Stairwell Platform Access Policy
Which Stairwell teams can access your environment, at what level, and what each of them uses that access for.
Three Stairwell teams hold access to customer environments, for onboarding, operations, and troubleshooting. This page states which, at what level, and why, because it is a question your security review will ask and you should not have to request the answer.
| Team | Access level | What they use it for |
|---|---|---|
| Customer Success | Organization and environment admin | Configuration, troubleshooting, and training your team on search, deployment, and the rest of the platform |
| Threat Team | Power user | Threat hunts, threat report management, and YARA rule management |
| Engineering | Platform admin | Troubleshooting backend and frontend issues |
What does that mean in practice?
Customer Success acts at the same level as your own administrators, which is what lets them fix a misconfigured environment or a broken SSO connection without asking you to reproduce it.
The Threat Team works as an analyst would: hunting, managing threat reports, and writing YARA rules. This is the access behind the rule feeds you subscribe to and the research that informs them.
Engineering access exists to diagnose platform faults, and is the level reached for when something is wrong with Stairwell rather than with your configuration.
What is recorded?
Actions in Stairwell are attributed to the account that took them, whether that account is yours or ours. An opinion carries the user who set it and their comment; a threat report records who added an indicator. That attribution is why disabled accounts are retained rather than deleted, so the record keeps pointing at somebody real. See User Roles and Types.
What should I read next?
- Environments, for how data is partitioned in the first place.
- User Roles and Types, for the access levels named above.
- Who to Contact for Support, for reaching the teams on this page.
Updated 19 days ago