Stairwell Platform Access Policy

Which Stairwell teams can access your environment, at what level, and what each of them uses that access for.

Three Stairwell teams hold access to customer environments, for onboarding, operations, and troubleshooting. This page states which, at what level, and why, because it is a question your security review will ask and you should not have to request the answer.

TeamAccess levelWhat they use it for
Customer SuccessOrganization and environment adminConfiguration, troubleshooting, and training your team on search, deployment, and the rest of the platform
Threat TeamPower userThreat hunts, threat report management, and YARA rule management
EngineeringPlatform adminTroubleshooting backend and frontend issues

What does that mean in practice?

Customer Success acts at the same level as your own administrators, which is what lets them fix a misconfigured environment or a broken SSO connection without asking you to reproduce it.

The Threat Team works as an analyst would: hunting, managing threat reports, and writing YARA rules. This is the access behind the rule feeds you subscribe to and the research that informs them.

Engineering access exists to diagnose platform faults, and is the level reached for when something is wrong with Stairwell rather than with your configuration.

What is recorded?

Actions in Stairwell are attributed to the account that took them, whether that account is yours or ours. An opinion carries the user who set it and their comment; a threat report records who added an indicator. That attribution is why disabled accounts are retained rather than deleted, so the record keeps pointing at somebody real. See User Roles and Types.

What should I read next?


Did this page help you?