Detailed Role Permissions

When deciding whether to use default team roles or create a custom role, it can be helpful to review the Role-Based Access Control (RBAC) permissions that Sysdig grants to the default roles.

This page provides a detailed outline of the permissions granted to the default roles in Secure and Monitor.

Sysdig Monitor System Roles


Integrationspromcat.integrations.manageMANAGEChange monitoring integration type or status
INTERNAL_SERVICEmetrics-data-admin.readREADAccess metrics data associated with a time series.
Reportsreports.manageMANAGEChange monitoring reports
Explore / Metricsagent.cli.agent_internal_diagnosticsREADUse Agent Console commands which access internal diagnostics of the agent
Explore / Metricsagent.cli.agent_network_calls_to_remote_podsEXECUse Agent Console commands which make network calls to remote pods and endpoints
Explore / Metricsagent.cli.agent_statusREADUse Agent Console commands which access agent status
Explore / Metricsagent.cli.viewVIEWUse Agent Console commands
Explore / Metricsagent.cli.view_configurationVIEWUse Agent Console commands to view the configuration of the agent which does not contain sensitive information like passwords
Explore / Metricsagent.cli.view_sensitive_configurationVIEWUse Agent Console commands to view the configuration of the agent which does contain sensitive information like passwords. There are currently zero commands that implement this permission
Settingscustomer-admin-users.createCREATECreate new customer admin users
Settingsusers.createCREATEInvite new users
Scanning (Legacy)agentscanning.config.editEDITN/A
Settingsapi-token.editEDITReset users API token in scope of a team
Costscost-advisor.editEDITChange Cost Advisor pricing
Costscost-reports.editEDITChange cost reports
USERSuser-deactivation-configuration.editEDITModify user deactivation configuration
Data Access Settingsdatastream.editEDITN/A
Data Access Settingsgroupings.editEDITCreate and edit custom groupings
Settingsgroup-mappings.editEDITModify mapping of users IDP groups to Sysdig teams/roles
Settingsip-filters.editEDITModify IP filter configuration
Settingsmemberships.editEDITInvite other users to the teams
Settingsmemberships-roles.editEDITModify team members roles
Network Securitynetsec.editEDITN/A
Get Startedonboarding.editEDITN/A
INTERNAL_ADMINservice.platform-alerts-settings.editEDITEdit platform alerts settings
Integrationspromcat.integrations.editEDITChange monitoring integration type or status
Scanning (Legacy)scanning.retention.editEDITN/A
Scanning (Legacy)secure.images.editEDITN/A
Settingssecure-settings.editEDITModify Sysdig Secure configuration
Settingsservice-account.editEDITModify service accounts in scope of a team
Settingsservice-account-role.editEDITChange service account roles
Settingsteam-agent-cli-settings.editEDITToggle access to agent console for a team
Settingsteam-capture-settings.editEDITToggle access to captures for a team
Ticketingticketing-customer-settings.editEDITEdit ticketing customer settings
UI Settingsui-customer-settings.editEDITN/A
UI Settingsui-inactivity-settings.editEDITN/A
UI Settingsui-settings.editEDITN/A
UI Settingsui-user-app-settings.editEDITN/A
Captures / Investigatesecure.rapid-response.execEXECUse rapid response
Data Access Settingsingest.prwsOTHERN/A
Data Access Settingsingest.prws.controlledOTHERN/A
Captures / Investigatesecure.rapid-response.killKILLN/A
INTERNAL_SERVICEmetrics-descriptors.manageMANAGEManage metrics descriptors, which are unique combinations of metrics and labels that create a time series. For example, sysdig_container_cpu_used_percent{host_hostname=foo,region=bar}.
Settingssecure.risk-spotlight-integration-tokens.manageMANAGEManage risk spotlight integration tokens from the UI
Scanning (Legacy)agentscanning.config.readREADN/A
Settingsagent-installation.readREADGet agent access key (required for agent installation)
Settingsapi-token.readREADAccess users API token in scope of a team
Settingsaws-settings.readREADAccess AWS settings
Settingscloud.accounts.readREADAccess cloud accounts
Costscost-advisor.readREADAccess Cost Advisor
INTERNAL_SERVICEcost-digest.readREADRead cost digest enabled customers
Costscost-explorer.readREADAccess Cost Explorer
Costscost-reports.readREADAccess cost reports
Settingscustomer-teams.readREADAccess and list teams data
USERSuser-deactivation-configuration.readREADAccess user deactivation configuration
Eventscustom-events.readREADAccess the infrastructure and other events created by Sysdig Agent or Sysdig API
Dashboardsdashboard-metrics-data.readREADAccess metrics data associated with a dashboard.
Data Access Settingsdatastream.readREADAccess data stream configuration
Settingsdowntimes.readREADList alert downtimes for the customer
Settingsevents-forwarder.readREADAccess event forwarding configuration
Explore / Metricsexplore.readREADMetric querying with Explore
Data Access Settingsgroupings.readREADAccess default and custom groupings
Settingsgroup-mappings.readREADAccess mapping of users IDP groups to Sysdig teams/roles
Integrationshelmsrenderer.readREADAccess Helm-renderer component. During cloud account setup in Secure, the wizard calls the Helm Renderer to generate the Terraform snippet.
Data Access Settingshistory-data.readREADN/A
Integrationsinfrastructure.readREADView discovered infrastructure
Integrationsintegrations.readREADView discovered workload integrations
Settingsip-filters.readREADAccess IP Filter configuration
Advisorkubernetes-api-commands.readREADKubernetes API feature
Advisorlive-logs.viewVIEWAccess Live Logs feature
Settings
Settingsmemberships.readREADAccess team members
Data Access Settingsmetadata-defaults.readREADN/A
Data Access Settingsmetrics-data.readREADAccess metrics data associated with a time series.
Data Access Settingsmetrics-descriptors.readREADAccess metrics descriptors, which are unique combinations of metrics and labels that create a time series. For example, sysdig_container_cpu_used_percent{host_hostname=foo,region=bar}.
Get Startedonboarding.readREADN/A
Advisoroverviews.readREADAccess Advisor
INTERNAL_ADMINservice.platform-alerts-settings.readREADRead platform alerts settings
Integrationspromcat.integrations.readREADAccess monitoring integration type or status
Data Access Settingspromql-metadata.readREADAccess Prometheus metrics and labels
Integrationsproviders.readREADRelated to cloud account setups (both Metric Stream and Cost Private Pricing).
Scanning (Legacy)scanning.readREADRead scan results
Scanning (Legacy)scanning.retention.readREADN/A
Get Startedsecure.onboarding.readREADN/A
Settingsservice-account.readREADAccess service accounts in scope of a team
Integrationsspotlight.readREADAccess spotlight
Settingssubscription.readREADAccess customer subscription details
Settingssysdig-storage.readREADView Sysdig storage configuration
Settingsteam-agent-cli-settings.readREADSee the agent console access settings for a team
Settingsteam-capture-settings.readREADSee the capture settings for a team
Ticketingticketing-customer-settings.readREADRead ticketing customer settings
UI Settingsui-customer-settings.readREADN/A
UI Settingsui-inactivity-settings.readREADN/A
UI Settingsui-settings.readREADN/A
UI Settingsui-user-app-settings.readREADN/A
Settingsusers.readREADAccess existing users data
Settingsuser-list.readREADSee the list of users for a customer
Investigate
Sagesage.execEXECSysdig Sage chat
Integrationspromcat.integrations.validateVALIDATEChange monitoring integration status to Pending Metrics

Sysdig Monitor Team Roles

Standard User

Manage access to Advisor
AdvisorREADAccess Advisor
Kubernetes APIREADKubernetes API feature
Live LogsVIEWAccess Live Logs feature
Manage access to Alerts
Alert EventsEDITAcknowledge an event triggered by an alert in the events feed in scope of a team
Alert EventsREADAccess the events generated by triggered alerts in scope of a team
AlertsEDITModify alerts in scope of a team
AlertsREADAccess the alerts in scope of a team
Captures / Investigate
Manage access to Captures / Investigate
CapturesEDITModify captures
CapturesREADAccess captures
CapturesVIEWView captures in the UI
Manage access to dashboards
Dashboard Metrics DataREADN/A
DashboardsEDITModify dashboards in scope of a team
DashboardsREADAccess dashboards in scope of a team
Data Access Settings
Manage access to Data Settings
DatastreamREADAccess data stream configuration
GroupingsEDITCreate and edit custom groupings
GroupingsREADAccess default and custom groupings
Metrics DataREADAccess metrics data associated with a time series.
Metrics DescriptorsREADAccess metrics descriptors, which are unique combinations of metrics and labels that create a time series. For example, sysdig_container_cpu_used_percent{host_hostname=foo,region=bar}.
PromQL MetadataREADAccess Prometheus metrics and labels
Manage access to Events
Custom EventsEDITAcknowledge the infrastructure and other events created by Sysdig Agent or Sysdig API
Custom EventsREADAccess the infrastructure and other events created by Sysdig Agent or Sysdig API
Explore / Metrics
Manage access to Explore / Metrics
Agent ConsoleVIEWUse Agent Console commands
Agent Console - Agent StatusREADUse Agent Console commands which access agent status
Agent Console - ConfigurationVIEWUse Agent Console commands to view the configuration of the agent which does not contain sensitive information like passwords
Agent Console - Network CallsEXECUse Agent Console commands which make network calls to remote pods and endpoints
ExploreREADUse metric querying with Explore
IntegrationsCustom IntegrationsEDITModify custom integrations in spotlight
Custom IntegrationsREADAccess custom integrations in spotlight
Helm RendererREADAccess Helm-renderer component. During cloud account setup in Secure, the wizard calls the Helm Renderer to generate the terraform snippet.
InfrastructureREADView discovered infrastructure
IntegrationsREADView discovered workload integrations
Monitoring IntegrationsEDITChange monitoring integration type or status
Monitoring IntegrationsREADAccess monitoring integration type or status
Monitoring IntegrationsVALIDATEChange monitoring integration status to Pending Metrics
ProvidersREADRelated to cloud account setups (both Metric Stream and Cost Private Pricing).
SpotlightREADAccess spotlight
SettingsAgent InstallationREADGet agent access key (required for agent installation)
Alert DowntimesREADList alert downtimes for the customer
API Access TokenEDITReset users API token in scope of a team
API Access TokenREADAccess users API token in scope of a team
API Access TokenVIEWView your API token
AWS SettingsREADAccess AWS settings
Events ForwarderREADAccess event forwarding configuration
Global Notification ChannelsREADAccess global notification channels
Notification ChannelsREADAccess notification channels in scope of a team
Service AccountsREADAccess service accounts in scope of a team
SubscriptionsREADAccess customer subscription details
Sysdig StorageREADView Sysdig storage configuration

View Only

Manage access to Advisor
AdvisorREADAccess Advisor
Kubernetes APIREADKubernetes API feature
Live LogsVIEWAccess Live Logs feature
Manage access to Alerts
Alert EventsREADAccess the events generated by triggered alerts in scope of a team
AlertsREADAccess the alerts in scope of a team
Captures / Investigate
Manage access to Captures / Investigate
CapturesREADAccess captures
CapturesVIEWView captures in the UI
Manage access to dashboards
Dashboard Metrics DataREADN/A
DashboardsREADAccess dashboards in scope of a team
Data Access Settings
Manage access to Data Settings
DatastreamREADAccess data stream configuration
GroupingsEDITCreate and edit custom groupings
GroupingsREADAccess default and custom groupings
Metrics DataREADAccess metrics data associated with a time series.
Metrics DescriptorsREADAccess metrics descriptors, which are unique combinations of metrics and labels that create a time series. For example, sysdig_container_cpu_used_percent{host_hostname=foo,region=bar}.
PromQL MetadataREADAccess Prometheus metrics and labels
Manage access to Events
Custom EventsREADAccess the infrastructure and other events created by Sysdig Agent or Sysdig API
Explore / Metrics
Manage access to Explore / Metrics
Agent ConsoleVIEWUse Agent Console commands
Agent Console - Agent StatusREADUse Agent Console commands which access agent status
Agent Console - ConfigurationVIEWUse Agent Console commands to view the configuration of the agent which does not contain sensitive information like passwords
Agent Console - Network CallsEXECUse Agent Console commands which make network calls to remote pods and endpoints
ExploreREADMetric querying with Explore
IntegrationsCustom IntegrationsREADAccess custom integrations in spotlight
File Storage ConfigREADN/A
Helm RendererREADAccess Helm-renderer component. During cloud account setup in Secure, the wizard calls the Helm Renderer to generate the terraform snippet.
InfrastructureREADView discovered infrastructure
IntegrationsREADView discovered workload integrations
Monitoring IntegrationsREADAccess monitoring integration type or status
Monitoring IntegrationsVALIDATEChange monitoring integration status to Pending Metrics
ProvidersREADRelated to cloud account setups (both Metric Stream and Cost Private Pricing).
SpotlightREADAccess spotlight
SettingsAgent InstallationREADGet agent access key (required for agent installation)
Alert DowntimesREADList alert downtimes for the user.
API Access TokenREADAccess users API token in scope of a team
API Access TokenVIEWView your API token
AWS SettingsREADAccess AWS settings
Events ForwarderREADAccess event forwarding configuration
Global Notification ChannelsREADAccess global notification channels
Notification ChannelsREADAccess notification channels in scope of a team
Service AccountsREADAccess service accounts in scope of a team
SubscriptionsREADAccess customer subscription details
Sysdig StorageREADView Sysdig storage configuration

Team Manager

AdvisorAdvisorREADAccess Advisor
Kubernetes APIREADKubernetes API feature
Live LogsVIEWAccess Live Logs feature
AlertsAlert EventsEDITAcknowledge an event triggered by an alert in the events feed in scope of a team
Alert EventsREADAccess the events generated by triggered alerts in scope of a team
AlertsEDITModify alerts in scope of a team
AlertsREADAccess the alerts in scope of a team
Captures / InvestigateCapturesEDITModify captures
CapturesREADAccess captures
CapturesVIEWView captures in the UI
DashboardsDashboard Metrics DataREADN/A
DashboardsEDITModify dashboards in scope of a team
DashboardsREADAccess dashboards in scope of a team
Data Access SettingsGroupingsEDITCreate and edit custom groupings
GroupingsREADAccess default and custom groupings
Metrics DataREADAccess metrics data associated with a time series.
Metrics DescriptorsREADAccess metrics descriptors, which are unique combinations of metrics and labels that create a time series. For example, sysdig_container_cpu_used_percent{host_hostname=foo,region=bar}.
PromQL MetadataREADAccess Prometheus metrics and labels
EventsCustom EventsEDITAcknowledge the infrastructure and other events created by Sysdig Agent or Sysdig API
Custom EventsREADAccess the infrastructure and other events created by Sysdig Agent or Sysdig API
Explore / MetricsAgent ConsoleVIEWUse Agent Console commands
Agent Console - Agent StatusREADUse Agent Console commands which access agent status
Agent Console - ConfigurationVIEWUse Agent Console commands to view the configuration of the agent which does not contain sensitive information like passwords
Agent Console - Network CallsEXECUse Agent Console commands which make network calls to remote pods and endpoints
ExploreREADMetric querying with Explore
Shared Groupings with TeamTOGGLEWhether the user can share a custom Explore Grouping to the team.
IntegrationsCustom IntegrationsEDITModify custom integrations in spotlight
Custom IntegrationsREADAccess custom integrations in spotlight
Helm RendererREADAccess Helm-renderer component. During cloud account setup in Secure, the wizard calls the Helm Renderer to generate the terraform snippet.
InfrastructureREADView discovered infrastructure
IntegrationsREADView discovered workload integrations
Monitoring IntegrationsEDITChange monitoring integration type or status
Monitoring IntegrationsREADAccess monitoring integration type or status
Monitoring IntegrationsVALIDATEChange monitoring integration status to Pending Metrics
ProvidersREADRelated to cloud account setups (both Metric Stream and Cost Private Pricing).
SpotlightREADAccess spotlight
SettingsAgent InstallationREADGet agent access key (required for agent installation)
Alert DowntimesREADList alert downtimes for the customer
API Access TokenEDITReset users API token in scope of a team
API Access TokenREADAccess users API token in scope of a team
API Access TokenVIEWView your API token
AWS SettingsREADAccess AWS settings
Events ForwarderREADAccess event forwarding configuration
Global Notification ChannelsREADAccess global notification channels
Notification ChannelsEDITModify notification channels in scope of a team
Notification ChannelsREADAccess notification channels in scope of a team
Service AccountsEDITModify service accounts in scope of a team
Service AccountsREADAccess service accounts in scope of a team
SubscriptionsREADAccess customer subscription details
Sysdig StorageREADView Sysdig storage configuration
TeamsMANAGEModify team settings without the ability to modify team membership for users

Advanced User

AdvisorAdvisorREADAccess Advisor
Kubernetes APIREADKubernetes API feature
Live LogsVIEWAccess Live Logs feature
AlertsAlert EventsEDITAcknowledge an event triggered by an alert in the events feed in scope of a team
Alert EventsREADAccess the events generated by triggered alerts in scope of a team
AlertsEDITModify alerts in scope of a team
AlertsREADAccess the alerts in scope of a team
Captures / InvestigateCapturesEDITModify captures
CapturesREADAccess captures
CapturesVIEWView captures in the UI
DashboardsDashboard Metrics DataREADN/A
DashboardsEDITModify dashboards in scope of a team
DashboardsREADAccess dashboards in scope of a team
Data SettingsGroupingsEDITCreate and edit custom groupings
GroupingsREADAccess default and custom groupings
Metrics DataREADAccess metrics data associated with a time series.
Metrics DescriptorsREADAccess metrics descriptors, which are unique combinations of metrics and labels that create a time series. For example, sysdig_container_cpu_used_percent{host_hostname=foo,region=bar}.
PromQL MetadataREADAccess Prometheus metrics and labels
EventsCustom EventsEDITAcknowledge the infrastructure and other events created by Sysdig Agent or Sysdig API
Custom EventsREADAccess the infrastructure and other events created by Sysdig Agent or Sysdig API
Explore / MetricsAgent ConsoleVIEWUse Agent Console commands
Agent Console - Agent StatusREADUse Agent Console commands which access agent status
Agent Console - ConfigurationVIEWUse Agent Console commands to view the configuration of the agent which does not contain sensitive information like passwords
Agent Console - Network CallsEXECUse Agent Console commands which make network calls to remote pods and endpoints
ExploreREADMetric querying with Explore
Shared Groupings with TeamTOGGLEWhether the user can share a custom Explore Grouping to the team.
IntegrationsCustom IntegrationsEDITModify custom integrations in spotlight
Custom IntegrationsREADAccess custom integrations in spotlight
Helm RendererREADAccess Helm-renderer component. During cloud account setup in Secure, the wizard calls the Helm Renderer to generate the Terraform snippet.
InfrastructureREADView discovered infrastructure
IntegrationsREADView discovered workload integrations
Monitoring IntegrationsEDITChange monitoring integration type or status
Monitoring IntegrationsREADAccess monitoring integration type or status
Monitoring IntegrationsVALIDATEChange monitoring integration status to Pending Metrics
ProvidersREADRelated to cloud account setups (both Metric Stream and Cost Private Pricing).
SpotlightREADAccess spotlight
SettingsAgent InstallationREADGet agent access key (required for agent installation)
Alert DowntimesREADList alert downtimes for the customer
API Access TokenEDITReset users API token in scope of a team
API Access TokenREADAccess users API token in scope of a team
API Access TokenVIEWView your API token
AWS SettingsREADAccess AWS settings
Events ForwarderREADAccess event forwarding configuration
Global Notification ChannelsREADAccess global notification channels
Notification ChannelsEDITModify notification channels in scope of a team
Notification ChannelsREADAccess notification channels in scope of a team
Service AccountsREADAccess service accounts in scope of a team
SubscriptionsREADAccess customer subscription details
Sysdig StorageREADView Sysdig storage configuration

Sysdig Secure System Roles


Captures / Investigatesecure.rapid-response.execEXECUse rapid response
Captures / Investigatesecure.rapid-response.killKILLN/A
Investigate
Costscost-advisor.editEDITChange Cost Advisor pricing
Costscost-reports.editEDITChange cost reports
Costscost-advisor.readREADAccess Cost Advisor
Costscost-explorer.readREADAccess Cost Explorer
Costscost-reports.readREADAccess cost reports
Data Access Settingsdatastream.editEDITN/A
Data Access Settingsdatastream.readREADAccess data stream configuration
Data Access Settingsgroupings.editEDITCreate and edit custom groupings
Data Access Settingsgroupings.readREADAccess default and custom groupings
Data Access Settingshistory-data.readREADN/A
Data Access Settingsingest.prwsOTHERN/A
Data Access Settingsingest.prws.controlledOTHERN/A
Settings
Data Access Settingsmetadata-defaults.readREADN/A
Data Access Settingsmetrics-data.readREADAccess metrics data associated with a time series.
Data Access Settingsmetrics-descriptors.readREADAccess metrics descriptors, which are unique combinations of metrics and labels that create a time series. For example, sysdig_container_cpu_used_percent{host_hostname=foo,region=bar}.
Data Access Settingspromql-metadata.readREADAccess Prometheus metrics and labels
Eventscustom-events.readREADAccess the infrastructure and other events created by Sysdig Agent or Sysdig API
Explore / Metricsagent.cli.agent_internal_diagnosticsREADUse Agent Console commands which access internal diagnostics of the agent
Explore / Metricsagent.cli.agent_network_calls_to_remote_podsEXECUse Agent Console commands which make network calls to remote pods and endpoints
Explore / Metricsagent.cli.agent_statusREADUse Agent Console commands which access agent status
Explore / Metricsagent.cli.viewVIEWUse Agent Console commands
Explore / Metricsagent.cli.view_configurationVIEWUse Agent Console commands to view the configuration of the agent which does not contain sensitive information like passwords
Explore / Metricsagent.cli.view_sensitive_configurationVIEWUse Agent Console commands to view the configuration of the agent which does contain sensitive information like passwords. There are currently zero commands that implement this permission
Explore / Metricsexplore.readREADMetric querying with Explore
Get Startedonboarding.readREADN/A
Integrationspromcat.integrations.manageMANAGEChange monitoring integration type or status
INTERNAL_SERVICEmetrics-data-admin.readREADAccess metrics data.
Settingscustomer-admin-users.createCREATECreate new customer admin users
Reportsreports.manageMANAGEChange monitoring reports
Settingsusers.createCREATEInvite new users
Scanning (Legacy)agentscanning.config.editEDITN/A
Settingsapi-token.editEDITReset users API token in scope of a team
USERSuser-deactivation-configuration.editEDITModify user deactivation configuration
Settingsgroup-mappings.editEDITModify mapping of users IDP groups to Sysdig teams/roles
Settingsip-filters.editEDITModify IP filter configuration
Settingsmemberships.editEDITInvite other users to the teams
Settingsmemberships-roles.editEDITModify team members roles
Network Securitynetsec.editEDITN/A
Get Startedonboarding.editEDITN/A
INTERNAL_ADMINservice.platform-alerts-settings.editEDITEdit platform alerts settings
Integrationspromcat.integrations.editEDITChange monitoring integration type or status
Scanning (Legacy)scanning.retention.editEDITN/A
Scanning (Legacy)secure.images.editEDITN/A
Settingssecure-settings.editEDITModify Sysdig Secure configuration
Settingsservice-account.editEDITModify service accounts in scope of a team
Settingsservice-account-role.editEDITChange service account roles
Settingsteam-agent-cli-settings.editEDITToggle access to agent console for a team
Settingsteam-capture-settings.editEDITToggle access to captures for a team
Ticketingticketing-customer-settings.editEDITEdit ticketing customer settings
UI Settingsui-customer-settings.editEDITN/A
UI Settingsui-inactivity-settings.editEDITN/A
UI Settingsui-settings.editEDITN/A
UI Settingsui-user-app-settings.editEDITN/A
INTERNAL_SERVICEmetrics-descriptors.manageMANAGEManage metrics descriptors, which are unique combinations of metrics and labels that create a time series. For example, sysdig_container_cpu_used_percent{host_hostname=foo,region=bar}.
Settingssecure.risk-spotlight-integration-tokens.manageMANAGEManage risk spotlight integration tokens from the UI
Scanning (Legacy)agentscanning.config.readREADN/A
Settingsagent-installation.readREADGet agent access key (required for agent installation)
Settingsapi-token.readREADAccess users API token in scope of a team
Settingsaws-settings.readREADAccess AWS settings
Settingscloud.accounts.readREADAccess cloud accounts
INTERNAL_SERVICEcost-digest.readREADRead cost digest enabled customers
Settingscustomer-teams.readREADAccess and list teams data
USERSuser-deactivation-configuration.readREADAccess user deactivation configuration
Settingsdowntimes.readREADList alert downtimes for the customer
Settingsevents-forwarder.readREADAccess event forwarding configuration
Settingsgroup-mappings.readREADAccess mapping of users IDP groups to Sysdig teams/roles
Integrationshelmsrenderer.readREADAccess Helm-renderer component. During cloud account setup in Secure, the wizard calls the Helm Renderer to generate the terraform snippet.
Integrationsinfrastructure.readREADView discovered infrastructure
Integrationsintegrations.readREADView discovered workload integrations
Settingsip-filters.readREADAccess IP Filter configuration
Advisorkubernetes-api-commands.readREADKubernetes API feature
Advisorlive-logs.viewVIEWAccess Live Logs feature
Settingsmemberships.readREADAccess team members
Advisoroverviews.readREADAccess Advisor
INTERNAL_ADMINservice.platform-alerts-settings.readREADRead platform alerts settings
Integrationspromcat.integrations.readREADAccess monitoring integration type or status
Integrationsproviders.readREADRelated to cloud account setups (both Metric Stream and Cost Private Pricing).
Scanning (Legacy)scanning.readREADRead scan results
Scanning (Legacy)scanning.retention.readREADN/A
Get Startedsecure.onboarding.readREADN/A
Settingsservice-account.readREADAccess service accounts in scope of a team
Integrationsspotlight.readREADAccess spotlight
Settingssubscription.readREADAccess customer subscription details
Settingssysdig-storage.readREADView Sysdig storage configuration
Settingsteam-agent-cli-settings.readREADSee the agent console access settings for a team
Settingsteam-capture-settings.readREADSee the capture settings for a team
Ticketingticketing-customer-settings.readREADRead ticketing customer settings
UI Settingsui-customer-settings.readREADN/A
UI Settingsui-inactivity-settings.readREADN/A
UI Settingsui-settings.readREADN/A
UI Settingsui-user-app-settings.readREADN/A
Settingsusers.readREADAccess existing users data
Settingsuser-list.readREADSee the list of users for a customer
Sagesage.execEXECSysdig Sage chat
Integrationspromcat.integrations.validateVALIDATEChange monitoring integration status to Pending Metrics

Sysdig Secure Team Roles

Standard User

AdvisorKubernetes APIREADKubernetes API feature
Live LogsVIEWAccess Live Logs feature
AlertsAlertsREADAccess the alerts in scope of a team
Captures / InvestigateCapturesREADAccess captures
CapturesVIEWView captures in the UI
Data Access SettingsGroupingsEDITCreate and edit custom groupings
GroupingsREADAccess default and custom groupings
Metrics DataREADAccess metrics data
Metrics DescriptorsREADAccess metrics descriptors, which are unique combinations of metrics and labels that create a time series. For example, sysdig_container_cpu_used_percent{host_hostname=foo,region=bar}.
EventsCustom EventsREADAccess the infrastructure and other events created by Sysdig Agent or Sysdig API
Policy EventsREADAccess policy events
Explore / MetricsAgent ConsoleVIEWUse Agent Console commands
Agent Console - Agent StatusREADUse Agent Console commands which access agent status
Agent Console - ConfigurationVIEWUse Agent Console commands to view the configuration of the agent which does not contain sensitive information like passwords
Agent Console - Network CallsEXECUse Agent Console commands which make network calls to remote pods and endpoints
ExploreREADMetric querying with Explore
Shared Groupings with TeamTOGGLEWhether the user can share a custom Explore Grouping to the team.
IntegrationsHelm RendererREADAccess Helm-renderer component. During cloud account setup in Secure, the wizard calls the Helm Renderer to generate the terraform snippet.
InfrastructureREADView discovered infrastructure
Monitoring IntegrationsREADAccess monitoring integration type or status
ProvidersREADRelated to cloud account setups (both Metric Stream and Cost Private Pricing).
PoliciesPosture PoliciesREADView Posture policies
Posture ControlsREADView Posture Controls
ZonesREADView Zones that are assigned to current team
PostureComplianceREADAccess Compliance results
Risk AcceptanceREADAccess to Posture Risk Acceptance management page
Legacy Benchmark TasksEDITCreate and modify scheduled Legacy benchmark and compliance tasks
Legacy Benchmark TasksREADAccess scheduled Legacy benchmark tasks
Legacy BenchmarksREADAccess Legacy benchmark results
Legacy ComplianceREADAccess Legacy Compliance tasks and reports
RiskRisksREADRead Risks
Scanning (legacy)Image ImportEDITImport scanning images
ScanningREADRead scan results
Scanning AlertsREADAccess scanning alerts
Scanning Image ResultsCREATECreate scanning events
Scanning Image ResultsREADList scanning images
Scanning RuntimeEDITQuery runtime containers API
Scanning Scheduled ReportsREADView and download existing reports
Scanning Trusted ImagesREADAccess the trusted images list
Scanning Untrusted ImagesREADAccess the untrusted images list
Scanning Vulnerability ExceptionsREADAccess vulnerability exceptions
SettingsAgent InstallationREADGet agent access key (required for agent installation)
API Access TokenEDITReset users API token in scope of a team
API Access TokenREADAccess users API token in scope of a team
API Access TokenVIEWView your API token
AWS SettingsREADAccess AWS settings
Cloud AccountsREADAccess cloud accounts
Global Notification ChannelsREADAccess global notification channels
IACREADAccess IAC results
Notification ChannelsREADAccess notification channels in scope of a team
Service AccountsREADAccess service accounts in scope of a team
SubscriptionsREADAccess customer subscription details
Sysdig Secure SettingsEDITModify Sysdig Secure configuration
Sysdig StorageREADView Sysdig storage configuration
Vulnerability ManagementScan ResultsREADView scan results on the Pipeline, Runtime, and Registry UI. Retrieve SBOM results from the SBOM API.
ReportingREADView and download scan reports
PolicyREADView policy details
Risk AcceptanceREADView Exceptions
Registry CredentialsREADView registry credentials

Service Manager

AdvisorKubernetes APIREADKubernetes API feature
Live LogsVIEWAccess Live Logs feature
AlertsAlertsREADAccess the alerts in scope of a team
Captures / InvestigateCapturesREADAccess captures
CapturesVIEWView captures in the UI
Data Access SettingsGroupingsEDITCreate and edit custom groupings
GroupingsREADAccess default and custom groupings
Metrics DataREADAccess metrics data associated with a time series.
Metrics DescriptorsREADAccess metrics descriptors, which are unique combinations of metrics and labels that create a time series. For example, sysdig_container_cpu_used_percent{host_hostname=foo,region=bar}.
EventsCustom EventsREADAccess the infrastructure and other events created by Sysdig Agent or Sysdig API
Policy EventsREADAccess policy events
Explore / MetricsAgent ConsoleVIEWUse Agent Console commands
Agent Console - Agent StatusREADUse Agent Console commands which access agent status
Agent Console - ConfigurationVIEWUse Agent Console commands to view the configuration of the agent which does not contain sensitive information like passwords
Agent Console - Network CallsEXECUse Agent Console commands which make network calls to remote pods and endpoints
ExploreREADMetric querying with Explore
Shared Groupings with TeamTOGGLEWhether the user can share a custom Explore Grouping to the team.
IntegrationsHelm RendererREADAccess Helm-renderer component. During cloud account setup in Secure, the wizard calls the Helm Renderer to generate the Terraform snippet.
InfrastructureREADView discovered infrastructure
Monitoring IntegrationsREADAccess monitoring integration type or status
ProvidersREADRelated to cloud account setups (both Metric Stream and Cost Private Pricing).
PoliciesPosture PoliciesREADView Posture policies
Posture ControlsREADView Posture Controls
ZonesREADView Zones that are assigned to current team
PostureComplianceREADAccess Compliance results
Risk AcceptanceREADAccess to Posture Risk Acceptance management page
Legacy Benchmark TasksEDITCreate and modify scheduled Legacy benchmark and compliance tasks
Legacy Benchmark TasksREADAccess scheduled Legacy benchmark tasks
Legacy BenchmarksREADAccess Legacy benchmark results
Legacy ComplianceREADAccess Legacy Compliance tasks and reports
RiskRisksREADRead Risks
Scanning (Legacy)Image ImportEDITImport scanning images
ScanningEXECExecute backend scanning
ScanningREADRead scan results
ScanningWRITEModify scanning alerts and registry credentials
Scanning AlertsEDITModify scanning alerts
Scanning AlertsREADAccess scanning alerts
ScanningScanning Image ResultsCREATECreate scanning events
Scanning Image ResultsREADList scanning images
Scanning Policy AssignmentsREADAccess policy mappings
Scanning RuntimeEDITQuery runtime containers API
Scanning Scheduled ReportsREADView and download existing reports
Scanning Trusted ImagesREADAccess the trusted images list
Scanning Untrusted ImagesREADAccess the untrusted images list
Scanning Vulnerability ExceptionsREADAccess vulnerability exceptions
SettingsAgent InstallationREADGet agent access key (required for agent installation)
API Access TokenEDITReset users API token in scope of a team
API Access TokenREADAccess users API token in scope of a team
API Access TokenVIEWView your API token
AWS SettingsREADAccess AWS settings
Cloud AccountsREADAccess cloud accounts
Global Notification ChannelsREADAccess global notification channels
IACREADAccess IAC results
Notification ChannelsEDITModify notification channels in scope of a team
Notification ChannelsREADAccess notification channels in scope of a team
Service AccountsREADAccess service accounts in scope of a team
SubscriptionsREADAccess customer subscription details
Sysdig Secure SettingsEDITModify Sysdig Secure configuration
Sysdig StorageREADView Sysdig storage configuration
Team MembershipEDITInvite other users to the teams
Team MembershipREADAccess team members
Team Membership RolesEDITModify team members roles
TeamsMANAGEModify team settings without the ability to modify team membership for users
UsersREADAccess existing users data
Vulnerability ManagementScan ResultsREADView scan results on the Pipeline, Runtime, and Registry UI. Retrieve SBOM results from the SBOM API.
ReportingREADView and download scan reports
ReportingWRITECreate, modify, and delete reports
PolicyREADView policy details
PolicyWRITECreate, edit, and delete policies
Risk AcceptanceREADView Exceptions
CLI ExecutionEXECAbility to run CLI Scanner
Scan NowEXECAbility to instantly scan using Scan Now
Registry CredentialsREADView registry credentials
Registry CredentialsWRITEAdd registry credentials
Registry ScannerEXECAbility to run Registry Scanner

View Only

AdvisorKubernetes APIREADKubernetes API feature
Live LogsVIEWAccess Live Logs feature
AlertsAlertsREADAccess the alerts in scope of a team
Captures / InvestigateActivity Audit CommandsREADAccess activity audit commands
CapturesREADAccess captures
CapturesVIEWView captures in the UI
Data Access SettingsGroupingsEDITCreate and edit custom groupings
GroupingsREADAccess default and custom groupings
Metrics DataREADAccess metrics data associated with a time series.
Metrics DescriptorsREADAccess metrics descriptors, which are unique combinations of metrics and labels that create a time series. For example, sysdig_container_cpu_used_percent{host_hostname=foo,region=bar}.
EventsCustom EventsREADAccess the infrastructure and other events created by Sysdig Agent or Sysdig API
Policy EventsREADAccess policy events
Explore / MetricsAgent ConsoleVIEWUse Agent Console commands
Agent Console - Agent StatusREADUse Agent Console commands which access agent status
Agent Console - ConfigurationVIEWUse Agent Console commands to view the configuration of the agent which does not contain sensitive information like passwords
Agent Console - Network CallsEXECUse Agent Console commands which make network calls to remote pods and endpoints
ExploreREADMetric querying with Explore
IntegrationsHelm RendererREADAccess Helm-renderer component. During cloud account setup in Secure, the wizard calls the Helm Renderer to generate the Terraform snippet.
InfrastructureREADView discovered infrastructure
Monitoring IntegrationsREADAccess monitoring integration type or status
ProvidersREADRelated to cloud account setups (both Metric Stream and Cost Private Pricing).
Network SecurityNetwork SecurityREADAccess Kubernetes Network Security policy advisor
PoliciesPosture PoliciesREADView Posture policies
Posture ControlsREADView Posture Controls
ZonesREADView Zones that are assigned to current team
Image profilingREADView existing image profiles
PoliciesREADAccess policies
Policy AdvisorREADRead PSP advisor simulations
PostureComplianceREADAccess Compliance results
Risk AcceptanceREADAccess to Posture Risk Acceptance management page
Legacy Benchmark TasksEDITCreate and modify scheduled Legacy benchmark and compliance tasks
Legacy Benchmark TasksREADAccess scheduled Legacy benchmark tasks
Legacy BenchmarksREADAccess Legacy benchmark results
Legacy ComplianceREADAccess Legacy Compliance tasks and reports
Scanning (Legacy)ScanningREADRead scan results
Scanning AlertsREADAccess scanning alerts
Scanning Image ResultsREADList scanning images
Scanning PoliciesREADAccess security policies
Scanning Policy AssignmentsREADAccess policy mappings
Scanning Registry CredentialsREADList container registries
Scanning RuntimeEDITQuery runtime containers API
Scanning Scheduled ReportsREADView and download existing reports
Scanning Trusted ImagesREADAccess the trusted images list
Scanning Untrusted ImagesREADAccess the untrusted images list
Scanning Vulnerability ExceptionsREADAccess vulnerability exceptions
SettingsAgent InstallationREADGet agent access key (required for agent installation)
API Access TokenEDITReset users API token in scope of a team
API Access TokenREADAccess users API token in scope of a team
API Access TokenVIEWView your API token
AWS SettingsREADAccess AWS settings
Cloud AccountsREADAccess cloud accounts
Global Notification ChannelsREADAccess global notification channels
IACREADAccess IAC results
Notification ChannelsREADAccess notification channels in scope of a team
Service AccountsREADAccess service accounts in scope of a team
SubscriptionsREADAccess customer subscription details
Sysdig Secure SettingsEDITModify Sysdig Secure configuration
SettingsSysdig StorageREADView Sysdig storage configuration
Vulnerability ManagementScan ResultsREADView scan results on the Pipeline, Runtime, and Registry UI. Retrieve SBOM results from the SBOM API.
ReportingREADView and download scan reports
PolicyREADView policy details
Risk AcceptanceREADView Exceptions
Registry CredentialsREADView registry credentials

Team Manager

AdvisorKubernetes APIREADKubernetes API feature
Live LogsVIEWAccess Live Logs feature
AlertsAlertsEDITModify alerts in scope of a team
AlertsREADAccess the alerts in scope of a team
Captures / InvestigateActivity Audit CommandsREADAccess activity audit commands
CapturesEDITModify captures
CapturesREADAccess captures
CapturesVIEWView captures in the UI
Rapid ResponseEXECUse rapid response
Data Access SettingsDatastreamREADAccess data stream configuration
GroupingsEDITCreate and edit custom groupings
GroupingsREADAccess default and custom groupings
Metrics DataREADAccess metrics data associated with a time series.
Metrics DescriptorsREADAccess metrics descriptors, which are unique combinations of metrics and labels that create a time series. For example, sysdig_container_cpu_used_percent{host_hostname=foo,region=bar}.
EventsCustom EventsREADAccess the infrastructure and other events created by Sysdig Agent or Sysdig API
Policy EventsREADAccess policy events
Explore / MetricsAgent ConsoleVIEWUse Agent Console commands
Agent Console - Agent StatusREADUse Agent Console commands which access agent status
Agent Console - ConfigurationVIEWUse Agent Console commands to view the configuration of the agent which does not contain sensitive information like passwords
Agent Console - Network CallsEXECUse Agent Console commands which make network calls to remote pods and endpoints
ExploreREADMetric querying with Explore
Shared Groupings with TeamTOGGLEWhether the user can share a custom Explore Grouping to the team.
IntegrationsHelm RendererREADAccess Helm-renderer component. During cloud account setup in Secure, the wizard calls the Helm Renderer to generate the Terraform snippet.
InfrastructureREADView discovered infrastructure
Monitoring IntegrationsREADAccess monitoring integration type or status
ProvidersREADRelated to cloud account setups (both Metric Stream and Cost Private Pricing).
Network SecurityNetwork SecurityREADAccess Kubernetes Network Security policy advisor
PoliciesZonesEDITView and Edit All Zones
Posture PoliciesEDITView and Edit Posture policies
Posture ControlsEDITView and Edit Posture Controls
Image profilingEXECExecute image profiling
Image profilingREADView existing image profiles
Image profilingWRITEWrite image profiles
PoliciesEDITModify policies
PoliciesREADAccess policies
Policy AdvisorEXECExecute PSP advisor simulation
Policy AdvisorREADRead PSP advisor simulations
Policy AdvisorWRITECreate PSP advisor simulation
PostureComplianceREADAccess Compliance results
Risk AcceptanceEDITAccess and modify Posture Risk Acceptance
Open PREDITSetup Pull Requests from posture remediation panel
Legacy Benchmark TasksEDITAccess, Create and modify scheduled Legacy benchmark and compliance tasks
Legacy BenchmarksREADAccess Legacy benchmark results
Legacy ComplianceREADAccess Legacy Compliance tasks and reports
RiskRisksREADRead Risks
ScanningImage ImportEDITImport scanning images
ScanningEXECExecute backend scanning
ScanningREADRead scan results
ScanningWRITEModify scanning alerts and registry credentials
Scanning AlertsEDITModify scanning alerts
Scanning AlertsREADAccess scanning alerts
Scanning Image ResultsCREATECreate scanning events
Scanning Image ResultsREADList scanning images
Scanning PoliciesEDITModify security policies
Scanning PoliciesREADAccess security policies
Scanning Policy AssignmentsEDITCreate and modify policy mappings
Scanning Policy AssignmentsREADAccess policy mappings
Scanning Registry CredentialsEDITCreate and modify container registries configuration
Scanning Registry CredentialsREADList container registries
Scanning RuntimeEDITQuery runtime containers API
Scanning Scheduled ReportsEDITCreate and modify reports
Scanning Scheduled ReportsREADView and download existing reports
Scanning Trusted ImagesEDITModify the trusted images list
Scanning Trusted ImagesREADAccess the trusted images list
Scanning Untrusted ImagesEDITModify the untrusted images list
Scanning Untrusted ImagesREADAccess the untrusted images list
Scanning Vulnerability ExceptionsEDITEdit vulnerability exceptions
Scanning Vulnerability ExceptionsREADAccess vulnerability exceptions
SettingsAgent InstallationREADGet agent access key (required for agent installation)
API Access TokenEDITReset users API token in scope of a team
API Access TokenREADAccess users API token in scope of a team
API Access TokenVIEWView your API token
AWS SettingsREADAccess AWS settings
Cloud AccountsREADAccess cloud accounts
Global Notification ChannelsREADAccess global notification channels
IACREADAccess IAC results
Notification ChannelsEDITModify notification channels in scope of a team
Notification ChannelsREADAccess notification channels in scope of a team
Service AccountsEDITModify service accounts in scope of a team
Service AccountsREADAccess service accounts in scope of a team
SubscriptionsREADAccess customer subscription details
Sysdig Secure SettingsEDITModify Sysdig Secure configuration
Sysdig StorageREADView Sysdig storage configuration
TeamsMANAGEModify team settings without the ability to modify team membership for users
Vulnerability ManagementScan ResultsREADView scan results on the Pipeline, Runtime, and Registry UI. Retrieve SBOM results from the SBOM API.
ReportingREADView and download scan reports
ReportingWRITECreate, modify, and delete reports
PolicyREADView policy details
PolicyWRITECreate, edit, and delete policies
Risk AcceptanceREADView Exceptions
Risk AcceptanceWRITECreate, update, and delete Exceptions
CLI ExecutionEXECAbility to run CLI Scanner
Scan NowEXECAbility to instantly scan using Scan Now
Registry CredentialsREADView registry credentials
Registry CredentialsWRITEAdd registry credentials
Registry ScannerEXECAbility to run Registry Scanner

Advanced User

AdvisorKubernetes APIREADKubernetes API feature
Live LogsVIEWAccess Live Logs feature
AlertsAlertsEDITModify alerts in scope of a team
AlertsREADAccess the alerts in scope of a team
Captures / InvestigateActivity Audit CommandsREADAccess activity audit commands
CapturesEDITModify captures
CapturesREADAccess captures
CapturesVIEWView captures in the UI
Rapid ResponseEXECUse rapid response
Data Access SettingsDatastreamREADAccess data stream configuration
GroupingsEDITCreate and edit custom groupings
GroupingsREADAccess default and custom groupings
Metrics DataREADAccess metrics data associated with a time series.
Metrics DescriptorsREADAccess metrics descriptors, which are unique combinations of metrics and labels that create a time series. For example, sysdig_container_cpu_used_percent{host_hostname=foo,region=bar}.
EventsCustom EventsREADAccess the infrastructure and other events created by Sysdig Agent or Sysdig API
Policy EventsREADAccess policy events
Explore / MetricsAgent ConsoleVIEWUse Agent Console commands
Agent Console - Agent StatusREADUse Agent Console commands which access agent status
Agent Console - ConfigurationVIEWUse Agent Console commands to view the configuration of the agent which does not contain sensitive information like passwords
Agent Console - Network CallsEXECUse Agent Console commands which make network calls to remote pods and endpoints
ExploreREADMetric querying with Explore
Shared Groupings with TeamTOGGLEWhether the user can share a custom Explore Grouping to the team.
IntegrationsHelm RendererREADAccess Helm-renderer component. During cloud account setup in Secure, the wizard calls the Helm Renderer to generate the Terraform snippet.
InfrastructureREADView discovered infrastructure
Monitoring IntegrationsREADAccess monitoring integration type or status
ProvidersREADCloud account setups (both Metric Stream and Cost Private Pricing).
Network SecurityNetwork SecurityREADAccess Kubernetes Network Security policy advisor
PoliciesZonesEDITView and Edit All Zones
Posture PoliciesEDITView and Edit Posture policies
Posture ControlsEDITView and Edit Posture Controls
Image profilingEXECExecute image profiling
Image profilingREADView existing image profiles
Image profilingWRITEWrite image profiles
PoliciesEDITModify policies
PoliciesREADAccess policies
Policy AdvisorEXECExecute PSP advisor simulation
Policy AdvisorREADRead PSP advisor simulations
Policy AdvisorWRITECreate PSP advisor simulation
ComplianceREADAccess Compliance results
Risk AcceptanceEDITAccess and modify Posture Risk Acceptance
PostureOpen PREDITSetup Pull Requests from posture remediation panel
Legacy Benchmark TasksEDITAccess, Create and modify scheduled Legacy benchmark and compliance tasks
Legacy BenchmarksREADAccess Legacy benchmark results
Legacy ComplianceREADAccess Legacy Compliance tasks and reports
RiskRisksREADRead Risks
Scanning (Legacy)Image ImportEDITImport scanning images
ScanningEXECExecute backend scanning
ScanningREADRead scan results
ScanningWRITEModify scanning alerts and registry credentials
Scanning AlertsEDITModify scanning alerts
Scanning AlertsREADAccess scanning alerts
Scanning Image ResultsCREATECreate scanning events
Scanning Image ResultsREADList scanning images
Scanning PoliciesEDITModify security policies
Scanning PoliciesREADAccess security policies
Scanning Policy AssignmentsEDITCreate and modify policy mappings
Scanning Policy AssignmentsREADAccess policy mappings
Scanning Registry CredentialsEDITCreate and modify container registries configuration
Scanning Registry CredentialsREADList container registries
Scanning RuntimeEDITQuery runtime containers API
Scanning Scheduled ReportsEDITCreate and modify reports
Scanning Scheduled ReportsREADView and download existing reports
Scanning Trusted ImagesEDITModify the trusted images list
Scanning Trusted ImagesREADAccess the trusted images list
Scanning Untrusted ImagesEDITModify the untrusted images list
Scanning Untrusted ImagesREADAccess the untrusted images list
Scanning Vulnerability ExceptionsEDITEdit vulnerability exceptions
Scanning Vulnerability ExceptionsREADAccess vulnerability exceptions
SettingsAgent InstallationREADGet agent access key (required for agent installation)
API Access TokenEDITReset users API token in scope of a team
API Access TokenREADAccess users API token in scope of a team
API Access TokenVIEWView your API token
AWS SettingsREADAccess AWS settings
Cloud AccountsREADAccess cloud accounts
Global Notification ChannelsREADAccess global notification channels
IACREADAccess IAC results
Notification ChannelsEDITModify notification channels in scope of a team
Notification ChannelsREADAccess notification channels in scope of a team
Service AccountsREADAccess service accounts in scope of a team
SubscriptionsREADAccess customer subscription details
Sysdig Secure SettingsEDITModify Sysdig Secure configuration
Sysdig StorageREADView Sysdig storage configuration
Vulnerability ManagementScan ResultsREADView scan results on the Pipeline, Runtime, and Registry UI. Retrieve SBOM results from the SBOM API.
ReportingREADView and download scan reports
ReportingWRITECreate, modify, and delete reports
PolicyREADView policy details
PolicyWRITECreate, edit, and delete policies
Risk AcceptanceREADView Exceptions
Risk AcceptanceWRITECreate, update, and delete Exceptions
CLI ExecutionEXECAbility to run CLI Scanner
Scan NowEXECAbility to instantly scan using Scan Now
Registry CredentialsREADView registry credentials
Registry CredentialsWRITEAdd registry credentials
Registry ScannerEXECAbility to run Registry Scanner