> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/rbac-permissions/role-permissions-by-components.md).

# Role permissions by components

You can manage role permissions in Cortex XDR, which are listed by the various components according to the sidebar navigation in Cortex XDR. Dataset permissions are also included for custom roles. Some components include additional action permissions, such as pivot (right-click) options, to which you can also assign access to, but only when you’ve given the user **View/Edit** permissions to the applicable component. Whenever you create a new role or edit an existing role, these role permissions are configurable for all Cortex XDR apps and services in the **Components** tab of the **Create Role** window on the **Roles** page. For more information, see [Manage user roles](/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/manage-user-roles-and-access-management/manage-user-roles.md).

{% hint style="info" %}

### Note

Cortex XDR provides predefined Palo Alto Networks roles, which have set role permissions. For more information, see [Default PANW roles](/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/rbac-permissions/default-panw-roles.md).
{% endhint %}

The following table explains for each Cortex XDR component and additional action permissions, which are listed according to the sidebar navigation headings, the pages that can be accessed with this role permission with the detailed edit permissions available on each page, and any additional information you should know about the role permissions for this component.

<details>

<summary>Dashboards &#x26; Reports</summary>

| Components           | Additional Action Permissions with View/Edit Permissions | Access Permissions to these Pages with Detailed View/Edit Permissions                                                                                                                                                                                                                                                                                                                                                                                                                                                         | Additional Information                                                                                                                                                                                                                                                                          |
| -------------------- | :------------------------------------------------------: | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Dashboards           |                             —                            | <ul><li><p><strong>Dashboards & Reports</strong> → <strong>Dashboard</strong> → <strong>Data Ingestion</strong> dashboard</p><ul><li>Change mode</li><li>Edit</li><li>Mark as default</li><li>Save as report template</li></ul></li><li><p><strong>Dashboards & Reports</strong> → <strong>Customize</strong> → <strong>Dashboards Manager</strong></p><ul><li>New</li><li>Edit</li><li>Save as new</li><li>Set as default</li><li>Save as a report</li><li>Private/public</li><li>Disable</li><li>Delete</li></ul></li></ul> | <p><strong>Dashboards & Reports</strong> → <strong>Customize</strong> → <strong>Widget Library</strong> is displayed when the user role permissions is set to at least one of the following:</p><ul><li><strong>Dashboards</strong>: View/Edit</li><li><strong>Reports</strong>: View</li></ul> |
| Ingestion Monitoring |                             —                            | <p><strong>Dashboards & Reports</strong> → <strong>Dashboard</strong> → <strong>Data Ingestion Dashboard</strong></p><ul><li>No detailed View/Edit permissions</li></ul>                                                                                                                                                                                                                                                                                                                                                      |                                                                                                                                                                                                                                                                                                 |
| Reports              |                             —                            | <ul><li><p><strong>Dashboards & Reports</strong> → <strong>Reports</strong></p><ul><li>Delete</li></ul></li><li><p><strong>Dashboards & Reports</strong> → <strong>Customize</strong> → <strong>Reports Templates</strong></p><ul><li>New</li><li>Delete</li><li>Edit</li><li>Generate Report</li><li>Save as new</li></ul></li></ul>                                                                                                                                                                                         | <p><strong>Customize</strong> → <strong>Widget Library</strong> is displayed when the user role permissions is set to at least one of the following:</p><ul><li><strong>Dashboards</strong>: View/Edit</li><li><strong>Reports</strong>: View</li></ul>                                         |

</details>

<details>

<summary>Incident Response</summary>

Incident & Alerts

| Components         | Additional Action Permissions with View/Edit Permissions | Access Permissions to these Pages with Detailed View/Edit Permissions                                                                                                                                                                                                                                                                                                                                                | Additional Information |
| ------------------ | :------------------------------------------------------: | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------- |
| Alerts & Incidents |                             —                            | <ul><li><p><strong>Incident Response</strong> → <strong>Incidents</strong></p><ul><li>All actions</li></ul></li><li><p><strong>Incident Response</strong> → <strong>Incidents</strong> → <strong>Alerts Table</strong> → <strong>Alerts</strong></p><ul><li>All actions</li></ul></li><li><p><strong>Incident Response</strong> → <strong>Incident Configuration</strong></p><ul><li>All actions</li></ul></li></ul> |                        |

Investigation

| Components             | Additional Action Permissions with View/Edit Permissions | Access Permissions to these Pages with Detailed View/Edit Permissions                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | Additional Information                                                                                                                                                                                                     |
| ---------------------- | :------------------------------------------------------: | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Query Center           |                             —                            | <ul><li><p><strong>Incident Response</strong> → <strong>Investigation</strong> → <strong>Query Builder</strong></p><ul><li>Pivot to XQL Query Builder (editor).</li></ul></li><li><p><strong>Incident Response</strong> → <strong>Investigation</strong> → <strong>Query Center</strong></p><ul><li>Show results</li><li>Rename</li><li>Save query results</li><li>Schedule queries</li><li>Remove queries</li></ul></li><li><p><strong>Incident Response</strong> → <strong>Investigation</strong> → <strong>Scheduled Queries</strong></p><ul><li>Show executed queries</li><li>Edit</li><li>Remove</li><li>Rename</li><li>Disable</li></ul></li><li><p><strong>Detection & Threat Intel</strong> → <strong>Detection Rules</strong> → BIOC → <strong>BIOC Rules</strong></p><ul><li>Add BIOC with <strong>View/Edit</strong> permissions for the Query Center.</li></ul></li><li><p><strong>Detection & Threat Intel</strong> → <strong>Detection Rules</strong> → <strong>Correlations</strong> → <strong>Correlation Rules</strong></p><ul><li>Add Correlation with <strong>View/Edit</strong> permissions for the Query Center.</li></ul></li><li><p><strong>Settings</strong> → <strong>Configurations</strong> → <strong>Data Management</strong> → <strong>Compute Units Usage</strong></p><ul><li>View only as an informative page with <strong>View</strong> permissions for the Query Center.</li></ul></li></ul> | Editing BIOC and Correlation Rules requires **View/Edit** permissions for both the **Incident Response** → **Investigation** → **Query Center** and **Detections & Threat Intel** → **Detections** → **Rules** (see below) |
| Personal Query Library |                             —                            | <p><strong>Incident Response</strong> → <strong>Investigation</strong> → <strong>Query Builder</strong> → <strong>XQL Search</strong> to access your personal queries in the <strong>Query Library</strong> tab.</p><ul><li>Save to library</li><li>Edit</li><li>Labels</li><li>Description</li><li>Private/public</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |                                                                                                                                                                                                                            |
| Forensics              |                             —                            | **Incident Response** → **Investigation** → **Forensics**, where all pages related to Forensics are accessible and all actions can be performed.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |                                                                                                                                                                                                                            |
| Host Insights          |                             —                            | <ul><li><p><strong>Incident Response</strong> → <strong>Investigation</strong> → <strong>Host Inventory</strong></p><ul><li>Can open in asset view without being able to perform any actions.</li></ul></li><li><p><strong>Assets</strong> → <strong>Vulnerability Assessment</strong></p><ul><li>Exclude</li><li>Add comment</li></ul></li><li><strong>Asset View</strong> from <strong>Quick Launcher</strong> → <strong>IP View</strong>, and pivot (right-click) from a host with a Cortex XDR agent installed.</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |                                                                                                                                                                                                                            |

Response

| Components            | Additional Action Permissions with View/Edit Permissions | Access Permissions to these Pages with Detailed View/Edit Permissions                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | Additional Information |
| --------------------- | :------------------------------------------------------: | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------- |
| Action Center         |                             ✓                            | **Incident Response** → **Response** → **Action Center**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |                        |
|                       |                  <p>Isolate</p><p>✓</p>                  | <ul><li><strong>Incident Response</strong> → <strong>Response</strong> → <strong>Action Center</strong> → <strong>All Actions</strong> → <strong>New Action</strong> and from the <strong>Define an Action</strong> page, select <strong>Isolate</strong>.</li><li><strong>Endpoints</strong> → <strong>All Endpoints</strong>, and pivot (right-click) from a host with a Cortex XDR agent installed, and select <strong>Security Operations</strong> → <strong>Isolate Endpoint</strong>.</li><li><p><strong>Incident Response</strong> → <strong>Incidents</strong> → <strong>Executions</strong> tab</p><ul><li>All actions</li></ul></li></ul>                                                                                                                                                                                                                                                                          |                        |
|                       |             <p>Terminate Process</p><p>✓</p>             | <p>Causality chain view is available from the Alerts table (<strong>Incident Response</strong> → <strong>Incidents</strong> → <strong>Alerts Table</strong>), or from the <strong>Query Results</strong> after running a query on the related data. From both of these places, you can pivot (right-click) to the causality chain view from any row in the table and select:</p><ul><li><strong>Investigate Causality Chain</strong> → <strong>Open Card in new tab</strong></li><li><strong>Investigate Causality Chain</strong> → <strong>Open Card in same tab</strong></li></ul>                                                                                                                                                                                                                                                                                                                                         |                        |
|                       |                 <p>Quarantine</p><p>✓</p>                | <p>Causality chain view is available from the Alerts table (<strong>Incident Response</strong> → <strong>Incidents</strong> → <strong>Alerts Table</strong>), or from the <strong>Query Results</strong> after running a query on the related data. From both of these places, you can pivot (right-click) to the causality chain view from any row in the table and select:</p><ul><li><strong>Investigate Causality Chain</strong> → <strong>Open Card in new tab</strong></li><li><strong>Investigate Causality Chain</strong> → <strong>Open Card in same tab</strong></li></ul>                                                                                                                                                                                                                                                                                                                                         |                        |
|                       |               <p>File Retrieval</p><p>✓</p>              | <ul><li><strong>Incident Response</strong> → <strong>Response</strong> → <strong>Action Center</strong> → <strong>All Actions</strong> → <strong>New Action</strong> and from the <strong>Define an Action</strong> page, select <strong>Files Retrieval</strong>.</li><li><strong>Endpoints</strong> → <strong>All Endpoints</strong>, and pivot (right-click) from a host with a Cortex XDR agent installed, and select <strong>Security Operations</strong> → <strong>Retrieve Endpoint Files</strong>.</li><li><p><strong>Incident Response</strong> → <strong>Incidents</strong> → <strong>Executions</strong> tab</p><ul><li><strong>Retrieve Support File</strong></li></ul></li></ul>                                                                                                                                                                                                                                |                        |
|                       |                <p>File Search</p><p>✓</p>                | **Incident Response** → **Incidents** → **Key Assets & Artifacts** tab, and search for a file.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |                        |
|                       |               <p>Destroy Files</p><p>✓</p>               | <p><strong>Incident Response</strong> → <strong>Response</strong> → <strong>Action Center</strong> → <strong>All Actions</strong> → <strong>New Action</strong> and from the <strong>Define an Action</strong> page, select <strong>Destroy file</strong>.</p><ul><li>All actions</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |                        |
|                       |           <p>Allow List/Block List</p><p>✓</p>           | <ul><li><p><strong>Incident Response</strong> → <strong>Response</strong> → <strong>Action Center</strong> → <strong>All Actions</strong> → <strong>New Action</strong> and from the <strong>Define an Action</strong> page, select either:</p><ul><li><strong>Add to block list</strong></li><li><strong>Add to allow list</strong></li></ul></li><li><p><strong>Incident Response</strong> → <strong>Response</strong> → <strong>Action Center</strong> → <strong>Currently Applied Actions</strong> → <strong>Block List</strong></p><ul><li>Disable</li><li>Move to Allow List</li><li>Edit Comment</li><li>Delete</li></ul></li><li><p><strong>Incident Response</strong> → <strong>Response</strong> → <strong>Action Center</strong> → <strong>Currently Applied Actions</strong> → <strong>Allow List</strong></p><ul><li>Disable</li><li>Move to Block List</li><li>Edit Comment</li><li>Delete</li></ul></li></ul> |                        |
|                       |          <p>Disable Response Actions</p><p>✓</p>         | **Endpoints** → **All Endpoints**, and pivot (right-click) an endpoint that isn't an iOS endpoint, and select **Endpoint Control** → **Disable Capabilities**.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |                        |
|                       |                <p>Remediation</p><p>✓</p>                |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |                        |
|                       |                 Delete Quarantined Files                 | <p><strong>Incident Response</strong> → <strong>Response</strong> → <strong>Action Center</strong> → <strong>Currently Applied Actions</strong> → <strong>File Quarantine</strong></p><ul><li>Delete</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |                        |
| EDL                   |                             —                            | <p><strong>Incident Response</strong> → <strong>Response</strong> → <strong>EDL</strong></p><ul><li>Add</li><li>Delete</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |                        |
| Agent Scripts Library |                             ✓                            | **Incident Response** → **Response** → **Action Center** → **Agent Script Library**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |                        |
|                       |            <p>Run Standard Script</p><p>✓</p>            | <ul><li><p><strong>Incident Response</strong> → <strong>Response</strong> → <strong>Action Center</strong> → <strong>Agent Script Library</strong>, and any script from the <strong>Scripts Library</strong> table, where the <strong>Outcome</strong> column is set to <strong>Standard</strong>, you can select:</p><ul><li>Run</li></ul></li><li><p><strong>Incident Response</strong> → <strong>Response</strong> → <strong>Action Center</strong> → <strong>All Actions</strong>+<strong>New Action</strong>, and from the <strong>Choose</strong> page, select <strong>Run Endpoint Script</strong>.</p><ul><li>The standard scripts are available in the <strong>Scripts</strong> list to select from.</li></ul></li></ul>                                                                                                                                                                                            |                        |
|                       |            <p>Run High-Risk Script</p><p>✓</p>           | <p><strong>Incident Response</strong> → <strong>Response</strong> → <strong>Action Center</strong> → <strong>Agent Script Library</strong>, and any script from the <strong>Scripts Library</strong> table, where the <strong>Outcome</strong> column is set to <strong>High Risk</strong>, you can select:</p><ul><li>Run</li><li><p><strong>Incident Response</strong> → <strong>Response</strong> → <strong>Action Center</strong> → <strong>All Actions</strong>+<strong>New Action</strong>, and from the <strong>Choose</strong> page, select <strong>Run Endpoint Script</strong>.</p><ul><li>The high-risk scripts are available in the <strong>Scripts</strong> list to select from.</li></ul></li></ul>                                                                                                                                                                                                            |                        |
|                       |           <p>Script Configurations</p><p>✓</p>           | <p><strong>Incident Response</strong> → <strong>Response</strong> → <strong>Action Center</strong> → <strong>Agent Script Library</strong></p><ul><li>New Script</li><li>Edit</li><li>Save as new</li><li>Delete</li><li>Download definitions file</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |                        |
| Live Terminal         |                             —                            | <ul><li><strong>Incident Response</strong> → <strong>Response</strong> → <strong>Live Terminal</strong></li><li><strong>Incident Response</strong> → <strong>Incidents</strong> → <strong>Executions</strong> tab</li><li><strong>Endpoints</strong> → <strong>All Endpoints</strong>, pivot (right-click) from a host with a Cortex XDR agent installed, and select <strong>Security Operations</strong> → <strong>Initiate Live Terminal</strong>.</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                               |                        |
| Automation Rules      |                             —                            | <p><strong>Incident Response</strong> → <strong>Response</strong> → <strong>Automation</strong> → <strong>Automation Rules</strong></p><ul><li>All actions</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |                        |

</details>

<details>

<summary>Detections &#x26; Threat Intel</summary>

Detections

| Components | Additional Action Permissions with View/Edit Permissions | Access Permissions to these Pages with Detailed View/Edit Permissions                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | Additional Information                                                                                                                                                                                                     |
| ---------- | :------------------------------------------------------: | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Rules      |                             ✓                            | <ul><li><p><strong>Detection & Threat Intel</strong> → <strong>Detection Rules</strong> → <strong>IOC</strong> → <strong>IOC Rules</strong></p><ul><li>Add IOC</li><li>Edit</li><li>Disable</li><li>Delete</li><li>Add to EDL</li></ul></li><li><p><strong>Detection & Threat Intel</strong> → <strong>Detection Rules</strong> → <strong>BIOC</strong> → <strong>BIOC Rules</strong></p><ul><li>Add BIOC</li><li>Import Rules</li><li>Disable</li><li>Save as new</li><li>Open in Query Builder</li></ul></li><li><p><strong>Detection & Threat Intel</strong> → <strong>Detection Rules</strong> → <strong>Correlations</strong> → <strong>Correlation Rules</strong></p><ul><li>Add Correlation</li><li>Exclude Rule</li><li>Disable</li><li>Edit</li><li>Save as new</li><li>Delete</li></ul></li><li><p><strong>Detection & Threat Intel</strong> → <strong>Detection Rules</strong> → <strong>Exceptions</strong></p><ul><li>New Exception</li><li>Import Exceptions</li><li>Edit</li><li>Delete</li><li>Export</li></ul></li></ul> | Editing BIOC and Correlation Rules requires **View/Edit** permissions for both the **Incident Response** → **Investigation** → **Query Center** (see above) and **Detections & Threat Intel** → **Detections** → **Rules** |
|            |              <p>Prevention Rules</p><p>✓</p>             | <ul><li><p><strong>Detection & Threat Intel</strong> → <strong>Threat Intel Management</strong> → <strong>Indicator Rules</strong></p><ul><li>Add Rule > Prevention Rule</li><li>Add Rule > Detection Rule</li></ul></li><li><p><strong>Detection Rules</strong> → <strong>BIOC</strong>, select one or more BIOC rules, and right-click:</p><ul><li>Add selection to restrictions profile (only agent-supported) rules</li></ul></li><li><p><strong>Endpoints</strong> → <strong>Policy Management</strong> → <strong>Prevention</strong> → <strong>Profiles</strong>, click <strong>Add Profile</strong>, and select whether to create a new profile or import a profile from a file. Select the applicable platform, and <strong>Restrictions</strong> as the profile type. When you continue configuring the restrictions profile, the following section is displayed:</p><ul><li>Custom Prevention Rules</li></ul></li></ul>                                                                                                         |                                                                                                                                                                                                                            |
|            |      <p>Request WildFire Verdict Change</p><p>✓</p>      | <p>From a WildFire report, you can click <strong>Report Verdict as Incorrect</strong>, and under <strong>Suggested Verdict</strong>, suggest a new verdict. Open a WildFire report from:</p><ul><li><strong>Incident Response</strong> → <strong>Incidents</strong> → <strong>Key Assets & Artifacts</strong> tab, and under <strong>Artifacts</strong>, identify a file with a WildFire verdict and click <strong>Wildfire Analysis Report</strong></li><li><strong>Incident Response</strong> → <strong>Incidents</strong> → <strong>Alerts Table</strong> → <strong>Alerts</strong>, hover over the alert, and <strong>Investigate</strong>. You can open the WildFire report of any file included in the alert Causality Chain.</li></ul>                                                                                                                                                                                                                                                                                             |                                                                                                                                                                                                                            |

</details>

<details>

<summary>Assets</summary>

| Components                | Additional Action Permissions with View/Edit Permissions | Access Permissions to these Pages with Detailed View/Edit Permissions                                                                                                                                                                                                                                                                                           | Additional Information                                                                                                                                                                                                                               |
| ------------------------- | :------------------------------------------------------: | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Network Configuration     |                             —                            | <ul><li><p><strong>Assets</strong> → <strong>Network Configuration</strong> → <strong>IP Addresses Ranges</strong></p><ul><li>Edit</li><li>Delete</li></ul></li><li><p><strong>Assets</strong> → <strong>Network Configuration</strong> → <strong>Internal Domain Suffixes</strong></p><ul><li>Edit</li></ul></li></ul>                                         | You can only edit and delete new IP address ranges added, and not the out-of-the-box IP addresses.                                                                                                                                                   |
| Compliance                |                             —                            | <ul><li><strong>Assets</strong> → <strong>Cloud Compliance</strong> → <strong>Compliance Violation</strong> table</li><li><strong>Dashboards & Reports</strong> → <strong>Dashboard</strong> → <strong>Compliance Violation</strong></li></ul>                                                                                                                  |                                                                                                                                                                                                                                                      |
| Asset Inventory           |                             —                            | <ul><li><p><strong>Assets</strong> → <strong>Asset Inventory</strong></p><ul><li>All actions</li></ul></li><li><p><strong>Assets</strong> → <strong>Asset Scores</strong></p><ul><li>All actions</li></ul></li><li><p><strong>Assets</strong> → <strong>Cloud Inventory</strong> → <strong>All Cloud Assets</strong></p><ul><li>All actions</li></ul></li></ul> | <p><strong>Assets</strong> → <strong>Asset Scores</strong> is displayed when the user role permissions is set to:</p><ul><li><strong>Incident Response</strong> → <strong>Incident & Alerts</strong> → <strong>Alerts & Incidents</strong></li></ul> |
| Asset Roles Configuration |                             —                            | <p><strong>Assets</strong> → <strong>Asset Roles Configuration</strong></p><ul><li>All actions</li></ul>                                                                                                                                                                                                                                                        |                                                                                                                                                                                                                                                      |

</details>

<details>

<summary>Endpoints</summary>

| Components                   | Additional Action Permissions with View/Edit Permissions | Access Permissions to these Pages with Detailed View/Edit Permissions                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | Additional Information                                                          |
| ---------------------------- | :------------------------------------------------------: | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------- |
| Endpoint Administrations     |                             ✓                            | <p><strong>Settings</strong> → <strong>Exceptions Configuration</strong></p><ul><li>All actions</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |                                                                                 |
|                              |            <p>Endpoint Management</p><p>✓</p>            | <p><strong>Endpoints</strong> → <strong>All Endpoints</strong></p><p>Locate one or more endpoints, right-click and select:</p><ul><li><strong>Endpoint Control</strong> → <strong>Perform Heartbeat</strong></li><li>Select one or more endpoints that you want to force the check-in of, and right-click + Alt to open the options menu in advanced mode, and select <strong>Endpoint Control</strong> → <strong>Force Check-in</strong>.</li><li>Select one or more agents that you want to restart, and right-click + Alt to open the options menu in advanced mode, and select <strong>Endpoint Control</strong> → <strong>Restart Agent</strong>.</li><li><strong>Endpoint Control</strong> → <strong>Change Endpoint Alias</strong></li><li><strong>Endpoint Control</strong> → <strong>Upgrade Agent Version</strong></li><li><strong>Endpoint Control</strong> → <strong>Set Agent Proxy</strong></li><li><strong>Endpoint Control</strong> → <strong>Uninstall Agent</strong></li><li><strong>Endpoint Control</strong> → <strong>Delete Endpoint</strong></li><li><strong>Endpoint Control</strong> → <strong>Exclude endpoints from auto upgrade</strong></li><li><strong>Endpoint Control</strong> → <strong>Include endpoints in auto upgrade</strong></li></ul> |                                                                                 |
|                              |           <p>Retrieve Endpoint Data</p><p>✓</p>          | <ul><li><p><strong>Endpoints</strong> → <strong>All Endpoints</strong></p><ul><li>Locate one or more endpoints, right-click and select <strong>Endpoint Control</strong> → <strong>Retrieve Support File</strong>.</li></ul></li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |                                                                                 |
|                              |               <p>Endpoint Scan</p><p>✓</p>               | <p><strong>Endpoints</strong> → <strong>All Endpoints</strong></p><p>Locate one or more endpoints, right-click and select:</p><ul><li><strong>Security Operations</strong> → <strong>Initiate Malware Scan</strong></li><li><strong>Security Operations</strong> → <strong>Abort Malware Scan</strong></li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |                                                                                 |
|                              |           <p>Change Managing Server</p><p>✓</p>          | <p><strong>Endpoints</strong> → <strong>All Endpoints</strong></p><ul><li>Select one or more agents that you want to move to the target server, and right-click + Alt to open the options menu in advanced mode, and select <strong>Endpoint Control</strong> → <strong>Change managing server</strong>.</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |                                                                                 |
|                              |              <p>Pause Protection</p><p>✓</p>             | <p><strong>Endpoints</strong> → <strong>All Endpoints</strong></p><ul><li>Select the endpoints you want to pause protection on, right-click and select <strong>Endpoint Control</strong> → <strong>Pause Endpoint Protection</strong>.</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |                                                                                 |
|                              |         <p>Endpoint Token Management</p><p>✓</p>         | <p><strong>Endpoints</strong> → <strong>All Endpoints</strong></p><p>On the top right corner of the screen, the Tokens and Passwords icon is displayed, which you can left-click and select:</p><ul><li>Retrieve Token</li><li>Retrieve Support File Password</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |                                                                                 |
| Endpoint Groups              |                             —                            | <p><strong>Endpoints</strong> → <strong>Endpoint Groups</strong></p><ul><li>Add Group</li><li>View endpoints</li><li>Edit</li><li>Delete</li><li>Save as new</li><li>Export group</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |                                                                                 |
| Endpoint Prevention Policies |                             —                            | <p><strong>Endpoints</strong> → <strong>Policy Management</strong> → <strong>Prevention</strong> → <strong>Policy Rules</strong></p><ul><li>View Policy Details</li><li>Edit</li><li>Save As New</li><li>Disable</li><li>Delete</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |                                                                                 |
| Global Exceptions            |                             —                            | <p><strong>Endpoints</strong> → <strong>Policy Management</strong> → <strong>Prevention</strong> → <strong>Global Exceptions</strong></p><ul><li>All actions</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |                                                                                 |
| Endpoint Profiles            |                             —                            | <p><strong>Endpoints</strong> → <strong>Policy Management</strong> → <strong>Extensions</strong> → <strong>Profiles</strong></p><ul><li>Add Profile</li><li>Edit Profile</li><li>Save As New</li><li>Delete</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |                                                                                 |
| Endpoint Extension Policies  |                             —                            | <p><strong>Endpoints</strong> → <strong>Policy Management</strong> → <strong>Extensions</strong></p><ul><li><p>Policy Rules:</p><ul><li>View Policy Details</li><li>Edit</li><li>Save As New</li><li>Disable</li><li>Delete</li></ul></li><li><p>Profiles</p><ul><li>Add Profile</li><li>Edit Profile</li><li>Save As New</li><li>Delete</li></ul></li><li><p>Device Permanent Exceptions</p><ul><li>All actions</li></ul></li><li><p>Device Temporary Exceptions</p><ul><li>All actions</li></ul></li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |                                                                                 |
| Endpoint Installations       |                             —                            | <p><strong>Endpoints</strong> → <strong>Agent Installations</strong></p><ul><li>Create</li><li>Edit</li><li>Delete</li><li>64 bit installer</li><li>32 bit installer</li><li>Hide this row</li><li>Show rows</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |                                                                                 |
| Host Firewall                |                             —                            | <ul><li><p><strong>Endpoints</strong> → <strong>Host Firewall</strong> → <strong>Rule Groups</strong></p><ul><li>New Group</li><li>Edit Group</li><li>Save As New</li><li>Disable Group</li><li>Delete Group</li><li>Export Group Rules</li><li>Import Group Rules</li><li>Show rows</li><li>Hide rows</li></ul></li><li><p><strong>Endpoints</strong> → <strong>Host Firewall</strong> → <strong>Host Firewall Events</strong></p><ul><li>Collect Detailed Host Firewall Logs</li></ul></li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | Users can still view Extensions profiles when the type is set to host firewall. |
| Device Control               |                             ✓                            |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |                                                                                 |
|                              |            <p>Device Control Rules</p><p>✓</p>           | <p><strong>Endpoints</strong> → <strong>Device Control Violations</strong></p><ul><li>Add device to permanent exceptions</li><li>Add device to temporary exceptions</li><li>Add device to a profile exception</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |                                                                                 |
|                              |         <p>Device Control Exceptions</p><p>✓</p>         | <p><strong>Endpoints</strong> → <strong>Policy Management</strong> → <strong>Extensions</strong></p><ul><li>Policy Rules</li><li>Profiles</li><li>Device Permanent Exceptions</li><li>Device Temporary Exceptions</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |                                                                                 |

</details>

<details>

<summary>Configurations</summary>

General Settings

| Components            | Additional Action Permissions with View/Edit Permissions | Access Permissions to these Pages with Detailed View/Edit Permissions                                                                                                                                                                                                                                                                                                                                                                                                                                                | Additional Information                                             |
| --------------------- | :------------------------------------------------------: | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------ |
| Auditing              |                             —                            | <ul><li><p><strong>Settings</strong> → <strong>Management Audit Logs</strong></p><ul><li>No detailed View/Edit permissions</li></ul></li><li><p><strong>Settings</strong> → <strong>Agent Audit Logs</strong></p><ul><li>No detailed View/Edit permissions</li></ul></li><li><strong>Settings</strong> → <strong>XDR Collector Audit Logs</strong></li></ul>                                                                                                                                                         | XDR Collector Audit Logs requires a Cortex XDR Pro per GB license. |
| Alert Notification    |                             —                            | Notifications                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |                                                                    |
| General Configuration |                             —                            | <p><strong>Settings</strong> → <strong>Configurations</strong> → <strong>General</strong> → <strong>Server Settings</strong></p><ul><li><p>Timezone:</p><ul><li>Edit timezone</li></ul></li><li><p>Timestamp Format</p><ul><li>Edit timestamp format</li></ul></li><li><p>Email Contacts</p><ul><li>Add</li></ul></li><li><p>Define the incidents target MTTR per incident severity</p><ul><li>Set the days and hours</li></ul></li><li><p>Impersonation Role</p><ul><li>Edit impersonation role</li></ul></li></ul> |                                                                    |

Cortex XDR - Analytics

| Components          | Additional Action Permissions with View/Edit Permissions | Access Permissions to these Pages with Detailed View/Edit Permissions                                                                                           | Additional Information |
| ------------------- | :------------------------------------------------------: | --------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------- |
| On-demand Analytics |                             —                            | <p><strong>Settings</strong> → <strong>Configurations</strong> → <strong>Cortex XDR - Analytics</strong></p><ul><li>Enable</li><li>Identity Analytics</li></ul> |                        |

Data Broker

| Components                 | Additional Action Permissions with View/Edit Permissions | Access Permissions to these Pages with Detailed View/Edit Permissions                                                                                                                                                                                                                                                              | Additional Information                                                                                                                                                    |
| -------------------------- | :------------------------------------------------------: | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Broker Service             |                             ✓                            | <p><strong>Settings</strong> → <strong>Configurations</strong> → <strong>Data Broker</strong> → <strong>Broker VMs</strong></p><ul><li><strong>Add Broker</strong> → <strong>Download</strong> any of the broker images</li><li><strong>Add Broker</strong> → <strong>Generate Token</strong></li><li>All applet actions</li></ul> |                                                                                                                                                                           |
|                            |             <p>Pathfinder Applet</p><p>✓</p>             | <p><strong>Settings</strong> → <strong>Configurations</strong> → <strong>Data Broker</strong> → <strong>Broker VMs</strong>, and in the APPS column of the Broker VMs page, the Pathfinder applet is displayed.</p><ul><li>All actions</li></ul>                                                                                   |                                                                                                                                                                           |
| Pathfinder Data Collection |                             —                            | <p><strong>Settings</strong> → <strong>Configurations</strong> → <strong>Data Collection</strong> → <strong>Pathfinder Collection Center</strong></p><ul><li>All actions</li></ul>                                                                                                                                                 | To use the Pathfinder Collection Center page, you need to have **View/Edit** permission for the **Broker Service** and the **Pathfinder Applet** (see permissions above). |

Data Collection

| Components              | Additional Action Permissions with View/Edit Permissions | Access Permissions to these Pages with Detailed View/Edit Permissions                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           | Additional Information                                              |
| ----------------------- | :------------------------------------------------------: | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------- |
| Log Collections         |                             —                            | <ul><li><p><strong>Settings</strong> → <strong>Configurations</strong> → <strong>XDR Collectors</strong> → <strong>Configuration</strong></p><ul><li>All actions</li></ul></li><li><p><strong>Settings</strong> → <strong>Configurations</strong> → <strong>XDR Collectors</strong> → <strong>Administration</strong></p><ul><li>Change Collector Alias</li><li>Upgrade Collector Version</li><li>Set Collector Proxy</li><li>Uninstall Collector</li><li>Delete Collector</li><li>Retrieve Support Files</li></ul></li><li><p><strong>Settings</strong> → <strong>Configurations</strong> → <strong>XDR Collectors</strong> → <strong>Groups</strong></p><ul><li>Add Group</li><li>Edit</li><li>Delete</li><li>Save as new</li></ul></li><li><p><strong>Settings</strong> → <strong>Configurations</strong> → <strong>XDR Collectors</strong> → <strong>Installers</strong></p><ul><li>Create</li><li>Delete</li><li>Hide</li></ul></li><li><p><strong>Settings</strong> → <strong>Configurations</strong> → <strong>XDR Collectors</strong> → <strong>Profiles</strong></p><ul><li>Add Profile</li><li>Edit</li><li>Save As New</li><li>Delete</li></ul></li><li><p><strong>Settings</strong> → <strong>Configurations</strong> → <strong>XDR Collectors</strong> → <strong>Policies</strong></p><ul><li>Add Policy</li><li>Disable</li><li>Delete</li><li>Save As New</li><li>Edit</li></ul></li><li><p><strong>Settings</strong> → <strong>Configurations</strong> → <strong>Data Collection</strong> → <strong>Custom Collectors</strong></p><ul><li>All actions</li></ul></li><li><p><strong>Settings</strong> → <strong>Configurations</strong> → <strong>Data Collection</strong> → <strong>Collection Integrations</strong></p><ul><li>All actions</li></ul></li></ul> | Ingestion of logs and data requires a Cortex XDR Pro per GB license |
| External Alerts Mapping |                             —                            | <p><strong>Settings</strong> → <strong>Configurations</strong> → <strong>Data Collection</strong> → <strong>External Alert Mapping</strong></p><ul><li>Save as new</li><li>Disable</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |                                                                     |

Data Management

| Components      | Additional Action Permissions with View/Edit Permissions | Access Permissions to these Pages with Detailed View/Edit Permissions                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | Additional Information                                                                              |
| --------------- | :------------------------------------------------------: | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------- |
| Data Management |                             —                            | <ul><li><p><strong>Settings</strong> → <strong>Configurations</strong> → <strong>Data Management</strong> → <strong>Dataset Management</strong></p><ul><li>All actions</li></ul></li><li><p><strong>Settings</strong> → <strong>Configurations</strong> → <strong>Data Management</strong> → <strong>Parsing Rules</strong></p><ul><li>All actions</li></ul></li><li><p><strong>Settings</strong> → <strong>Configurations</strong> → <strong>Data Management</strong> → <strong>Event Forwarding</strong></p><ul><li>All actions</li></ul></li></ul> | To set permissions for Compute Unit Usage, use **Integrations** → **Public API** (see table below). |

Integrations

| Components                                   | Additional Action Permissions with View/Edit Permissions | Access Permissions to these Pages with Detailed View/Edit Permissions                                                                                                                                                                                                                                                                                                  | Additional Information |
| -------------------------------------------- | :------------------------------------------------------: | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------- |
| Public API                                   |                             —                            | <ul><li><strong>Settings</strong> → <strong>Configurations</strong> → <strong>Data Management</strong> → <strong>Compute Unit Usage</strong></li><li><p><strong>Settings</strong> → <strong>Configurations</strong> → <strong>Integrations</strong> → <strong>API Keys</strong></p><ul><li>New Key</li><li>Edit</li><li>Delete</li><li>Save as new</li></ul></li></ul> |                        |
| Threat Intelligence                          |                             —                            | <p><strong>Settings</strong> → <strong>Configurations</strong> → <strong>Integrations</strong> → <strong>Threat intelligence</strong></p><ul><li>Create</li><li>Delete</li><li>Edit</li></ul>                                                                                                                                                                          |                        |
| Long Running HTTP Integrations configuration |                             —                            | Settings → Configurations → **Integrations** → **Long Running HTTP Integrations configuration**                                                                                                                                                                                                                                                                        |                        |

</details>

<details>

<summary>Help</summary>

| Components | Additional Action Permissions with View/Edit Permissions | Access Permissions to these Pages with Detailed View/Edit Permissions | Additional Information |
| ---------- | :------------------------------------------------------: | --------------------------------------------------------------------- | ---------------------- |
| Support    |                             —                            | **Help** → **Submit a Support Case**r                                 |                        |

</details>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/rbac-permissions/role-permissions-by-components.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
