II.
Role JSON
Structured · liverole:blue-team-lead
Blue Team Lead json
Inspect the normalized record payload exactly as the atlas UI reads it.
{
"id": "role:blue-team-lead",
"_kind": "Role",
"_file": "role/roles/roles-expanded-2.yaml",
"_cluster": "role",
"attributes": {
"displayName": "Blue Team Lead",
"isAgentic": false,
"requiredCapabilities": [],
"requiredDomains": [],
"description": "Leads defensive security operations — detection engineering, incident\nresponse playbooks, security monitoring tuning, and defensive\ninfrastructure improvements based on red team findings.\n"
},
"outgoingEdges": [
{
"from": "role:blue-team-lead",
"to": "responsibility:security-incident-triage",
"kind": "holds_responsibility"
},
{
"from": "role:blue-team-lead",
"to": "responsibility:incident-response",
"kind": "holds_responsibility"
},
{
"from": "role:blue-team-lead",
"to": "skill-area:security-monitoring-siem",
"kind": "requires_expertise",
"attributes": {}
},
{
"from": "role:blue-team-lead",
"to": "skill-area:threat-detection",
"kind": "requires_expertise",
"attributes": {}
},
{
"from": "role:blue-team-lead",
"to": "skill-area:incident-response",
"kind": "requires_expertise",
"attributes": {}
},
{
"from": "role:blue-team-lead",
"to": "domain:cybersecurity",
"kind": "applies_to",
"attributes": {}
}
],
"incomingEdges": [
{
"from": "responsibility:security-incident-triage",
"to": "role:blue-team-lead",
"kind": "held_by",
"attributes": {}
},
{
"from": "workflow:security-incident-response",
"to": "role:blue-team-lead",
"kind": "involves_role",
"attributes": {}
}
]
}