Defines agent behavior and configuration settings, including agent communication settings and proxy configurations.
| Permissions | Description | Roles Example |
| ----------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| None | Cannot view the **Prevention Profiles** page (**Inventory** → **Endpoints** → **Policy Management** → **Prevention** → **Profiles** and is limited to the profile name when viewing the profile in endpoint details. | SOC Tier-1 Analyst: Profile details are typically not needed for basic triage. Although it may be useful for understanding why certain agent features are enabled/disabled on specific endpoints |
| View | View the Agent Profiles menu and read-only access for the Profiles list, details, settings, and view assigned groups. | <ul><li>SOC Tier-2 Analyst: Understanding agent profiles helps explain agent behavior and capabilities during investigations. Profiles determine what data the agent collects and reports</li><li>SOC Tier-3 Analyst: Full profile visibility needed for advanced analysis and understanding agent configuration. Critical for determining if an agent was properly configured during a case.</li><li>Threat Hunter: Profile visibility helps understand agent capabilities and potential detection gaps. Hunters need to know what telemetry is available from each endpoint.</li></ul> |
| View/Edit | All view capabilities, plus managing profiles, assigning to groups, and configuring all settings. | Security Engineer: Responsible for profile configuration and optimization. Creates and maintains profiles for different endpoint types. |
**Required and recommended permissions**
Consider adding the following permissions:
| Permission | Permission Level | Reason |
| ------------------------- | ---------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Agent Groups | View | Required. Profiles are assigned to groups. Without group visibility, users cannot understand which endpoints use which profiles. |
| Agent Administrations | View | Required. Must see endpoints to validate profile deployment and verify agent configuration after changes. |
| Agent Prevention Policies | View | Strongly recommended. Profiles define settings within policies. Understanding policy context prevents conflicting configurations. |
| Network Configuration | View | Strongly recommended. Profiles include proxy and network settings. Network configuration visibility ensures profile settings align with network infrastructure. |
| Agent Installations | View | Recommended. Profile settings may depend on the agent version. Installation visibility helps ensure profile compatibility. |