billing, API keys, SMTP configuration, and administrator provisioning.
  11. Admin: Operational authority to manage campaigns, LMS training missions, employee rosters, and generate executive reports, without access to platform billing or tenant-level settings.
  12. Sub-Admin / Security Analyst: Focused operational access to monitor live simulation campaigns, review reported emails in Phish Detect, and generate departmental analytics.
  13. Granular Permission Scopes:
  14. Toggle specific operational privileges: Campaign Execution, Template Studio Access, Employee Directory Management, Incident Triage, and Compliance Export.

4. Key Business Benefits & Measurable ROI

  • Enforce Least Privilege: Restrict sensitive configuration access to authorized personnel while delegating day-to-day campaign tasks.
  • Satisfy SOC 2 & ISO 27001 Requirements: Provide auditors with clear, documented evidence of access segmentation and administrative boundaries.
  • Empower Regional Security Leads: Allow regional business units to manage their own awareness initiatives safely without risking global tenant configurations.
  • Prevent Unintended Outages: Avoid catastrophic misconfigurations by locking critical delivery engine and integration settings.

5. Real-World Attack Scenario & Case Study

Scenario: The Regional Branch Delegation

  • The Situation: A global financial institution with 18,000 employees needed regional security managers in London, Singapore, and New York to create localized phishing simulations reflecting regional banking regulations.
  • SimuPhish Action: The primary CISO provisioned three regional Sub-Admin accounts. Each regional admin was granted permissions to create campaigns, review local triage reports, and edit local email templates, but restricted from modifying global SMTP configurations, tenant billing, or global risk formulas.
  • Outcome: Regional teams launched highly tailored, culturally relevant training drills in parallel, while corporate security maintained complete governance and control over global platform integrity.