In Splunk, the architect designs the RBAC model to enforce least privilege. Roles inherit capabilities and are assigned index access. A SOC Analyst role might have access to `network_*` indexes but not `hr_*` or `finance_*` indexes. Capability restrictions prevent analysts from editing saved searches or exporting large datasets.
The architect also designs audit logging for the security platform itself. Splunk's `_audit` index records all user activity: logins, searches, dashboard views, and data exports. This enables insider threat detection on the Splunk platform and satisfies compliance requirements for audit log protection.