Existing access controls for a Carbon Black Cloud Organization will apply to Audit and Remediation Features.
Only Users with the correct permissions can see and use the Live Query Features.
CSR Roles cannot see the Live Query Features in a organization, however they may have access to turn on of off the Live Query feature in an Organization.
Existing 2FA or SAML setups will be used as before.
Tamper protections are in place to prevent unauthorized deletion of the sensor components. However, by design, osqueryi can still be run on the endpoint.