> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/user-management/manage-user-scope.md).

# Manage user scope

{% hint style="warning" %}

### Prerequisite

* Configuring user scopes in Cortex AgentiX Access Management requires **View/Edit** RBAC permissions for **Access Management** (under **Configurations**). Account Admin and Instance Administrator roles are granted this permission by default. For more information, see *Predefined user roles* in [Set up users and roles](/cortex-agentix/onboard-cortex-agentix/post-deployment-steps/set-up-users-and-roles.md).
* By default, **Enable Scope Based Access Control** is disabled in **Settings** → **Configurations** → **General** → **Server Settings**, and granular scoping is not enforced. Before enabling SBAC, we recommend that you first ensure that the users, user groups, and API Keys defined in Cortex AgentiX are granted the required access by assigning the relevant scopes.
  {% endhint %}

Review the following topics:

* [Set up users and roles](/cortex-agentix/onboard-cortex-agentix/post-deployment-steps/set-up-users-and-roles.md)
* [User group management](/cortex-agentix/configure-cortex-agentix/users-and-roles-management/user-group-management.md)
* [Assign user roles and groups](/cortex-agentix/configure-cortex-agentix/users-and-roles-management/user-management.md)
* [Manage user roles and access management](/cortex-agentix/configure-cortex-agentix/users-and-roles-management/roles-management.md)

<details>

<summary>What is SBAC?</summary>

Cortex AgentiX enables you to use Scope-Based Access Control (SBAC) in combination with Role-Based Access Control (RBAC) to define precise access controls according to your organization's security policies. While RBAC defines what a role can access and the actions that can be performed, SBAC determines the specific data and content displayed when accessing these areas and performing those actions.

Users with **Access Management** permission apply scopes to limit the cases and issues that users can be granted access to in Cortex AgentiX. For example, an Investigator role might have access to cases based on the RBAC permissions, but the SBAC granular scoping configuration could limit that investigator's view and control to only cases within a particular domain. This hybrid approach ensures scalability and granular control, significantly strengthening system security by ensuring only authorized users are granted access to the relevant data that the user requires for their designated role.

Granular scoping is configured in users, user groups, or API Keys according to the designated user role. Users are granted granular scoping access based on the user role assigned to them either in a user group or directly.

</details>

<details>

<summary>Things to consider before configuring SBAC</summary>

Before you begin setting Scope-Based Access Control (SBAC) granular scoping, consider the following information:

* SBAC is disabled by default, which means that users have access to all content and data in the areas they have access to according to the RBAC permissions defined in their role.
* To best address cases that span across all scopes, we recommend that there always be designated users with full access to all cases and issues.
* Some areas and features in Cortex AgentiX do not comply with SBAC. In these cases, use RBAC permissions to restrict access. For more information, see Functional areas.
* Respecting SBAC has some performance overhead which can cause the cases and issues tables to take more time to load.
* For reports, SBAC applies when a report is manually generated. Scheduled reports run in the scope of the user who created or last updated the report template. Be aware that once a report is generated, it can be shared with others; exercise caution when distributing reports, as recipients might not be authorized to view the data they contain.

</details>

<details>

<summary>Functional areas</summary>

### Functional areas respected

Scope-Based Access Control (SBAC) applies to the following functional areas in Cortex AgentiX:

{% hint style="info" %}
Important:

Some areas and features in Cortex AgentiX do not respect SBAC. In these cases, use RBAC permissions to restrict access.
{% endhint %}

| Functional Area         | Description                                                                         |
| ----------------------- | ----------------------------------------------------------------------------------- |
| Cases and issues tables | View and manage cases and issues and take actions in these tables.                  |
| Public APIs             | Public APIs that access cases and issues respect Scope-Based Access Control (SBAC). |

### SBAC not fully respected functional areas

Ensure that you review the points below that explain the main functional areas with limitations with respecting SBAC, so you can decide how to handle this in your tenant. A suggested action is provided when applicable.

* Automation Rules: Automation rules are executed using the full system scope. Users authorized to edit or run automation rules can configure the system to run scripts or playbooks that can interact with data across the entire system. It is recommended to allow users with full access to all assets to create and edit automation rules.
* Command Centers: Aggregate numbers in Command Centers can also sum up data that is not in the user scope. When pivoting from Command Centers to the Cases and Issues tables, these tables do respect SBAC. We recommend limiting the users who access Command Centers, and these users should be granted a broader scope. For all other users, disable access in RBAC settings (**Dashboards & Reports → Command Center Dashboards)**.
* Timeline widget: As a workaround, you can disable access through RBAC permissions by disabling Dashboards (**Dashboards & Reports → Dashboards**).
* Notification Center
* Drop-downs of cases and issues domains: Drop-downs of these domains display all domains.

</details>

<details>

<summary>How to configure granular scoping</summary>

Granular scoping is configured in users, user groups, or API keys, and applied to the user roles assigned. Users are then granted granular scoping access according to the user roles assigned to them in a user group or directly. The instructions below explain how to configure granular scoping according to Palo Alto Networks best practices.

Granular scoping is disabled and not enforced in Cortex AgentiX by default. Before enabling SBAC, we recommend that an administrator or a user with **Access Management** permissions first ensure that the users, user groups, and API Keys defined in Cortex AgentiX are granted the required access by assigning the relevant scopes. This user can then assign a scoping area to a Cortex AgentiX user (non-administrator), so the non-administrator user can manage only the specific scoping areas that are predefined within that scope.

Any changes made to the granular scoping of a user, user group, or API key are recorded on the **Management Audit Logs** page (**Settings → Management Audit Logs**). These events are categorized with the **Type** set to **Permissions** and the **Subtype** set to **Scope Edit**.

{% hint style="info" %}
Make sure to assign the required default granular scoping for users. This depends on the structure and divisions within your organization and the particular purpose of each organizational unit to which scoped users belong.
{% endhint %}

1. Ensure that you have the necessary administrator-level permissions.
2. Verify that the users, user groups, and API keys defined in Cortex AgentiX are assigned the relevant scopes.
   * To verify the granular scoping of a user, select **Settings → Configurations → Access Management → Users**, right-click the user name, and select **Edit User Permissions**.
   * To verify the granular scoping of a user group, select **Settings → Configurations → Access Management → User Groups**, right-click the user group, and select **Edit Group**.
   * To verify the granular scoping of an API key, select **Settings → Configurations → Integrations → API Keys**, right-click the API key, and select **Edit**.
3. In the **Scope** tab, expand the scoping areas to review the current granular scoping definitions by clicking the chevron icon (>) beside the scoping area title, and make any changes required. The following table explains the options available to configure:

| SCOPING AREA     | GRANULAR SCOPING CONFIGURATIONS                                                                                                                                                                                                                                                                                                                                                                                                                           |
| ---------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Cases and Issues | <p>Set the Scope by selecting one of the following:<br></p><ul><li><strong>No cases and issues</strong>: Defines access to no cases and issues.</li><li><strong>All cases and issues</strong>: Defines access to all cases and issues.</li><li><strong>Select domains</strong>: Defines access to the domains selected to view their related cases and issues. Under Select domains, define the specific domains that you want to grant access.</li></ul> |

4. Click **Save**.
5. Repeat steps 2 to 4 until you have configured all users, user groups, and API keys with the correct granular scoping access.
6. Enable granular scoping in Cortex AgentiX.
   1. Select **Settings → Configurations → General → Server Settings**, and select the **Enable Scope Based Access Control** toggle.
   2. Click **Save**.

When you are finished, all the users in Cortex AgentiX are now able to use Cortex AgentiX only within the granular scoping granted according to their assigned user roles.

</details>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/user-management/manage-user-scope.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
