Skip to content

Add admin tools for managing Groups and Users max confidence levels #5692

Closed

Description

The introduction of confidence level to Users and Groups will leave existing platforms in a potentially unstable state: the existing users and groups are not migrated to any confidence value, and it will be mandatory to have a proper confidence policy implemented to each platform according to the CTI team needs.

There will be a delay between the introduction of confidence levels and their usage in the platform ingestion mechanisms. Admins will have time to setup their confidence policy, then update to the next version of OpenCTI that leverages it into the platform internals.

This issue i about providing platform admins with tools to facilitate greatly the implementation of their confidence policy across users and groups.

The easiest way to tackle this problem is to configure the existing groups with a max confidence level.
As Users are members of groups (if not, it means they do not have any permissions in the app), they will inherit the group(s) confidence level properly.

subtasks

  • add a popup dialog at the start of the platform (login or refresh) that warns platform admins that there is problems with their confidence policy. Specifically, we warn about groups without confidence level set. No issue, no popup.
  • Highlight in the UI issues with users and groups without confidence level, with alerts, icons, and tooltips
  • add the ability to select groups when creating a user (if groups are specified this way, they overrides the default groups that have been set in the platform)
  • show group max confidence level in the Select UI when creating a user
  • show groups confidence level in the user edition > group tab

linked to

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Assignees

Labels

featureuse for describing a new feature to developsolveduse to identify issue that has been solved (must be linked to the solving PR)

Type

No type

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions