## Cohesity Helios Help ### Minimum Permission for Helios API user to generate APIKey To run the workflow, you need to pass the Helios API Key. The user that creates this APIKey must have the following privileges. * *Viewer Role*: This role enables the user to log in to Cohesity Helios and [create the APIKey.](https://developer.cohesity.com/docs/helios-getting-started) * *Manage Protection Groups and Manage Recovery*: This enables the user to get a clean snapshot and recover the VM to the latest known safe state. To know more about Cohesity Roles, go to [Cohesity Product Documentation](https://docs.cohesity.com/6_5_1/Web/UserGuide/Content/Dashboard/Admin/RoleManage.htm?tocpath=Administration%7CAccess%20Management%7CRoles%7C_____0#ManageRoles).