Skip to main content
Access to the LARK is managed centrally through Keycloak, which provides single sign-on across all of the appliance’s applications. Every application routes its authentication through Keycloak, so operators authenticate once and then reach the applications their role permits.

Access model

Single sign-on

Rather than each application maintaining its own logins, Keycloak authenticates operators once and grants access to the applications they are permitted to use.

Role-based access

Access is determined by the role assigned to an account, so analysts and administrators receive the access appropriate to their function.

Administrator credentials

An administrator account is provided with each appliance. These credentials are delivered with the appliance and are not included in this documentation. The administrator uses them to sign in and to create accounts for other operators.
Creating operators, assigning roles, and removing access are administrative tasks covered on the user management page. This page describes only how identity and access operate at a high level.