Agent Groups

Create and manage logical groups of endpoints. These groups are used to assign specific security policies and target actions to specific subsets of devices.

Permissions Description Roles Example
None No access to the Groups page (Inventory → Endpoints → Groups.  
View Read-only access to the Endpoint Groups page, including read-only access to agent group configurations, group details, members, and criteria. <ul><li>SOC Tier 1 Analyst: Understanding which group an endpoint belongs to helps contextualize issues.</li><li>SOC Tier 2 Analyst: Group membership is important for understanding applied policies.</li><li>SOC Tier 3 Analyst: Full visibility helps understand policy application and identify misconfigurations.</li><li>Threat Hunter: Understanding endpoint grouping helps target hunting activities</li></ul>
View/Edit All view capabilities plus management actions, such as creating, editing, and deleting groups. Security Engineer: Responsible for organizing endpoints into appropriate groups

Required and recommended permissions

Consider adding the following permissions:

Permission Permission Level Reason
Agent Administrations View Required. Groups organize endpoints. Without endpoint visibility, group membership cannot be understood or validated.
Agent Prevention Policies View Required. Policies are assigned to groups. Understanding which policies target which groups is essential for group context.
Agent Profiles View Strongly recommended. Profiles are assigned to groups. Understanding profile assignments prevents configuration conflicts when reorganizing groups.
Agent Extension Policies View Strongly recommended. Extension policies target groups. Understanding extension assignments prevents disrupting Device Control, Host Firewall, or Disk Encryption when modifying groups.
Agent Installations View Recommended. Installation packages may be targeted by group. Visibility helps coordinate deployment with group structure.