Detailed Role Permissions

When deciding whether to use default team roles or create a custom role, it can be helpful to review the Role-Based Access Control (RBAC) permissions that Sysdig grants to the default roles.

This page provides a detailed outline of the permissions granted to the default roles in Secure and Monitor.

Sysdig Monitor System Roles

Admin

CategoryItemPermissionDescription
INTERNAL_UNCATEGORIZEDsecure.accessOTHERN/A
Posturecompliance.policies.adminOTHER_MUTATORN/A
INTERNAL_UNCATEGORIZEDcustomer.adminOTHER_MUTATORN/A
INTERNAL_UNCATEGORIZEDteam-admin.insightOTHERN/A
INTERNAL_ADMINonboarding.adminOTHER_MUTATORN/A
Integrationspromcat.integrations.manageMANAGEChange monitoring integration type or status
INTERNAL_SERVICEactive-secure-compliance-users-admin.readREADN/A
INTERNAL_SERVICEactive-secure-overview-users-admin.readREADN/A
INTERNAL_ADMINinactive-users-admin.readREADN/A
INTERNAL_SERVICEmetrics-data-admin.readREADAccess metrics data associated with a time series.
Reportsreports.manageMANAGEChange monitoring reports
Posturesecure.onboarding.adminOTHER_MUTATORN/A
Posturesecure.todo.adminOTHER_MUTATORN/A
INTERNAL_ADMINsystem-admin.editEDITN/A
INTERNAL_ADMINsystem-admin.readREADN/A
Explore / Metricsagent.cli.agent_internal_diagnosticsREADUse Agent Console commands which access internal diagnostics of the agent
Explore / Metricsagent.cli.agent_network_calls_to_remote_podsEXECUse Agent Console commands which make network calls to remote pods and endpoints
Explore / Metricsagent.cli.agent_statusREADUse Agent Console commands which access agent status
Explore / Metricsagent.cli.viewVIEWUse Agent Console commands
Explore / Metricsagent.cli.view_configurationVIEWUse Agent Console commands to view the configuration of the agent which does not contain sensitive information like passwords
Explore / Metricsagent.cli.view_sensitive_configurationVIEWUse Agent Console commands to view the configuration of the agent which does contain sensitive information like passwords. There are currently zero commands that implement this permission
Settingssso.configEDITN/A
INTERNAL_ADMINsso-system.configEDITN/A
Settingscustomer-admin-users.createCREATECreate new customer admin users
ROLE_MANAGEMENTcustom-team-roles.createCREATEN/A
Settingsteams.createCREATEN/A
Settingsusers.createCREATEInvite new users
ROLE_MANAGEMENTcustom-team-roles.deleteDELETEN/A
Settingsteams.deleteDELETEN/A
Settingsaccess-keys.editEDITN/A
Settingssso-active.editEDITN/A
Policiessecure.admission-controller.editEDITN/A
Scanning (Legacy)agentscanning.config.editEDITN/A
Settingsapi-token.editEDITReset users API token in scope of a team
Settingsaws-settings.editEDITN/A
Settingsbeacon-configuration.editEDITN/A
Posturesecure.benchmark.results.editEDITN/A
Settingscertman.editEDITN/A
Costscost-advisor.editEDITChange Cost Advisor pricing
Costscost-reports.editEDITChange cost reports
USERSuser-deactivation-configuration.editEDITModify user deactivation configuration
Data Access Settingsdatastream.editEDITN/A
INTERNAL_SERVICEdata-api-settings.editEDITN/A
INTERNAL_SERVICEdata-throttling-settings.editEDITN/A
Settingsdowntimes.editEDITN/A
Settingsevents-forwarder.editEDITN/A
Integrationsfile-storage-config.editEDITN/A
Settingsglobal.notification-channels.editEDITN/A
Settingsglobal.service-accounts.editEDITN/A
Settingsglobal-service-account-notification-settings.editEDITN/A
Data Access Settingsgroupings.editEDITCreate and edit custom groupings
Settingsgroup-mappings.editEDITModify mapping of users IDP groups to Sysdig teams/roles
Settingsip-filters.editEDITModify IP filter configuration
Settingslogin-banner.editEDITN/A
Settingsmemberships.editEDITInvite other users to the teams
Settingsmemberships-roles.editEDITModify team members roles
Network Securitynetsec.editEDITN/A
Get Startedonboarding.editEDITN/A
INTERNAL_ADMINservice.platform-alerts-settings.editEDITEdit platform alerts settings
Policiespolicy-tuner.editEDITN/A
Integrationspromcat.integrations.editEDITChange monitoring integration type or status
Integrationsproviders.editEDITN/A
Scanning (Legacy)scanning.retention.editEDITN/A
Scanning (Legacy)secure.images.editEDITN/A
Settingssecure-settings.editEDITModify Sysdig Secure configuration
Settingsteam-service-accounts.editEDITModify service accounts in scope of a team
Settingsservice-account-notification-settings.editEDITN/A
Settingsservice-account-role.editEDITChange service account roles
Settingssubscription.editEDITN/A
Settingssysdig-storage.editEDITN/A
INTERNAL_ADMINsystem-falco.editEDITN/A
Settingsteams.editEDITN/A
Settingsteam-agent-cli-settings.editEDITToggle access to agent console for a team
Settingsteam-capture-settings.editEDITToggle access to captures for a team
Settingsteam-rapid-response-settings.editEDITN/A
Integrationsthird-party-integrations.editEDITN/A
Ticketingticketing-customer-settings.editEDITEdit ticketing customer settings
UI Settingsui-customer-settings.editEDITN/A
UI Settingsui-inactivity-settings.editEDITN/A
UI Settingsui-settings.editEDITN/A
UI Settingsui-user-app-settings.editEDITN/A
Settingsusers.editEDITN/A
Settingsuser-list.editEDITN/A
USERSuser-password.editEDITN/A
USERSuser-profile.editEDITN/A
INTERNAL_UNCATEGORIZEDdev-task.execEXECN/A
INTERNAL_UNCATEGORIZEDes-query.execEXECN/A
Captures / Investigatesecure.rapid-response.execEXECUse rapid response
INTERNAL_ADMINprotobuf.exportOTHER_MUTATORN/A
INTERNAL_ADMINimpersonate.editEDITN/A
Data Access Settingsingest.prwsOTHERN/A
Data Access Settingsingest.prws.controlledOTHERN/A
Captures / Investigatesecure.rapid-response.killKILLN/A
INTERNAL_SERVICEmetrics-descriptors.manageMANAGEManage metrics descriptors, which are unique combinations of metrics and labels that create a time series. For example, sysdig_container_cpu_used_percent{host_hostname=foo,region=bar}.
INTERNAL_UNCATEGORIZEDquartz-jobs.manageMANAGEN/A
Settingssecure.risk-spotlight-integration-tokens.manageMANAGEManage risk spotlight integration tokens from the UI
Settingsaccess-keys.readREADN/A
Scanning (Legacy)agentscanning.config.readREADN/A
Settingsagent-installation.readREADGet agent access key (required for agent installation)
Settingsagreement.readREADN/A
Settingsapi-token.readREADAccess users API token in scope of a team
INTERNAL_UNCATEGORIZEDaudit-trail-events.readREADN/A
Settingsaws-settings.readREADAccess AWS settings
Settingsazure-settings.readREADN/A
Settingsbeacon-configuration.readREADN/A
Settingscertman.readREADN/A
Settingscloud.accounts.readREADAccess cloud accounts
Costscost-advisor.readREADAccess Cost Advisor
INTERNAL_SERVICEcost-digest.readREADRead cost digest enabled customers
Costscost-explorer.readREADAccess Cost Explorer
Costscost-reports.readREADAccess cost reports
INTERNAL_SERVICEcustomer-by-accesskey.readREADN/A
Settingscustomer-plan.readREADN/A
Settingscustomer-teams.readREADAccess and list teams data
USERSuser-deactivation-configuration.readREADAccess user deactivation configuration
Eventscustom-events.readREADAccess the infrastructure and other events created by Sysdig Agent or Sysdig API
ROLE_MANAGEMENTcustom-team-roles.readREADN/A
Dashboardsdashboard-metrics-data.readREADAccess metrics data associated with a dashboard.
Data Access Settingsdatastream.readREADAccess data stream configuration
INTERNAL_SERVICEdata-api-settings.readREADN/A
INTERNAL_SERVICEdata-throttling-settings.readREADN/A
Settingsdowntimes.readREADList alert downtimes for the customer
Settingsevents-forwarder.readREADAccess event forwarding configuration
Explore / Metricsexplore.readREADMetric querying with Explore
INTERNAL_UNCATEGORIZEDexternal-links.readREADN/A
Integrationsfile-storage-config.readREADN/A
Settingsglobal.service-accounts.readREADN/A
Settingsglobal-service-account-notification-settings.readREADN/A
Data Access Settingsgroupings.readREADAccess default and custom groupings
Settingsgroup-mappings.readREADAccess mapping of users IDP groups to Sysdig teams/roles
Integrationshelmsrenderer.readREADAccess Helm-renderer component. During cloud account setup in Secure, the wizard calls the Helm Renderer to generate the Terraform snippet.
Data Access Settingshistory-data.readREADN/A
INTERNAL_UNCATEGORIZEDimpersonate.readREADN/A
Integrationsinfrastructure.readREADView discovered infrastructure
Integrationsintegrations.readREADView discovered workload integrations
Settingsip-filters.readREADAccess IP Filter configuration
Advisorkubernetes-api-commands.readREADKubernetes API feature
Advisorlive-logs.viewVIEWAccess Live Logs feature
Settingslogin-banner.readREADN/A
Data Access Settingsmds.read-metadataREADN/A
Settingsmemberships.readREADAccess team members
Data Access Settingsmetadata-defaults.readREADN/A
Data Access Settingsmetrics-data.readREADAccess metrics data associated with a time series.
Data Access Settingsmetrics-descriptors.readREADAccess metrics descriptors, which are unique combinations of metrics and labels that create a time series. For example, sysdig_container_cpu_used_percent{host_hostname=foo,region=bar}.
Get Startedonboarding.readREADN/A
Advisoroverviews.readREADAccess Advisor
Settingspayment-details.readREADN/A
ROLE_MANAGEMENTpermissions.readREADN/A
INTERNAL_ADMINservice.platform-alerts-settings.readREADRead platform alerts settings
Integrationspromcat.integrations.readREADAccess monitoring integration type or status
Data Access Settingspromql-metadata.readREADAccess Prometheus metrics and labels
Integrationsproviders.readREADRelated to cloud account setups (both Metric Stream and Cost Private Pricing).
Scanning (Legacy)scanning.readREADRead scan results
Scanning (Legacy)scanning.retention.readREADN/A
Get Startedsecure.onboarding.readREADN/A
Settingssecure-settings.readREADN/A
Settingsteam-service-accounts.readREADAccess service accounts in scope of a team
Settingsservice-account-notification-settings.readREADN/A
Integrationsspotlight.readREADAccess spotlight
Settingssubscription.readREADAccess customer subscription details
Settingssysdig-storage.readREADView Sysdig storage configuration
INTERNAL_UNCATEGORIZEDteams.readREADN/A
Settingsteam-agent-cli-settings.readREADSee the agent console access settings for a team
Settingsteam-capture-settings.readREADSee the capture settings for a team
Settingsteam-rapid-response-settings.readREADN/A
INTERNAL_UNCATEGORIZEDteam-search.readREADN/A
Integrationsthird-party-integrations.readREADN/A
Ticketingticketing-customer-settings.readREADRead ticketing customer settings
UI Settingsui-customer-settings.readREADN/A
UI Settingsui-inactivity-settings.readREADN/A
UI Settingsui-settings.readREADN/A
UI Settingsui-user-app-settings.readREADN/A
Settingsusers.readREADAccess existing users data
Settingsuser-list.readREADSee the list of users for a customer
USERSuser-profile.readREADN/A
Captures / Investigatesecure.rapid-response.sessions.read.allREADN/A
Settingsagreement.signSIGNN/A
INTERNAL_UNCATEGORIZEDsystem-support.editEDITN/A
INTERNAL_ADMINagent-availability.toggleTOGGLEN/A
INTERNAL_UNCATEGORIZEDtrack.eventOTHER_MUTATORN/A
ROLE_MANAGEMENTcustom-team-roles.updateUPDATEN/A
Sagesage.execEXECSysdig Sage chat
Integrationspromcat.integrations.validateVALIDATEChange monitoring integration status to Pending Metrics

Sysdig Monitor Team Roles

Standard User

CategoryItemPermissionDescription
Advisor
Manage access to Advisor
AdvisorREADAccess Advisor
Kubernetes APIREADKubernetes API feature
Live LogsVIEWAccess Live Logs feature
Alerts
Manage access to Alerts
Alert EventsEDITAcknowledge an event triggered by an alert in the events feed in scope of a team
Alert EventsREADAccess the events generated by triggered alerts in scope of a team
AlertsEDITModify alerts in scope of a team
AlertsREADAccess the alerts in scope of a team
Captures / Investigate
Manage access to Captures / Investigate
CapturesEDITModify captures
CapturesREADAccess captures
CapturesVIEWView captures in the UI
Dashboards
Manage access to dashboards
Dashboard Metrics DataREADN/A
DashboardsEDITModify dashboards in scope of a team
DashboardsREADAccess dashboards in scope of a team
Data Access Settings
Manage access to Data Settings
DatastreamREADAccess data stream configuration
GroupingsEDITCreate and edit custom groupings
GroupingsREADAccess default and custom groupings
Metrics DataREADAccess metrics data associated with a time series.
Metrics DescriptorsREADAccess metrics descriptors, which are unique combinations of metrics and labels that create a time series. For example, sysdig_container_cpu_used_percent{host_hostname=foo,region=bar}.
PromQL MetadataREADAccess Prometheus metrics and labels
Events
Manage access to Events
Custom EventsEDITAcknowledge the infrastructure and other events created by Sysdig Agent or Sysdig API
Custom EventsREADAccess the infrastructure and other events created by Sysdig Agent or Sysdig API
Explore / Metrics
Manage access to Explore / Metrics
Agent ConsoleVIEWUse Agent Console commands
Agent Console - Agent StatusREADUse Agent Console commands which access agent status
Agent Console - ConfigurationVIEWUse Agent Console commands to view the configuration of the agent which does not contain sensitive information like passwords
Agent Console - Network CallsEXECUse Agent Console commands which make network calls to remote pods and endpoints
ExploreREADUse metric querying with Explore
IntegrationsCustom IntegrationsEDITModify custom integrations in spotlight
Custom IntegrationsREADAccess custom integrations in spotlight
Helm RendererREADAccess Helm-renderer component. During cloud account setup in Secure, the wizard calls the Helm Renderer to generate the terraform snippet.
InfrastructureREADView discovered infrastructure
IntegrationsREADView discovered workload integrations
Monitoring IntegrationsEDITChange monitoring integration type or status
Monitoring IntegrationsREADAccess monitoring integration type or status
Monitoring IntegrationsVALIDATEChange monitoring integration status to Pending Metrics
EnvironmentsREADRelated to cloud account setups (both Metric Stream and Cost Private Pricing).
SpotlightREADAccess spotlight
SettingsAgent InstallationREADGet agent access key (required for agent installation)
Alert DowntimesREADList alert downtimes for the customer
API Access TokenEDITReset users API token in scope of a team
API Access TokenREADAccess users API token in scope of a team
API Access TokenVIEWView your API token
AWS SettingsREADAccess AWS settings
Events ForwarderREADAccess event forwarding configuration
Global Notification ChannelsREADAccess global notification channels
Notification ChannelsREADAccess notification channels in scope of a team
Service AccountsREADAccess service accounts in scope of a team
SubscriptionsREADAccess customer subscription details
Sysdig StorageREADView Sysdig storage configuration

View Only

CategoryItemPermissionDescription
Advisor
Manage access to Advisor
AdvisorREADAccess Advisor
Kubernetes APIREADKubernetes API feature
Live LogsVIEWAccess Live Logs feature
Alerts
Manage access to Alerts
Alert EventsREADAccess the events generated by triggered alerts in scope of a team
AlertsREADAccess the alerts in scope of a team
Captures / Investigate
Manage access to Captures / Investigate
CapturesREADAccess captures
CapturesVIEWView captures in the UI
Dashboards
Manage access to dashboards
Dashboard Metrics DataREADN/A
DashboardsREADAccess dashboards in scope of a team
Data Access Settings
Manage access to Data Settings
DatastreamREADAccess data stream configuration
GroupingsEDITCreate and edit custom groupings
GroupingsREADAccess default and custom groupings
Metrics DataREADAccess metrics data associated with a time series.
Metrics DescriptorsREADAccess metrics descriptors, which are unique combinations of metrics and labels that create a time series. For example, sysdig_container_cpu_used_percent{host_hostname=foo,region=bar}.
PromQL MetadataREADAccess Prometheus metrics and labels
Events
Manage access to Events
Custom EventsREADAccess the infrastructure and other events created by Sysdig Agent or Sysdig API
Explore / Metrics
Manage access to Explore / Metrics
Agent ConsoleVIEWUse Agent Console commands
Agent Console - Agent StatusREADUse Agent Console commands which access agent status
Agent Console - ConfigurationVIEWUse Agent Console commands to view the configuration of the agent which does not contain sensitive information like passwords
Agent Console - Network CallsEXECUse Agent Console commands which make network calls to remote pods and endpoints
ExploreREADMetric querying with Explore
IntegrationsCustom IntegrationsREADAccess custom integrations in spotlight
File Storage ConfigREADN/A
Helm RendererREADAccess Helm-renderer component. During cloud account setup in Secure, the wizard calls the Helm Renderer to generate the terraform snippet.
InfrastructureREADView discovered infrastructure
IntegrationsREADView discovered workload integrations
Monitoring IntegrationsREADAccess monitoring integration type or status
Monitoring IntegrationsVALIDATEChange monitoring integration status to Pending Metrics
EnvironmentsREADRelated to cloud account setups (both Metric Stream and Cost Private Pricing).
SpotlightREADAccess spotlight
SettingsAgent InstallationREADGet agent access key (required for agent installation)
Alert DowntimesREADList alert downtimes for the user.
API Access TokenREADAccess users API token in scope of a team
API Access TokenVIEWView your API token
AWS SettingsREADAccess AWS settings
Events ForwarderREADAccess event forwarding configuration
Global Notification ChannelsREADAccess global notification channels
Notification ChannelsREADAccess notification channels in scope of a team
Service AccountsREADAccess service accounts in scope of a team
SubscriptionsREADAccess customer subscription details
Sysdig StorageREADView Sysdig storage configuration

Team Manager

CategoryItemPermissiondescription
AdvisorAdvisorREADAccess Advisor
Kubernetes APIREADKubernetes API feature
Live LogsVIEWAccess Live Logs feature
AlertsAlert EventsEDITAcknowledge an event triggered by an alert in the events feed in scope of a team
Alert EventsREADAccess the events generated by triggered alerts in scope of a team
AlertsEDITModify alerts in scope of a team
AlertsREADAccess the alerts in scope of a team
Captures / InvestigateCapturesEDITModify captures
CapturesREADAccess captures
CapturesVIEWView captures in the UI
DashboardsDashboard Metrics DataREADN/A
DashboardsEDITModify dashboards in scope of a team
DashboardsREADAccess dashboards in scope of a team
Data Access SettingsGroupingsEDITCreate and edit custom groupings
GroupingsREADAccess default and custom groupings
Metrics DataREADAccess metrics data associated with a time series.
Metrics DescriptorsREADAccess metrics descriptors, which are unique combinations of metrics and labels that create a time series. For example, sysdig_container_cpu_used_percent{host_hostname=foo,region=bar}.
PromQL MetadataREADAccess Prometheus metrics and labels
EventsCustom EventsEDITAcknowledge the infrastructure and other events created by Sysdig Agent or Sysdig API
Custom EventsREADAccess the infrastructure and other events created by Sysdig Agent or Sysdig API
Explore / MetricsAgent ConsoleVIEWUse Agent Console commands
Agent Console - Agent StatusREADUse Agent Console commands which access agent status
Agent Console - ConfigurationVIEWUse Agent Console commands to view the configuration of the agent which does not contain sensitive information like passwords
Agent Console - Network CallsEXECUse Agent Console commands which make network calls to remote pods and endpoints
ExploreEDITN/A
ExploreREADMetric querying with Explore
Shared Groupings with TeamTOGGLEWhether the user can share a custom Explore Grouping to the team.
IntegrationsCustom IntegrationsEDITModify custom integrations in spotlight
Custom IntegrationsREADAccess custom integrations in spotlight
Helm RendererREADAccess Helm-renderer component. During cloud account setup in Secure, the wizard calls the Helm Renderer to generate the terraform snippet.
InfrastructureREADView discovered infrastructure
IntegrationsREADView discovered workload integrations
Monitoring IntegrationsEDITChange monitoring integration type or status
Monitoring IntegrationsREADAccess monitoring integration type or status
Monitoring IntegrationsVALIDATEChange monitoring integration status to Pending Metrics
EnvironmentsREADRelated to cloud account setups (both Metric Stream and Cost Private Pricing).
SpotlightREADAccess spotlight
SettingsAgent InstallationREADGet agent access key (required for agent installation)
Alert DowntimesREADList alert downtimes for the customer
API Access TokenEDITReset users API token in scope of a team
API Access TokenREADAccess users API token in scope of a team
API Access TokenVIEWView your API token
AWS SettingsREADAccess AWS settings
Events ForwarderREADAccess event forwarding configuration
Global Notification ChannelsREADAccess global notification channels
Notification ChannelsEDITModify notification channels in scope of a team
Notification ChannelsREADAccess notification channels in scope of a team
Service AccountsEDITModify service accounts in scope of a team
Service AccountsREADAccess service accounts in scope of a team
SubscriptionsREADAccess customer subscription details
Sysdig StorageREADView Sysdig storage configuration
TeamsMANAGEModify team settings without the ability to modify team membership for users

Advanced User

CategoryItemPermissionDescription
AdvisorAdvisorREADAccess Advisor
Kubernetes APIREADKubernetes API feature
Live LogsVIEWAccess Live Logs feature
AlertsAlert EventsEDITAcknowledge an event triggered by an alert in the events feed in scope of a team
Alert EventsREADAccess the events generated by triggered alerts in scope of a team
AlertsEDITModify alerts in scope of a team
AlertsREADAccess the alerts in scope of a team
Captures / InvestigateCapturesEDITModify captures
CapturesREADAccess captures
CapturesVIEWView captures in the UI
DashboardsDashboard Metrics DataREADN/A
DashboardsEDITModify dashboards in scope of a team
DashboardsREADAccess dashboards in scope of a team
Data SettingsGroupingsEDITCreate and edit custom groupings
GroupingsREADAccess default and custom groupings
Metrics DataREADAccess metrics data associated with a time series.
Metrics DescriptorsREADAccess metrics descriptors, which are unique combinations of metrics and labels that create a time series. For example, sysdig_container_cpu_used_percent{host_hostname=foo,region=bar}.
PromQL MetadataREADAccess Prometheus metrics and labels
EventsCustom EventsEDITAcknowledge the infrastructure and other events created by Sysdig Agent or Sysdig API
Custom EventsREADAccess the infrastructure and other events created by Sysdig Agent or Sysdig API
Explore / MetricsAgent ConsoleVIEWUse Agent Console commands
Agent Console - Agent StatusREADUse Agent Console commands which access agent status
Agent Console - ConfigurationVIEWUse Agent Console commands to view the configuration of the agent which does not contain sensitive information like passwords
Agent Console - Network CallsEXECUse Agent Console commands which make network calls to remote pods and endpoints
ExploreEDITN/A
ExploreREADMetric querying with Explore
Shared Groupings with TeamTOGGLEWhether the user can share a custom Explore Grouping to the team.
IntegrationsCustom IntegrationsEDITModify custom integrations in spotlight
Custom IntegrationsREADAccess custom integrations in spotlight
Helm RendererREADAccess Helm-renderer component. During cloud account setup in Secure, the wizard calls the Helm Renderer to generate the Terraform snippet.
InfrastructureREADView discovered infrastructure
IntegrationsREADView discovered workload integrations
Monitoring IntegrationsEDITChange monitoring integration type or status
Monitoring IntegrationsREADAccess monitoring integration type or status
Monitoring IntegrationsVALIDATEChange monitoring integration status to Pending Metrics
EnvironmentsREADRelated to cloud account setups (both Metric Stream and Cost Private Pricing).
SpotlightREADAccess spotlight
SettingsAgent InstallationREADGet agent access key (required for agent installation)
Alert DowntimesREADList alert downtimes for the customer
API Access TokenEDITReset users API token in scope of a team
API Access TokenREADAccess users API token in scope of a team
API Access TokenVIEWView your API token
AWS SettingsREADAccess AWS settings
Events ForwarderREADAccess event forwarding configuration
Global Notification ChannelsREADAccess global notification channels
Notification ChannelsEDITModify notification channels in scope of a team
Notification ChannelsREADAccess notification channels in scope of a team
Service AccountsREADAccess service accounts in scope of a team
SubscriptionsREADAccess customer subscription details
Sysdig StorageREADView Sysdig storage configuration

Sysdig Secure System Roles

Admin

CategoryItemPermissionDescription
Detection & Response › Respondsecure.rapid-response.execEXECUse rapid response
Captures / Investigatesecure.rapid-response.killKILLN/A
Detection & Response › Respondsecure.rapid-response.sessions.read.allREADN/A
Costscost-advisor.editEDITChange Cost Advisor pricing
cost-reports.editEDITChange cost reports
cost-advisor.readREADAccess Cost Advisor
cost-explorer.readREADAccess Cost Explorer
cost-reports.readREADAccess cost reports
Data Access Settingsdatastream.editEDITN/A
datastream.readREADAccess data stream configuration
groupings.editEDITCreate and edit custom groupings
Settings › Data Accessgroupings.readREADAccess default and custom groupings
Data Access Settingshistory-data.readREADN/A
ingest.prwsOTHERN/A
ingest.prws.controlledOTHERN/A
mds.read-metadataREADN/A
metadata-defaults.readREADN/A
Settings › Data Accessmetrics-data.readREADAccess metrics data associated with a time series.
metrics-descriptors.readREADAccess metrics descriptors, which are unique combinations of metrics and labels that create a time series. For example, sysdig_container_cpu_used_percent{host_hostname=foo,region=bar}.
Data Access Settingspromql-metadata.readREADAccess Prometheus metrics and labels
Eventscustom-events.readREADAccess the infrastructure and other events created by Sysdig Agent or Sysdig API
Settings › Agentsagent.cli.agent_internal_diagnosticsREADUse Agent Console commands which access internal diagnostics of the agent
agent.cli.agent_network_calls_to_remote_podsEXECUse Agent Console commands which make network calls to remote pods and endpoints
agent.cli.agent_statusREADUse Agent Console commands which access agent status
agent.cli.viewVIEWUse Agent Console commands
agent.cli.view_configurationVIEWUse Agent Console commands to view the configuration of the agent which does not contain sensitive information like passwords
agent.cli.view_sensitive_configurationVIEWUse Agent Console commands to view the configuration of the agent which does contain sensitive information like passwords. There are currently zero commands that implement this permission
Explore / Metricsexplore.readREADMetric querying with Explore
Get Startedonboarding.readREADN/A
Attack Surface › Identity Findingsidentity.readREADAccess data related to Cloud Infrastructure Entitlements Management (CIEM)
identity.editEDITChange compromised status of users flagged as Potentially Compromised
INTERNAL_UNCATEGORIZEDsecure.accessOTHERN/A
customer.adminOTHER_MUTATORN/A
team-admin.insightOTHERN/A
INTERNAL_ADMINonboarding.adminOTHER_MUTATORN/A
Integrationspromcat.integrations.manageMANAGEChange monitoring integration type or status
INTERNAL_SERVICEactive-secure-compliance-users-admin.readREADN/A
active-secure-overview-users-admin.readREADN/A
INTERNAL_ADMINinactive-users-admin.readREADN/A
INTERNAL_SERVICEmetrics-data-admin.readREADAccess metrics data.
Settingssso.configEDITN/A
INTERNAL_ADMINsso-system.configEDITN/A
Settingscustomer-admin-users.createCREATECreate new customer admin users
Posturecompliance.policies.adminOTHER_MUTATORN/A
Reportsreports.manageMANAGEChange monitoring reports
Posturesecure.onboarding.adminOTHER_MUTATORN/A
secure.todo.adminOTHER_MUTATORN/A
INTERNAL_ADMINsystem-admin.editEDITN/A
system-admin.readREADN/A
ROLE_MANAGEMENTcustom-team-roles.createCREATEN/A
Settingsteams.createCREATEN/A
Settings › Users & Teamsusers.createCREATEInvite new users
ROLE_MANAGEMENTcustom-team-roles.deleteDELETEN/A
Settingsteams.deleteDELETEN/A
access-keys.editEDITN/A
sso-active.editEDITN/A
Policiessecure.admission-controller.editEDITN/A
Scanning (Legacy)agentscanning.config.editEDITN/A
Settings › Access & Authenticationapi-token.editEDITReset users API token in scope of a team
Settingsaws-settings.editEDITN/A
beacon-configuration.editEDITN/A
Posturesecure.benchmark.results.editEDITN/A
Settingscertman.editEDITN/A
USERSuser-deactivation-configuration.editEDITModify user deactivation configuration
INTERNAL_SERVICEdata-api-settings.editEDITN/A
data-throttling-settings.editEDITN/A
Settingsdowntimes.editEDITN/A
events-forwarder.editEDITN/A
Integrationsfile-storage-config.editEDITN/A
Settingsglobal.notification-channels.editEDITN/A
global.service-accounts.editEDITN/A
global-service-account-notification-settings.editEDITN/A
group-mappings.editEDITModify mapping of users IDP groups to Sysdig teams/roles
ip-filters.editEDITModify IP filter configuration
login-banner.editEDITN/A
Settings › Users & Teamsmemberships.editEDITInvite other users to the teams
memberships-roles.editEDITModify team members roles
Network Securitynetsec.editEDITN/A
Get Startedonboarding.editEDITN/A
INTERNAL_ADMINservice.platform-alerts-settings.editEDITEdit platform alerts settings
Policiespolicy-tuner.editEDITN/A
Integrationspromcat.integrations.editEDITChange monitoring integration type or status
providers.editEDITN/A
Scanning (Legacy)scanning.retention.editEDITN/A
secure.images.editEDITN/A
Settings › Platformsecure-settings.editEDITModify Sysdig Secure configuration
Settings › Access & Authenticationteam-service-accounts.editEDITModify service accounts in scope of a team
service-account-notification-settings.editEDITN/A
service-account-role.editEDITChange service account roles
Settingssubscription.editEDITN/A
sysdig-storage.editEDITN/A
INTERNAL_ADMINsystem-falco.editEDITN/A
Settingsteams.editEDITN/A
Settings › Agentsteam-agent-cli-settings.editEDITToggle access to agent console for a team
Settings › Users & Teamsteam-capture-settings.editEDITToggle access to captures for a team
Settingsteam-rapid-response-settings.editEDITN/A
Integrationsthird-party-integrations.editEDITN/A
Ticketingticketing-customer-settings.editEDITEdit ticketing customer settings
UI Settingsui-customer-settings.editEDITN/A
ui-inactivity-settings.editEDITN/A
ui-settings.editEDITN/A
ui-user-app-settings.editEDITN/A
Settingsusers.editEDITN/A
user-list.editEDITN/A
USERSuser-password.editEDITN/A
user-profile.editEDITN/A
INTERNAL_UNCATEGORIZEDdev-task.execEXECN/A
es-query.execEXECN/A
INTERNAL_ADMINprotobuf.exportOTHER_MUTATORN/A
impersonate.editEDITN/A
INTERNAL_SERVICEmetrics-descriptors.manageMANAGEManage metrics descriptors, which are unique combinations of metrics and labels that create a time series. For example, sysdig_container_cpu_used_percent{host_hostname=foo,region=bar}.
INTERNAL_UNCATEGORIZEDquartz-jobs.manageMANAGEN/A
Settingssecure.risk-spotlight-integration-tokens.manageMANAGEManage risk spotlight integration tokens from the UI
access-keys.readREADN/A
Scanning (Legacy)agentscanning.config.readREADN/A
Settings › Agentsagent-installation.readREADGet agent access key (required for agent installation)
Settingsagreement.readREADN/A
Settings › Access & Authenticationapi-token.readREADAccess users API token in scope of a team
INTERNAL_UNCATEGORIZEDaudit-trail-events.readREADN/A
Settings › Platformaws-settings.readREADAccess AWS settings
Settingsazure-settings.readREADN/A
beacon-configuration.readREADN/A
certman.readREADN/A
Integrations › Environmentscloud.accounts.readREADAccess cloud accounts
INTERNAL_SERVICEcost-digest.readREADRead cost digest enabled customers
customer-by-accesskey.readREADN/A
Settingscustomer-plan.readREADN/A
customer-teams.readREADAccess and list teams data
USERSuser-deactivation-configuration.readREADAccess user deactivation configuration
ROLE_MANAGEMENTcustom-team-roles.readREADN/A
Dashboardsdashboard-metrics-data.readREADN/A
INTERNAL_SERVICEdata-api-settings.readREADN/A
data-throttling-settings.readREADN/A
Settingsdowntimes.readREADList alert downtimes for the customer
Settings › Platformevents-forwarder.readREADAccess event forwarding configuration
INTERNAL_UNCATEGORIZEDexternal-links.readREADN/A
Integrationsfile-storage-config.readREADN/A
Settingsglobal.service-accounts.readREADN/A
global-service-account-notification-settings.readREADN/A
group-mappings.readREADAccess mapping of users IDP groups to Sysdig teams/roles
Integrationshelmsrenderer.readREADAccess Helm-renderer component. During cloud account setup in Secure, the wizard calls the Helm Renderer to generate the terraform snippet.
INTERNAL_UNCATEGORIZEDimpersonate.readREADN/A
Integrationsinfrastructure.readREADView discovered infrastructure
integrations.readREADView discovered workload integrations
Settingsip-filters.readREADAccess IP Filter configuration
Advisorkubernetes-api-commands.readREADKubernetes API feature
live-logs.viewVIEWAccess Live Logs feature
Settingslogin-banner.readREADN/A
Settings › Users & Teamsmemberships.readREADAccess team members
Advisoroverviews.readREADAccess Advisor
Settingspayment-details.readREADN/A
ROLE_MANAGEMENTpermissions.readREADN/A
INTERNAL_ADMINservice.platform-alerts-settings.readREADRead platform alerts settings
Integrationspromcat.integrations.readREADAccess monitoring integration type or status
Integrations › Environmentsproviders.readREADRelated to cloud account setups (both Metric Stream and Cost Private Pricing).
Attack Surface › Vulnerability Findingsscanning.readREADRead scan results
Scanning (Legacy)scanning.retention.readREADN/A
Get Startedsecure.onboarding.readREADN/A
Settingssecure-settings.readREADN/A
Settings › Access & Authenticationteam-service-accounts.readREADAccess service accounts in scope of a team
service-account-notification-settings.readREADN/A
Integrationsspotlight.readREADAccess spotlight
Settings › Platformsubscription.readREADAccess customer subscription details
sysdig-storage.readREADView Sysdig storage configuration
INTERNAL_UNCATEGORIZEDteams.readREADN/A
Settings › Agentsteam-agent-cli-settings.readREADSee the agent console access settings for a team
Settings › Users & Teamsteam-capture-settings.readREADSee the capture settings for a team
Settingsteam-rapid-response-settings.readREADN/A
INTERNAL_UNCATEGORIZEDteam-search.readREADN/A
Integrations › Third Partythird-party-integrations.readREADN/A
Ticketingticketing-customer-settings.readREADRead ticketing customer settings
UI Settingsui-customer-settings.readREADN/A
ui-inactivity-settings.readREADN/A
ui-settings.readREADN/A
ui-user-app-settings.readREADN/A
Settings › Users & Teamsusers.readREADAccess existing users data
user-list.readREADSee the list of users for a customer
USERSuser-profile.readREADN/A
Settingsagreement.signSIGNN/A
INTERNAL_UNCATEGORIZEDsystem-support.editEDITN/A
INTERNAL_ADMINagent-availability.toggleTOGGLEN/A
INTERNAL_UNCATEGORIZEDtrack.eventOTHER_MUTATORN/A
ROLE_MANAGEMENTcustom-team-roles.updateUPDATEN/A
Sysdig Sagesage.execEXECSysdig Sage chat
Integrationspromcat.integrations.validateVALIDATEChange monitoring integration status to Pending Metrics

Sysdig Secure Team Roles

Standard User

CategoryItemPermissionDescription
AdvisorKubernetes APIREADKubernetes API feature
Live LogsVIEWAccess Live Logs feature
AlertsAlertsREADAccess the alerts in scope of a team
Detection & Response › RespondCapturesREADAccess captures
CapturesVIEWView captures in the UI
Containment Response ActionsVIEWView executions of Containment Response Actions
Data Gathering Response ActionsVIEWView executions of Response Actions that collect Data
Settings › Data AccessGroupingsEDITCreate and edit custom groupings
GroupingsREADAccess default and custom groupings
Metrics DataREADAccess metrics data
Metrics DescriptorsREADAccess metrics descriptors, which are unique combinations of metrics and labels that create a time series. For example, sysdig_container_cpu_used_percent{host_hostname=foo,region=bar}.
EventsCustom EventsREADAccess the infrastructure and other events created by Sysdig Agent or Sysdig API
Detection & Response › EventsPolicy EventsREADAccess policy events
Explore / MetricsAgent ConsoleVIEWUse Agent Console commands
Settings › AgentsAgent Console - Agent StatusREADUse Agent Console commands which access agent status
Agent Console - ConfigurationVIEWUse Agent Console commands to view the configuration of the agent which does not contain sensitive information like passwords
Agent Console - Network CallsEXECUse Agent Console commands which make network calls to remote pods and endpoints
Explore / MetricsExploreREADMetric querying with Explore
Shared Groupings with TeamTOGGLEWhether the user can share a custom Explore Grouping to the team.
IdentityCIEM featuresREADAccess information related to Cloud Infrastructure Entitlement Management.
CIEM featuresEDITModify compromised status of users flagged as Potentially Compromised.
IntegrationsHelm RendererREADAccess Helm-renderer component. During cloud account setup in Secure, the wizard calls the Helm Renderer to generate the terraform snippet.
InfrastructureREADView discovered infrastructure
Monitoring IntegrationsREADAccess monitoring integration type or status
EnvironmentsREADRelated to cloud account setups (both Metric Stream and Cost Private Pricing).
Policies › Attack Surface PoliciesPosture PoliciesREADView Posture policies
Attack Surface › Posture FindingsPosture ControlsREADView Posture Controls
Settings › PlatformZonesREADView Zones that are assigned to current team
Attack Surface › Compliance FindingsComplianceREADAccess Compliance results
PostureRisk AcceptanceREADAccess to Posture Risk Acceptance management page
Legacy Benchmark TasksEDITCreate and modify scheduled Legacy benchmark and compliance tasks
Legacy Benchmark TasksREADAccess scheduled Legacy benchmark tasks
Legacy BenchmarksREADAccess Legacy benchmark results
Legacy ComplianceREADAccess Legacy Compliance tasks and reports
Attack Surface › RisksRisksREADRead Risks
Attack Surface › Vulnerability FindingsImage ImportEDITImport scanning images
Scanning (legacy)ScanningREADRead scan results
Attack Surface › Vulnerability FindingsScanning AlertsREADAccess scanning alerts
Scanning Image ResultsCREATECreate scanning events
Scanning Image ResultsREADList scanning images
Scanning (legacy)Scanning RuntimeEDITQuery runtime containers API
Reporting › Vulnerability Reporting (Legacy)Scanning Scheduled ReportsREADView and download existing reports
Scanning (legacy)Scanning Trusted ImagesREADAccess the trusted images list
Scanning Untrusted ImagesREADAccess the untrusted images list
Scanning Vulnerability ExceptionsREADAccess vulnerability exceptions
Settings › AgentsAgent InstallationREADGet agent access key (required for agent installation)
Settings › Access & AuthenticationAPI Access TokenEDITReset users API token in scope of a team
API Access TokenREADAccess users API token in scope of a team
API Access TokenVIEWView your API token
Settings › PlatformAWS SettingsREADAccess AWS settings
Integrations › EnvironmentsCloud AccountsREADAccess cloud accounts
Integrations › Third PartyGlobal Notification ChannelsREADAccess global notification channels
SettingsIACREADAccess IAC results
Integrations › Third PartyNotification ChannelsREADAccess notification channels in scope of a team
Settings › Access & AuthenticationService AccountsREADAccess service accounts in scope of a team
Settings › PlatformSubscriptionsREADAccess customer subscription details
SettingsSysdig Secure SettingsEDITModify Sysdig Secure configuration
Sysdig StorageREADView Sysdig storage configuration
Attack Surface › Vulnerability FindingsScan ResultsREADView scan results on the Pipeline, Runtime, and Registry UI. Retrieve SBOM results from the SBOM API.
Vulnerability ManagementReportingREADView and download scan reports
PolicyREADView policy details
Risk AcceptanceREADView Exceptions
Attack Surface › Vulnerability FindingsRegistry CredentialsREADView registry credentials

Service Manager

CategoryItemPermissionDescription
AdvisorKubernetes APIREADKubernetes API feature
Live LogsVIEWAccess Live Logs feature
AlertsAlertsREADAccess the alerts in scope of a team
Detection & Response › RespondCapturesREADAccess captures
CapturesVIEWView captures in the UI
Containment Response ActionsVIEWView executions of Containment Response Actions
Data Gathering Response ActionsVIEWView executions of Response Actions that collect Data
Settings › Data AccessGroupingsEDITCreate and edit custom groupings
GroupingsREADAccess default and custom groupings
Metrics DataREADAccess metrics data associated with a time series.
Metrics DescriptorsREADAccess metrics descriptors, which are unique combinations of metrics and labels that create a time series. For example, sysdig_container_cpu_used_percent{host_hostname=foo,region=bar}.
EventsCustom EventsREADAccess the infrastructure and other events created by Sysdig Agent or Sysdig API
Detection & Response › EventsPolicy EventsREADAccess policy events
Explore / MetricsAgent ConsoleVIEWUse Agent Console commands
Settings › AgentsAgent Console - Agent StatusREADUse Agent Console commands which access agent status
Agent Console - ConfigurationVIEWUse Agent Console commands to view the configuration of the agent which does not contain sensitive information like passwords
Agent Console - Network CallsEXECUse Agent Console commands which make network calls to remote pods and endpoints
Explore / MetricsExploreREADMetric querying with Explore
Shared Groupings with TeamTOGGLEWhether the user can share a custom Explore Grouping to the team.
IdentityCIEM featuresREADAccess information related to Cloud Infrastructure Entitlement Management.
CIEM featuresEDITModify compromised status of users flagged as Potentially Compromised.
IntegrationsHelm RendererREADAccess Helm-renderer component. During cloud account setup in Secure, the wizard calls the Helm Renderer to generate the Terraform snippet.
InfrastructureREADView discovered infrastructure
Monitoring IntegrationsREADAccess monitoring integration type or status
EnvironmentsREADRelated to cloud account setups (both Metric Stream and Cost Private Pricing).
Policies › Attack Surface PoliciesPosture PoliciesREADView Posture policies
Attack Surface › Posture FindingsPosture ControlsREADView Posture Controls
Settings › PlatformZonesREADView Zones that are assigned to current team
Attack Surface › Compliance FindingsComplianceREADAccess Compliance results
PostureRisk AcceptanceREADAccess to Posture Risk Acceptance management page
Legacy Benchmark TasksEDITCreate and modify scheduled Legacy benchmark and compliance tasks
Legacy Benchmark TasksREADAccess scheduled Legacy benchmark tasks
Legacy BenchmarksREADAccess Legacy benchmark results
Legacy ComplianceREADAccess Legacy Compliance tasks and reports
Attack Surface › RisksRisksREADRead Risks
Attack Surface › Vulnerability FindingsImage ImportEDITImport scanning images
Scanning (Legacy)ScanningEXECExecute backend scanning
ScanningREADRead scan results
ScanningWRITEModify scanning alerts and registry credentials
Attack Surface › Vulnerability FindingsScanning AlertsEDITModify scanning alerts
Scanning AlertsREADAccess scanning alerts
Scanning Image ResultsCREATECreate scanning events
Scanning Image ResultsREADList scanning images
ScanningScanning Policy AssignmentsREADAccess policy mappings
Scanning RuntimeEDITQuery runtime containers API
Reporting › Vulnerability Reporting (Legacy)Scanning Scheduled ReportsREADView and download existing reports
ScanningScanning Trusted ImagesREADAccess the trusted images list
Scanning Untrusted ImagesREADAccess the untrusted images list
Scanning Vulnerability ExceptionsREADAccess vulnerability exceptions
Settings › AgentsAgent InstallationREADGet agent access key (required for agent installation)
Settings › Access & AuthenticationAPI Access TokenEDITReset users API token in scope of a team
API Access TokenREADAccess users API token in scope of a team
API Access TokenVIEWView your API token
Settings › PlatformAWS SettingsREADAccess AWS settings
Integrations › EnvironmentsCloud AccountsREADAccess cloud accounts
Integrations › Third PartyGlobal Notification ChannelsREADAccess global notification channels
SettingsIACREADAccess IAC results
Integrations › Third PartyNotification ChannelsEDITModify notification channels in scope of a team
Notification ChannelsREADAccess notification channels in scope of a team
Settings › Access & AuthenticationService AccountsREADAccess service accounts in scope of a team
Settings › PlatformSubscriptionsREADAccess customer subscription details
SettingsSysdig Secure SettingsEDITModify Sysdig Secure configuration
Sysdig StorageREADView Sysdig storage configuration
Settings › Users & TeamsTeam MembershipEDITInvite other users to the teams
Team MembershipREADAccess team members
Team Membership RolesEDITModify team members roles
TeamsMANAGEModify team settings without the ability to modify team membership for users
TeamsREADN/A
UsersREADAccess existing users data
Attack Surface › Vulnerability FindingsScan ResultsREADView scan results on the Pipeline, Runtime, and Registry UI. Retrieve SBOM results from the SBOM API.
Vulnerability ManagementReportingREADView and download scan reports
ReportingWRITECreate, modify, and delete reports
PolicyREADView policy details
PolicyWRITECreate, edit, and delete policies
Risk AcceptanceREADView Exceptions
Attack Surface › Vulnerability FindingsCLI ExecutionEXECAbility to run CLI Scanner
Attack Surface › Scan NowScan NowEXECAbility to instantly scan using Scan Now
Attack Surface › Vulnerability FindingsRegistry CredentialsREADView registry credentials
Registry CredentialsWRITEAdd registry credentials
Registry ScannerEXECAbility to run Registry Scanner

View Only

CategoryItemPermissionDescription
AdvisorKubernetes APIREADKubernetes API feature
Live LogsVIEWAccess Live Logs feature
AlertsAlertsREADAccess the alerts in scope of a team
Detection & Response › EventsActivity Audit CommandsREADAccess activity audit commands
Detection & Response › RespondCapturesREADAccess captures
CapturesVIEWView captures in the UI
Containment Response ActionsVIEWView executions of Containment Response Actions
Data Gathering Response ActionsVIEWView executions of Response Actions that collect Data
Settings › Data AccessGroupingsEDITCreate and edit custom groupings
GroupingsREADAccess default and custom groupings
Metrics DataREADAccess metrics data associated with a time series.
Metrics DescriptorsREADAccess metrics descriptors, which are unique combinations of metrics and labels that create a time series. For example, sysdig_container_cpu_used_percent{host_hostname=foo,region=bar}.
EventsCustom EventsREADAccess the infrastructure and other events created by Sysdig Agent or Sysdig API
Detection & Response › EventsPolicy EventsREADAccess policy events
Explore / MetricsAgent ConsoleVIEWUse Agent Console commands
Settings › AgentsAgent Console - Agent StatusREADUse Agent Console commands which access agent status
Agent Console - ConfigurationVIEWUse Agent Console commands to view the configuration of the agent which does not contain sensitive information like passwords
Agent Console - Network CallsEXECUse Agent Console commands which make network calls to remote pods and endpoints
Explore / MetricsExploreREADMetric querying with Explore
IdentityCIEM featuresREADAccess information related to Cloud Infrastructure Entitlement Management.
IntegrationsHelm RendererREADAccess Helm-renderer component. During cloud account setup in Secure, the wizard calls the Helm Renderer to generate the Terraform snippet.
InfrastructureREADView discovered infrastructure
Monitoring IntegrationsREADAccess monitoring integration type or status
EnvironmentsREADRelated to cloud account setups (both Metric Stream and Cost Private Pricing).
InventoryNetwork SecurityREADAccess Kubernetes Network Security policy advisor
Policies › Attack Surface PoliciesPosture PoliciesREADView Posture policies
Attack Surface › Posture FindingsPosture ControlsREADView Posture Controls
Settings › PlatformZonesREADView Zones that are assigned to current team
PoliciesImage profilingREADView existing image profiles
PoliciesREADAccess policies
Policies › Detection & Response PoliciesPolicy AdvisorREADRead PSP advisor simulations
Attack Surface › Compliance FindingsComplianceREADAccess Compliance results
PostureRisk AcceptanceREADAccess to Posture Risk Acceptance management page
Legacy Benchmark TasksEDITCreate and modify scheduled Legacy benchmark and compliance tasks
Legacy Benchmark TasksREADAccess scheduled Legacy benchmark tasks
Legacy BenchmarksREADAccess Legacy benchmark results
Legacy ComplianceREADAccess Legacy Compliance tasks and reports
Scanning (Legacy)ScanningREADRead scan results
Attack Surface › Vulnerability FindingsScanning AlertsREADAccess scanning alerts
Scanning Image ResultsREADList scanning images
Scanning (Legacy)Scanning PoliciesREADAccess security policies
Scanning Policy AssignmentsREADAccess policy mappings
Attack Surface › Vulnerability FindingsScanning Registry CredentialsREADList container registries
Scanning (Legacy)Scanning RuntimeEDITQuery runtime containers API
Reporting › Vulnerability Reporting (Legacy)Scanning Scheduled ReportsREADView and download existing reports
Scanning (Legacy)Scanning Trusted ImagesREADAccess the trusted images list
Scanning Untrusted ImagesREADAccess the untrusted images list
Scanning Vulnerability ExceptionsREADAccess vulnerability exceptions
Settings › AgentsAgent InstallationREADGet agent access key (required for agent installation)
Settings › Access & AuthenticationAPI Access TokenEDITReset users API token in scope of a team
API Access TokenREADAccess users API token in scope of a team
API Access TokenVIEWView your API token
Settings › PlatformAWS SettingsREADAccess AWS settings
Integrations › EnvironmentsCloud AccountsREADAccess cloud accounts
Integrations › Third PartyGlobal Notification ChannelsREADAccess global notification channels
SettingsIACREADAccess IAC results
Integrations › Third PartyNotification ChannelsREADAccess notification channels in scope of a team
Settings › Access & AuthenticationService AccountsREADAccess service accounts in scope of a team
Settings › PlatformSubscriptionsREADAccess customer subscription details
SettingsSysdig Secure SettingsEDITModify Sysdig Secure configuration
Sysdig StorageREADView Sysdig storage configuration
Attack Surface › Vulnerability FindingsScan ResultsREADView scan results on the Pipeline, Runtime, and Registry UI. Retrieve SBOM results from the SBOM API.
Vulnerability ManagementReportingREADView and download scan reports
PolicyREADView policy details
Risk AcceptanceREADView Exceptions
Attack Surface › Vulnerability FindingsRegistry CredentialsREADView registry credentials

Team Manager

CategoryItemPermissionDescription
AdvisorKubernetes APIREADKubernetes API feature
Live LogsVIEWAccess Live Logs feature
AlertsAlertsEDITModify alerts in scope of a team
AlertsREADAccess the alerts in scope of a team
Detection & Response › EventsActivity Audit CommandsREADAccess activity audit commands
Detection & Response › RespondCapturesEDITModify captures
CapturesREADAccess captures
CapturesVIEWView captures in the UI
Containment Response ActionsVIEWView executions of Containment Response Actions
Containment Response ActionsEXECExecute Containment Response Actions
Data Gathering Response ActionsVIEWView executions of Response Actions that collect Data
Data Gathering Response ActionsEXECExecute Response Actions that collect Data
Containment Response ActionsEXECExecute Containment Response Actions
Rapid ResponseEXECUse rapid response
Data Access SettingsDatastreamREADAccess data stream configuration
Settings › Data AccessGroupingsEDITCreate and edit custom groupings
GroupingsREADAccess default and custom groupings
Metrics DataREADAccess metrics data associated with a time series.
Metrics DescriptorsREADAccess metrics descriptors, which are unique combinations of metrics and labels that create a time series. For example, sysdig_container_cpu_used_percent{host_hostname=foo,region=bar}.
EventsCustom EventsREADAccess the infrastructure and other events created by Sysdig Agent or Sysdig API
Detection & Response › EventsPolicy EventsREADAccess policy events
Explore / MetricsAgent ConsoleVIEWUse Agent Console commands
Settings › AgentsAgent Console - Agent StatusREADUse Agent Console commands which access agent status
Agent Console - ConfigurationVIEWUse Agent Console commands to view the configuration of the agent which does not contain sensitive information like passwords
Agent Console - Network CallsEXECUse Agent Console commands which make network calls to remote pods and endpoints
Explore / MetricsExploreEDITN/A
ExploreREADMetric querying with Explore
Shared Groupings with TeamTOGGLEWhether the user can share a custom Explore Grouping to the team.
IdentityCIEM featuresREADAccess information related to Cloud Infrastructure Entitlement Management.
CIEM featuresEDITModify compromised status of users flagged as Potentially Compromised.
IntegrationsHelm RendererREADAccess Helm-renderer component. During cloud account setup in Secure, the wizard calls the Helm Renderer to generate the Terraform snippet.
InfrastructureREADView discovered infrastructure
Monitoring IntegrationsREADAccess monitoring integration type or status
EnvironmentsREADRelated to cloud account setups (both Metric Stream and Cost Private Pricing).
InventoryNetwork SecurityREADAccess Kubernetes Network Security policy advisor
Settings › PlatformZonesEDITView and Edit All Zones
Policies › Attack Surface PoliciesPosture PoliciesEDITView and Edit Posture policies
Attack Surface › Posture FindingsPosture ControlsEDITView and Edit Posture Controls
PoliciesImage profilingEXECExecute image profiling
Image profilingREADView existing image profiles
Image profilingWRITEWrite image profiles
PoliciesEDITModify policies
PoliciesREADAccess policies
Policies › Detection & Response PoliciesPolicy AdvisorEXECExecute PSP advisor simulation
Policy AdvisorREADRead PSP advisor simulations
Policy AdvisorWRITECreate PSP advisor simulation
Attack Surface › Compliance FindingsComplianceREADAccess Compliance results
PostureRisk AcceptanceEDITAccess and modify Posture Risk Acceptance
Open PREDITSetup Pull Requests from posture remediation panel
Legacy Benchmark TasksEDITAccess, Create and modify scheduled Legacy benchmark and compliance tasks
Legacy BenchmarksREADAccess Legacy benchmark results
Legacy ComplianceREADAccess Legacy Compliance tasks and reports
Attack Surface › RisksRisksREADRead Risks
Attack Surface › Vulnerability FindingsImage ImportEDITImport scanning images
ScanningScanningEXECExecute backend scanning
ScanningREADRead scan results
ScanningWRITEModify scanning alerts and registry credentials
Attack Surface › Vulnerability FindingsScanning AlertsEDITModify scanning alerts
Scanning AlertsREADAccess scanning alerts
Scanning Image ResultsCREATECreate scanning events
Scanning Image ResultsREADList scanning images
ScanningScanning PoliciesEDITModify security policies
Scanning PoliciesREADAccess security policies
Scanning Policy AssignmentsEDITCreate and modify policy mappings
Scanning Policy AssignmentsREADAccess policy mappings
Attack Surface › Vulnerability FindingsScanning Registry CredentialsEDITCreate and modify container registries configuration
Scanning Registry CredentialsREADList container registries
ScanningScanning RuntimeEDITQuery runtime containers API
Reporting › Vulnerability Reporting (Legacy)Scanning Scheduled ReportsEDITCreate and modify reports
Scanning Scheduled ReportsREADView and download existing reports
ScanningScanning Trusted ImagesEDITModify the trusted images list
Scanning Trusted ImagesREADAccess the trusted images list
Scanning Untrusted ImagesEDITModify the untrusted images list
Scanning Untrusted ImagesREADAccess the untrusted images list
Scanning Vulnerability ExceptionsEDITEdit vulnerability exceptions
Scanning Vulnerability ExceptionsREADAccess vulnerability exceptions
Settings › AgentsAgent InstallationREADGet agent access key (required for agent installation)
Settings › Access & AuthenticationAPI Access TokenEDITReset users API token in scope of a team
API Access TokenREADAccess users API token in scope of a team
API Access TokenVIEWView your API token
Settings › PlatformAWS SettingsREADAccess AWS settings
Integrations › EnvironmentsCloud AccountsREADAccess cloud accounts
Integrations › Third PartyGlobal Notification ChannelsREADAccess global notification channels
SettingsIACREADAccess IAC results
Integrations › Third PartyNotification ChannelsEDITModify notification channels in scope of a team
Notification ChannelsREADAccess notification channels in scope of a team
Settings › Access & AuthenticationService AccountsEDITModify service accounts in scope of a team
Service AccountsREADAccess service accounts in scope of a team
Settings › PlatformSubscriptionsREADAccess customer subscription details
SettingsSysdig Secure SettingsEDITModify Sysdig Secure configuration
Sysdig StorageREADView Sysdig storage configuration
Settings › Users & TeamsTeamsMANAGEModify team settings without the ability to modify team membership for users
Attack Surface › Vulnerability FindingsScan ResultsREADView scan results on the Pipeline, Runtime, and Registry UI. Retrieve SBOM results from the SBOM API.
Vulnerability ManagementReportingREADView and download scan reports
ReportingWRITECreate, modify, and delete reports
PolicyREADView policy details
PolicyWRITECreate, edit, and delete policies
Risk AcceptanceREADView Exceptions
Risk AcceptanceWRITECreate, update, and delete Exceptions
Attack Surface › Vulnerability FindingsCLI ExecutionEXECAbility to run CLI Scanner
Attack Surface › Scan NowScan NowEXECAbility to instantly scan using Scan Now
Attack Surface › Vulnerability FindingsRegistry CredentialsREADView registry credentials
Registry CredentialsWRITEAdd registry credentials
Registry ScannerEXECAbility to run Registry Scanner

Advanced User

CategoryItemPermissionDescription
AdvisorKubernetes APIREADKubernetes API feature
Live LogsVIEWAccess Live Logs feature
AlertsAlertsEDITModify alerts in scope of a team
AlertsREADAccess the alerts in scope of a team
Detection & Response › EventsActivity Audit CommandsREADAccess activity audit commands
Detection & Response › RespondCapturesEDITModify captures
CapturesREADAccess captures
CapturesVIEWView captures in the UI
Containment Response ActionsVIEWView executions of Containment Response Actions
Containment Response ActionsEXECExecute Containment Response Actions
Data Gathering Response ActionsVIEWView executions of Response Actions that collect Data
Data Gathering Response ActionsEXECExecute Response Actions that collect Data
Rapid ResponseEXECUse rapid response
Data Access SettingsDatastreamREADAccess data stream configuration
Settings › Data AccessGroupingsEDITCreate and edit custom groupings
GroupingsREADAccess default and custom groupings
Metrics DataREADAccess metrics data associated with a time series.
Metrics DescriptorsREADAccess metrics descriptors, which are unique combinations of metrics and labels that create a time series. For example, sysdig_container_cpu_used_percent{host_hostname=foo,region=bar}.
EventsCustom EventsREADAccess the infrastructure and other events created by Sysdig Agent or Sysdig API
Detection & Response › EventsPolicy EventsREADAccess policy events
Explore / MetricsAgent ConsoleVIEWUse Agent Console commands
Settings › AgentsAgent Console - Agent StatusREADUse Agent Console commands which access agent status
Agent Console - ConfigurationVIEWUse Agent Console commands to view the configuration of the agent which does not contain sensitive information like passwords
Agent Console - Network CallsEXECUse Agent Console commands which make network calls to remote pods and endpoints
Explore / MetricsExploreEDITN/A
ExploreREADMetric querying with Explore
Shared Groupings with TeamTOGGLEWhether the user can share a custom Explore Grouping to the team.
IdentityCIEM featuresREADAccess information related to Cloud Infrastructure Entitlement Management.
CIEM featuresEDITModify compromised status of users flagged as Potentially Compromised.
IntegrationsHelm RendererREADAccess Helm-renderer component. During cloud account setup in Secure, the wizard calls the Helm Renderer to generate the Terraform snippet.
InfrastructureREADView discovered infrastructure
Monitoring IntegrationsREADAccess monitoring integration type or status
EnvironmentsREADCloud account setups (both Metric Stream and Cost Private Pricing).
InventoryNetwork SecurityREADAccess Kubernetes Network Security policy advisor
Settings › PlatformZonesEDITView and Edit All Zones
Policies › Attack Surface PoliciesPosture PoliciesEDITView and Edit Posture policies
Attack Surface › Posture FindingsPosture ControlsEDITView and Edit Posture Controls
PoliciesImage profilingEXECExecute image profiling
Image profilingREADView existing image profiles
Image profilingWRITEWrite image profiles
PoliciesEDITModify policies
PoliciesREADAccess policies
Policies › Detection & Response PoliciesPolicy AdvisorEXECExecute PSP advisor simulation
Policy AdvisorREADRead PSP advisor simulations
Policy AdvisorWRITECreate PSP advisor simulation
Attack Surface › Compliance FindingsComplianceREADAccess Compliance results
PoliciesRisk AcceptanceEDITAccess and modify Posture Risk Acceptance
PostureOpen PREDITSetup Pull Requests from posture remediation panel
Legacy Benchmark TasksEDITAccess, Create and modify scheduled Legacy benchmark and compliance tasks
Legacy BenchmarksREADAccess Legacy benchmark results
Legacy ComplianceREADAccess Legacy Compliance tasks and reports
Attack Surface › RisksRisksREADRead Risks
Attack Surface › Vulnerability FindingsImage ImportEDITImport scanning images
Scanning (Legacy)ScanningEXECExecute backend scanning
ScanningREADRead scan results
ScanningWRITEModify scanning alerts and registry credentials
Attack Surface › Vulnerability FindingsScanning AlertsEDITModify scanning alerts
Scanning AlertsREADAccess scanning alerts
Scanning Image ResultsCREATECreate scanning events
Scanning Image ResultsREADList scanning images
Scanning (Legacy)Scanning PoliciesEDITModify security policies
Scanning PoliciesREADAccess security policies
Scanning Policy AssignmentsEDITCreate and modify policy mappings
Scanning Policy AssignmentsREADAccess policy mappings
Attack Surface › Vulnerability FindingsScanning Registry CredentialsEDITCreate and modify container registries configuration
Scanning Registry CredentialsREADList container registries
Scanning (Legacy)Scanning RuntimeEDITQuery runtime containers API
Reporting › Vulnerability Reporting (Legacy)Scanning Scheduled ReportsEDITCreate and modify reports
Scanning Scheduled ReportsREADView and download existing reports
Scanning (Legacy)Scanning Trusted ImagesEDITModify the trusted images list
Scanning Trusted ImagesREADAccess the trusted images list
Scanning Untrusted ImagesEDITModify the untrusted images list
Scanning Untrusted ImagesREADAccess the untrusted images list
Scanning Vulnerability ExceptionsEDITEdit vulnerability exceptions
Scanning Vulnerability ExceptionsREADAccess vulnerability exceptions
Settings › AgentsAgent InstallationREADGet agent access key (required for agent installation)
Settings › Access & AuthenticationAPI Access TokenEDITReset users API token in scope of a team
API Access TokenREADAccess users API token in scope of a team
API Access TokenVIEWView your API token
Settings › PlatformAWS SettingsREADAccess AWS settings
Integrations › EnvironmentsCloud AccountsREADAccess cloud accounts
Integrations › Third PartyGlobal Notification ChannelsREADAccess global notification channels
SettingsIACREADAccess IAC results
Integrations › Third PartyNotification ChannelsEDITModify notification channels in scope of a team
Notification ChannelsREADAccess notification channels in scope of a team
Settings › Access & AuthenticationService AccountsREADAccess service accounts in scope of a team
Settings › PlatformSubscriptionsREADAccess customer subscription details
SettingsSysdig Secure SettingsEDITModify Sysdig Secure configuration
Sysdig StorageREADView Sysdig storage configuration
Attack Surface › Vulnerability FindingsScan ResultsREADView scan results on the Pipeline, Runtime, and Registry UI. Retrieve SBOM results from the SBOM API.
Vulnerability ManagementReportingREADView and download scan reports
ReportingWRITECreate, modify, and delete reports
PolicyREADView policy details
PolicyWRITECreate, edit, and delete policies
Risk AcceptanceREADView Exceptions
Risk AcceptanceWRITECreate, update, and delete Exceptions
Attack Surface › Vulnerability FindingsCLI ExecutionEXECAbility to run CLI Scanner
Attack Surface › Scan NowScan NowEXECAbility to instantly scan using Scan Now
Attack Surface › Vulnerability FindingsRegistry CredentialsREADView registry credentials
Registry CredentialsWRITEAdd registry credentials
Registry ScannerEXECAbility to run Registry Scanner