Detailed Role Permissions

When deciding whether to use default team roles or create a custom role, it can be helpful to review the RBAC permissions that Sysdig grants to the default roles.

This page provides a detailed outline of the permissions granted to the various default roles in Secure and Monitor.

Sysdig Monitor

Standard User

CategoryItemPermissionDescription
Advisor
Manage access to Advisor
AdvisorREADAccess Advisor
Kubernetes APIREADKubernetes API feature
Live LogsVIEWAccess Live Logs feature
Alerts
Manage access to Alerts
Alert EventsEDITAcknowledge an event triggerred by an alert in the events feed in scope of a team
Alert EventsREADAccess the events generated by triggered alerts in scope of a team
AlertsEDITModify alerts in scope of a team
AlertsREADAccess the alerts in scope of a team
Captures / Investigate
Manage access to Captures / Investigate
CapturesEDITModify captures
CapturesREADAccess captures
CapturesVIEWView captures in the UI
Dashboards
Manage access to dashboards
Dashboard Metrics DataREADN/A
DashboardsEDITModify dashboards in scope of a team
DashboardsREADAccess dashboards in scope of a team
Data Access Settings
Manage access to Data Settings
DatastreamREADAccess data stream configuration
GroupingsEDITCreate and edit custom groupings
GroupingsREADAccess default and custom groupings
Metrics DataREADAccess metrics data
Metrics DescriptorsREADAccess metrics descriptors
PromQL MetadataREADAccess Prometheus metrics and labels
Events
Manage access to Events
Custom EventsEDITAcknowledge the infrastructure and other events created by Sysdig Agent or Sysdig API
Custom EventsREADAccess the infrastructure and other events created by Sysdig Agent or Sysdig API
Explore / Metrics
Manage access to Explore / Metrics
Agent ConsoleVIEWUse Agent Console commands
Agent Console - Agent StatusREADUse Agent Console commands which access agent status
Agent Console - ConfigurationVIEWUse Agent Console commands to view the configuration of the agent which does not contain sensitive information like passwords
Agent Console - Network CallsEXECUse Agent Console commands which make network calls to remote pods and endpoints
IntegrationsCustom IntegrationsEDITModify custom integrations in spotlight
Custom IntegrationsREADAccess custom integrations in spotlight
Helm RendererREADAccess Helm-renderer component
InfrastructureREADView discovered infrastructure
IntegrationsREADView discovered workload integrations
Monitoring IntegrationsEDITChange monitoring integration type or status
Monitoring IntegrationsREADAccess monitoring integration type or status
Monitoring IntegrationsVALIDATEChange monitoring integration status to Pending Metrics
ProvidersREADN/A
SpotlightREADAccess spotlight
SettingsAgent InstallationREADGet agent access key (required for agent installation)
Alert DowntimesREADList alert downtimes for the customer
API Access TokenEDITReset users API token in scope of a team
API Access TokenREADAccess users API token in scope of a team
API Access TokenVIEWView your API token
AWS SettingsREADAccess AWS settings
Events ForwarderREADAccess event forwarding configuration
Global Notification ChannelsREADAccess global notification channels
Notification ChannelsREADAccess notification channels in scope of a team
Service AccountsREADAccess service accounts in scope of a team
SubscriptionsREADAccess customer subscription details
Sysdig StorageREADView Sysdig storage configuration

View Only

CategoryItemPermissionDescription
Advisor
Manage access to Advisor
AdvisorREADAccess Advisor
Kubernetes APIREADKubernetes API feature
Live LogsVIEWAccess Live Logs feature
Alerts
Manage access to Alerts
Alert EventsREADAccess the events generated by triggered alerts in scope of a team
AlertsREADAccess the alerts in scope of a team
Captures / Investigate
Manage access to Captures / Investigate
CapturesREADAccess captures
CapturesVIEWView captures in the UI
Dashboards
Manage access to dashboards
Dashboard Metrics DataREADN/A
DashboardsREADAccess dashboards in scope of a team
Data Access Settings
Manage access to Data Settings
DatastreamREADAccess data stream configuration
GroupingsEDITCreate and edit custom groupings
GroupingsREADAccess default and custom groupings
Metrics DataREADAccess metrics data
Metrics DescriptorsREADAccess metrics descriptors
PromQL MetadataREADAccess Prometheus metrics and labels
Events
Manage access to Events
Custom EventsREADAccess the infrastructure and other events created by Sysdig Agent or Sysdig API
Explore / Metrics
Manage access to Explore / Metrics
Agent ConsoleVIEWUse Agent Console commands
Agent Console - Agent StatusREADUse Agent Console commands which access agent status
Agent Console - ConfigurationVIEWUse Agent Console commands to view the configuration of the agent which does not contain sensitive information like passwords
Agent Console - Network CallsEXECUse Agent Console commands which make network calls to remote pods and endpoints
ExploreREADMetric querying with Explore
IntegrationsCustom IntegrationsREADAccess custom integrations in spotlight
File Storage ConfigREADN/A
Helm RendererREADAccess Helm-renderer component
InfrastructureREADView discovered infrastructure
IntegrationsREADView discovered workload integrations
Monitoring IntegrationsREADAccess monitoring integration type or status
Monitoring IntegrationsVALIDATEChange monitoring integration status to Pending Metrics
ProvidersREADN/A
SpotlightREADAccess spotlight
SettingsAgent InstallationREADGet agent access key (required for agent installation)
Alert DowntimesREADList alert downtimes for the user.
API Access TokenREADAccess users API token in scope of a team
API Access TokenVIEWView your API token
AWS SettingsREADAccess AWS settings
Events ForwarderREADAccess event forwarding configuration
Global Notification ChannelsREADAccess global notification channels
Notification ChannelsREADAccess notification channels in scope of a team
Service AccountsREADAccess service accounts in scope of a team
SubscriptionsREADAccess customer subscription details
Sysdig StorageREADView Sysdig storage configuration

Team Manager

CategoryItemPermissiondescription
AdvisorAdvisorREADAccess Advisor
Kubernetes APIREADKubernetes API feature
Live LogsVIEWAccess Live Logs feature
AlertsAlert EventsEDITAcknowledge an event triggerred by an alert in the events feed in scope of a team
Alert EventsREADAccess the events generated by triggered alerts in scope of a team
AlertsEDITModify alerts in scope of a team
AlertsREADAccess the alerts in scope of a team
Captures / InvestigateCapturesEDITModify captures
CapturesREADAccess captures
CapturesVIEWView captures in the UI
DashboardsDashboard Metrics DataREADN/A
DashboardsEDITModify dashboards in scope of a team
DashboardsREADAccess dashboards in scope of a team
Data Access SettingsGroupingsEDITCreate and edit custom groupings
GroupingsREADAccess default and custom groupings
Metrics DataREADAccess metrics data
Metrics DescriptorsREADAccess metrics descriptors
PromQL MetadataREADAccess Prometheus metrics and labels
EventsCustom EventsEDITAcknowledge the infrastructure and other events created by Sysdig Agent or Sysdig API
Custom EventsREADAccess the infrastructure and other events created by Sysdig Agent or Sysdig API
Explore / MetricsAgent ConsoleVIEWUse Agent Console commands
Agent Console - Agent StatusREADUse Agent Console commands which access agent status
Agent Console - ConfigurationVIEWUse Agent Console commands to view the configuration of the agent which does not contain sensitive information like passwords
Agent Console - Network CallsEXECUse Agent Console commands which make network calls to remote pods and endpoints
ExploreEDITN/A
ExploreREADMetric querying with Explore
Shared Groupings with TeamTOGGLEShare metrics grouping with the team
IntegrationsCustom IntegrationsEDITModify custom integrations in spotlight
Custom IntegrationsREADAccess custom integrations in spotlight
Helm RendererREADAccess Helm-renderer component
InfrastructureREADView discovered infrastructure
IntegrationsREADView discovered workload integrations
Monitoring IntegrationsEDITChange monitoring integration type or status
Monitoring IntegrationsREADAccess monitoring integration type or status
Monitoring IntegrationsVALIDATEChange monitoring integration status to Pending Metrics
ProvidersREADN/A
SpotlightREADAccess spotlight
SettingsAgent InstallationREADGet agent access key (required for agent installation)
Alert DowntimesREADList alert downtimes for the customer
API Access TokenEDITReset users API token in scope of a team
API Access TokenREADAccess users API token in scope of a team
API Access TokenVIEWView your API token
AWS SettingsREADAccess AWS settings
Events ForwarderREADAccess event forwarding configuration
Global Notification ChannelsREADAccess global notification channels
Notification ChannelsEDITModify notification channels in scope of a team
Notification ChannelsREADAccess notification channels in scope of a team
Service AccountsEDITModify service accounts in scope of a team
Service AccountsREADAccess service accounts in scope of a team
SubscriptionsREADAccess customer subscription details
Sysdig StorageREADView Sysdig storage configuration
TeamsMANAGEModify team settings without the ability to modify team membership for users

Advanced User

CategoryItemPermissionDescription
AdvisorAdvisorREADAccess Advisor
Kubernetes APIREADKubernetes API feature
Live LogsVIEWAccess Live Logs feature
AlertsAlert EventsEDITAcknowledge an event triggerred by an alert in the events feed in scope of a team
Alert EventsREADAccess the events generated by triggered alerts in scope of a team
AlertsEDITModify alerts in scope of a team
AlertsREADAccess the alerts in scope of a team
Captures / InvestigateCapturesEDITModify captures
CapturesREADAccess captures
CapturesVIEWView captures in the UI
DashboardsDashboard Metrics DataREADN/A
DashboardsEDITModify dashboards in scope of a team
DashboardsREADAccess dashboards in scope of a team
Data SettingsGroupingsEDITCreate and edit custom groupings
GroupingsREADAccess default and custom groupings
Metrics DataREADAccess metrics data
Metrics DescriptorsREADAccess metrics descriptors
PromQL MetadataREADAccess Prometheus metrics and labels
EventsCustom EventsEDITAcknowledge the infrastructure and other events created by Sysdig Agent or Sysdig API
Custom EventsREADAccess the infrastructure and other events created by Sysdig Agent or Sysdig API
Explore / MetricsAgent ConsoleVIEWUse Agent Console commands
Agent Console - Agent StatusREADUse Agent Console commands which access agent status
Agent Console - ConfigurationVIEWUse Agent Console commands to view the configuration of the agent which does not contain sensitive information like passwords
Agent Console - Network CallsEXECUse Agent Console commands which make network calls to remote pods and endpoints
ExploreEDITN/A
ExploreREADMetric querying with Explore
Shared Groupings with TeamTOGGLEShare metrics grouping with the team
IntegrationsCustom IntegrationsEDITModify custom integrations in spotlight
Custom IntegrationsREADAccess custom integrations in spotlight
Helm RendererREADAccess Helm-renderer component
InfrastructureREADView discovered infrastructure
IntegrationsREADView discovered workload integrations
Monitoring IntegrationsEDITChange monitoring integration type or status
Monitoring IntegrationsREADAccess monitoring integration type or status
Monitoring IntegrationsVALIDATEChange monitoring integration status to Pending Metrics
SettingsProvidersREADN/A
SpotlightREADAccess spotlight
Agent InstallationREADGet agent access key (required for agent installation)
Alert DowntimesREADList alert downtimes for the customer
API Access TokenEDITReset users API token in scope of a team
API Access TokenREADAccess users API token in scope of a team
API Access TokenVIEWView your API token
AWS SettingsREADAccess AWS settings
Events ForwarderREADAccess event forwarding configuration
Global Notification ChannelsREADAccess global notification channels
Notification ChannelsEDITModify notification channels in scope of a team
Notification ChannelsREADAccess notification channels in scope of a team
Service AccountsREADAccess service accounts in scope of a team
SubscriptionsREADAccess customer subscription details
Sysdig StorageREADView Sysdig storage configuration

Sysdig Secure Team Roles

Standard User

CategoryItemPermissionDescription
AdvisorKubernetes APIREADKubernetes API feature
Live LogsVIEWAccess Live Logs feature
AlertsAlertsREADAccess the alerts in scope of a team
Captures / InvestigateCapturesREADAccess captures
CapturesVIEWView captures in the UI
Data Access SettingsGroupingsEDITCreate and edit custom groupings
GroupingsREADAccess default and custom groupings
Metrics DataREADAccess metrics data
Metrics DescriptorsREADAccess metrics descriptors
EventsCustom EventsREADAccess the infrastructure and other events created by Sysdig Agent or Sysdig API
Policy EventsREADAccess policy events
Explore / MetricsAgent ConsoleVIEWUse Agent Console commands
Agent Console - Agent StatusREADUse Agent Console commands which access agent status
Agent Console - ConfigurationVIEWUse Agent Console commands to view the configuration of the agent which does not contain sensitive information like passwords
Agent Console - Network CallsEXECUse Agent Console commands which make network calls to remote pods and endpoints
ExploreREADMetric querying with Explore
Shared Groupings with TeamTOGGLEShare metrics grouping with the team
IntegrationsHelm RendererREADAccess Helm-renderer component
InfrastructureREADView discovered infrastructure
Monitoring IntegrationsREADAccess monitoring integration type or status
ProvidersREADN/A
PoliciesPosture PoliciesREADView Posture policies
Posture ControlsREADView Posture Controls
ZonesREADView Zones that are assigned to current team
PostureComplianceREADAccess Compliance results
Risk AcceptanceREADAccess to Posture Risk Acceptance management page
Legacy Benchmark TasksEDITCreate and modify scheduled Legacy benchmark and compliance tasks
Legacy Benchmark TasksREADAccess scheduled Legacy benchmark tasks
Legacy BenchmarksREADAccess Legacy benchmark results
Legacy ComplianceREADAccess Legacy Compliance tasks and reports
RiskRisksREADRead Risks
Scanning (legacy)Image ImportEDITImport scanning images
ScanningREADRead scan results
Scanning AlertsREADAccess scanning alerts
Scanning Image ResultsCREATECreate scanning events
Scanning Image ResultsREADList scanning images
Scanning RuntimeEDITQuery runtime containers API
Scanning Scheduled ReportsREADView and download existing reports
Scanning Trusted ImagesREADAccess the trusted images list
Scanning Untrusted ImagesREADAccess the untrusted images list
Scanning Vulnerability ExceptionsREADAccess vulnerability exceptions
SettingsAgent InstallationREADGet agent access key (required for agent installation)
API Access TokenEDITReset users API token in scope of a team
API Access TokenREADAccess users API token in scope of a team
API Access TokenVIEWView your API token
AWS SettingsREADAccess AWS settings
Cloud AccountsREADAccess cloud accounts
Global Notification ChannelsREADAccess global notification channels
IACREADAccess IAC results
Notification ChannelsREADAccess notification channels in scope of a team
Service AccountsREADAccess service accounts in scope of a team
SubscriptionsREADAccess customer subscription details
Sysdig Secure SettingsEDITModify Sysdig Secure configuration
Sysdig StorageREADView Sysdig storage configuration
Vulnerability ManagementScan ResultsREADView scan results on the Pipeline, Runtime, and Registry UI. Retrieve SBOM results from the SBOM API.
ReportingREADView and download scan reports
PolicyREADView policy details
Risk AcceptanceREADView Exceptions
Registry CredentialsREADView registry credentials
Registry ScannerEXECAbility to run Registry Scanner

Service Manager

CategoryItemPermissionDescription
AdvisorKubernetes APIREADKubernetes API feature
Live LogsVIEWAccess Live Logs feature
AlertsAlertsREADAccess the alerts in scope of a team
Captures / InvestigateCapturesREADAccess captures
CapturesVIEWView captures in the UI
Data Access SettingsGroupingsEDITCreate and edit custom groupings
GroupingsREADAccess default and custom groupings
Metrics DataREADAccess metrics data
Metrics DescriptorsREADAccess metrics descriptors
EventsCustom EventsREADAccess the infrastructure and other events created by Sysdig Agent or Sysdig API
Policy EventsREADAccess policy events
Explore / MetricsAgent ConsoleVIEWUse Agent Console commands
Agent Console - Agent StatusREADUse Agent Console commands which access agent status
Agent Console - ConfigurationVIEWUse Agent Console commands to view the configuration of the agent which does not contain sensitive information like passwords
Agent Console - Network CallsEXECUse Agent Console commands which make network calls to remote pods and endpoints
ExploreREADMetric querying with Explore
Shared Groupings with TeamTOGGLEShare metrics grouping with the team
IntegrationsHelm RendererREADAccess Helm-renderer component
InfrastructureREADView discovered infrastructure
Monitoring IntegrationsREADAccess monitoring integration type or status
ProvidersREADN/A
PoliciesPosture PoliciesREADView Posture policies
Posture ControlsREADView Posture Controls
ZonesREADView Zones that are assigned to current team
PostureComplianceREADAccess Compliance results
Risk AcceptanceREADAccess to Posture Risk Acceptance management page
Legacy Benchmark TasksEDITCreate and modify scheduled Legacy benchmark and compliance tasks
Legacy Benchmark TasksREADAccess scheduled Legacy benchmark tasks
Legacy BenchmarksREADAccess Legacy benchmark results
Legacy ComplianceREADAccess Legacy Compliance tasks and reports
RiskRisksREADRead Risks
Scanning (Legacy)Image ImportEDITImport scanning images
ScanningEXECExecute backend scanning
ScanningREADRead scan results
ScanningWRITEModify scanning alerts and registry credentials
Scanning AlertsEDITModify scanning alerts
Scanning AlertsREADAccess scanning alerts
ScanningScanning Image ResultsCREATECreate scanning events
Scanning Image ResultsREADList scanning images
Scanning Policy AssignmentsREADAccess policy mappings
Scanning RuntimeEDITQuery runtime containers API
Scanning Scheduled ReportsREADView and download existing reports
Scanning Trusted ImagesREADAccess the trusted images list
Scanning Untrusted ImagesREADAccess the untrusted images list
Scanning Vulnerability ExceptionsREADAccess vulnerability exceptions
SettingsAgent InstallationREADGet agent access key (required for agent installation)
API Access TokenEDITReset users API token in scope of a team
API Access TokenREADAccess users API token in scope of a team
API Access TokenVIEWView your API token
AWS SettingsREADAccess AWS settings
Cloud AccountsREADAccess cloud accounts
Global Notification ChannelsREADAccess global notification channels
IACREADAccess IAC results
Notification ChannelsEDITModify notification channels in scope of a team
Notification ChannelsREADAccess notification channels in scope of a team
Service AccountsREADAccess service accounts in scope of a team
SubscriptionsREADAccess customer subscription details
Sysdig Secure SettingsEDITModify Sysdig Secure configuration
Sysdig StorageREADView Sysdig storage configuration
Team MembershipEDITInvite other users to the teams
Team MembershipREADAccess team members
Team Membership RolesEDITModify team members roles
TeamsMANAGEModify team settings without the ability to modify team membership for users
TeamsREADN/A
UsersREADAccess existing users data
Vulnerability ManagementScan ResultsREADView scan results on the Pipeline, Runtime, and Registry UI. Retrieve SBOM results from the SBOM API.
ReportingREADView and download scan reports
ReportingWRITECreate, modify, and delete reports
PolicyREADView policy details
PocilyWRITECreate, edit, and delete policies
Risk AcceptanceREADView Exceptions
CLI ExecutionEXECAbility to run CLI Scanner
Scan NowEXECAbility to instantly scan using Scan Now
Registry CredentialsREADView registry credentials
Registry CredentialsWRITEAdd registry credentials
Registry ScannerEXECAbility to run Registry Scanner

View Only

CategoryItemPermissionDescription
AdvisorKubernetes APIREADKubernetes API feature
Live LogsVIEWAccess Live Logs feature
AlertsAlertsREADAccess the alerts in scope of a team
Captures / InvestigateActivity Audit CommandsREADAccess activity audit commands
CapturesREADAccess captures
CapturesVIEWView captures in the UI
Data Access SettingsGroupingsEDITCreate and edit custom groupings
GroupingsREADAccess default and custom groupings
Metrics DataREADAccess metrics data
Metrics DescriptorsREADAccess metrics descriptors
EventsCustom EventsREADAccess the infrastructure and other events created by Sysdig Agent or Sysdig API
Policy EventsREADAccess policy events
Explore / MetricsAgent ConsoleVIEWUse Agent Console commands
Agent Console - Agent StatusREADUse Agent Console commands which access agent status
Agent Console - ConfigurationVIEWUse Agent Console commands to view the configuration of the agent which does not contain sensitive information like passwords
Agent Console - Network CallsEXECUse Agent Console commands which make network calls to remote pods and endpoints
ExploreREADMetric querying with Explore
IntegrationsHelm RendererREADAccess Helm-renderer component
InfrastructureREADView discovered infrastructure
Monitoring IntegrationsREADAccess monitoring integration type or status
ProvidersREADN/A
Network SecurityNetwork SecurityREADAccess Kubernetes Network Security policy advisor
PoliciesPosture PoliciesREADView Posture policies
Posture ControlsREADView Posture Controls
ZonesREADView Zones that are assigned to current team
Image profilingREADView existing image profiles
PoliciesREADAccess policies
Policy AdvisorREADRead PSP advisor simulations
PostureComplianceREADAccess Compliance results
Risk AcceptanceREADAccess to Posture Risk Acceptance management page
Legacy Benchmark TasksEDITCreate and modify scheduled Legacy benchmark and compliance tasks
Legacy Benchmark TasksREADAccess scheduled Legacy benchmark tasks
Legacy BenchmarksREADAccess Legacy benchmark results
Legacy ComplianceREADAccess Legacy Compliance tasks and reports
Scanning (Legacy)ScanningREADRead scan results
Scanning AlertsREADAccess scanning alerts
Scanning Image ResultsREADList scanning images
Scanning PoliciesREADAccess security policies
Scanning Policy AssignmentsREADAccess policy mappings
Scanning Registry CredentialsREADList container registries
Scanning RuntimeEDITQuery runtime containers API
Scanning Scheduled ReportsREADView and download existing reports
Scanning Trusted ImagesREADAccess the trusted images list
Scanning Untrusted ImagesREADAccess the untrusted images list
Scanning Vulnerability ExceptionsREADAccess vulnerability exceptions
SettingsAgent InstallationREADGet agent access key (required for agent installation)
API Access TokenEDITReset users API token in scope of a team
API Access TokenREADAccess users API token in scope of a team
API Access TokenVIEWView your API token
AWS SettingsREADAccess AWS settings
Cloud AccountsREADAccess cloud accounts
Global Notification ChannelsREADAccess global notification channels
IACREADAccess IAC results
Notification ChannelsREADAccess notification channels in scope of a team
Service AccountsREADAccess service accounts in scope of a team
SubscriptionsREADAccess customer subscription details
Sysdig Secure SettingsEDITModify Sysdig Secure configuration
SettingsSysdig StorageREADView Sysdig storage configuration
Vulnerability ManagementScan ResultsREADView scan results on the Pipeline, Runtime, and Registry UI. Retrieve SBOM results from the SBOM API.
ReportingREADView and download scan reports
PolicyREADView policy details
Risk AcceptanceREADView Exceptions
Registry CredentialsREADView registry credentials
Registry ScannerEXECAbility to run Registry Scanner

Team Manager

CategoryItemPermissionDescription
AdvisorKubernetes APIREADKubernetes API feature
Live LogsVIEWAccess Live Logs feature
AlertsAlertsEDITModify alerts in scope of a team
AlertsREADAccess the alerts in scope of a team
Captures / InvestigateActivity Audit CommandsREADAccess activity audit commands
CapturesEDITModify captures
CapturesREADAccess captures
CapturesVIEWView captures in the UI
Rapid ResponseEXECUse rapid response
Data Access SettingsDatastreamREADAccess data stream configuration
GroupingsEDITCreate and edit custom groupings
GroupingsREADAccess default and custom groupings
Metrics DataREADAccess metrics data
Metrics DescriptorsREADAccess metrics descriptors
EventsCustom EventsREADAccess the infrastructure and other events created by Sysdig Agent or Sysdig API
Policy EventsREADAccess policy events
Explore / MetricsAgent ConsoleVIEWUse Agent Console commands
Agent Console - Agent StatusREADUse Agent Console commands which access agent status
Agent Console - ConfigurationVIEWUse Agent Console commands to view the configuration of the agent which does not contain sensitive information like passwords
Agent Console - Network CallsEXECUse Agent Console commands which make network calls to remote pods and endpoints
ExploreEDITN/A
ExploreREADMetric querying with Explore
Shared Groupings with TeamTOGGLEShare metrics grouping with the team
IntegrationsHelm RendererREADAccess Helm-renderer component
InfrastructureREADView discovered infrastructure
Monitoring IntegrationsREADAccess monitoring integration type or status
ProvidersREADN/A
Network SecurityNetwork SecurityREADAccess Kubernetes Network Security policy advisor
PoliciesZonesEDITView and Edit All Zones
Posture PoliciesEDITView and Edit Posture policies
Posture ControlsEDITView and Edit Posture Controls
Image profilingEXECExecute image profiling
Image profilingREADView existing image profiles
Image profilingWRITEWrite image profiles
PoliciesEDITModify policies
PoliciesREADAccess policies
Policy AdvisorEXECExecute PSP advisor simulation
Policy AdvisorREADRead PSP advisor simulations
Policy AdvisorWRITECreate PSP advisor simulation
PostureComplianceREADAccess Compliance results
Risk AcceptanceEDITAccess and modify Posture Risk Acceptance
Open PREDITSetup Pull Requests from posture remediation panel
Legacy Benchmark TasksEDITAccess, Create and modify scheduled Legacy benchmark and compliance tasks
Legacy BenchmarksREADAccess Legacy benchmark results
Legacy ComplianceREADAccess Legacy Compliance tasks and reports
RiskRisksREADRead Risks
ScanningImage ImportEDITImport scanning images
ScanningEXECExecute backend scanning
ScanningREADRead scan results
ScanningWRITEModify scanning alerts and registry credentials
Scanning AlertsEDITModify scanning alerts
Scanning AlertsREADAccess scanning alerts
Scanning Image ResultsCREATECreate scanning events
Scanning Image ResultsREADList scanning images
Scanning PoliciesEDITModify security policies
Scanning PoliciesREADAccess security policies
Scanning Policy AssignmentsEDITCreate and modify policy mappings
Scanning Policy AssignmentsREADAccess policy mappings
Scanning Registry CredentialsEDITCreate and modify container registries configuration
Scanning Registry CredentialsREADList container registries
Scanning RuntimeEDITQuery runtime containers API
Scanning Scheduled ReportsEDITCreate and modify reports
Scanning Scheduled ReportsREADView and download existing reports
Scanning Trusted ImagesEDITModify the trusted images list
Scanning Trusted ImagesREADAccess the trusted images list
Scanning Untrusted ImagesEDITModify the untrusted images list
Scanning Untrusted ImagesREADAccess the untrusted images list
Scanning Vulnerability ExceptionsEDITEdit vulnerability exceptions
Scanning Vulnerability ExceptionsREADAccess vulnerability exceptions
SettingsAgent InstallationREADGet agent access key (required for agent installation)
API Access TokenEDITReset users API token in scope of a team
API Access TokenREADAccess users API token in scope of a team
API Access TokenVIEWView your API token
AWS SettingsREADAccess AWS settings
Cloud AccountsREADAccess cloud accounts
Global Notification ChannelsREADAccess global notification channels
IACREADAccess IAC results
Notification ChannelsEDITModify notification channels in scope of a team
Notification ChannelsREADAccess notification channels in scope of a team
Service AccountsEDITModify service accounts in scope of a team
Service AccountsREADAccess service accounts in scope of a team
SubscriptionsREADAccess customer subscription details
Sysdig Secure SettingsEDITModify Sysdig Secure configuration
Sysdig StorageREADView Sysdig storage configuration
TeamsMANAGEModify team settings without the ability to modify team membership for users
Vulnerability ManagementScan ResultsREADView scan results on the Pipeline, Runtime, and Registry UI. Retrieve SBOM results from the SBOM API.
ReportingREADView and download scan reports
ReportingWRITECreate, modify, and delete reports
PolicyREADView policy details
PocilyWRITECreate, edit, and delete policies
Risk AcceptanceREADView Exceptions
Risk AcceptanceWRITECreate, update, and delete Exceptions
CLI ExecutionEXECAbility to run CLI Scanner
Scan NowEXECAbility to instantly scan using Scan Now
Registry CredentialsREADView registry credentials
Registry CredentialsWRITEAdd registry credentials
Registry ScannerEXECAbility to run Registry Scanner

Advanced User

CategoryItemPermissionDescription
AdvisorKubernetes APIREADKubernetes API feature
Live LogsVIEWAccess Live Logs feature
AlertsAlertsEDITModify alerts in scope of a team
AlertsREADAccess the alerts in scope of a team
Captures / InvestigateActivity Audit CommandsREADAccess activity audit commands
CapturesEDITModify captures
CapturesREADAccess captures
CapturesVIEWView captures in the UI
Rapid ResponseEXECUse rapid response
Data Access SettingsDatastreamREADAccess data stream configuration
GroupingsEDITCreate and edit custom groupings
GroupingsREADAccess default and custom groupings
Metrics DataREADAccess metrics data
Metrics DescriptorsREADAccess metrics descriptors
EventsCustom EventsREADAccess the infrastructure and other events created by Sysdig Agent or Sysdig API
Policy EventsREADAccess policy events
Explore / MetricsAgent ConsoleVIEWUse Agent Console commands
Agent Console - Agent StatusREADUse Agent Console commands which access agent status
Agent Console - ConfigurationVIEWUse Agent Console commands to view the configuration of the agent which does not contain sensitive information like passwords
Agent Console - Network CallsEXECUse Agent Console commands which make network calls to remote pods and endpoints
ExploreEDITN/A
ExploreREADMetric querying with Explore
Shared Groupings with TeamTOGGLEShare metrics grouping with the team
IntegrationsHelm RendererREADAccess Helm-renderer component
InfrastructureREADView discovered infrastructure
Monitoring IntegrationsREADAccess monitoring integration type or status
ProvidersREADN/A
Network SecurityNetwork SecurityREADAccess Kubernetes Network Security policy advisor
PoliciesZonesEDITView and Edit All Zones
Posture PoliciesEDITView and Edit Posture policies
Posture ControlsEDITView and Edit Posture Controls
Image profilingEXECExecute image profiling
Image profilingREADView existing image profiles
Image profilingWRITEWrite image profiles
PoliciesEDITModify policies
PoliciesREADAccess policies
Policy AdvisorEXECExecute PSP advisor simulation
Policy AdvisorREADRead PSP advisor simulations
Policy AdvisorWRITECreate PSP advisor simulation
ComplianceREADAccess Compliance results
Risk AcceptanceEDITAccess and modify Posture Risk Acceptance
PostureOpen PREDITSetup Pull Requests from posture remediation panel
Legacy Benchmark TasksEDITAccess, Create and modify scheduled Legacy benchmark and compliance tasks
Legacy BenchmarksREADAccess Legacy benchmark results
Legacy ComplianceREADAccess Legacy Compliance tasks and reports
RiskRisksREADRead Risks
Scanning (Legacy)Image ImportEDITImport scanning images
ScanningEXECExecute backend scanning
ScanningREADRead scan results
ScanningWRITEModify scanning alerts and registry credentials
Scanning AlertsEDITModify scanning alerts
Scanning AlertsREADAccess scanning alerts
Scanning Image ResultsCREATECreate scanning events
Scanning Image ResultsREADList scanning images
Scanning PoliciesEDITModify security policies
Scanning PoliciesREADAccess security policies
Scanning Policy AssignmentsEDITCreate and modify policy mappings
Scanning Policy AssignmentsREADAccess policy mappings
Scanning Registry CredentialsEDITCreate and modify container registries configuration
Scanning Registry CredentialsREADList container registries
Scanning RuntimeEDITQuery runtime containers API
Scanning Scheduled ReportsEDITCreate and modify reports
Scanning Scheduled ReportsREADView and download existing reports
Scanning Trusted ImagesEDITModify the trusted images list
Scanning Trusted ImagesREADAccess the trusted images list
Scanning Untrusted ImagesEDITModify the untrusted images list
Scanning Untrusted ImagesREADAccess the untrusted images list
Scanning Vulnerability ExceptionsEDITEdit vulnerability exceptions
Scanning Vulnerability ExceptionsREADAccess vulnerability exceptions
SettingsAgent InstallationREADGet agent access key (required for agent installation)
API Access TokenEDITReset users API token in scope of a team
API Access TokenREADAccess users API token in scope of a team
API Access TokenVIEWView your API token
AWS SettingsREADAccess AWS settings
Cloud AccountsREADAccess cloud accounts
Global Notification ChannelsREADAccess global notification channels
IACREADAccess IAC results
Notification ChannelsEDITModify notification channels in scope of a team
Notification ChannelsREADAccess notification channels in scope of a team
Service AccountsREADAccess service accounts in scope of a team
SubscriptionsREADAccess customer subscription details
Sysdig Secure SettingsEDITModify Sysdig Secure configuration
Sysdig StorageREADView Sysdig storage configuration
Vulnerability ManagementScan ResultsREADView scan results on the Pipeline, Runtime, and Registry UI. Retrieve SBOM results from the SBOM API.
ReportingREADView and download scan reports
ReportingWRITECreate, modify, and delete reports
PolicyREADView policy details
PocilyWRITECreate, edit, and delete policies
Risk AcceptanceREADView Exceptions
Risk AcceptanceWRITECreate, update, and delete Exceptions
CLI ExecutionEXECAbility to run CLI Scanner
Scan NowEXECAbility to instantly scan using Scan Now
Registry CredentialsREADView registry credentials
Registry CredentialsWRITEAdd registry credentials
Registry ScannerEXECAbility to run Registry Scanner