Agentic Assistant role-based access control

Instance and Account admins have full control over the permissions and access that users have to the Cortex Agentic Assistant. Cortex XSIAM uses role-based access control (RBAC) to manage access to the chat, as well as access to view, create, edit, delete, disable, and enable Agents and Actions in the Agentic Assistant Hub.

By default, Instance and Account admins have full view/edit permissions enabled. When editing or creating other roles, in the Cortex Agentic AssistantAgents section, you can select the following:

Permission Description
View/Edit <p>When selected (and nothing else is checked in this section), the user role can only see actions and public agents in the Agentic Assistant Hub, but cannot interact with agents.</p><p>You can also select the following permissions:</p><ul><li><p>Interact with agents: Users can:</p><ul><li>Trigger Agents in the Cortex Agentic Assistant.</li><li>Access their own agents, public agents, and system agents.</li><li>Manage script development using the Automation Engineer agent.</li><li>Manage playbook development using the Automation Engineer agent (preview).</li></ul></li><li>Manage actions: Users can view, create, update, and delete actions.</li><li>Manage agents: Users can view, create, update, and delete their own custom agents.</li><li><p>Agents admin: Users can:</p><ul><li>View, create, update, and delete all actions and agents.</li><li>Enable or disable system actions and agents.</li><li>Attach system knowledge to custom agents and view all documents uploaded within the Knowledge Center (preview).</li></ul></li></ul>
View N/A
None The user role does not see any agents and can’t use the chat. The Agentic Assistant Hub is not visible to the user. Cortex Agentic Assistant is only available for navigation and insights.

Agents are limited by the individual permissions of the user. For example, if users do not have sufficient permissions to isolate an endpoint, they cannot use an agent to isolate an endpoint.

The execution of system or custom actions that are based on integration commands can be restricted to specific roles using integration permissions.