> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/response-permissions-1/action-center-permissions.md).

# Action Center permissions

In the Action Center, you can initiate and monitor actions on your endpoints. You can limit access to the Action Center (**Investigation & Response** → **Response** → **Action Center**) and response actions (outside the Action Center). When you select View/Edit, you can set additional permissions.

For more information, see [Overview of the Action Center](/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/investigate-endpoints/overview-of-the-action-center.md).

| Permission | Description                                                                                                                                                                                                                                                                                                                                                                                                             | Roles Example                                                                                                                                                                                                                                                         |
| ---------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| None       | No access to the Action Center, and response action buttons are hidden.                                                                                                                                                                                                                                                                                                                                                 | SOC Tier-1 Analysts: View action history, isolation status, and quarantine lists, but cannot execute any actions.                                                                                                                                                     |
| View       | Read-only access. You can see the action history and results, but cannot initiate any actions. All action buttons are hidden.                                                                                                                                                                                                                                                                                           | IT Admin: Response actions (isolate, terminate process, quarantine, file retrieval, file search, destroy files) are security response functions. Granting IT Admins access to these actions creates significant risk — they could isolate endpoints or destroy files. |
| View/Edit  | <p>Full control to initiate, retry, or cancel actions. This is a high-privilege permission that enables the Response in Endpoint Detection and Response (EDR). Unchecked actions remain view only.</p><p>When <strong>Action Center</strong> is set to <strong>View/Edit</strong>, the following action checkboxes become available. Each checkbox controls whether the user can execute that specific action type.</p> | SOC Tier 2 and 3 Analysts, Threat Hunters, and Security Engineers have full access with granular controls.                                                                                                                                                            |

{% hint style="warning" %}

### Warning

* High-risk/destructive actions: The Destroy Files and Delete Quarantine Files actions are irreversible and permanently delete data from endpoints. Disable Response Actions temporarily pauses endpoint protection, leaving the system vulnerable. Live Terminal allows arbitrary command execution and file manipulation. These features should be strictly restricted to Security Engineers and Admins.
* Checkbox dependencies: Certain actions rely on others to function. To grant File Retrieval or Destroy Files, you must also enable the File Search checkbox. To grant Delete Quarantine Files, you must also enable the Quarantine checkbox.
* Master switch: Setting the primary Action Center permission to View/Edit acts as a master switch that reveals granular execution checkboxes (such as Isolate or Run Standard Scripts). Leaving these checkboxes unchecked allows the user to view the action history without the ability to execute the action.
  {% endhint %}

Action Center sub-permissions

| Sub-permission           | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          | Roles Example                                                                                                                                                                                                                                                                                                                      |
| ------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Isolate                  | <p>Isolates an endpoint from the network while maintaining communication with the Cortex XSIAM tenant.</p><ul><li>Checked: Full access to Isolate in all menus, such as <strong>Isolate</strong> when defining an action in the <strong>Action Center</strong> and isolating endpoints on the <strong>Vulnerability Assessment</strong> page. Initiate, cancel, and edit isolation with comments.</li><li>Unchecked: Users can view isolation history and status in the Action Center, but cannot initiate or cancel isolation.</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | All Responders/Admins. The SOC Tier-1 Analyst should escalate isolation decisions to Tier 2, but can monitor isolation status.                                                                                                                                                                                                     |
| Terminate Process        | <p>Terminates running processes on endpoints. Can terminate individual processes by process ID or entire causality chains (all processes from a malicious parent). This stops active malicious activity without requiring full endpoint isolation.</p><p>The Causality view is available from the Cases or Issues pages, or from the <strong>Query Results</strong> (<strong>Investigation & Response)</strong> → <strong>Query Builder</strong> → \*\*Build an XQL Query)\*\*after running a query on the related data. From both of these places, you can pivot (right-click) to the causality chain view.</p><ul><li>Checked: Full access to the Terminate Process option in the Causality View. Users can initiate termination from remediation suggestions.</li><li>Unchecked: Users can view process termination history in Action Center, but can't initiate termination.</li></ul><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Tip</strong></p><p>Consider adding the Remedation permission. Terminate Process appears in the Remediation Suggestions panel. Enabling both provides a complete response workflow.</p></div> | All Responders/Admins. The SOC Tier-1 Analyst should escalate process termination to Tier 2, but can view termination history.                                                                                                                                                                                                     |
| Quarantine               | <p>Moves malicious or suspicious files to a secure quarantine folder on the endpoint, preventing execution while preserving the file for analysis. Quarantined files can be restored if determined to be false positives.</p><ul><li>Checked: Full access to quarantine files in the Action Center and in the Causality View. Users can restore quarantined files, can add a hash to the allow list during restore, and can view quarantine details per endpoint.</li><li>Unchecked: User can view the File Quarantine tab in the Action Center and view quarantine files in the Causality View, but can't quarantine or restore files.</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | All Responders/Admins. SOC Tier-1 Analysts and Threat Hunters need to hand off to SOC Tier 2 and 3 Analysts for containment.                                                                                                                                                                                                       |
| File Retrieval           | <p>Retrieves files from endpoints for forensic analysis. Files are uploaded to Cortex XSIAM where they can be downloaded for examination, malware analysis, or evidence preservation.</p><ul><li>Checked: Users can retrieve files from an endpoint in Action Center, from file search results, and view/download files from Action Center and from Cases.</li><li>Unchecked: Users can view retrieval history in Action Center, but can't download retrieved files.</li></ul><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Tip</strong></p><p>Consider adding the following permissions:</p><p>File Search. File Retrieval is typically initiated from File Search results. Without File Search, retrieval options are limited.</p></div>                                                                                                                                                                                                                                                                                                                                                                                           | All Responders/Admins. SOC Tier-1 and 2 Analysts and Threat Hunters need to hand off to SOC Tier 3 Analysts or the Forensics Team for containment.                                                                                                                                                                                 |
| File Search              | <p>Searches for files across all managed endpoints by hash (SHA256, MD5), file path, or file name patterns. Used to determine file prevalence, locate IOCs, and identify affected endpoints.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Notice</strong></p><p>Requires the Host Insights add-on, which is included in Cortex XSIAM Enterprise and Premium licenses.</p></div><ul><li>Checked: Full access to File Search when defining an action in the Action Center. Users can search files by hash, path, or pattern.</li><li>Unchecked: Users can view search history in Action Center, but can't rerun file searches.</li></ul><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Tip</strong></p><p>Consider adding File Retrieval. After finding files, users often need to retrieve them for analysis.</p></div>                                                                                                                                                                                                                                                            | All Responders/Admins. The SOC Tier-1 Analyst should escalate to the SOC Tier 2 Analyst.                                                                                                                                                                                                                                           |
| Destroy Files            | <p>High risk. Permanently and irreversibly deletes files from endpoints. This is a destructive action that cannot be undone. Used to remove persistent malware or malicious files that cannot be quarantined.</p><ul><li>Checked: Full access to take action to destroy files in the Action Center. Users can destroy files from file search results and permanently delete files from endpoints.</li><li>Unchecked: Users can view the destroyed file history in the Action Center, but can't permanently delete files.</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | SOC Tier-3 Analysts and Security Admins. This is a high-risk action that permanently deletes files and cannot be reversed.                                                                                                                                                                                                         |
| Allow List/Block List    | <p>Exempt or block files matching specified hashes across the environment.</p><ul><li>Checked: Full access to take action on the Allow List or Block List, such as adding hashes to the allow/block list when defining an action in the Action Center, editing list entries, and moving hashes between lists.</li><li>Unchecked: Users can view the Allow List and Block List tabs in Action Center, see hash entries and status, but can't add, edit, or delete allow/block lists.</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | SOC Tier-3 Analysts, Threat Hunters, Security Engineers, and Security Admins who manage hash-based prevention policies.                                                                                                                                                                                                            |
| Disable Response Actions | <p>High risk. Temporarily disables or pauses endpoint protection and response capabilities. This weakens endpoint security and should be used only for troubleshooting or specific operational requirements.</p><p>You can view disabled response actions by going to <strong>Inventory</strong> → <strong>Endpoints</strong> → <strong>All Endpoints</strong>. If you have View/Edit permissions, pivot (right-click) an endpoint that isn't an iOS endpoint, and select <strong>Endpoint Control</strong> → <strong>Disable Capabilities</strong>.</p><ul><li>Checked: Users can disable specific response actions on endpoints, pause endpoint protection temporarily, and can re-enable disabled actions.</li><li>Unchecked: Users can view current response action status, see which actions are disabled, but can't modify response action settings or pause endpoint protection.</li></ul>                                                                                                                                                                                                                                                                                    | Security Admins only. Disabling response actions reduces security posture and should require proper change management approval.                                                                                                                                                                                                    |
| Remediation              | <p>Execute automated actions to reverse malicious system changes (registry, files, processes).</p><ul><li>Checked: Full access to Remediation Suggestions from Case View. Users can initiate remediation from Causality View and can execute file restore, registry restore, and process termination.</li><li>Unchecked: Users can view remediation history in Action Center, see remediation results and status, but can't initiate remediation actions.</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | All Responders/Admins. The SOC Tier 1 Analyst should escalate to Tier 2 Analysts.                                                                                                                                                                                                                                                  |
| Delete Quarantine Files  | <p>High risk. Permanently deletes files from the quarantine folder on endpoints. Unlike restoring quarantined files, this action removes the files entirely and cannot be undone.</p><ul><li><p>Checked: Full access to delete files from the File Quarantine page, enabling a user to permanently remove quarantined files from endpoints.</p><p>The delete option only appears in the Aggregated by SHA256 tab in File Quarantine.</p></li><li>Unchecked: Users can view the quarantined files list in the Action Center, including file details and status, but can't permanently delete quarantined files.</li></ul><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Tip</strong></p><p>Consider adding Quarantine. Delete Quarantine Files operates on the quarantine list. Without the Quarantine checkbox, users can still see the list, but the Delete option requires the quarantine view to be meaningful.</p></div>                                                                                                                                                                                                          | <ul><li>SOC Tier-3 Analyst: May need to permanently remove confirmed malware after thorough analysis. Has experience for informed deletion decisions.</li><li>Security Engineer: Manages quarantine storage, cleans up confirmed malware, and maintains endpoint health. Understands implications of permanent deletion.</li></ul> |

**Required and recommended permissions for Action Center**

| Permission            | Permission Level                 | Reason                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| --------------------- | -------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Cases & Issues        | View or View/Edit                | <ul><li>View: Action Center actions link to cases/issues. Allow/Block List shows case IDs. Remediation is triggered from Case View. Without this, users can't see the context of their actions.</li><li>View/Edit: Needed to link actions to cases, update case status after remediation, and use Add to Block List from issue context menus. The Allow/Block List component checks cases and issues for creating cases from hash entries. Strongly recommended.</li></ul> |
| Agent Administrations | View                             | Isolate, Terminate, File Search, File Retrieval, and Quarantine all target endpoints. Without this, users can't select target endpoints for actions.                                                                                                                                                                                                                                                                                                                       |
| Query Center          | View                             | XQL Investigation results have been Add to EDL and Add to Block List context menus. File Search results are viewed through query results. Needed for investigating action outcomes.                                                                                                                                                                                                                                                                                        |
| Query Library         | Enabled with checkboxes selected | Allows saving and reusing XQL queries related to file search results and investigation.                                                                                                                                                                                                                                                                                                                                                                                    |
| Forensics             | View                             | Forensic Timeline and Event Log Search are related investigation tools.                                                                                                                                                                                                                                                                                                                                                                                                    |
| Host Insights         | View                             | File Search and Destroy Files depend on Host Insights. Provides endpoint context for action decisions.                                                                                                                                                                                                                                                                                                                                                                     |
| Scripts               | Enabled                          | Action Center's Scripts tab requires scripts. Script execution actions check script view permissions. Without this, the Scripts tab and script-related actions are hidden.                                                                                                                                                                                                                                                                                                 |
| EDL                   | View/Edit                        | Add EDLs from the Action Center.                                                                                                                                                                                                                                                                                                                                                                                                                                           |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/response-permissions-1/action-center-permissions.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
