> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/dashboards-and-reports-permissions/cloud-security-command-center-permissions.md).

# Cloud Security Command Center permissions

Controls the ability to view and edit the Cortex Cloud Command Center, which is the central command center for cloud security, and includes capabilities like Cloud Security Posture Management (CSPM), Application Security Posture Management (ASPM), and Data Security Posture Management (DSPM).

| Permission | Description                                                                                                                                                                                                                                                                                                                                                   | Roles Example                                                                         |
| ---------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------- |
| None       | No access to the Cloud Security Command Center.                                                                                                                                                                                                                                                                                                               | Most roles, unless they need Cloud Security.                                          |
| View       | Read-only access to the Cloud Security Command Center.                                                                                                                                                                                                                                                                                                        | Cloud viewer roles, such as Data Security Viewer, Developer, and AppSec Admin.        |
| View/Edit  | <p>Enables access and filtering, but it does not allow for editing the structure or widgets of the dashboard itself, as these are predefined.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>You also need Dashboards <strong>Enabled</strong> to view/edit these dashboards.</p></div> | Cloud admin roles, such as AI Security Administrator and Data Security Administrator. |

### Required and recommended permissions

As this dashboard aggregates data from complex cloud inventories, it will not populate correctly unless the following permissions are also granted:

| Permission                | Permission Level | Reason                                                                                            |
| ------------------------- | ---------------- | ------------------------------------------------------------------------------------------------- |
| Dashboards                | Enabled          | Required for the dashboard.                                                                       |
| Command Center Dashboards | View             | Cloud security cases and issues require this for click-through and context. Strongly recommended: |
| Asset Inventory           | View             | Cloud asset data requires this permission for full visibility. View: Strongly recommended:        |
| Graph Search              | View             | Cloud asset relationship visualization enhances cloud security context. Recommended.              |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/dashboards-and-reports-permissions/cloud-security-command-center-permissions.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
