Asset Inventory provides comprehensive visibility into organizational assets, such as a unified view of all assets (endpoints, cloud instances, domains, certificates), asset categorization and tagging, asset relationship mapping, and attack surface visibility.
Users access these features by going to **Inventory** → **Assets** → **All Assets**, where they can view assets such as all Cloud assets, AI assets, API Endpoints, Code assets, Compute assets, and data assets.
For more information, see [All assets](../../../detect-investigate-and-respond-to-threats/asset-management/all-assets).
The Asset Inventory permissions control the ability to view the unified asset landscape and manage overarching asset categorizations and tags.
| Permissions | Description | Roles Example |
| ----------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| None | Cannot view the Asset Inventory menu from **Inventory** → **Assets** → **All Assets**. Viewing asset data in cases is limited. | |
| View | Read-only access to the Asset Inventory Menu and categories, such as cloud assets, AI assets, API Endpoints, Code assets, Compute assets, and data assets. Users can browse assets but cannot modify tags or assignments. | <ul><li>SOC Tier 1 Analyst: Reference asset context during issue triage.</li><li>SOC Tier-2 Analyst: Investigate asset relationships.</li><li>SOC Tier-3 Analyst: Deep asset analysis for investigations.</li><li>Threat Hunters: Asset context for threat hunting.</li></ul> |
| View/Edit | <p>Full access. Includes all View capabilities plus read and write access to all categories. Users can manage asset tags, annotations, custom properties, and business unit assignments across all asset categories.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>The asset inventory is primarily populated dynamically through agents and integrations. The View/Edit permission governs the management of asset metadata (such as assigning tags, setting business units, and modifying annotations) rather than the manual creation of the assets themselves.</p></div> | Security Engineer: Maintain asset inventory and tags. |
**Required and recommended permissions**
Consider adding the following permissions:
| Permission | Permission Level | Reason |
| --------------------- | ---------------- | -------------------------------------------------------------- |
| Network Configuration | View | Strongly recommended to view IP ranges associated with assets. |
| Host Insights | View | Strongly recommended to view detailed endpoint information. |
| Agent Administrations | View | Strongly recommended to view endpoint agent details. |
| Query Center | View | Strongly recommended to run XQL queries on asset data. |
| Asset Groups | View | Strongly recommended to view asset group memberships. |