Cases and Issues permissions ↗
The Cases & Issues section is the heartbeat of SOC operations. It is the primary workspace where alerts are aggregated into issues, and issues are escalated into cases for full-scale investigation.
Limits permissions to the Cases, Issues, and Case Configuration pages. It controls how analysts interact with security events, from the initial triage of a single issue to the coordinated response to a multi-stage attack.
Caution
- To set Cases & Issues to View or View/Edit, you must first set the Scripts and Playbooks permissions to Enabled.
- When SBAC is set to Restrictive mode, users who don't have all the required tags shouldn't be able to read or edit the parent case (fields or context). For more information on setting restrictive mode, see Configure server settings.
- If users are assigned all tags on a child issue and have View/Edit permissions on Cases and Issues and Run Playbooks, they can trigger a playbook that could potentially change the parent case (even though users should not be able to do so according to SBAC). In this case, you can grant Add Trigger Playbook permissions, so users can bypass SBAC on the parent case fields and context data. For more information about updating fields in a playbook, see Update case fields.
- Users with View access to Cases and Issues can also view and edit Lists (under Settings → Configurations → Object Setup → Lists), provided they also have Script permissions.
| Permission | Description | Roles Example |
|---|---|---|
| None | Users cannot access Cases, Issues, and Case Configuration pages. | |
| View | Users can view cases and issues, see details, review investigation data, and view the Case Configuration page. Users cannot modify or take actions. | |
| View/Edit | <p>Full access to cases, issues, and case configuration. Users can view, modify, investigate, and take actions. Additional sub-permissions become available:</p><ul><li>Run Playbooks: Allows users to attach and trigger playbooks on issues for automated response</li><li>Create Case: Allows users to manually create new cases from issues or other sources.</li><li>Restrict Case Access: Allows users to change access to the case from the default scope to the assigned team only.</li></ul> | Most analyst roles should include View/Edit permissions to enable deeper investigation and case management. Run Playbooks and Restrict Case Access are not selected by default for most roles. |
Required and recommended permissions
For a Power User, the following permissions are essential for a complete investigation:
Note
Some roles require specific permissions. For example, a Security Engineer may require View/Edit for Playbooks, but a SOC Tier-1 Analyst does not.
| Permission | Permission Level | Reason |
|---|---|---|
| Query Center | View/Edit | XQL query results embedded in cases show errors without this. All roles need to view the query output for the case context. Required. |
| Query Library | Enabled | Strongly recommended/recommended. Allows saving and organizing personal XQL queries for reuse across investigations and rule development. |
| Playbooks | Enabled or Enabled with checkboxes selected | <ul><li>Enabled: Required. All roles need to be able to see the automated response history and playbook outputs.</li><li>Enabled with checkboxes selected: Required/strongly recommended. Create/modify playbooks for automated investigation and response workflows. Core for SOC Tier-3 Analysts and Security Engineers.</li></ul> |
| Scripts | Enabled or Enabled with checkboxes selected | <ul><li>Enabled: Required for most roles. Script output sections in cases are hidden without this. Needed to review automated enrichment and remediation results.</li><li>Enabled with checkboxes selected: Required for Security Engineers/Strongly recommended for SOC Tier-3, Threat Hunters, and Security Admins. Create/edit scripts for custom automation logic and specialized investigation tasks.</li></ul> |
| Asset Inventory | View or View/Edit | <ul><li>View: Required for most roles. The assets section in the case details is hidden without this. Need to see which hosts/users are involved in a case.</li><li>View/Edit: Strongly recommended/recommended for SOC Tier-3 Analysts, Threat Hunters, and Security Admins. Allows tagging and annotating assets during investigations.</li></ul> |
| Threat Intelligence | View or View/Edit | <ul><li>View: Required/Strongly recommended/recommended for all roles. Indicator enrichment data in cases is hidden without this. Needed for IOC context (reputation, WHOIS) during triage.</li><li>View/Edit: Strongly recommended/recommended for SOC Tier-3 Analysts, Threat Hunters, Security Admins, and Engineers. Create/edit IOCs. Hunters need to add custom indicators discovered during hunting.</li></ul> |
| Actions Center | View or View/Edit | <ul><li>View: Required/Strongly recommended for most roles. Response action history is not visible without this. Needed to see containment actions taken and their status.</li><li>View/Edit: Required for SOC Tier-3 Analysts, Threat Hunters, and Security Admins. Execute response actions (isolate, quarantine, block) during active case response.</li></ul> |
| Forensics | View or View/Edit | <ul><li>View: Recommended for SOC Tier-2 Analyst. Access host vulnerability and configuration data to assess the attack surface during investigations.</li><li>View/Edit: Required for SOC Tier 3 Analysts and Threat Hunters. Strongly recommended for Security Admins. Initiate host scans and file searches from host insights during investigations.</li></ul> |
| Host Insights | View or View/Edit | <ul><li>View: Required for SOC Tier-3 Analyst and Threat Hunter. Strongly recommended for Security Admin. Access host vulnerability and configuration data to assess the attack surface during investigations.</li><li>View/Edit: Strongly recommended for SOC Tier-3 Analysts, Threat Hunters, and Security Admins. Initiating host scans and file searches from host insights during investigations.</li></ul> |
| Graph Search | View or View/Edit | <ul><li>View: Visual investigation of entity relationships. Hunters use graph search to discover lateral movement and attack paths.</li><li>View/Edit: Save and share graph search queries for team collaboration.</li></ul><p>Strongly recommended for SOC Tier-3 Analysts and Threat Hunters. Recommended for Security Admins.</p> |
| Dashboards | Enabled or Enabled with checkboxes selected | <ul><li>Enabled: Used for queue prioritization and security posture assessment. Recommended for all roles.</li><li>Enabled with checkboxes selected: Create custom dashboards for hunting campaigns, rule monitoring, and investigation tracking. Recommended/Strongly recommended for SOC Tier-3 Analysts, Threat Hunters, Security Engineers, and Security Admins.</li></ul> |
| Reports | Enabled or Enabled with checkboxes selected | <ul><li>Enabled: View pre-built reports for shift handoff, trend analysis, and compliance evidence. Recommended for all roles.</li><li>Enabled with checkboxes selected: Create custom reports for hunting findings, rule performance, and executive briefings. Recommended/Strongly recommended for SOC Tier-3 Analysts, Threat Hunters, Security Engineers, and Security Admins.</li></ul> |
| Integrations | View | Integration data in cases is hidden without this. Useful for seeing third-party enrichment results (VirusTotal, MISP). Recommended for all roles. |
| Detection Rules | View or View/Edit | <ul><li>View: View detection rules to understand issue generation logic. Recommended/Strongly recommended for SOC Tier-3 Analysts, Threat Hunters, and Security Admins.</li><li>View/Edit: Create and modify BIOC, IOC, and correlation rules. Core for Security Engineers and strongly recommended for Security Admins.</li></ul> |