Reports permissions

Controls access to the generation and management of documented security summaries, ranging from shift handoffs to compliance evidence

Cortex XSIAM enforces least-privileged per-object access by allowing you to manage access for custom (user-defined) report templates. For more information, see Manage access to objects.

Permission Description Roles Example
Enabled <p>Access permissions change depending on the per-object access and sub-permissions granted as explained below. For example, when Reports are enabled users can view existing reports, but access to the Widget Library is dependent on Editor permissions.</p><p>Other access permissions include create, manage, and delete report templates, and generate new reports.</p><p>When set to Enabled, you can grant the following additional permissions:</p><ul><li>Create Report Templates: Enables the New Template button, allowing the user to create new custom report templates. The user who creates the report template is designated as the Owner.</li><li>Edit Public Report Templates: Allows the user to modify custom report templates set to Public, even if they are not the Owner.</li></ul> Most roles should be able to view and edit reports.
Disabled Users cannot access reports or report templates.  

Reports rely on populating data from various functional modules. For reports to be complete, consider the following dependencies:

Permission Permission Level Reason
Cases & Issues View Required. Reports containing cases/issue statistics require this permission to populate data.
Agent Administrations View Strongly Recommended. Reports containing endpoint metrics require this permission.
Asset Inventory View Recommended: Reports containing asset information require this permission.
Compliance View Recommended. Compliance reports require this permission to include compliance metrics.