Documentation — August 20, 2026
232 files changed, 1551 insertions, 588 deletions — view the commit on the mirror.
233 Cortex XSIAM pages restyled for search; SaaS section renamed; 18 compliance standards added
- Every changed file is in the Cortex XSIAM book: 192 modified and 41 renamed, with no page added or deleted.
- Mostly an authoring pass — 97 pages changed only by gaining a
description:frontmatter line, and 12 page titles were rewritten into keyword-rich forms. - The SaaS Security onboarding section moved from
onboard-a-supported-saas-applicationtoconnect-a-saas-application, taking 40 application pages with it. - The one substantive change is the compliance standards catalog, which gained 18 standards including CIS benchmarks for Ubuntu 24.04 LTS, Debian 13 and AWS Foundations v7.0.0.
- Egress, inbound and engine IP tables, supported regions, retention periods and licence tiers were all re-headed, but no value in them changed.
Highlights
-
The SaaS Security onboarding section was renamed, moving 41 pages
`onboard-a-supported-saas-application` became `connect-a-saas-application`; 40 of the 41 pages moved at 100% similarity, and the parent page's own per-app link table was left untouched and still points at the old segment.
-
The compliance standards catalog gained 18 standards
New CIS benchmarks for Alibaba Cloud 2.0.0, Debian 13, Ubuntu 24.04 LTS, Red Hat OpenShift 1.9.0, EKS 1.8.0, AWS Foundations v7.0.0 and Azure Foundations v6.0.0, each at Level 1 and Level 2, plus NIST SP 800-190.
-
The allowlist and region reference pages changed only in their headings
The egress, inbound, engine-IP and FedRAMP resource pages were retitled and given real `###` headings in place of bold labels, but every IP address, FQDN, port and App-ID in their tables is unchanged.
-
97 pages changed only by gaining a search description
Each added a four- or six-line `description:` frontmatter block and nothing else — zero deletions, no body text touched.
-
12 page titles were rewritten and the navigation manifest followed
`.meta/xsiam.json` records the new titles: "Engine IP addresses (outbound)" became "Cortex XSIAM engine outbound IP addresses", "Use the interface" became "Use the Cortex XSIAM interface", and "Limitations & supported regions" became "FedRAMP limitations and supported government cloud regions".
-
Role-based access control hub pages now link to their children
Plain-text component lists became cross-links — configuration permissions went from 8 bare names to 19 linked sub-pages, and cloud security and posture management gained links to its 9.
Changes
232 files listed, 14 written up and shaded below.
-
▸ ▾ Global Exceptions modified +4 −0
xsiam/reference-and-developer-docs/role-based-access-control/inventory-agent-permissions/global-exceptionsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,8 +1,12 @@---description: Manage global prevention exceptions and their endpoint scope in Cortex XSIAM.---# Global Exceptions# Global ExceptionsGlobal Exceptions allow security teams to exclude specific items from detection, such as creating hash-based exceptions (SHA256, MD5) and defining path-based exceptions for files and folders.Global Exceptions allow security teams to exclude specific items from detection, such as creating hash-based exceptions (SHA256, MD5) and defining path-based exceptions for files and folders.hint infohint info### Note### NoteGlobal Exceptions are part of the Prevention section and apply to prevention policies/profiles.Global Exceptions are part of the Prevention section and apply to prevention policies/profiles.Show markdown source
@@ -1,8 +1,12 @@ +--- +description: Manage global prevention exceptions and their endpoint scope in Cortex XSIAM. +--- + # Global Exceptions Global Exceptions allow security teams to exclude specific items from detection, such as creating hash-based exceptions (SHA256, MD5) and defining path-based exceptions for files and folders. {% hint style="info" %} ### Note Global Exceptions are part of the Prevention section and apply to prevention policies/profiles. -
▸ ▾ Host Firewall modified +4 −0
xsiam/reference-and-developer-docs/role-based-access-control/inventory-agent-permissions/host-firewallRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,8 +1,12 @@---description: Configure host firewall rules and review firewall events in Cortex XSIAM.---# Host Firewall# Host FirewallProvides endpoint-level network protection, such as defining inbound and outbound firewall rules and creating application-based rules in the Host Firewall page (Inventory → Endpoints → Host Firewall). Users can also Collect Detailed Host Firewall Logs from Inventory → Endpoints → Endpoint Control.Provides endpoint-level network protection, such as defining inbound and outbound firewall rules and creating application-based rules in the Host Firewall page (Inventory → Endpoints → Host Firewall). Users can also Collect Detailed Host Firewall Logs from Inventory → Endpoints → Endpoint Control.hint warninghint warning### Caution### CautionMisconfigured firewall rules can block legitimate traffic or allow malicious connections. Implement change management processes and test rules before deployment.Misconfigured firewall rules can block legitimate traffic or allow malicious connections. Implement change management processes and test rules before deployment.Show markdown source
@@ -1,8 +1,12 @@ +--- +description: Configure host firewall rules and review firewall events in Cortex XSIAM. +--- + # Host Firewall Provides endpoint-level network protection, such as defining inbound and outbound firewall rules and creating application-based rules in the Host Firewall page (**Inventory** → **Endpoints** → **Host Firewall)**. Users can also **Collect Detailed Host Firewall Logs** from **Inventory** → **Endpoints** → **Endpoint Control**. {% hint style="warning" %} ### Caution Misconfigured firewall rules can block legitimate traffic or allow malicious connections. Implement change management processes and test rules before deployment. -
▸ ▾ Inventory - Assets permissions modified +7 −1
xsiam/reference-and-developer-docs/role-based-access-control/inventory-assets-permissionsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,7 +1,13 @@------description: Consider adding inventory permissions for Assets and Agents (Endpoints).description: Configure inventory permissions for assets and endpoints in Cortex XSIAM.------# Inventory - Assets permissions# Inventory - Assets permissionsInventory manages all assets in your environment, ensuring complete visibility, control, and protection for Assets, which includes Network Configuration, Compliance, Asset Inventory, Asset Roles Configuration, and Asset Groups. For Agent Management, see Inventory - Agent permissions.Inventory manages all assets in your environment, ensuring complete visibility, control, and protection for Assets, which includes Network Configuration, Compliance, Asset Inventory, Asset Roles Configuration, and Asset Groups. For Agent Management, see Inventory - Agent permissions.• network-configuration-permissions• compliance-legacy-permissions• asset-inventory-permissions• asset-roles-configuration-permissions• asset-groups-permissionsShow markdown source
@@ -1,7 +1,13 @@ --- -description: Consider adding inventory permissions for Assets and Agents (Endpoints). +description: Configure inventory permissions for assets and endpoints in Cortex XSIAM. --- # Inventory - Assets permissions Inventory manages all assets in your environment, ensuring complete visibility, control, and protection for Assets, which includes Network Configuration, Compliance, Asset Inventory, Asset Roles Configuration, and Asset Groups. For Agent Management, see [Inventory - Agent permissions](inventory-agent-permissions). + +* [network-configuration-permissions](inventory-assets-permissions/network-configuration-permissions "mention") +* [compliance-legacy-permissions](inventory-assets-permissions/compliance-legacy-permissions "mention") +* [asset-inventory-permissions](inventory-assets-permissions/asset-inventory-permissions "mention") +* [asset-roles-configuration-permissions](inventory-assets-permissions/asset-roles-configuration-permissions "mention") +* [asset-groups-permissions](inventory-assets-permissions/asset-groups-permissions "mention")
-
▸ ▾ Asset Groups permissions modified +4 −4
xsiam/reference-and-developer-docs/role-based-access-control/inventory-assets-permissions/asset-groups-permissionsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,17 +1,17 @@# Asset Groups permissions---description: Manage asset groups and scoped access controls in Cortex XSIAM.---Asset Groups permissions# Asset Groups permissionsAsset Groups enable organizations to manage asset groups, such as creating logical groupings of assets, applying policies and rules to asset groups, scoping user access to specific asset groups (SBAC), and supporting automation exclusions by asset group.Asset Groups enable organizations to manage asset groups, such as creating logical groupings of assets, applying policies and rules to asset groups, scoping user access to specific asset groups (SBAC), and supporting automation exclusions by asset group.hint warninghint warning### CautionSBAC: Asset Groups form the foundation of Scope-Based Access Control (SBAC). Granting a user View/Edit access to Asset Groups allows them to modify the groups that dictate data access boundaries for other users in the tenant.SBAC: Asset Groups form the foundation of Scope-Based Access Control (SBAC). Granting a user View/Edit access to Asset Groups allows them to modify the groups that dictate data access boundaries for other users in the tenant.endhintendhintThe following features are affected:The following features are affected:• Asset Groups: Inventory → Assets → Groups. For more information, see Asset groups.• Asset Groups: Inventory → Assets → Groups. For more information, see Asset groups.• User Groups: When defining or editing a user group, you can scope an asset by defining the access group. For more information, see Scope user access to applications (Application SBAC).• User Groups: When defining or editing a user group, you can scope an asset by defining the access group. For more information, see Scope user access to applications (Application SBAC).• Automations Exclusion Center: When selecting Edit Policy, you can add an Asset Group to exclude the relevant asset class. For more information, see Manage automation exclusion policies.• Automations Exclusion Center: When selecting Edit Policy, you can add an Asset Group to exclude the relevant asset class. For more information, see Manage automation exclusion policies.Show markdown source
@@ -1,17 +1,17 @@ -# Asset Groups permissions +--- +description: Manage asset groups and scoped access controls in Cortex XSIAM. +--- -**Asset Groups permissions** +# Asset Groups permissions Asset Groups enable organizations to manage asset groups, such as creating logical groupings of assets, applying policies and rules to asset groups, scoping user access to specific asset groups (SBAC), and supporting automation exclusions by asset group. {% hint style="warning" %} -### Caution - SBAC: Asset Groups form the foundation of Scope-Based Access Control (SBAC). Granting a user View/Edit access to Asset Groups allows them to modify the groups that dictate data access boundaries for other users in the tenant. {% endhint %} The following features are affected: * Asset Groups: **Inventory** → **Assets** → **Groups**. For more information, see [Asset groups](../../../detect-investigate-and-respond-to-threats/asset-management/asset-groups). * User Groups: When defining or editing a user group, you can scope an asset by defining the access group. For more information, see [Scope user access to applications (Application SBAC)](https://app.gitbook.com/s/8Z0RLJ1BFF5TQL8VtUeK/application-security-posture-management-aspm/applications/scope-user-access-to-applications-application-sbac). * Automations Exclusion Center: When selecting Edit Policy, you can add an Asset Group to exclude the relevant asset class. For more information, see [Manage automation exclusion policies](../../../configure-cortex-xsiam/automations/automation-exclusion-center/manage-automation-exclusion-policies). -
▸ ▾ Asset Inventory permissions modified +4 −0
xsiam/reference-and-developer-docs/role-based-access-control/inventory-assets-permissions/asset-inventory-permissionsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,8 +1,12 @@---description: Control access to asset inventory data and metadata in Cortex XSIAM.---# Asset Inventory permissions# Asset Inventory permissionsAsset Inventory provides comprehensive visibility into organizational assets, such as a unified view of all assets (endpoints, cloud instances, domains, certificates), asset categorization and tagging, asset relationship mapping, and attack surface visibility.Asset Inventory provides comprehensive visibility into organizational assets, such as a unified view of all assets (endpoints, cloud instances, domains, certificates), asset categorization and tagging, asset relationship mapping, and attack surface visibility.Users access these features by going to Inventory → Assets → All Assets, where they can view assets such as all Cloud assets, AI assets, API Endpoints, Code assets, Compute assets, and data assets.Users access these features by going to Inventory → Assets → All Assets, where they can view assets such as all Cloud assets, AI assets, API Endpoints, Code assets, Compute assets, and data assets.For more information, see All assets.For more information, see All assets.Show markdown source
@@ -1,8 +1,12 @@ +--- +description: Control access to asset inventory data and metadata in Cortex XSIAM. +--- + # Asset Inventory permissions Asset Inventory provides comprehensive visibility into organizational assets, such as a unified view of all assets (endpoints, cloud instances, domains, certificates), asset categorization and tagging, asset relationship mapping, and attack surface visibility. Users access these features by going to **Inventory** → **Assets** → **All Assets**, where they can view assets such as all Cloud assets, AI assets, API Endpoints, Code assets, Compute assets, and data assets. For more information, see [All assets](../../../detect-investigate-and-respond-to-threats/asset-management/all-assets).
-
▸ ▾ Asset Roles configuration permissions modified +4 −0
xsiam/reference-and-developer-docs/role-based-access-control/inventory-assets-permissions/asset-roles-configuration-permissionsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,8 +1,12 @@---description: Configure functional asset roles and endpoint assignments in Cortex XSIAM.---# Asset Roles configuration permissions# Asset Roles configuration permissionsAsset Roles Configuration allows organizations to define and manage specific functional roles for assets across their environment (such as Admin, User, or Server). By associating specific users and endpoints with these roles, security teams can enrich security events with role context and support role-based analytics and alerting. Users access these features by going to Inventory → Assets → Asset Roles Configuration.Asset Roles Configuration allows organizations to define and manage specific functional roles for assets across their environment (such as Admin, User, or Server). By associating specific users and endpoints with these roles, security teams can enrich security events with role context and support role-based analytics and alerting. Users access these features by going to Inventory → Assets → Asset Roles Configuration.hint infohint info### Notice### NoticeRequires the Identity Threat Detection and Response add-on.Requires the Identity Threat Detection and Response add-on.Show markdown source
@@ -1,8 +1,12 @@ +--- +description: Configure functional asset roles and endpoint assignments in Cortex XSIAM. +--- + # Asset Roles configuration permissions Asset Roles Configuration allows organizations to define and manage specific functional roles for assets across their environment (such as Admin, User, or Server). By associating specific users and endpoints with these roles, security teams can enrich security events with role context and support role-based analytics and alerting. Users access these features by going to **Inventory** → **Assets** → **Asset Roles Configuration**. {% hint style="info" %} ### Notice Requires the Identity Threat Detection and Response add-on. -
▸ ▾ Compliance (Legacy) permissions modified +4 −0
xsiam/reference-and-developer-docs/role-based-access-control/inventory-assets-permissions/compliance-legacy-permissionsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,8 +1,12 @@---description: View legacy cloud compliance violations for assets in Cortex XSIAM.---# Compliance (Legacy) permissions# Compliance (Legacy) permissionsCloud Compliance (Legacy) under Inventory → Endpoints → Cloud Compliance provides a read-only view of CIS benchmark compliance violations for cloud assets.Cloud Compliance (Legacy) under Inventory → Endpoints → Cloud Compliance provides a read-only view of CIS benchmark compliance violations for cloud assets.hint infohint info### Notice### NoticeRequires a Cortex XSIAM Enterprise Plus license. If you have a Cloud Posture Security, Cloud Runtime Security, or Cortex XSIAM Premium license, see Compliance - Cloud permissions.Requires a Cortex XSIAM Enterprise Plus license. If you have a Cloud Posture Security, Cloud Runtime Security, or Cortex XSIAM Premium license, see Compliance - Cloud permissions.Show markdown source
@@ -1,8 +1,12 @@ +--- +description: View legacy cloud compliance violations for assets in Cortex XSIAM. +--- + # Compliance (Legacy) permissions Cloud Compliance (Legacy) under **Inventory** → **Endpoints** → **Cloud Compliance** provides a read-only view of CIS benchmark compliance violations for cloud assets. {% hint style="info" %} ### Notice Requires a Cortex XSIAM Enterprise Plus license. If you have a Cloud Posture Security, Cloud Runtime Security, or Cortex XSIAM Premium license, see [Compliance - Cloud permissions](../cloud-security-and-posture-management-permissions/compliance-cloud-permissions). -
▸ ▾ Network Configuration permissions modified +4 −0
xsiam/reference-and-developer-docs/role-based-access-control/inventory-assets-permissions/network-configuration-permissionsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,8 +1,12 @@---description: Configure network topology, ranges, and trusted networks in Cortex XSIAM.---# Network Configuration permissions# Network Configuration permissionsNetwork Configuration (Inventory → Assets → Network Configuration) enables administrators to define and manage the organization's network topology, such as internal and external IP address ranges, internal domain suffixes, and trusted networks.Network Configuration (Inventory → Assets → Network Configuration) enables administrators to define and manage the organization's network topology, such as internal and external IP address ranges, internal domain suffixes, and trusted networks.hint infohint info### Notice### NoticeExternal IP address ranges: Requires an ASM or Cortex XSIAM Premium license.External IP address ranges: Requires an ASM or Cortex XSIAM Premium license.Show markdown source
@@ -1,8 +1,12 @@ +--- +description: Configure network topology, ranges, and trusted networks in Cortex XSIAM. +--- + # Network Configuration permissions Network Configuration (**Inventory** → **Assets** → **Network Configuration**) enables administrators to define and manage the organization's network topology, such as internal and external IP address ranges, internal domain suffixes, and trusted networks. {% hint style="info" %} ### Notice External IP address ranges: Requires an ASM or Cortex XSIAM Premium license. -
▸ ▾ Investigation and Response permissions modified +5 −5
xsiam/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissionsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,13 +1,13 @@------description: >-description: >-Configure investigation and response permissions, which include search,Configure role permissions for search, response, and automation capabilitiesresponse, and automation permissions.in Cortex XSIAM.------# Investigation and Response permissions# Investigation and Response permissionsInvestigation and Response permissions are split as follows:Investigation and Response permissions are split as follows:• Search permissions: Query Library, Query Center, Forensics, Host Insights, and Graph Search.• Search permissions: Query Library permissions, Query Center permissions, Forensics permissions, Host Insights permissions, and Graph Search permissions.• Response permissions: Action Center, EDL, Agent Scripts Library, and Live Terminal.• Response permissions: Action Center permissions, EDL permissions, Agent Scripts Library permissions, and Live Terminal permissions.• Automation permissions: Playbooks, Scripts, Playground, and Automation Exclusion Center.• Automation permissions: Playbook permissions, Script permissions, Jobs permissions, Playground permissions, and Automation Exclusion Center permissions.Show markdown source
@@ -1,13 +1,13 @@ --- description: >- - Configure investigation and response permissions, which include search, - response, and automation permissions. + Configure role permissions for search, response, and automation capabilities + in Cortex XSIAM. --- # Investigation and Response permissions Investigation and Response permissions are split as follows: -* Search permissions: Query Library, Query Center, Forensics, Host Insights, and Graph Search. -* Response permissions: Action Center, EDL, Agent Scripts Library, and Live Terminal. -* Automation permissions: Playbooks, Scripts, Playground, and Automation Exclusion Center. +* **Search permissions:** Query Library permissions, Query Center permissions, Forensics permissions, Host Insights permissions, and Graph Search permissions. +* **Response permissions:** Action Center permissions, EDL permissions, Agent Scripts Library permissions, and Live Terminal permissions. +* **Automation permissions:** Playbook permissions, Script permissions, Jobs permissions, Playground permissions, and Automation Exclusion Center permissions.
-
▸ ▾ Automation permissions modified +12 −0
xsiam/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/automation-permissionsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,9 +1,21 @@---description: >-Configure permissions for playbooks, scripts, playground, and automatedexclusions in Cortex XSIAM.---# Automation permissions# Automation permissionsThis section covers permissions for playbooks, scripts, playground, and the Automated Exclusion Center.This section covers permissions for playbooks, scripts, playground, and the Automated Exclusion Center.• playbook-permissions• script-permissions• jobs-permissions• playground-permissions• automation-exclusion-center-permissionshint warninghint warning### Caution### CautionCortex XSIAM enforces a strict permission dependency chain for automation and case management. You must grant at least View access to Scripts before you can grant access to Playbooks. Consequently, you must grant at least View access to Playbooks before you can enable Cases & Issues.Cortex XSIAM enforces a strict permission dependency chain for automation and case management. You must grant at least View access to Scripts before you can grant access to Playbooks. Consequently, you must grant at least View access to Playbooks before you can enable Cases & Issues.endhintendhintShow markdown source
@@ -1,9 +1,21 @@ +--- +description: >- + Configure permissions for playbooks, scripts, playground, and automated + exclusions in Cortex XSIAM. +--- + # Automation permissions This section covers permissions for playbooks, scripts, playground, and the Automated Exclusion Center. +* [playbook-permissions](automation-permissions/playbook-permissions "mention") +* [script-permissions](automation-permissions/script-permissions "mention") +* [jobs-permissions](automation-permissions/jobs-permissions "mention") +* [playground-permissions](automation-permissions/playground-permissions "mention") +* [automation-exclusion-center-permissions](automation-permissions/automation-exclusion-center-permissions "mention") + {% hint style="warning" %} ### Caution Cortex XSIAM enforces a strict permission dependency chain for automation and case management. You must grant at least View access to Scripts before you can grant access to Playbooks. Consequently, you must grant at least View access to Playbooks before you can enable Cases & Issues. {% endhint %} -
▸ ▾ Automation Exclusion Center permissions modified +6 −0
xsiam/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/automation-permissions/automation-exclusion-center-permissionsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,8 +1,14 @@---description: >-Manage Cortex XSIAM automation exclusions for commands, scripts, andremediation.---# Automation Exclusion Center permissions# Automation Exclusion Center permissionsControls access to the Automation Exclusion Center (Settings → Configurations → Automation → Automation Exclusion Center), which prevents a command or script from a remediation action. For more information, see Automation Exclusion Center.Controls access to the Automation Exclusion Center (Settings → Configurations → Automation → Automation Exclusion Center), which prevents a command or script from a remediation action. For more information, see Automation Exclusion Center.Permission│Description│Roles ExamplePermission│Description│Roles Example| ---------- | ----------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------ || ---------- | ----------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------ |None│Cannot access the Automation Exclusion Center, view any exclusion policies, or view excluded assets.│SOC Tier 1: Do not need to view exclusion policies or excluded assets.None│Cannot access the Automation Exclusion Center, view any exclusion policies, or view excluded assets.│SOC Tier 1: Do not need to view exclusion policies or excluded assets.View│Can access the Automation Exclusion Center (read-only), view exclusion policies, excluded assets and counts, and view policy compliance status.│SOC Tier 2 and 3 Analysts and Threat Hunters: Need View access to help understand automation behavior.View│Can access the Automation Exclusion Center (read-only), view exclusion policies, excluded assets and counts, and view policy compliance status.│SOC Tier 2 and 3 Analysts and Threat Hunters: Need View access to help understand automation behavior.Show markdown source
@@ -1,8 +1,14 @@ +--- +description: >- + Manage Cortex XSIAM automation exclusions for commands, scripts, and + remediation. +--- + # Automation Exclusion Center permissions Controls access to the Automation Exclusion Center (**Settings** → **Configurations** → **Automation** → **Automation Exclusion Center**), which prevents a command or script from a remediation action. For more information, see [Automation Exclusion Center](../../../../configure-cortex-xsiam/automations/automation-exclusion-center). | Permission | Description | Roles Example | | ---------- | ----------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------ | | None | Cannot access the Automation Exclusion Center, view any exclusion policies, or view excluded assets. | SOC Tier 1: Do not need to view exclusion policies or excluded assets. | | View | Can access the Automation Exclusion Center (read-only), view exclusion policies, excluded assets and counts, and view policy compliance status. | SOC Tier 2 and 3 Analysts and Threat Hunters: Need View access to help understand automation behavior. |
-
▸ ▾ Jobs permissions modified +4 −0
xsiam/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/automation-permissions/jobs-permissionsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,8 +1,12 @@---description: Manage access to Cortex XSIAM scheduled automation jobs and their execution.---# Jobs permissions# Jobs permissionsConfigure access to automation jobs. Jobs are scheduled playbook tasks that run at predefined intervals or in response to feed changes.Configure access to automation jobs. Jobs are scheduled playbook tasks that run at predefined intervals or in response to feed changes.By default, the Jobs permission is set to None. While you can enable the Jobs permission itself, you will not be able to select playbooks to run within the job unless you have at least Viewer access to those playbooks. Additionally, viewing the results of a job within a case requires access to the Cases & Issues component.By default, the Jobs permission is set to None. While you can enable the Jobs permission itself, you will not be able to select playbooks to run within the job unless you have at least Viewer access to those playbooks. Additionally, viewing the results of a job within a case requires access to the Cases & Issues component.Permission│Description│Roles ExamplePermission│Description│Roles Example| ---------- | ---------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------- || ---------- | ---------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------- |Show markdown source
@@ -1,8 +1,12 @@ +--- +description: Manage access to Cortex XSIAM scheduled automation jobs and their execution. +--- + # Jobs permissions Configure access to automation jobs. Jobs are scheduled playbook tasks that run at predefined intervals or in response to feed changes. By default, the **Jobs** permission is set to **None**. While you can enable the Jobs permission itself, you will not be able to select playbooks to run within the job unless you have at least Viewer access to those playbooks. Additionally, viewing the results of a job within a case requires access to the Cases & Issues component. | Permission | Description | Roles Example | | ---------- | ---------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------- |
-
▸ ▾ Playbook permissions modified +4 −0
xsiam/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/automation-permissions/playbook-permissionsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,8 +1,12 @@---description: Manage access to Cortex XSIAM playbooks and automated response workflows.---# Playbook permissions# Playbook permissionsPlaybooks are automated response workflows. By default, the Playbooks permission is set to Disabled. To set it to Enabled, you must first set Scripts to Enabled. When you enable Playbooks, you can then set Cases and Issues to View or View/Edit.Playbooks are automated response workflows. By default, the Playbooks permission is set to Disabled. To set it to Enabled, you must first set Scripts to Enabled. When you enable Playbooks, you can then set Cases and Issues to View or View/Edit.hint infohint info### Important### ImportantPlaybooks are a prerequisite for the entire Investigation & Response workspace. You cannot set Cases and Issues to View/Edit unless Playbooks is Enabled.Playbooks are a prerequisite for the entire Investigation & Response workspace. You cannot set Cases and Issues to View/Edit unless Playbooks is Enabled.Show markdown source
@@ -1,8 +1,12 @@ +--- +description: Manage access to Cortex XSIAM playbooks and automated response workflows. +--- + # Playbook permissions Playbooks are automated response workflows. By default, the **Playbooks** permission is set to **Disabled**. To set it to **Enabled**, you must first set **Scripts** to **Enabled**. When you enable **Playbooks**, you can then set **Cases and Issues** to View or View/Edit. {% hint style="info" %} ### Important Playbooks are a prerequisite for the entire Investigation & Response workspace. You cannot set Cases and Issues to View/Edit unless Playbooks is Enabled. -
▸ ▾ Playground permissions modified +4 −0
xsiam/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/automation-permissions/playground-permissionsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,8 +1,12 @@---description: Manage access to the Cortex XSIAM playground for testing commands and scripts.---# Playground permissions# Playground permissionsControls Playground Investigation & Response → Automation → Playground, which is a testing environment for commands and scripts that is not connected to a live (active) investigation.Controls Playground Investigation & Response → Automation → Playground, which is a testing environment for commands and scripts that is not connected to a live (active) investigation.Permission│Description│Roles ExamplePermission│Description│Roles Example| ---------- | ------------------------------------------------------------------------------------------------ | ---------------------------------------------------------------------------------------------------------------------------- || ---------- | ------------------------------------------------------------------------------------------------ | ---------------------------------------------------------------------------------------------------------------------------- |None│Users cannot access the Playground page and cannot test commands, scripts, and integrations.│SOC Tier-1 analysts: Do not need Playground access for basic triage.None│Users cannot access the Playground page and cannot test commands, scripts, and integrations.│SOC Tier-1 analysts: Do not need Playground access for basic triage.View/Edit│Users can access the Playground page and can test commands, scripts, and integrations.│SOC Tier 2 and 3 Analysts, Security Engineers, and Security Admins: Benefit from playground access for testing and learning.View/Edit│Users can access the Playground page and can test commands, scripts, and integrations.│SOC Tier 2 and 3 Analysts, Security Engineers, and Security Admins: Benefit from playground access for testing and learning.Show markdown source
@@ -1,8 +1,12 @@ +--- +description: Manage access to the Cortex XSIAM playground for testing commands and scripts. +--- + # Playground permissions Controls Playground **Investigation & Response** → **Automation** → **Playground**, which is a testing environment for commands and scripts that is not connected to a live (active) investigation. | Permission | Description | Roles Example | | ---------- | ------------------------------------------------------------------------------------------------ | ---------------------------------------------------------------------------------------------------------------------------- | | None | Users cannot access the **Playground** page and cannot test commands, scripts, and integrations. | SOC Tier-1 analysts: Do not need Playground access for basic triage. | | View/Edit | Users can access the **Playground** page and can test commands, scripts, and integrations. | SOC Tier 2 and 3 Analysts, Security Engineers, and Security Admins: Benefit from playground access for testing and learning. |
-
▸ ▾ Script permissions modified +4 −0
xsiam/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/automation-permissions/script-permissionsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,8 +1,12 @@---description: Manage access to Cortex XSIAM scripts for automation and remediation.---# Script permissions# Script permissionsThe Scripts permission is a foundational administrative and operational tool. In Cortex XSIAM, scripts (primarily Python-based) are the engine behind automated enrichment, complex data manipulation, and custom remediation actions.. For more information, see Scripts.The Scripts permission is a foundational administrative and operational tool. In Cortex XSIAM, scripts (primarily Python-based) are the engine behind automated enrichment, complex data manipulation, and custom remediation actions.. For more information, see Scripts.hint warninghint warning### Caution### CautionScripts are a prerequisite for Playbooks. You cannot set Playbooks to Enabled unless Scripts is Enabled.Scripts are a prerequisite for Playbooks. You cannot set Playbooks to Enabled unless Scripts is Enabled.Show markdown source
@@ -1,8 +1,12 @@ +--- +description: Manage access to Cortex XSIAM scripts for automation and remediation. +--- + # Script permissions The Scripts permission is a foundational administrative and operational tool. In Cortex XSIAM, scripts (primarily Python-based) are the engine behind automated enrichment, complex data manipulation, and custom remediation actions.. For more information, see [Scripts](../../../../configure-cortex-xsiam/automations/scripts). {% hint style="warning" %} ### Caution Scripts are a prerequisite for Playbooks. You cannot set Playbooks to Enabled unless Scripts is Enabled. -
▸ ▾ Response permissions modified +11 −0
xsiam/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/response-permissionsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,3 +1,14 @@---description: >-Configure access to endpoint and network response actions and tools in CortexXSIAM.---# Response permissions# Response permissionsConfigure access to endpoint and network response actions. This module controls access to the Action Center, External Dynamic Lists (EDL) indicator management, the Agent Script Library, and Live Terminal interactive shells.Configure access to endpoint and network response actions. This module controls access to the Action Center, External Dynamic Lists (EDL) indicator management, the Agent Script Library, and Live Terminal interactive shells.• action-center-permissions• edl-permissions• agent-scripts-library-permissions• live-terminal-permissionsShow markdown source
@@ -1,3 +1,14 @@ +--- +description: >- + Configure access to endpoint and network response actions and tools in Cortex + XSIAM. +--- + # Response permissions Configure access to endpoint and network response actions. This module controls access to the Action Center, External Dynamic Lists (EDL) indicator management, the Agent Script Library, and Live Terminal interactive shells. + +* [action-center-permissions](response-permissions/action-center-permissions "mention") +* [edl-permissions](response-permissions/edl-permissions "mention") +* [agent-scripts-library-permissions](response-permissions/agent-scripts-library-permissions "mention") +* [live-terminal-permissions](response-permissions/live-terminal-permissions "mention")
-
▸ ▾ Action Center permissions modified +4 −0
xsiam/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/response-permissions/action-center-permissionsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,8 +1,12 @@---description: Manage access to Cortex XSIAM endpoint response actions and action history.---# Action Center permissions# Action Center permissionsAction Center permissionsAction Center permissionsIn the Action Center, you can initiate and monitor actions on your endpoints. You can limit access to the Action Center (Investigation & Response → Response → Action Center) and response actions (outside the Action Center). When you select View/Edit, you can set additional permissions.In the Action Center, you can initiate and monitor actions on your endpoints. You can limit access to the Action Center (Investigation & Response → Response → Action Center) and response actions (outside the Action Center). When you select View/Edit, you can set additional permissions.For more information, see Overview of the Action Center.For more information, see Overview of the Action Center.Show markdown source
@@ -1,8 +1,12 @@ +--- +description: Manage access to Cortex XSIAM endpoint response actions and action history. +--- + # Action Center permissions **Action Center permissions** In the Action Center, you can initiate and monitor actions on your endpoints. You can limit access to the Action Center (**Investigation & Response** → **Response** → **Action Center**) and response actions (outside the Action Center). When you select View/Edit, you can set additional permissions. For more information, see [Overview of the Action Center](../../../../detect-investigate-and-respond-to-threats/investigation-and-response/investigate-endpoints/overview-of-the-action-center).
-
▸ ▾ Agent Scripts Library permissions modified +9 −5
xsiam/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/response-permissions/agent-scripts-library-permissionsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,17 +1,21 @@---description: Manage Cortex XSIAM endpoint scripts for response, collection, and automation.---# Agent Scripts Library permissions# Agent Scripts Library permissionsThe Agents Script Library in the Action Center (Investigation & Response → Response → Action Center → Agent Script Library) enables security teams to create, manage, and execute Python scripts on endpoints for response actions, forensic collection, and custom automation.The Agents Script Library in the Action Center (Investigation & Response → Response → Action Center → Agent Script Library) enables security teams to create, manage, and execute Python scripts on endpoints for response actions, forensic collection, and custom automation.Permission│Description│Roles ExamplePermission│Description│Roles Example| ---------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------- || ---------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ----------------------------------------------------------------------------------------------------------------- |None│No access to the Agent Script Library. Users cannot run scripts on endpoints, access script execution history, create, edit, or delete scripts.│None│No access to the Agent Script Library. Users cannot run scripts on endpoints, access script execution history, create, edit, or delete scripts.│View│Users can access the Agent Script Library and view the script list, details, and code. Download the script code and definitions file and view the script history and results.│SOC Analyst Tier-1: Should have visibility into scripts and execution history, but no execution capabilities.View│Users can access the Agent Script Library and view the script list, details, and code. Download the script code and definitions file and view the script history and results.│SOC Analyst Tier-1: Should have visibility into scripts and execution history, but no execution capabilities.View/Edit│When set to View/Edit, the following action checkboxes become available:- Run Standard Script
- Run High Risk Script
- Script Configurations
View/Edit│When set to View/Edit, the following action checkboxes become available:
- Run Standard Script
- Run High Risk Script
- Script Configurations
Agent Script Sub-permissionsAgent Script Sub-permissionsSub-permission│Description│Roles ExampleSub-permission│Description│Roles Example| --------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------- || --------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------- |Run Standard Scripts│Enables execution of standard scripts, which are lower-risk operations that don't make significant system changes, such as data collection, log retrieval, or read-only queries.
- Checked: Full access to run standard scripts in the Action Center (where the Outcome column is set to Standard), when defining an action (select Run Endpoint Script), Agent Management, and can rerun standard script executions and use interactive script mode for standard scripts.
- Unchecked: Can view standard scripts in the Agent Script Library, but cannot execute standard scripts.
Run Standard Scripts│Enables execution of standard scripts, which are lower-risk operations that don't make significant system changes, such as data collection, log retrieval, or read-only queries.
- Checked: Full access to run standard scripts in the Action Center (where the Outcome column is set to Standard), when defining an action (select Run Endpoint Script), Agent Management, and can rerun standard script executions and use interactive script mode for standard scripts.
- Unchecked: Can view standard scripts in the Agent Script Library, but cannot execute standard scripts.
Run High-Risk Scripts│Enables execution of scripts marked as High-Risk, which can make significant system changes, including file modifications, process termination, registry changes, or system configuration alterations. These scripts require elevated permissions due to their potential impact.
- Checked: Full access to run high-risk scripts in the Action Center (where the Outcome column is set to High-Risk), when defining an action (select Run Endpoint Script), Agent Management, and can rerun High-Risk script executions and use interactive script mode for standard scripts.
- Unchecked: Can view high-risk scripts in the Agent Script Library, but cannot execute standard scripts.
│SOC Tier-3 Analysts, Security Engineers, and Threat Hunters.Tip
Consider adding Run Standard Scripts. High-risk scripts permission is typically granted alongside standard scripts.
Run High-Risk Scripts│Enables execution of scripts marked as High-Risk, which can make significant system changes, including file modifications, process termination, registry changes, or system configuration alterations. These scripts require elevated permissions due to their potential impact.
- Checked: Full access to run high-risk scripts in the Action Center (where the Outcome column is set to High-Risk), when defining an action (select Run Endpoint Script), Agent Management, and can rerun High-Risk script executions and use interactive script mode for standard scripts.
- Unchecked: Can view high-risk scripts in the Agent Script Library, but cannot execute standard scripts.
│SOC Tier-3 Analysts, Security Engineers, and Threat Hunters.Tip
Consider adding Run Standard Scripts. High-risk scripts permission is typically granted alongside standard scripts.
Script Configurations│Controls the ability to create, edit, clone, and delete scripts in the Agents Script Library. This is separate from the ability to run scripts.
Checked: Full script management capabilities, including creating, editing, deleting, and saving a script
Note
Only local scripts (created in the tenant) can be edited or deleted. Scripts from content packs can only be viewed or copied.
- Unchecked: Can only view and download scripts.
Script Configurations│Controls the ability to create, edit, clone, and delete scripts in the Agents Script Library. This is separate from the ability to run scripts.
Checked: Full script management capabilities, including creating, editing, deleting, and saving a script
Note
Only local scripts (created in the tenant) can be edited or deleted. Scripts from content packs can only be viewed or copied.
- Unchecked: Can only view and download scripts.
Show markdown source
@@ -1,17 +1,21 @@ +--- +description: Manage Cortex XSIAM endpoint scripts for response, collection, and automation. +--- + # Agent Scripts Library permissions The Agents Script Library in the Action Center (**Investigation & Response** → **Response** → **Action Center** → **Agent Script Library**) enables security teams to create, manage, and execute Python scripts on endpoints for response actions, forensic collection, and custom automation. -| Permission | Description | Roles Example | -| ---------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------- | -| None | No access to the Agent Script Library. Users cannot run scripts on endpoints, access script execution history, create, edit, or delete scripts. | | -| View | Users can access the Agent Script Library and view the script list, details, and code. Download the script code and definitions file and view the script history and results. | SOC Analyst Tier-1: Should have visibility into scripts and execution history, but no execution capabilities. | -| View/Edit | <p>When set to <strong>View/Edit</strong>, the following action checkboxes become available:</p><ul><li>Run Standard Script</li><li>Run High Risk Script</li><li>Script Configurations</li></ul><p></p> | SOC Tier 2 and 3 Analysts, Threat Hunters, and Security Engineers should have full access with granular controls. | +| Permission | Description | Roles Example | +| ---------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ----------------------------------------------------------------------------------------------------------------- | +| None | No access to the Agent Script Library. Users cannot run scripts on endpoints, access script execution history, create, edit, or delete scripts. | | +| View | Users can access the Agent Script Library and view the script list, details, and code. Download the script code and definitions file and view the script history and results. | SOC Analyst Tier-1: Should have visibility into scripts and execution history, but no execution capabilities. | +| View/Edit | <p>When set to <strong>View/Edit</strong>, the following action checkboxes become available:</p><ul><li>Run Standard Script</li><li>Run High Risk Script</li><li>Script Configurations</li></ul> | SOC Tier 2 and 3 Analysts, Threat Hunters, and Security Engineers should have full access with granular controls. | Agent Script Sub-permissions | Sub-permission | Description | Roles Example | | --------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------- | | Run Standard Scripts | <p>Enables execution of standard scripts, which are lower-risk operations that don't make significant system changes, such as data collection, log retrieval, or read-only queries.</p><ul><li>Checked: Full access to run standard scripts in the Action Center (where the <strong>Outcome</strong> column is set to <strong>Standard</strong>), when defining an action (select <strong>Run Endpoint Script</strong>), Agent Management, and can rerun standard script executions and use interactive script mode for standard scripts.</li><li>Unchecked: Can view standard scripts in the Agent Script Library, but cannot execute standard scripts.</li></ul> | SOC Tier 2 and 3 Analysts, Security Engineers, Threat Hunters. | | Run High-Risk Scripts | <p>Enables execution of scripts marked as High-Risk, which can make significant system changes, including file modifications, process termination, registry changes, or system configuration alterations. These scripts require elevated permissions due to their potential impact.</p><ul><li>Checked: Full access to run high-risk scripts in the Action Center (where the <strong>Outcome</strong> column is set to <strong>High-Risk</strong>), when defining an action (select <strong>Run Endpoint Script</strong>), Agent Management, and can rerun High-Risk script executions and use interactive script mode for standard scripts.</li><li>Unchecked: Can view high-risk scripts in the Agent Script Library, but cannot execute standard scripts.</li></ul><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Tip</strong></p><p>Consider adding Run Standard Scripts. High-risk scripts permission is typically granted alongside standard scripts.</p></div> | SOC Tier-3 Analysts, Security Engineers, and Threat Hunters. | | Script Configurations | <p>Controls the ability to create, edit, clone, and delete scripts in the Agents Script Library. This is separate from the ability to run scripts.</p><ul><li><p>Checked: Full script management capabilities, including creating, editing, deleting, and saving a script</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>Only local scripts (created in the tenant) can be edited or deleted. Scripts from content packs can only be viewed or copied.</p></div></li><li>Unchecked: Can only view and download scripts.</li></ul> | Security Engineer |
-
▸ ▾ EDL permissions modified +6 −0
xsiam/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/response-permissions/edl-permissionsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,8 +1,14 @@---description: >-Manage Cortex XSIAM External Dynamic Lists for firewall-enforced threatblocking.---# EDL permissions# EDL permissionsEDL (External Dynamic List) enables security teams to:EDL (External Dynamic List) enables security teams to:• Add IP Addresses and Domains to Dynamic Lists - Create lists of malicious or suspicious IPs/domains• Add IP Addresses and Domains to Dynamic Lists - Create lists of malicious or suspicious IPs/domains• Integrate with Palo Alto Networks Firewalls - EDL lists are automatically synced and enforceable on PANW firewalls.• Integrate with Palo Alto Networks Firewalls - EDL lists are automatically synced and enforceable on PANW firewalls.• Block Malicious Traffic - Firewalls can use EDL to block traffic to/from listed entities• Block Malicious Traffic - Firewalls can use EDL to block traffic to/from listed entities• Centralized Threat Response - Manage blocklists from a single location across your security infrastructure• Centralized Threat Response - Manage blocklists from a single location across your security infrastructureShow markdown source
@@ -1,8 +1,14 @@ +--- +description: >- + Manage Cortex XSIAM External Dynamic Lists for firewall-enforced threat + blocking. +--- + # EDL permissions EDL (External Dynamic List) enables security teams to: * Add IP Addresses and Domains to Dynamic Lists - Create lists of malicious or suspicious IPs/domains * Integrate with Palo Alto Networks Firewalls - EDL lists are automatically synced and enforceable on PANW firewalls. * Block Malicious Traffic - Firewalls can use EDL to block traffic to/from listed entities * Centralized Threat Response - Manage blocklists from a single location across your security infrastructure
-
▸ ▾ Live Terminal permissions modified +6 −0
xsiam/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/response-permissions/live-terminal-permissionsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,8 +1,14 @@---description: >-Manage Cortex XSIAM interactive endpoint shell access for investigation andremediation.---# Live Terminal permissions# Live Terminal permissionsLive Terminal enables security teams to establish real-time interactive shell sessions with endpoints for investigation, forensic analysis, and remediation activities.Live Terminal enables security teams to establish real-time interactive shell sessions with endpoints for investigation, forensic analysis, and remediation activities.Permission│Description│Roles ExamplePermission│Description│Roles Example| ---------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- || ---------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |None│No access to Live Terminal│SOC Tier-1 Analyst: Initial triage role - should not have direct endpoint shell access. Risk of accidental damage or evidence tampering. Requires advanced skills they may not have.
None│No access to Live Terminal│SOC Tier-1 Analyst: Initial triage role - should not have direct endpoint shell access. Risk of accidental damage or evidence tampering. Requires advanced skills they may not have.
View/Edit│Full access to the Live Terminal Investigation & Response → Response → Live Terminal, and to start a Live Terminal in all menus such as Casuality View, Asset View, Case View, and Broker VM. Users can do the following:
- Initiate terminal sessions
- File Explorer (browse, upload, download, delete files)
- Task Manager (view, terminate processes)
- Command Line (CMD, PowerShell, Python)
- All terminal capabilities
- SOC Tier 2 and 3 Analysts: Perform deeper investigation needing direct endpoint access for evidence collection, process analysis, and targeted remediation.
- Threat Hunter: Needs direct endpoint access to investigate suspicious activity, collect artifacts, analyze processes, and validate threat hypotheses. Core hunting tool.
- Security Engineer: Troubleshoots agent issues, tests endpoint configurations, validates security controls, and supports complex case response.
View/Edit│Full access to the Live Terminal Investigation & Response → Response → Live Terminal, and to start a Live Terminal in all menus such as Casuality View, Asset View, Case View, and Broker VM. Users can do the following:
- Initiate terminal sessions
- File Explorer (browse, upload, download, delete files)
- Task Manager (view, terminate processes)
- Command Line (CMD, PowerShell, Python)
- All terminal capabilities
- SOC Tier 2 and 3 Analysts: Perform deeper investigation needing direct endpoint access for evidence collection, process analysis, and targeted remediation.
- Threat Hunter: Needs direct endpoint access to investigate suspicious activity, collect artifacts, analyze processes, and validate threat hypotheses. Core hunting tool.
- Security Engineer: Troubleshoots agent issues, tests endpoint configurations, validates security controls, and supports complex case response.
Show markdown source
@@ -1,8 +1,14 @@ +--- +description: >- + Manage Cortex XSIAM interactive endpoint shell access for investigation and + remediation. +--- + # Live Terminal permissions Live Terminal enables security teams to establish real-time interactive shell sessions with endpoints for investigation, forensic analysis, and remediation activities. | Permission | Description | Roles Example | | ---------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | None | No access to Live Terminal | <p>SOC Tier-1 Analyst: Initial triage role - should not have direct endpoint shell access. Risk of accidental damage or evidence tampering. Requires advanced skills they may not have</p><p>.</p> | | View/Edit | <p>Full access to the Live Terminal <strong>Investigation & Response</strong> → <strong>Response</strong> → <strong>Live Terminal</strong>, and to start a Live Terminal in all menus such as Casuality View, Asset View, Case View, and Broker VM. Users can do the following:</p><ul><li>Initiate terminal sessions</li><li>File Explorer (browse, upload, download, delete files)</li><li>Task Manager (view, terminate processes)</li><li>Command Line (CMD, PowerShell, Python)</li><li>All terminal capabilities</li></ul> | <ul><li>SOC Tier 2 and 3 Analysts: Perform deeper investigation needing direct endpoint access for evidence collection, process analysis, and targeted remediation.</li><li>Threat Hunter: Needs direct endpoint access to investigate suspicious activity, collect artifacts, analyze processes, and validate threat hypotheses. Core hunting tool.</li><li>Security Engineer: Troubleshoots agent issues, tests endpoint configurations, validates security controls, and supports complex case response.</li></ul> |
-
▸ ▾ Search permissions modified +14 −4
xsiam/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/search-permissionsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,20 @@---description: >-Configure access to threat hunting, query, and forensic investigation tools inCortex XSIAM.---# Search permissions# Search permissionsConfigure access to threat hunting, querying, and forensic data collection tools, including the Query Library, Query Center, Forensics, Host Insights, and Graph Search.Configure access to threat hunting, querying, and forensic data collection tools, including the Query Library, Query Center, Forensics, Host Insights, and Graph Search.hint warning• query-library-permissions### Caution• query-center-permissions• forensics-permissions• host-insights-permissions• graph-search-permissions• Dataset Access (SBAC) Requirement: Even with full Query Center access, queries will return empty results or errors if the user lacks the specific dataset permissions (configured per dataset).hint warning• Query Library/Center: If you want users to execute and schedule queries from the Query Library, they must have View/Edit permission in the Query Center. To save queries directly from the Query Center to the Library, they need View/Edit in the Query Library.• Dataset Access (SBAC) Requirement: Even with full Query Center access, queries will return empty results or errors if the user lacks the specific dataset permissions (configured per dataset).• Query Library/Center: If you want users to execute and schedule queries from the Query Library, they must have View/Edit permission in the Query Center. To save queries directly from the Query Center to the Library, they need View/Edit in the Query Library.endhintendhintShow markdown source
@@ -1,10 +1,20 @@ +--- +description: >- + Configure access to threat hunting, query, and forensic investigation tools in + Cortex XSIAM. +--- + # Search permissions Configure access to threat hunting, querying, and forensic data collection tools, including the Query Library, Query Center, Forensics, Host Insights, and Graph Search. -{% hint style="warning" %} -### Caution +* [query-library-permissions](search-permissions/query-library-permissions "mention") +* [query-center-permissions](search-permissions/query-center-permissions "mention") +* [forensics-permissions](search-permissions/forensics-permissions "mention") +* [host-insights-permissions](search-permissions/host-insights-permissions "mention") +* [graph-search-permissions](search-permissions/graph-search-permissions "mention") -* Dataset Access (SBAC) Requirement: Even with full Query Center access, queries will return empty results or errors if the user lacks the specific dataset permissions (configured per dataset). -* Query Library/Center: If you want users to execute and schedule queries from the Query Library, they must have View/Edit permission in the Query Center. To save queries directly from the Query Center to the Library, they need View/Edit in the Query Library. +{% hint style="warning" %} +- Dataset Access (SBAC) Requirement: Even with full Query Center access, queries will return empty results or errors if the user lacks the specific dataset permissions (configured per dataset). +- Query Library/Center: If you want users to execute and schedule queries from the Query Library, they must have View/Edit permission in the Query Center. To save queries directly from the Query Center to the Library, they need View/Edit in the Query Library. {% endhint %} -
▸ ▾ Forensics permissions modified +6 −0
xsiam/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/search-permissions/forensics-permissionsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,8 +1,14 @@---description: >-Manage access to Cortex XSIAM forensic investigations, collections, and threathunts.---# Forensics permissions# Forensics permissionsControls access to Forensics (Investigation & Response → Forensics). Forensic investigations streamline your case response, data collection, threat hunting, and analysis of your endpoints.Controls access to Forensics (Investigation & Response → Forensics). Forensic investigations streamline your case response, data collection, threat hunting, and analysis of your endpoints.hint infohint info### Notice### NoticeYou need the Forensics add-on to view Forensic investigations.You need the Forensics add-on to view Forensic investigations.Show markdown source
@@ -1,8 +1,14 @@ +--- +description: >- + Manage access to Cortex XSIAM forensic investigations, collections, and threat + hunts. +--- + # Forensics permissions Controls access to Forensics (**Investigation & Response** → **Forensics**). Forensic investigations streamline your case response, data collection, threat hunting, and analysis of your endpoints. {% hint style="info" %} ### Notice You need the Forensics add-on to view Forensic investigations. -
▸ ▾ Graph Search permissions modified +6 −0
xsiam/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/search-permissions/graph-search-permissionsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,8 +1,14 @@---description: >-Manage access to Cortex XSIAM's Graph Search for cloud assets and securityfindings.---# Graph Search permissions# Graph Search permissionsLimits access to Graph Search Investigation & Response → Search → Query Builder → Graph Search), which enables visual exploration of cloud asset relationships, configurations, and security findings through an interactive graph interface, such as discovering cloud asset relationships, investigating security findings, and analyzing effective permissions.Limits access to Graph Search Investigation & Response → Search → Query Builder → Graph Search), which enables visual exploration of cloud asset relationships, configurations, and security findings through an interactive graph interface, such as discovering cloud asset relationships, investigating security findings, and analyzing effective permissions.hint infohint info### Notice### NoticeGraph Search requires a Cloud Posture Security, Cloud Runtime Security, or Cortex XSIAM Premium license.Graph Search requires a Cloud Posture Security, Cloud Runtime Security, or Cortex XSIAM Premium license.Show markdown source
@@ -1,8 +1,14 @@ +--- +description: >- + Manage access to Cortex XSIAM's Graph Search for cloud assets and security + findings. +--- + # Graph Search permissions Limits access to Graph Search **Investigation & Response** → **Search** → **Query Builder** → **Graph Search)**, which enables visual exploration of cloud asset relationships, configurations, and security findings through an interactive graph interface, such as discovering cloud asset relationships, investigating security findings, and analyzing effective permissions. {% hint style="info" %} ### Notice Graph Search requires a Cloud Posture Security, Cloud Runtime Security, or Cortex XSIAM Premium license. -
▸ ▾ Host Insights permissions modified +6 −0
xsiam/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/search-permissions/host-insights-permissionsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,8 +1,14 @@---description: >-Manage access to Cortex XSIAM's endpoint inventory, host details, and hygienedata.---# Host Insights permissions# Host Insights permissionsLimits access to Host Insights/Inventory (Inventory → Endpoints → Host Insights)), which enables you to gain visibility and inventory into the business and IT operational data on all your endpoints. For more information, see Host Inventory.Limits access to Host Insights/Inventory (Inventory → Endpoints → Host Insights)), which enables you to gain visibility and inventory into the business and IT operational data on all your endpoints. For more information, see Host Inventory.Unlike Forensics, which is a point-in-time snapshot, Host Insights is designed for broad fleet visibility and hygiene. It covers:Unlike Forensics, which is a point-in-time snapshot, Host Insights is designed for broad fleet visibility and hygiene. It covers:• Host Inventory: Operating system details, installed software, local user accounts, and listening ports.• Host Inventory: Operating system details, installed software, local user accounts, and listening ports.• Searchability: The ability to hunt for "at-risk" systems across the environment (e.g., finding every server running an outdated version of Java).• Searchability: The ability to hunt for "at-risk" systems across the environment (e.g., finding every server running an outdated version of Java).Show markdown source
@@ -1,8 +1,14 @@ +--- +description: >- + Manage access to Cortex XSIAM's endpoint inventory, host details, and hygiene + data. +--- + # Host Insights permissions Limits access to Host Insights/Inventory (**Inventory** → **Endpoints** → **Host Insights)**), which enables you to gain visibility and inventory into the business and IT operational data on all your endpoints. For more information, see [Host Inventory](../../../../protect-your-endpoints/endpoint-security/install-and-manage-endpoints/harden-endpoint-security/host-inventory). Unlike Forensics, which is a point-in-time snapshot, Host Insights is designed for broad fleet visibility and hygiene. It covers: * Host Inventory: Operating system details, installed software, local user accounts, and listening ports. * Searchability: The ability to hunt for "at-risk" systems across the environment (e.g., finding every server running an outdated version of Java).
-
▸ ▾ Query Center permissions modified +4 −0
xsiam/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/search-permissions/query-center-permissionsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,8 +1,12 @@---description: Manage access to write, run, schedule, and export XQL queries in Cortex XSIAM.---# Query Center permissions# Query Center permissionsControls access to the Query Center (under Investigation & Response → Search), which is the primary interface for writing, executing, and managing XQL queries in Cortex XSIAM. It is the core investigation tool that enables security analysts to search across all ingested data using a powerful query language. Key capabilities:Controls access to the Query Center (under Investigation & Response → Search), which is the primary interface for writing, executing, and managing XQL queries in Cortex XSIAM. It is the core investigation tool that enables security analysts to search across all ingested data using a powerful query language. Key capabilities:• Write and execute XQL queries against any ingested dataset.• Write and execute XQL queries against any ingested dataset.• View query execution history and results.• View query execution history and results.• Schedule recurring queries• Schedule recurring queries• Export query results• Export query resultsShow markdown source
@@ -1,8 +1,12 @@ +--- +description: Manage access to write, run, schedule, and export XQL queries in Cortex XSIAM. +--- + # Query Center permissions Controls access to the Query Center (under **Investigation & Response** → **Search**), which is the primary interface for writing, executing, and managing XQL queries in Cortex XSIAM. It is the core investigation tool that enables security analysts to search across all ingested data using a powerful query language. Key capabilities: * Write and execute XQL queries against any ingested dataset. * View query execution history and results. * Schedule recurring queries * Export query results
-
▸ ▾ Query Library permissions modified +4 −0
xsiam/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/search-permissions/query-library-permissionsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,8 +1,12 @@---description: Manage access to saved XQL queries in Cortex XSIAM's Query Library.---# Query Library permissions# Query Library permissionsControls access to the Query Library, which is a repository of saved XQL queries within Cortex XSIAM. It allows users to save, organize, share, and reuse XQL queries across the team. Key capabilities include:Controls access to the Query Library, which is a repository of saved XQL queries within Cortex XSIAM. It allows users to save, organize, share, and reuse XQL queries across the team. Key capabilities include:• Browse, search, and filter saved queries by name, labels, and type• Browse, search, and filter saved queries by name, labels, and type• Save new queries from XQL Search results• Save new queries from XQL Search results• Share queries with specific users or make them public• Share queries with specific users or make them publicShow markdown source
@@ -1,8 +1,12 @@ +--- +description: Manage access to saved XQL queries in Cortex XSIAM's Query Library. +--- + # Query Library permissions Controls access to the Query Library, which is a repository of saved XQL queries within Cortex XSIAM. It allows users to save, organize, share, and reuse XQL queries across the team. Key capabilities include: * Browse, search, and filter saved queries by name, labels, and type * Save new queries from XQL Search results * Share queries with specific users or make them public
-
▸ ▾ Jupyter and Observability apps permissions modified +4 −4
xsiam/reference-and-developer-docs/role-based-access-control/jupyter-and-observability-apps-permissionsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -7,66 +7,66 @@ description: Configure permissions to use Jupyter and Observability applicationsThe following permissions enable users to use Jupyter and Observability applications.The following permissions enable users to use Jupyter and Observability applications.hint warninghint warning### Caution### CautionUsage and management: The permissions allow users to use and access existing application instances. If a user needs to manage, install, configure, or delete application instances, they must be granted the separate Apps permission under the Configurations menu. For more information, see Apps - Instance permissions.Usage and management: The permissions allow users to use and access existing application instances. If a user needs to manage, install, configure, or delete application instances, they must be granted the separate Apps permission under the Configurations menu. For more information, see Apps - Instance permissions.endhintendhintJupyter Notebook permissions### Jupyter Notebook permissionsAn interactive notebook environment for creating and running Python-based analyses and automations. Jupyter Notebooks let you explore security data, build custom analytics, and prototype detections.An interactive notebook environment for creating and running Python-based analyses and automations. Jupyter Notebooks let you explore security data, build custom analytics, and prototype detections.hint warninghint warning### Caution### CautionJupyter Data Access (SBAC): Granting access to Jupyter does not bypass dataset restrictions. Users must have the appropriate Scope-Based Access Control (SBAC) dataset permissions to query specific data via the Cortex SDK within their notebooks.Jupyter Data Access (SBAC): Granting access to Jupyter does not bypass dataset restrictions. Users must have the appropriate Scope-Based Access Control (SBAC) dataset permissions to query specific data via the Cortex SDK within their notebooks.endhintendhintFor more information, see Notebooks.For more information, see Notebooks.Component│Description│Roles ExampleComponent│Description│Roles Example| --------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- || --------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |None│No access to Jupyter Notebooks.│- SOC Analyst Tier-1: Focus on issue triage.
- SOC Analyst Tier-2: Standard investigation tools are sufficient. Consider View/Edit if the team performs advanced analysis.
None│No access to Jupyter Notebooks.│- SOC Analyst Tier-1: Focus on issue triage.
- SOC Analyst Tier-2: Standard investigation tools are sufficient. Consider View/Edit if the team performs advanced analysis.
View/Edit│Full access to Jupyter Notebooks, including installing, creating, editing, saving, and exporting notebooks. You can also execute Python code and access datasets.│- SOC Analyst Tier-3: Advanced investigations often require custom analysis, data exploration, and ad-hoc queries.
- Threat Hunter: Critical - Notebooks are essential for hypothesis-driven hunting, custom analytics, and data exploration.
- Security Engineer: Develops custom detection logic, automation scripts, and analysis tools.
View/Edit│Full access to Jupyter Notebooks, including installing, creating, editing, saving, and exporting notebooks. You can also execute Python code and access datasets.│- SOC Analyst Tier-3: Advanced investigations often require custom analysis, data exploration, and ad-hoc queries.
- Threat Hunter: Critical - Notebooks are essential for hypothesis-driven hunting, custom analytics, and data exploration.
- Security Engineer: Develops custom detection logic, automation scripts, and analysis tools.
Jupyter Notebook - required and recommended permissions#### Jupyter Notebook - required and recommended permissionsConsider adding the following permissions:Consider adding the following permissions:Permission│Permission Level│ReasonPermission│Permission Level│Reason| ------------------- | -------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- || ------------------- | -------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |Query Center│View or View/Edit│- View: Required to run XQL queries from notebooks via Cortex SDK.
- View/Edit: Strongly recommended to save and manage queries created in notebooks.
Query Center│View or View/Edit│- View: Required to run XQL queries from notebooks via Cortex SDK.
- View/Edit: Strongly recommended to save and manage queries created in notebooks.
Dataset Permissions│N/a│Various. Control which datasets are queryable from notebooks.Dataset Permissions│N/a│Various. Control which datasets are queryable from notebooks.Query Library│Enabled│Strongly recommended to access and save queries.Query Library│Enabled│Strongly recommended to access and save queries.Cases & Issues│View or View/Edit│- View: Strongly recommended to view cases and issues data for correlation in notebooks.
- View/Edit: Recommended to create/update cases from notebook analysis.
Cases & Issues│View or View/Edit│- View: Strongly recommended to view cases and issues data for correlation in notebooks.
- View/Edit: Recommended to create/update cases from notebook analysis.
Threat Intel│View│Strongly recommended to enrich data with threat intelligence in notebooks.Threat Intel│View│Strongly recommended to enrich data with threat intelligence in notebooks.Playbooks│Enabled with checkboxes selected│Enabled with Playbooks and Create Playbooks selected. Recommended to reference and develop playbooks from notebooks.Playbooks│Enabled with checkboxes selected│Enabled with Playbooks and Create Playbooks selected. Recommended to reference and develop playbooks from notebooks.Scripts│Enabled with checkboxes selected│Enabled with Scripts and Create Scripts selected. Recommended to reference and develop scripts alongside notebooks.Scripts│Enabled with checkboxes selected│Enabled with Scripts and Create Scripts selected. Recommended to reference and develop scripts alongside notebooks.Detection Rules│View/Edit│Recommended to view and create detection rules for analysis.Detection Rules│View/Edit│Recommended to view and create detection rules for analysis.Forensics│View/Edit│Recommended to access the forensics data for analysis and initiate forensic action.Forensics│View/Edit│Recommended to access the forensics data for analysis and initiate forensic action.Action Center│View/Edit│Recommended to view and execute response actions.Action Center│View/Edit│Recommended to view and execute response actions.Observability### ObservabilityObservability provides infrastructure and application monitoring capabilities within Cortex XSIAM, leveraging Prometheus-based metrics collection, alerting, and visualization through Grafana integration.Observability provides infrastructure and application monitoring capabilities within Cortex XSIAM, leveraging Prometheus-based metrics collection, alerting, and visualization through Grafana integration.hint infohint info### Note### NoteObservability is a Beta feature and is still subject to changes. To enable the feature in your tenant, contact your Customer Support Team.Observability is a Beta feature and is still subject to changes. To enable the feature in your tenant, contact your Customer Support Team.endhintendhintComponent│Description│Roles ExampleComponent│Description│Roles Example| --------- | --------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------- || --------- | --------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------- |None│No access to Observability.│SOC Analyst Tier-1, 2, and 3, and Threat Hunters who do not need tool development.None│No access to Observability.│SOC Analyst Tier-1, 2, and 3, and Threat Hunters who do not need tool development.View/Edit│Full access to Observability, including access to the Observability interface, View Prometheus UI, and Alert Manager.│Security Engineers: Require full access for tool development and configuration.View/Edit│Full access to Observability, including access to the Observability interface, View Prometheus UI, and Alert Manager.│Security Engineers: Require full access for tool development and configuration.Observability - required and recommended permissions#### Observability - required and recommended permissionsConsider adding the following permissions:Consider adding the following permissions:Permission│Permission Level│ReasonPermission│Permission Level│Reason| ------------------- | ----------------- | ------------------------------------------------------------------------------------------------------------------------------ || ------------------- | ----------------- | ------------------------------------------------------------------------------------------------------------------------------ |Broker VM│View or View/Edit│Strongly recommended to view Broker VMs hosting Observability collectors and configure Observability collectors on Broker VMs.Broker VM│View or View/Edit│Strongly recommended to view Broker VMs hosting Observability collectors and configure Observability collectors on Broker VMs.Alert Notifications│View/Edit│Recommended to configure alert notifications from Observability alerts.Alert Notifications│View/Edit│Recommended to configure alert notifications from Observability alerts.Data Sources│View/Edit│Recommended to manage data sources that feed into Observability.Data Sources│View/Edit│Recommended to manage data sources that feed into Observability.Show markdown source
@@ -7,66 +7,66 @@ description: Configure permissions to use Jupyter and Observability applications The following permissions enable users to use Jupyter and Observability applications. {% hint style="warning" %} ### Caution Usage and management: The permissions allow users to use and access existing application instances. If a user needs to manage, install, configure, or delete application instances, they must be granted the separate Apps permission under the Configurations menu. For more information, see [Apps - Instance permissions](../configuration-permissions#UUID-6cdf81f3-ce41-0fe9-5b3b-08c9f7ecd29f). {% endhint %} -**Jupyter Notebook permissions** +### **Jupyter Notebook permissions** An interactive notebook environment for creating and running Python-based analyses and automations. Jupyter Notebooks let you explore security data, build custom analytics, and prototype detections. {% hint style="warning" %} ### Caution Jupyter Data Access (SBAC): Granting access to Jupyter does not bypass dataset restrictions. Users must have the appropriate Scope-Based Access Control (SBAC) dataset permissions to query specific data via the Cortex SDK within their notebooks. {% endhint %} For more information, see [Notebooks](../../detect-investigate-and-respond-to-threats/investigation-and-response/notebooks). | Component | Description | Roles Example | | --------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | None | No access to Jupyter Notebooks. | <ul><li>SOC Analyst Tier-1: Focus on issue triage.</li><li>SOC Analyst Tier-2: Standard investigation tools are sufficient. Consider View/Edit if the team performs advanced analysis.</li></ul> | | View/Edit | Full access to Jupyter Notebooks, including installing, creating, editing, saving, and exporting notebooks. You can also execute Python code and access datasets. | <ul><li>SOC Analyst Tier-3: Advanced investigations often require custom analysis, data exploration, and ad-hoc queries.</li><li>Threat Hunter: Critical - Notebooks are essential for hypothesis-driven hunting, custom analytics, and data exploration.</li><li>Security Engineer: Develops custom detection logic, automation scripts, and analysis tools.</li></ul> | -**Jupyter Notebook - required and recommended permissions** +#### **Jupyter Notebook - required and recommended permissions** Consider adding the following permissions: | Permission | Permission Level | Reason | | ------------------- | -------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | Query Center | View or View/Edit | <ul><li>View: Required to run XQL queries from notebooks via Cortex SDK.</li><li>View/Edit: Strongly recommended to save and manage queries created in notebooks.</li></ul> | | Dataset Permissions | N/a | Various. Control which datasets are queryable from notebooks. | | Query Library | Enabled | Strongly recommended to access and save queries. | | Cases & Issues | View or View/Edit | <ul><li>View: Strongly recommended to view cases and issues data for correlation in notebooks.</li><li>View/Edit: Recommended to create/update cases from notebook analysis.</li></ul> | | Threat Intel | View | Strongly recommended to enrich data with threat intelligence in notebooks. | | Playbooks | Enabled with checkboxes selected | Enabled with **Playbooks** and **Create Playbooks** selected. Recommended to reference and develop playbooks from notebooks. | | Scripts | Enabled with checkboxes selected | Enabled with **Scripts** and **Create Scripts** selected. Recommended to reference and develop scripts alongside notebooks. | | Detection Rules | View/Edit | Recommended to view and create detection rules for analysis. | | Forensics | View/Edit | Recommended to access the forensics data for analysis and initiate forensic action. | | Action Center | View/Edit | Recommended to view and execute response actions. | -**Observability** +### **Observability** Observability provides infrastructure and application monitoring capabilities within Cortex XSIAM, leveraging Prometheus-based metrics collection, alerting, and visualization through Grafana integration. {% hint style="info" %} ### Note Observability is a Beta feature and is still subject to changes. To enable the feature in your tenant, contact your Customer Support Team. {% endhint %} | Component | Description | Roles Example | | --------- | --------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------- | | None | No access to Observability. | SOC Analyst Tier-1, 2, and 3, and Threat Hunters who do not need tool development. | | View/Edit | Full access to Observability, including access to the Observability interface, View Prometheus UI, and Alert Manager. | Security Engineers: Require full access for tool development and configuration. | -**Observability - required and recommended permissions** +#### **Observability - required and recommended permissions** Consider adding the following permissions: | Permission | Permission Level | Reason | | ------------------- | ----------------- | ------------------------------------------------------------------------------------------------------------------------------ | | Broker VM | View or View/Edit | Strongly recommended to view Broker VMs hosting Observability collectors and configure Observability collectors on Broker VMs. | | Alert Notifications | View/Edit | Recommended to configure alert notifications from Observability alerts. | | Data Sources | View/Edit | Recommended to manage data sources that feed into Observability. | -
▸ ▾ Managed Services permissions modified +0 −4
xsiam/reference-and-developer-docs/role-based-access-control/managed-services-permissionsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,21 +1,17 @@------description: >-description: >-Configure access to Managed Services for Unit 42 Managed Threat Hunting andConfigure access to Managed Services for Unit 42 Managed Threat Hunting andManaged Detection and Response.Managed Detection and Response.------# Managed Services permissions# Managed Services permissionsControls access to the Managed Services page for the Unit 42 Managed Threat Hunting (MTH) and Managed Detection & Response (MDR).hint infohint info### NoticeRequires a Managed Threat Hunting or Managed Detection and Response license. The tenant must be paired as a managed service tenant.Requires a Managed Threat Hunting or Managed Detection and Response license. The tenant must be paired as a managed service tenant.endhintendhintThreadsThreadsThreads are a collaborative communication record between a managed service provider (Unit 42 Managed Threat Hunting or Managed Detection & Response) and your tenant. Each thread represents an operational report delivered by the provider to you, along with all associated collaboration artifacts.Threads are a collaborative communication record between a managed service provider (Unit 42 Managed Threat Hunting or Managed Detection & Response) and your tenant. Each thread represents an operational report delivered by the provider to you, along with all associated collaboration artifacts.The Threads permission controls whether a user can access the Managed Services page, where all threads are listed, and whether they can perform actions on those threads (update status, assign users, add/edit/delete comments, attach files).The Threads permission controls whether a user can access the Managed Services page, where all threads are listed, and whether they can perform actions on those threads (update status, assign users, add/edit/delete comments, attach files).Show markdown source
@@ -1,21 +1,17 @@ --- description: >- Configure access to Managed Services for Unit 42 Managed Threat Hunting and Managed Detection and Response. --- # Managed Services permissions -Controls access to the **Managed Services** page for the Unit 42 Managed Threat Hunting (MTH) and Managed Detection & Response (MDR). - {% hint style="info" %} -### Notice - Requires a Managed Threat Hunting or Managed Detection and Response license. The tenant must be paired as a managed service tenant. {% endhint %} **Threads** Threads are a collaborative communication record between a managed service provider (Unit 42 Managed Threat Hunting or Managed Detection & Response) and your tenant. Each thread represents an operational report delivered by the provider to you, along with all associated collaboration artifacts. The Threads permission controls whether a user can access the **Managed Services** page, where all threads are listed, and whether they can perform actions on those threads (update status, assign users, add/edit/delete comments, attach files). -
▸ ▾ Marketplace permissions modified +3 −1
xsiam/reference-and-developer-docs/role-based-access-control/marketplace-permissionsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,12 @@------description: Configure Marketplace permissions for RBAC.description: >-Control access to discover, install, and manage Marketplace content packs inCortex XSIAM.------# Marketplace permissions# Marketplace permissionsConfigure access to manage content packs in Marketplace.Configure access to manage content packs in Marketplace.Marketplace is the central hub for discovering, installing, and managing content packs in Cortex XSIAM. Content packs include integrations, playbooks, scripts, dashboards, and other automation content that extend capabilities. Installing a content pack is typically the first step; further configuration of the included integrations or credentials must be completed in the Configurations section.Marketplace is the central hub for discovering, installing, and managing content packs in Cortex XSIAM. Content packs include integrations, playbooks, scripts, dashboards, and other automation content that extend capabilities. Installing a content pack is typically the first step; further configuration of the included integrations or credentials must be completed in the Configurations section.Show markdown source
@@ -1,10 +1,12 @@ --- -description: Configure Marketplace permissions for RBAC. +description: >- + Control access to discover, install, and manage Marketplace content packs in + Cortex XSIAM. --- # Marketplace permissions Configure access to manage content packs in Marketplace. Marketplace is the central hub for discovering, installing, and managing content packs in Cortex XSIAM. Content packs include integrations, playbooks, scripts, dashboards, and other automation content that extend capabilities. Installing a content pack is typically the first step; further configuration of the included integrations or credentials must be completed in the Configurations section.
-
▸ ▾ Threat Management permissions modified +1 −1
xsiam/reference-and-developer-docs/role-based-access-control/threat-management-permissionsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@------description: Configure Detection Rules and Threat Intel permissions.description: Configure Detection Rules and Threat Intel permissions in Cortex XSIAM.------# Threat Management permissions# Threat Management permissionsThreat Management encompasses Detection rules and threat intelligence capabilities, providing security teams with tools to detect, investigate, and respond to threats.Threat Management encompasses Detection rules and threat intelligence capabilities, providing security teams with tools to detect, investigate, and respond to threats.hint warninghint warning### Caution### CautionShow markdown source
@@ -1,10 +1,10 @@ --- -description: Configure Detection Rules and Threat Intel permissions. +description: Configure Detection Rules and Threat Intel permissions in Cortex XSIAM. --- # Threat Management permissions Threat Management encompasses Detection rules and threat intelligence capabilities, providing security teams with tools to detect, investigate, and respond to threats. {% hint style="warning" %} ### Caution -
▸ ▾ Detection Rules permissions modified +1 −1
xsiam/reference-and-developer-docs/role-based-access-control/threat-management-permissions/detection-rules-permissionsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@------description: Configure Detection Rules permissions.description: Configure Detection Rules permissions in Cortex XSIAM.------# Detection Rules permissions# Detection Rules permissionsDetection Rules permissionsDetection Rules permissionsYou can limit permissions for Detection rules (Threat Management → Detection Rules), which include the following:You can limit permissions for Detection rules (Threat Management → Detection Rules), which include the following:Show markdown source
@@ -1,10 +1,10 @@ --- -description: Configure Detection Rules permissions. +description: Configure Detection Rules permissions in Cortex XSIAM. --- # Detection Rules permissions **Detection Rules permissions** You can limit permissions for Detection rules (**Threat Management** → **Detection Rules**), which include the following:
-
▸ ▾ Threat Intelligence permissions modified +1 −3
xsiam/reference-and-developer-docs/role-based-access-control/threat-management-permissions/threat-intelligence-permissionsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,16 +1,14 @@------description: Configure Threat Intelligence permissions.description: Configure Threat Intelligence permissions in Cortex XSIAM------# Threat Intelligence permissions# Threat Intelligence permissionsThreat Intelligence permissionsLocated under Threat Management → Threat Intelligence, these permissions govern how your organization interacts with indicators (IPs, URLs, Domains, Hashes) and intelligence feeds. It allows you to transform raw data from sources like Unit 42 or AlienVault into actionable security logic.Located under Threat Management → Threat Intelligence, these permissions govern how your organization interacts with indicators (IPs, URLs, Domains, Hashes) and intelligence feeds. It allows you to transform raw data from sources like Unit 42 or AlienVault into actionable security logic.hint infohint info### Notice### NoticeThe Extended Threat Intelligence feature requires the Cortex XSIAM Premium license or another XSIAM license with the Extended Threat Intelligence (XTI) add-on.The Extended Threat Intelligence feature requires the Cortex XSIAM Premium license or another XSIAM license with the Extended Threat Intelligence (XTI) add-on.The Threat Intelligence Management (TIM) requires the Threat Intelligence Management (TIM) license.The Threat Intelligence Management (TIM) requires the Threat Intelligence Management (TIM) license.Show markdown source
@@ -1,16 +1,14 @@ --- -description: Configure Threat Intelligence permissions. +description: Configure Threat Intelligence permissions in Cortex XSIAM --- # Threat Intelligence permissions -**Threat Intelligence permissions** - Located under **Threat Management** → **Threat Intelligence**, these permissions govern how your organization interacts with indicators (IPs, URLs, Domains, Hashes) and intelligence feeds. It allows you to transform raw data from sources like Unit 42 or AlienVault into actionable security logic. {% hint style="info" %} ### Notice The Extended Threat Intelligence feature requires the Cortex XSIAM Premium license or another XSIAM license with the Extended Threat Intelligence (XTI) add-on. The Threat Intelligence Management (TIM) requires the Threat Intelligence Management (TIM) license.