dnswatchdog.iodocs
Brand Protection

Roles and access

What each organisation role can do with copycat findings, and the Brand Protection role for teams that work nothing else.

Brand Protection follows the organisation's roles, with one addition: a role for a team that works copycat domains and nothing else.

What each role can do

CapabilityAdminMemberRead-onlyBrand Protection
View findings, the detail view and finding pages✅✅✅✅
Filter, search, sort and export findings✅✅✅✅
Set a finding's status (watch, flag, ignore with a reason, back to pending)✅✅❌✅
Raise a Jira ticket for a finding✅✅❌✅
Add domains by hand✅✅❌✅
Add a note to a finding✅✅❌✅
Manage brands on the Brands page✅✅❌❌
See the rest of the product (dashboard, inventory, issues, settings)✅✅✅❌
Configure the Jira connection and notification channels✅✅❌❌

Read-only users see the status menus disabled with a read-only mode hint.

Raising Jira tickets — from the list, the detail view, the finding page or the Review Pipeline — needs an enabled Jira connection, configured by an Admin or Member under Integrations. Without one the Jira column shows a dash.

The Brand Protection role

Give the Brand Protection role to a brand, legal or agency team that should see copycat findings and nothing else. For that role:

  • Brand Protection is the only entry in the sidebar, alongside their own profile and the help menu. Search and the inventory counts are not shown.
  • Every other page redirects to Brand Protection before it renders, and the API refuses the role outside Brand Protection — the restriction is enforced server-side, not merely hidden.
  • Within Brand Protection the role holds a Member's powers: it triages findings, exports them and raises Jira tickets for them. It can see whether a Jira connection exists, but cannot configure one.
  • The role does not manage brands. An Admin or Member curates the Brands page on the team's behalf.

Admins assign the role from the Organisation settings page like any other role; the role must exist in your organisation's authentication instance, which DNS Watchdog sets up when Brand Protection is enabled.

Who changed what

Every status change stamps the finding with who made it and when, shown in the detail view and on the finding page, and an ignore keeps its reason beside the finding — in the detail view, on the finding page, in the Review Pipeline's Ignored list and in exports.

On this page