Detailed Role Permissions
When deciding whether to use default team roles or create a custom role, it can be helpful to review the RBAC permissions that Sysdig grants to the default roles.
This page provides a detailed outline of the permissions granted to the various default roles in Secure and Monitor.
Sysdig Monitor
Standard User
Category | Item | Permission | Description |
---|---|---|---|
Advisor Manage access to Advisor | Advisor | READ | Access Advisor |
Kubernetes API | READ | Kubernetes API feature | |
Live Logs | VIEW | Access Live Logs feature | |
Alerts Manage access to Alerts | Alert Events | EDIT | Acknowledge an event triggerred by an alert in the events feed in scope of a team |
Alert Events | READ | Access the events generated by triggered alerts in scope of a team | |
Alerts | EDIT | Modify alerts in scope of a team | |
Alerts | READ | Access the alerts in scope of a team | |
Captures / Investigate Manage access to Captures / Investigate | Captures | EDIT | Modify captures |
Captures | READ | Access captures | |
Captures | VIEW | View captures in the UI | |
Dashboards Manage access to dashboards | Dashboard Metrics Data | READ | N/A |
Dashboards | EDIT | Modify dashboards in scope of a team | |
Dashboards | READ | Access dashboards in scope of a team | |
Data Access Settings Manage access to Data Settings | Datastream | READ | Access data stream configuration |
Groupings | EDIT | Create and edit custom groupings | |
Groupings | READ | Access default and custom groupings | |
Metrics Data | READ | Access metrics data | |
Metrics Descriptors | READ | Access metrics descriptors | |
PromQL Metadata | READ | Access Prometheus metrics and labels | |
Events Manage access to Events | Custom Events | EDIT | Acknowledge the infrastructure and other events created by Sysdig Agent or Sysdig API |
Custom Events | READ | Access the infrastructure and other events created by Sysdig Agent or Sysdig API | |
Explore / Metrics Manage access to Explore / Metrics | Agent Console | VIEW | Use Agent Console commands |
Agent Console - Agent Status | READ | Use Agent Console commands which access agent status | |
Agent Console - Configuration | VIEW | Use Agent Console commands to view the configuration of the agent which does not contain sensitive information like passwords | |
Agent Console - Network Calls | EXEC | Use Agent Console commands which make network calls to remote pods and endpoints | |
Integrations | Custom Integrations | EDIT | Modify custom integrations in spotlight |
Custom Integrations | READ | Access custom integrations in spotlight | |
Helm Renderer | READ | Access Helm-renderer component | |
Infrastructure | READ | View discovered infrastructure | |
Integrations | READ | View discovered workload integrations | |
Monitoring Integrations | EDIT | Change monitoring integration type or status | |
Monitoring Integrations | READ | Access monitoring integration type or status | |
Monitoring Integrations | VALIDATE | Change monitoring integration status to Pending Metrics | |
Providers | READ | N/A | |
Spotlight | READ | Access spotlight | |
Settings | Agent Installation | READ | Get agent access key (required for agent installation) |
Alert Downtimes | READ | List alert downtimes for the customer | |
API Access Token | EDIT | Reset users API token in scope of a team | |
API Access Token | READ | Access users API token in scope of a team | |
API Access Token | VIEW | View your API token | |
AWS Settings | READ | Access AWS settings | |
Events Forwarder | READ | Access event forwarding configuration | |
Global Notification Channels | READ | Access global notification channels | |
Notification Channels | READ | Access notification channels in scope of a team | |
Service Accounts | READ | Access service accounts in scope of a team | |
Subscriptions | READ | Access customer subscription details | |
Sysdig Storage | READ | View Sysdig storage configuration |
View Only
Category | Item | Permission | Description |
---|---|---|---|
Advisor Manage access to Advisor | Advisor | READ | Access Advisor |
Kubernetes API | READ | Kubernetes API feature | |
Live Logs | VIEW | Access Live Logs feature | |
Alerts Manage access to Alerts | Alert Events | READ | Access the events generated by triggered alerts in scope of a team |
Alerts | READ | Access the alerts in scope of a team | |
Captures / Investigate Manage access to Captures / Investigate | Captures | READ | Access captures |
Captures | VIEW | View captures in the UI | |
Dashboards Manage access to dashboards | Dashboard Metrics Data | READ | N/A |
Dashboards | READ | Access dashboards in scope of a team | |
Data Access Settings Manage access to Data Settings | Datastream | READ | Access data stream configuration |
Groupings | EDIT | Create and edit custom groupings | |
Groupings | READ | Access default and custom groupings | |
Metrics Data | READ | Access metrics data | |
Metrics Descriptors | READ | Access metrics descriptors | |
PromQL Metadata | READ | Access Prometheus metrics and labels | |
Events Manage access to Events | Custom Events | READ | Access the infrastructure and other events created by Sysdig Agent or Sysdig API |
Explore / Metrics Manage access to Explore / Metrics | Agent Console | VIEW | Use Agent Console commands |
Agent Console - Agent Status | READ | Use Agent Console commands which access agent status | |
Agent Console - Configuration | VIEW | Use Agent Console commands to view the configuration of the agent which does not contain sensitive information like passwords | |
Agent Console - Network Calls | EXEC | Use Agent Console commands which make network calls to remote pods and endpoints | |
Explore | READ | Metric querying with Explore | |
Integrations | Custom Integrations | READ | Access custom integrations in spotlight |
File Storage Config | READ | N/A | |
Helm Renderer | READ | Access Helm-renderer component | |
Infrastructure | READ | View discovered infrastructure | |
Integrations | READ | View discovered workload integrations | |
Monitoring Integrations | READ | Access monitoring integration type or status | |
Monitoring Integrations | VALIDATE | Change monitoring integration status to Pending Metrics | |
Providers | READ | N/A | |
Spotlight | READ | Access spotlight | |
Settings | Agent Installation | READ | Get agent access key (required for agent installation) |
Alert Downtimes | READ | List alert downtimes for the user. | |
API Access Token | READ | Access users API token in scope of a team | |
API Access Token | VIEW | View your API token | |
AWS Settings | READ | Access AWS settings | |
Events Forwarder | READ | Access event forwarding configuration | |
Global Notification Channels | READ | Access global notification channels | |
Notification Channels | READ | Access notification channels in scope of a team | |
Service Accounts | READ | Access service accounts in scope of a team | |
Subscriptions | READ | Access customer subscription details | |
Sysdig Storage | READ | View Sysdig storage configuration |
Team Manager
Category | Item | Permission | description |
---|---|---|---|
Advisor | Advisor | READ | Access Advisor |
Kubernetes API | READ | Kubernetes API feature | |
Live Logs | VIEW | Access Live Logs feature | |
Alerts | Alert Events | EDIT | Acknowledge an event triggerred by an alert in the events feed in scope of a team |
Alert Events | READ | Access the events generated by triggered alerts in scope of a team | |
Alerts | EDIT | Modify alerts in scope of a team | |
Alerts | READ | Access the alerts in scope of a team | |
Captures / Investigate | Captures | EDIT | Modify captures |
Captures | READ | Access captures | |
Captures | VIEW | View captures in the UI | |
Dashboards | Dashboard Metrics Data | READ | N/A |
Dashboards | EDIT | Modify dashboards in scope of a team | |
Dashboards | READ | Access dashboards in scope of a team | |
Data Access Settings | Groupings | EDIT | Create and edit custom groupings |
Groupings | READ | Access default and custom groupings | |
Metrics Data | READ | Access metrics data | |
Metrics Descriptors | READ | Access metrics descriptors | |
PromQL Metadata | READ | Access Prometheus metrics and labels | |
Events | Custom Events | EDIT | Acknowledge the infrastructure and other events created by Sysdig Agent or Sysdig API |
Custom Events | READ | Access the infrastructure and other events created by Sysdig Agent or Sysdig API | |
Explore / Metrics | Agent Console | VIEW | Use Agent Console commands |
Agent Console - Agent Status | READ | Use Agent Console commands which access agent status | |
Agent Console - Configuration | VIEW | Use Agent Console commands to view the configuration of the agent which does not contain sensitive information like passwords | |
Agent Console - Network Calls | EXEC | Use Agent Console commands which make network calls to remote pods and endpoints | |
Explore | EDIT | N/A | |
Explore | READ | Metric querying with Explore | |
Shared Groupings with Team | TOGGLE | Share metrics grouping with the team | |
Integrations | Custom Integrations | EDIT | Modify custom integrations in spotlight |
Custom Integrations | READ | Access custom integrations in spotlight | |
Helm Renderer | READ | Access Helm-renderer component | |
Infrastructure | READ | View discovered infrastructure | |
Integrations | READ | View discovered workload integrations | |
Monitoring Integrations | EDIT | Change monitoring integration type or status | |
Monitoring Integrations | READ | Access monitoring integration type or status | |
Monitoring Integrations | VALIDATE | Change monitoring integration status to Pending Metrics | |
Providers | READ | N/A | |
Spotlight | READ | Access spotlight | |
Settings | Agent Installation | READ | Get agent access key (required for agent installation) |
Alert Downtimes | READ | List alert downtimes for the customer | |
API Access Token | EDIT | Reset users API token in scope of a team | |
API Access Token | READ | Access users API token in scope of a team | |
API Access Token | VIEW | View your API token | |
AWS Settings | READ | Access AWS settings | |
Events Forwarder | READ | Access event forwarding configuration | |
Global Notification Channels | READ | Access global notification channels | |
Notification Channels | EDIT | Modify notification channels in scope of a team | |
Notification Channels | READ | Access notification channels in scope of a team | |
Service Accounts | EDIT | Modify service accounts in scope of a team | |
Service Accounts | READ | Access service accounts in scope of a team | |
Subscriptions | READ | Access customer subscription details | |
Sysdig Storage | READ | View Sysdig storage configuration | |
Teams | MANAGE | Modify team settings without the ability to modify team membership for users |
Advanced User
Category | Item | Permission | Description |
---|---|---|---|
Advisor | Advisor | READ | Access Advisor |
Kubernetes API | READ | Kubernetes API feature | |
Live Logs | VIEW | Access Live Logs feature | |
Alerts | Alert Events | EDIT | Acknowledge an event triggerred by an alert in the events feed in scope of a team |
Alert Events | READ | Access the events generated by triggered alerts in scope of a team | |
Alerts | EDIT | Modify alerts in scope of a team | |
Alerts | READ | Access the alerts in scope of a team | |
Captures / Investigate | Captures | EDIT | Modify captures |
Captures | READ | Access captures | |
Captures | VIEW | View captures in the UI | |
Dashboards | Dashboard Metrics Data | READ | N/A |
Dashboards | EDIT | Modify dashboards in scope of a team | |
Dashboards | READ | Access dashboards in scope of a team | |
Data Settings | Groupings | EDIT | Create and edit custom groupings |
Groupings | READ | Access default and custom groupings | |
Metrics Data | READ | Access metrics data | |
Metrics Descriptors | READ | Access metrics descriptors | |
PromQL Metadata | READ | Access Prometheus metrics and labels | |
Events | Custom Events | EDIT | Acknowledge the infrastructure and other events created by Sysdig Agent or Sysdig API |
Custom Events | READ | Access the infrastructure and other events created by Sysdig Agent or Sysdig API | |
Explore / Metrics | Agent Console | VIEW | Use Agent Console commands |
Agent Console - Agent Status | READ | Use Agent Console commands which access agent status | |
Agent Console - Configuration | VIEW | Use Agent Console commands to view the configuration of the agent which does not contain sensitive information like passwords | |
Agent Console - Network Calls | EXEC | Use Agent Console commands which make network calls to remote pods and endpoints | |
Explore | EDIT | N/A | |
Explore | READ | Metric querying with Explore | |
Shared Groupings with Team | TOGGLE | Share metrics grouping with the team | |
Integrations | Custom Integrations | EDIT | Modify custom integrations in spotlight |
Custom Integrations | READ | Access custom integrations in spotlight | |
Helm Renderer | READ | Access Helm-renderer component | |
Infrastructure | READ | View discovered infrastructure | |
Integrations | READ | View discovered workload integrations | |
Monitoring Integrations | EDIT | Change monitoring integration type or status | |
Monitoring Integrations | READ | Access monitoring integration type or status | |
Monitoring Integrations | VALIDATE | Change monitoring integration status to Pending Metrics | |
Providers | READ | N/A | |
Spotlight | READ | Access spotlight | |
Settings | Agent Installation | READ | Get agent access key (required for agent installation) |
Alert Downtimes | READ | List alert downtimes for the customer | |
API Access Token | EDIT | Reset users API token in scope of a team | |
API Access Token | READ | Access users API token in scope of a team | |
API Access Token | VIEW | View your API token | |
AWS Settings | READ | Access AWS settings | |
Events Forwarder | READ | Access event forwarding configuration | |
Global Notification Channels | READ | Access global notification channels | |
Notification Channels | EDIT | Modify notification channels in scope of a team | |
Notification Channels | READ | Access notification channels in scope of a team | |
Service Accounts | READ | Access service accounts in scope of a team | |
Subscriptions | READ | Access customer subscription details | |
Sysdig Storage | READ | View Sysdig storage configuration |
Sysdig Secure Team Roles
Standard User
Category | Item | Permission | Description |
---|---|---|---|
Advisor | Kubernetes API | READ | Kubernetes API feature |
Live Logs | VIEW | Access Live Logs feature | |
Alerts | Alerts | READ | Access the alerts in scope of a team |
Captures / Investigate | Captures | READ | Access captures |
Captures | VIEW | View captures in the UI | |
Data Access Settings | Groupings | EDIT | Create and edit custom groupings |
Groupings | READ | Access default and custom groupings | |
Metrics Data | READ | Access metrics data | |
Metrics Descriptors | READ | Access metrics descriptors | |
Events | Custom Events | READ | Access the infrastructure and other events created by Sysdig Agent or Sysdig API |
Policy Events | READ | Access policy events | |
Explore / Metrics | Agent Console | VIEW | Use Agent Console commands |
Agent Console - Agent Status | READ | Use Agent Console commands which access agent status | |
Agent Console - Configuration | VIEW | Use Agent Console commands to view the configuration of the agent which does not contain sensitive information like passwords | |
Agent Console - Network Calls | EXEC | Use Agent Console commands which make network calls to remote pods and endpoints | |
Explore | READ | Metric querying with Explore | |
Shared Groupings with Team | TOGGLE | Share metrics grouping with the team | |
Integrations | Helm Renderer | READ | Access Helm-renderer component |
Infrastructure | READ | View discovered infrastructure | |
Monitoring Integrations | READ | Access monitoring integration type or status | |
Providers | READ | N/A | |
Policies | Posture Policies | READ | View Posture policies |
Posture Controls | READ | View Posture Controls | |
Zones | READ | View Zones that are assigned to current team | |
Posture | Compliance | READ | Access Compliance results |
Risk Acceptance | READ | Access to Posture Risk Acceptance management page | |
Legacy Benchmark Tasks | EDIT | Create and modify scheduled Legacy benchmark and compliance tasks | |
Legacy Benchmark Tasks | READ | Access scheduled Legacy benchmark tasks | |
Legacy Benchmarks | READ | Access Legacy benchmark results | |
Legacy Compliance | READ | Access Legacy Compliance tasks and reports | |
Risk | Risks | READ | Read Risks |
Scanning (legacy) | Image Import | EDIT | Import scanning images |
Scanning | READ | Read scan results | |
Scanning Alerts | READ | Access scanning alerts | |
Scanning Image Results | CREATE | Create scanning events | |
Scanning Image Results | READ | List scanning images | |
Scanning Runtime | EDIT | Query runtime containers API | |
Scanning Scheduled Reports | READ | View and download existing reports | |
Scanning Trusted Images | READ | Access the trusted images list | |
Scanning Untrusted Images | READ | Access the untrusted images list | |
Scanning Vulnerability Exceptions | READ | Access vulnerability exceptions | |
Settings | Agent Installation | READ | Get agent access key (required for agent installation) |
API Access Token | EDIT | Reset users API token in scope of a team | |
API Access Token | READ | Access users API token in scope of a team | |
API Access Token | VIEW | View your API token | |
AWS Settings | READ | Access AWS settings | |
Cloud Accounts | READ | Access cloud accounts | |
Global Notification Channels | READ | Access global notification channels | |
IAC | READ | Access IAC results | |
Notification Channels | READ | Access notification channels in scope of a team | |
Service Accounts | READ | Access service accounts in scope of a team | |
Subscriptions | READ | Access customer subscription details | |
Sysdig Secure Settings | EDIT | Modify Sysdig Secure configuration | |
Sysdig Storage | READ | View Sysdig storage configuration | |
Vulnerability Management | Scan Results | READ | View scan results on the Pipeline, Runtime, and Registry UI. Retrieve SBOM results from the SBOM API. |
Reporting | READ | View and download scan reports | |
Policy | READ | View policy details | |
Risk Acceptance | READ | View Exceptions | |
Registry Credentials | READ | View registry credentials |
Service Manager
Category | Item | Permission | Description |
---|---|---|---|
Advisor | Kubernetes API | READ | Kubernetes API feature |
Live Logs | VIEW | Access Live Logs feature | |
Alerts | Alerts | READ | Access the alerts in scope of a team |
Captures / Investigate | Captures | READ | Access captures |
Captures | VIEW | View captures in the UI | |
Data Access Settings | Groupings | EDIT | Create and edit custom groupings |
Groupings | READ | Access default and custom groupings | |
Metrics Data | READ | Access metrics data | |
Metrics Descriptors | READ | Access metrics descriptors | |
Events | Custom Events | READ | Access the infrastructure and other events created by Sysdig Agent or Sysdig API |
Policy Events | READ | Access policy events | |
Explore / Metrics | Agent Console | VIEW | Use Agent Console commands |
Agent Console - Agent Status | READ | Use Agent Console commands which access agent status | |
Agent Console - Configuration | VIEW | Use Agent Console commands to view the configuration of the agent which does not contain sensitive information like passwords | |
Agent Console - Network Calls | EXEC | Use Agent Console commands which make network calls to remote pods and endpoints | |
Explore | READ | Metric querying with Explore | |
Shared Groupings with Team | TOGGLE | Share metrics grouping with the team | |
Integrations | Helm Renderer | READ | Access Helm-renderer component |
Infrastructure | READ | View discovered infrastructure | |
Monitoring Integrations | READ | Access monitoring integration type or status | |
Providers | READ | N/A | |
Policies | Posture Policies | READ | View Posture policies |
Posture Controls | READ | View Posture Controls | |
Zones | READ | View Zones that are assigned to current team | |
Posture | Compliance | READ | Access Compliance results |
Risk Acceptance | READ | Access to Posture Risk Acceptance management page | |
Legacy Benchmark Tasks | EDIT | Create and modify scheduled Legacy benchmark and compliance tasks | |
Legacy Benchmark Tasks | READ | Access scheduled Legacy benchmark tasks | |
Legacy Benchmarks | READ | Access Legacy benchmark results | |
Legacy Compliance | READ | Access Legacy Compliance tasks and reports | |
Risk | Risks | READ | Read Risks |
Scanning (Legacy) | Image Import | EDIT | Import scanning images |
Scanning | EXEC | Execute backend scanning | |
Scanning | READ | Read scan results | |
Scanning | WRITE | Modify scanning alerts and registry credentials | |
Scanning Alerts | EDIT | Modify scanning alerts | |
Scanning Alerts | READ | Access scanning alerts | |
Scanning | Scanning Image Results | CREATE | Create scanning events |
Scanning Image Results | READ | List scanning images | |
Scanning Policy Assignments | READ | Access policy mappings | |
Scanning Runtime | EDIT | Query runtime containers API | |
Scanning Scheduled Reports | READ | View and download existing reports | |
Scanning Trusted Images | READ | Access the trusted images list | |
Scanning Untrusted Images | READ | Access the untrusted images list | |
Scanning Vulnerability Exceptions | READ | Access vulnerability exceptions | |
Settings | Agent Installation | READ | Get agent access key (required for agent installation) |
API Access Token | EDIT | Reset users API token in scope of a team | |
API Access Token | READ | Access users API token in scope of a team | |
API Access Token | VIEW | View your API token | |
AWS Settings | READ | Access AWS settings | |
Cloud Accounts | READ | Access cloud accounts | |
Global Notification Channels | READ | Access global notification channels | |
IAC | READ | Access IAC results | |
Notification Channels | EDIT | Modify notification channels in scope of a team | |
Notification Channels | READ | Access notification channels in scope of a team | |
Service Accounts | READ | Access service accounts in scope of a team | |
Subscriptions | READ | Access customer subscription details | |
Sysdig Secure Settings | EDIT | Modify Sysdig Secure configuration | |
Sysdig Storage | READ | View Sysdig storage configuration | |
Team Membership | EDIT | Invite other users to the teams | |
Team Membership | READ | Access team members | |
Team Membership Roles | EDIT | Modify team members roles | |
Teams | MANAGE | Modify team settings without the ability to modify team membership for users | |
Teams | READ | N/A | |
Users | READ | Access existing users data | |
Vulnerability Management | Scan Results | READ | View scan results on the Pipeline, Runtime, and Registry UI. Retrieve SBOM results from the SBOM API. |
Reporting | READ | View and download scan reports | |
Reporting | WRITE | Create, modify, and delete reports | |
Policy | READ | View policy details | |
Pocily | WRITE | Create, edit, and delete policies | |
Risk Acceptance | READ | View Exceptions | |
CLI Execution | EXEC | Ability to run CLI Scanner | |
Scan Now | EXEC | Ability to instantly scan using Scan Now | |
Registry Credentials | READ | View registry credentials | |
Registry Credentials | WRITE | Add registry credentials | |
Registry Scanner | EXEC | Ability to run Registry Scanner |
View Only
Category | Item | Permission | Description |
---|---|---|---|
Advisor | Kubernetes API | READ | Kubernetes API feature |
Live Logs | VIEW | Access Live Logs feature | |
Alerts | Alerts | READ | Access the alerts in scope of a team |
Captures / Investigate | Activity Audit Commands | READ | Access activity audit commands |
Captures | READ | Access captures | |
Captures | VIEW | View captures in the UI | |
Data Access Settings | Groupings | EDIT | Create and edit custom groupings |
Groupings | READ | Access default and custom groupings | |
Metrics Data | READ | Access metrics data | |
Metrics Descriptors | READ | Access metrics descriptors | |
Events | Custom Events | READ | Access the infrastructure and other events created by Sysdig Agent or Sysdig API |
Policy Events | READ | Access policy events | |
Explore / Metrics | Agent Console | VIEW | Use Agent Console commands |
Agent Console - Agent Status | READ | Use Agent Console commands which access agent status | |
Agent Console - Configuration | VIEW | Use Agent Console commands to view the configuration of the agent which does not contain sensitive information like passwords | |
Agent Console - Network Calls | EXEC | Use Agent Console commands which make network calls to remote pods and endpoints | |
Explore | READ | Metric querying with Explore | |
Integrations | Helm Renderer | READ | Access Helm-renderer component |
Infrastructure | READ | View discovered infrastructure | |
Monitoring Integrations | READ | Access monitoring integration type or status | |
Providers | READ | N/A | |
Network Security | Network Security | READ | Access Kubernetes Network Security policy advisor |
Policies | Posture Policies | READ | View Posture policies |
Posture Controls | READ | View Posture Controls | |
Zones | READ | View Zones that are assigned to current team | |
Image profiling | READ | View existing image profiles | |
Policies | READ | Access policies | |
Policy Advisor | READ | Read PSP advisor simulations | |
Posture | Compliance | READ | Access Compliance results |
Risk Acceptance | READ | Access to Posture Risk Acceptance management page | |
Legacy Benchmark Tasks | EDIT | Create and modify scheduled Legacy benchmark and compliance tasks | |
Legacy Benchmark Tasks | READ | Access scheduled Legacy benchmark tasks | |
Legacy Benchmarks | READ | Access Legacy benchmark results | |
Legacy Compliance | READ | Access Legacy Compliance tasks and reports | |
Scanning (Legacy) | Scanning | READ | Read scan results |
Scanning Alerts | READ | Access scanning alerts | |
Scanning Image Results | READ | List scanning images | |
Scanning Policies | READ | Access security policies | |
Scanning Policy Assignments | READ | Access policy mappings | |
Scanning Registry Credentials | READ | List container registries | |
Scanning Runtime | EDIT | Query runtime containers API | |
Scanning Scheduled Reports | READ | View and download existing reports | |
Scanning Trusted Images | READ | Access the trusted images list | |
Scanning Untrusted Images | READ | Access the untrusted images list | |
Scanning Vulnerability Exceptions | READ | Access vulnerability exceptions | |
Settings | Agent Installation | READ | Get agent access key (required for agent installation) |
API Access Token | EDIT | Reset users API token in scope of a team | |
API Access Token | READ | Access users API token in scope of a team | |
API Access Token | VIEW | View your API token | |
AWS Settings | READ | Access AWS settings | |
Cloud Accounts | READ | Access cloud accounts | |
Global Notification Channels | READ | Access global notification channels | |
IAC | READ | Access IAC results | |
Notification Channels | READ | Access notification channels in scope of a team | |
Service Accounts | READ | Access service accounts in scope of a team | |
Subscriptions | READ | Access customer subscription details | |
Sysdig Secure Settings | EDIT | Modify Sysdig Secure configuration | |
Settings | Sysdig Storage | READ | View Sysdig storage configuration |
Vulnerability Management | Scan Results | READ | View scan results on the Pipeline, Runtime, and Registry UI. Retrieve SBOM results from the SBOM API. |
Reporting | READ | View and download scan reports | |
Policy | READ | View policy details | |
Risk Acceptance | READ | View Exceptions | |
Registry Credentials | READ | View registry credentials |
Team Manager
Category | Item | Permission | Description |
---|---|---|---|
Advisor | Kubernetes API | READ | Kubernetes API feature |
Live Logs | VIEW | Access Live Logs feature | |
Alerts | Alerts | EDIT | Modify alerts in scope of a team |
Alerts | READ | Access the alerts in scope of a team | |
Captures / Investigate | Activity Audit Commands | READ | Access activity audit commands |
Captures | EDIT | Modify captures | |
Captures | READ | Access captures | |
Captures | VIEW | View captures in the UI | |
Rapid Response | EXEC | Use rapid response | |
Data Access Settings | Datastream | READ | Access data stream configuration |
Groupings | EDIT | Create and edit custom groupings | |
Groupings | READ | Access default and custom groupings | |
Metrics Data | READ | Access metrics data | |
Metrics Descriptors | READ | Access metrics descriptors | |
Events | Custom Events | READ | Access the infrastructure and other events created by Sysdig Agent or Sysdig API |
Policy Events | READ | Access policy events | |
Explore / Metrics | Agent Console | VIEW | Use Agent Console commands |
Agent Console - Agent Status | READ | Use Agent Console commands which access agent status | |
Agent Console - Configuration | VIEW | Use Agent Console commands to view the configuration of the agent which does not contain sensitive information like passwords | |
Agent Console - Network Calls | EXEC | Use Agent Console commands which make network calls to remote pods and endpoints | |
Explore | EDIT | N/A | |
Explore | READ | Metric querying with Explore | |
Shared Groupings with Team | TOGGLE | Share metrics grouping with the team | |
Integrations | Helm Renderer | READ | Access Helm-renderer component |
Infrastructure | READ | View discovered infrastructure | |
Monitoring Integrations | READ | Access monitoring integration type or status | |
Providers | READ | N/A | |
Network Security | Network Security | READ | Access Kubernetes Network Security policy advisor |
Policies | Zones | EDIT | View and Edit All Zones |
Posture Policies | EDIT | View and Edit Posture policies | |
Posture Controls | EDIT | View and Edit Posture Controls | |
Image profiling | EXEC | Execute image profiling | |
Image profiling | READ | View existing image profiles | |
Image profiling | WRITE | Write image profiles | |
Policies | EDIT | Modify policies | |
Policies | READ | Access policies | |
Policy Advisor | EXEC | Execute PSP advisor simulation | |
Policy Advisor | READ | Read PSP advisor simulations | |
Policy Advisor | WRITE | Create PSP advisor simulation | |
Posture | Compliance | READ | Access Compliance results |
Risk Acceptance | EDIT | Access and modify Posture Risk Acceptance | |
Open PR | EDIT | Setup Pull Requests from posture remediation panel | |
Legacy Benchmark Tasks | EDIT | Access, Create and modify scheduled Legacy benchmark and compliance tasks | |
Legacy Benchmarks | READ | Access Legacy benchmark results | |
Legacy Compliance | READ | Access Legacy Compliance tasks and reports | |
Risk | Risks | READ | Read Risks |
Scanning | Image Import | EDIT | Import scanning images |
Scanning | EXEC | Execute backend scanning | |
Scanning | READ | Read scan results | |
Scanning | WRITE | Modify scanning alerts and registry credentials | |
Scanning Alerts | EDIT | Modify scanning alerts | |
Scanning Alerts | READ | Access scanning alerts | |
Scanning Image Results | CREATE | Create scanning events | |
Scanning Image Results | READ | List scanning images | |
Scanning Policies | EDIT | Modify security policies | |
Scanning Policies | READ | Access security policies | |
Scanning Policy Assignments | EDIT | Create and modify policy mappings | |
Scanning Policy Assignments | READ | Access policy mappings | |
Scanning Registry Credentials | EDIT | Create and modify container registries configuration | |
Scanning Registry Credentials | READ | List container registries | |
Scanning Runtime | EDIT | Query runtime containers API | |
Scanning Scheduled Reports | EDIT | Create and modify reports | |
Scanning Scheduled Reports | READ | View and download existing reports | |
Scanning Trusted Images | EDIT | Modify the trusted images list | |
Scanning Trusted Images | READ | Access the trusted images list | |
Scanning Untrusted Images | EDIT | Modify the untrusted images list | |
Scanning Untrusted Images | READ | Access the untrusted images list | |
Scanning Vulnerability Exceptions | EDIT | Edit vulnerability exceptions | |
Scanning Vulnerability Exceptions | READ | Access vulnerability exceptions | |
Settings | Agent Installation | READ | Get agent access key (required for agent installation) |
API Access Token | EDIT | Reset users API token in scope of a team | |
API Access Token | READ | Access users API token in scope of a team | |
API Access Token | VIEW | View your API token | |
AWS Settings | READ | Access AWS settings | |
Cloud Accounts | READ | Access cloud accounts | |
Global Notification Channels | READ | Access global notification channels | |
IAC | READ | Access IAC results | |
Notification Channels | EDIT | Modify notification channels in scope of a team | |
Notification Channels | READ | Access notification channels in scope of a team | |
Service Accounts | EDIT | Modify service accounts in scope of a team | |
Service Accounts | READ | Access service accounts in scope of a team | |
Subscriptions | READ | Access customer subscription details | |
Sysdig Secure Settings | EDIT | Modify Sysdig Secure configuration | |
Sysdig Storage | READ | View Sysdig storage configuration | |
Teams | MANAGE | Modify team settings without the ability to modify team membership for users | |
Vulnerability Management | Scan Results | READ | View scan results on the Pipeline, Runtime, and Registry UI. Retrieve SBOM results from the SBOM API. |
Reporting | READ | View and download scan reports | |
Reporting | WRITE | Create, modify, and delete reports | |
Policy | READ | View policy details | |
Pocily | WRITE | Create, edit, and delete policies | |
Risk Acceptance | READ | View Exceptions | |
Risk Acceptance | WRITE | Create, update, and delete Exceptions | |
CLI Execution | EXEC | Ability to run CLI Scanner | |
Scan Now | EXEC | Ability to instantly scan using Scan Now | |
Registry Credentials | READ | View registry credentials | |
Registry Credentials | WRITE | Add registry credentials | |
Registry Scanner | EXEC | Ability to run Registry Scanner |
Advanced User
Category | Item | Permission | Description |
---|---|---|---|
Advisor | Kubernetes API | READ | Kubernetes API feature |
Live Logs | VIEW | Access Live Logs feature | |
Alerts | Alerts | EDIT | Modify alerts in scope of a team |
Alerts | READ | Access the alerts in scope of a team | |
Captures / Investigate | Activity Audit Commands | READ | Access activity audit commands |
Captures | EDIT | Modify captures | |
Captures | READ | Access captures | |
Captures | VIEW | View captures in the UI | |
Rapid Response | EXEC | Use rapid response | |
Data Access Settings | Datastream | READ | Access data stream configuration |
Groupings | EDIT | Create and edit custom groupings | |
Groupings | READ | Access default and custom groupings | |
Metrics Data | READ | Access metrics data | |
Metrics Descriptors | READ | Access metrics descriptors | |
Events | Custom Events | READ | Access the infrastructure and other events created by Sysdig Agent or Sysdig API |
Policy Events | READ | Access policy events | |
Explore / Metrics | Agent Console | VIEW | Use Agent Console commands |
Agent Console - Agent Status | READ | Use Agent Console commands which access agent status | |
Agent Console - Configuration | VIEW | Use Agent Console commands to view the configuration of the agent which does not contain sensitive information like passwords | |
Agent Console - Network Calls | EXEC | Use Agent Console commands which make network calls to remote pods and endpoints | |
Explore | EDIT | N/A | |
Explore | READ | Metric querying with Explore | |
Shared Groupings with Team | TOGGLE | Share metrics grouping with the team | |
Integrations | Helm Renderer | READ | Access Helm-renderer component |
Infrastructure | READ | View discovered infrastructure | |
Monitoring Integrations | READ | Access monitoring integration type or status | |
Providers | READ | N/A | |
Network Security | Network Security | READ | Access Kubernetes Network Security policy advisor |
Policies | Zones | EDIT | View and Edit All Zones |
Posture Policies | EDIT | View and Edit Posture policies | |
Posture Controls | EDIT | View and Edit Posture Controls | |
Image profiling | EXEC | Execute image profiling | |
Image profiling | READ | View existing image profiles | |
Image profiling | WRITE | Write image profiles | |
Policies | EDIT | Modify policies | |
Policies | READ | Access policies | |
Policy Advisor | EXEC | Execute PSP advisor simulation | |
Policy Advisor | READ | Read PSP advisor simulations | |
Policy Advisor | WRITE | Create PSP advisor simulation | |
Compliance | READ | Access Compliance results | |
Risk Acceptance | EDIT | Access and modify Posture Risk Acceptance | |
Posture | Open PR | EDIT | Setup Pull Requests from posture remediation panel |
Legacy Benchmark Tasks | EDIT | Access, Create and modify scheduled Legacy benchmark and compliance tasks | |
Legacy Benchmarks | READ | Access Legacy benchmark results | |
Legacy Compliance | READ | Access Legacy Compliance tasks and reports | |
Risk | Risks | READ | Read Risks |
Scanning (Legacy) | Image Import | EDIT | Import scanning images |
Scanning | EXEC | Execute backend scanning | |
Scanning | READ | Read scan results | |
Scanning | WRITE | Modify scanning alerts and registry credentials | |
Scanning Alerts | EDIT | Modify scanning alerts | |
Scanning Alerts | READ | Access scanning alerts | |
Scanning Image Results | CREATE | Create scanning events | |
Scanning Image Results | READ | List scanning images | |
Scanning Policies | EDIT | Modify security policies | |
Scanning Policies | READ | Access security policies | |
Scanning Policy Assignments | EDIT | Create and modify policy mappings | |
Scanning Policy Assignments | READ | Access policy mappings | |
Scanning Registry Credentials | EDIT | Create and modify container registries configuration | |
Scanning Registry Credentials | READ | List container registries | |
Scanning Runtime | EDIT | Query runtime containers API | |
Scanning Scheduled Reports | EDIT | Create and modify reports | |
Scanning Scheduled Reports | READ | View and download existing reports | |
Scanning Trusted Images | EDIT | Modify the trusted images list | |
Scanning Trusted Images | READ | Access the trusted images list | |
Scanning Untrusted Images | EDIT | Modify the untrusted images list | |
Scanning Untrusted Images | READ | Access the untrusted images list | |
Scanning Vulnerability Exceptions | EDIT | Edit vulnerability exceptions | |
Scanning Vulnerability Exceptions | READ | Access vulnerability exceptions | |
Settings | Agent Installation | READ | Get agent access key (required for agent installation) |
API Access Token | EDIT | Reset users API token in scope of a team | |
API Access Token | READ | Access users API token in scope of a team | |
API Access Token | VIEW | View your API token | |
AWS Settings | READ | Access AWS settings | |
Cloud Accounts | READ | Access cloud accounts | |
Global Notification Channels | READ | Access global notification channels | |
IAC | READ | Access IAC results | |
Notification Channels | EDIT | Modify notification channels in scope of a team | |
Notification Channels | READ | Access notification channels in scope of a team | |
Service Accounts | READ | Access service accounts in scope of a team | |
Subscriptions | READ | Access customer subscription details | |
Sysdig Secure Settings | EDIT | Modify Sysdig Secure configuration | |
Sysdig Storage | READ | View Sysdig storage configuration | |
Vulnerability Management | Scan Results | READ | View scan results on the Pipeline, Runtime, and Registry UI. Retrieve SBOM results from the SBOM API. |
Reporting | READ | View and download scan reports | |
Reporting | WRITE | Create, modify, and delete reports | |
Policy | READ | View policy details | |
Pocily | WRITE | Create, edit, and delete policies | |
Risk Acceptance | READ | View Exceptions | |
Risk Acceptance | WRITE | Create, update, and delete Exceptions | |
CLI Execution | EXEC | Ability to run CLI Scanner | |
Scan Now | EXEC | Ability to instantly scan using Scan Now | |
Registry Credentials | READ | View registry credentials | |
Registry Credentials | WRITE | Add registry credentials | |
Registry Scanner | EXEC | Ability to run Registry Scanner |
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.