Dashboards permissions

Controls the ability to monitor security posture through visual data and documented summaries.

This is a master permission. To view any specific dashboard (e.g., Command Center), this primary permission must first be set to **Enabled.**

* Functionality: When enabled, users can manage the Dashboard Manager, use the widget library, and view accessible dashboards.
* Scope-Based Access Control (SBAC): Access to a dashboard does not grant access to the underlying data. If a user lacks the necessary SBAC data scope, widgets may appear empty or show errors
* Privacy: New dashboards are private by default. Administrators can configure sharing permissions under **Settings** → **Configurations** → **Access Management** → **Objects**.
* Predefined system dashboards and Marketplace dashboards cannot be deleted or have their privacy changed.

For more information on dashboards, see [Overview of dashboards and reports](../../../detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/overview-of-dashboards-and-reports).

| Permissions | Description | Roles Example |
| ----------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------- |
| Enabled | <p>Users can manage dashboards in the Dashboard Manager, manage the widget library, view all dashboards they have access to, and perform actions based on the following additional permissions:</p><ul><li><strong>Create Dashboards</strong>: Enables users to create custom dashboards. The creator becomes the owner with full control to edit, delete, and manage sharing for that dashboard.</li><li><p><strong>Edit Public Dashboards</strong>: Enables users to modify custom dashboards that an owner has made public. By default, only the owner can edit a public dashboard.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>By default, all new dashboards are restricted (private) and visible only to the creator (the owner). An administrator (or role with equivalent access) can configure how dashboards are shared across the tenant under <strong>Settings</strong> → <strong>Configurations</strong> → <strong>Access Management</strong> → <strong>Objects</strong>. These settings control whether dashboard owners are allowed to share their restricted dashboards directly with other users. For more information, see <a href="../../../../onboard-cortex-xsiam/post-deployment/manage-user-roles-and-access-management/manage-access-to-objects#step-1-configure-tenant-level-access-settings">Manage access to objects</a>.</p></div></li></ul> | Most roles should have Dashboards enabled and for users to create and edit dashboards. |
| Disabled | Users cannot access the Dashboard Manager or view any dashboards. | |

### Required and recommended permissions

Dashboards rely on data from across the platform. For widgets to populate correctly, consider these dependencies:

| Permission | Permission Level | Reason |
| --------------------- | ---------------- | ----------------------------------------------------------------------------------------------- |
| Cases & Issues | View | Dashboard widgets displaying case/issue data will show empty without this permission. Required. |
| Query Center | View | Query-based dashboard widgets require XQL query execution capability. Required. |
| Agent Administrations | View | Enables search functionality from within dashboards. Strongly recommended. |
| Asset Inventory | View | Asset widgets require this to display asset data. Recommended. |
| Forensics | View | Forensics widgets require this to display forensic data. Recommended. |
| Host Insights | View | Host insights widgets require this to display host analytics. Recommended. |