The Cases & Issues section is the heartbeat of SOC operations. It is the primary workspace where alerts are aggregated into issues, and issues are escalated into cases for full-scale investigation.
Limits permissions to the **Cases**, **Issues**, and **Case Configuration** pages. It controls how analysts interact with security events, from the initial triage of a single issue to the coordinated response to a multi-stage attack.
### Caution
* To set Cases & Issues to View or View/Edit, you must first set the Scripts and Playbooks permissions to **Enabled**.
* When SBAC is set to **Restrictive** mode, users who don't have all the required tags shouldn't be able to read or edit the parent case (fields or context). For more information on setting restrictive mode, see [Configure server settings](../../onboard-cortex-xsiam/post-deployment/configure-server-settings).
* If users are assigned all tags on a child issue and have **View/Edit** permissions on **Cases and Issues** and **Run Playbooks**, they can trigger a playbook that could potentially change the parent case (even though users should not be able to do so according to SBAC). In this case, you can grant **Add Trigger Playbook** permissions, so users can bypass SBAC on the parent case fields and context data. For more information about updating fields in a playbook, see [Update case fields](../../configure-cortex-xsiam/customize-cases-and-issues/customize-case-fields-and-layouts/case-fields/update-case-fields).
* Users with **View** access to **Cases and Issues** can also view and edit Lists (under **Settings** → **Configurations** → **Object Setup** → **Lists**), provided they also have Script permissions.
| Permission | Description | Roles Example |
| ---------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| None | Users cannot access **Cases**, **Issues**, and **Case Configuration** pages. | |
| View | Users can view cases and issues, see details, review investigation data, and view the **Case Configuration** page. Users cannot modify or take actions. | |
| View/Edit | <p>Full access to cases, issues, and case configuration. Users can view, modify, investigate, and take actions. Additional sub-permissions become available:</p><ul><li><strong>Run Playbooks</strong>: Allows users to attach and trigger playbooks on issues for automated response</li><li><strong>Create Case</strong>: Allows users to manually create new cases from issues or other sources.</li><li><strong>Restrict Case Access:</strong> Allows users to change access to the case from the default scope to the assigned team only.</li></ul> | Most analyst roles should include View/Edit permissions to enable deeper investigation and case management. **Run Playbooks** and R**estrict Case Access** are not selected by default for most roles. |
**Required and recommended permissions**
For a Power User, the following permissions are essential for a complete investigation:
### Note
Some roles require specific permissions. For example, a Security Engineer may require View/Edit for Playbooks, but a SOC Tier-1 Analyst does not.
| Permission | Permission Level | Reason |
| ------------------- | ------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Query Center | View/Edit | XQL query results embedded in cases show errors without this. All roles need to view the query output for the case context. Required. |
| Query Library | Enabled | Strongly recommended/recommended. Allows saving and organizing personal XQL queries for reuse across investigations and rule development. |
| Playbooks | Enabled or Enabled with checkboxes selected | <ul><li>Enabled: Required. All roles need to be able to see the automated response history and playbook outputs.</li><li>Enabled with checkboxes selected: Required/strongly recommended. Create/modify playbooks for automated investigation and response workflows. Core for SOC Tier-3 Analysts and Security Engineers.</li></ul> |
| Scripts | Enabled or Enabled with checkboxes selected | <ul><li>Enabled: Required for most roles. Script output sections in cases are hidden without this. Needed to review automated enrichment and remediation results.</li><li>Enabled with checkboxes selected: Required for Security Engineers/Strongly recommended for SOC Tier-3, Threat Hunters, and Security Admins. Create/edit scripts for custom automation logic and specialized investigation tasks.</li></ul> |
| Asset Inventory | View or View/Edit | <ul><li>View: Required for most roles. The assets section in the case details is hidden without this. Need to see which hosts/users are involved in a case.</li><li>View/Edit: Strongly recommended/recommended for SOC Tier-3 Analysts, Threat Hunters, and Security Admins. Allows tagging and annotating assets during investigations.</li></ul> |
| Threat Intelligence | View or View/Edit | <ul><li>View: Required/Strongly recommended/recommended for all roles. Indicator enrichment data in cases is hidden without this. Needed for IOC context (reputation, WHOIS) during triage.</li><li>View/Edit: Strongly recommended/recommended for SOC Tier-3 Analysts, Threat Hunters, Security Admins, and Engineers. Create/edit IOCs. Hunters need to add custom indicators discovered during hunting.</li></ul> |
| Actions Center | View or View/Edit | <ul><li>View: Required/Strongly recommended for most roles. Response action history is not visible without this. Needed to see containment actions taken and their status.</li><li>View/Edit: Required for SOC Tier-3 Analysts, Threat Hunters, and Security Admins. Execute response actions (isolate, quarantine, block) during active case response.</li></ul> |
| Forensics | View or View/Edit | <ul><li>View: Recommended for SOC Tier-2 Analyst. Access host vulnerability and configuration data to assess the attack surface during investigations.</li><li>View/Edit: Required for SOC Tier 3 Analysts and Threat Hunters. Strongly recommended for Security Admins. Initiate host scans and file searches from host insights during investigations.</li></ul> |
| Host Insights | View or View/Edit | <ul><li>View: Required for SOC Tier-3 Analyst and Threat Hunter. Strongly recommended for Security Admin. Access host vulnerability and configuration data to assess the attack surface during investigations.</li><li>View/Edit: Strongly recommended for SOC Tier-3 Analysts, Threat Hunters, and Security Admins. Initiating host scans and file searches from host insights during investigations.</li></ul> |
| Graph Search | View or View/Edit | <ul><li>View: Visual investigation of entity relationships. Hunters use graph search to discover lateral movement and attack paths.</li><li>View/Edit: Save and share graph search queries for team collaboration.</li></ul><p>Strongly recommended for SOC Tier-3 Analysts and Threat Hunters. Recommended for Security Admins.</p> |
| Dashboards | Enabled or Enabled with checkboxes selected | <ul><li>Enabled: Used for queue prioritization and security posture assessment. Recommended for all roles.</li><li>Enabled with checkboxes selected: Create custom dashboards for hunting campaigns, rule monitoring, and investigation tracking. Recommended/Strongly recommended for SOC Tier-3 Analysts, Threat Hunters, Security Engineers, and Security Admins.</li></ul> |
| Reports | Enabled or Enabled with checkboxes selected | <ul><li>Enabled: View pre-built reports for shift handoff, trend analysis, and compliance evidence. Recommended for all roles.</li><li>Enabled with checkboxes selected: Create custom reports for hunting findings, rule performance, and executive briefings. Recommended/Strongly recommended for SOC Tier-3 Analysts, Threat Hunters, Security Engineers, and Security Admins.</li></ul> |
| Integrations | View | Integration data in cases is hidden without this. Useful for seeing third-party enrichment results (VirusTotal, MISP). Recommended for all roles. |
| Detection Rules | View or View/Edit | <ul><li>View: View detection rules to understand issue generation logic. Recommended/Strongly recommended for SOC Tier-3 Analysts, Threat Hunters, and Security Admins.</li><li>View/Edit: Create and modify BIOC, IOC, and correlation rules. Core for Security Engineers and strongly recommended for Security Admins.</li></ul> |