> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/deployment-steps/set-up-users-and-roles/assign-user-roles-and-groups.md).

# Assign user roles and groups

Assign roles directly to users or create user groups and assign roles to those groups. We recommend creating user groups (with a user role), and assigning users to those user groups rather than creating direct roles for each user.

{% hint style="info" %}

### Note

If an existing user in the Cortex Gateway no longer has a role or a user group assigned, the user is revoked. Any roles, user groups, or egress configurations created by that user are shown as created by **Revoked user** instead of the user’s email address.
{% endhint %}

## Assign a user/user group to a role

Cortex XSIAM provides predefined built-in user roles that provide specific access rights that cannot be modified. You can also create custom, editable user roles. If a user does not have any Cortex XSIAM access permissions that are assigned specifically to them, the field displays **No-Role**.

1. Select **Settings** → **Configurations** → **Access Management** → **Users**.
2. Right-click the relevant user, and select **Edit User Permissions**.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>To apply the same settings to multiple users, select them, and then right-click and select <strong>Edit Users Permissions</strong>.</p></div>
3. Ensure the **Role** tab is selected.
4. Under **Role**, select the default or custom role.
5. (Optional) Under **User Groups**, add the user to a group.
6. (Optional) Under **Show Accumulated Permissions**:
   1. Do one of the following:
      * Select all to view the combined permissions for every role and user group assigned to the user.
      * Select a specific role assigned to the user to view the available permissions for that role.
   2. Under **Components**, expand each list to view the permissionsSetting Cortex Query Language (XQL) dataset access permissions for a user role can only be performed from **Cortex XSIAM Access Management**. For more information, see [Manage user roles](/cortex-xsiam/onboard-cortex-xsiam/post-deployment/manage-user-roles-and-access-management.md#UUID-751d26ed-9390-dddd-d4f6-bb1f20db3a1d).
7. (Optional) You can configure and manage granular scoping:

   1. Click the **Scope** tab.
   2. Under **Scope Definition**, expand the scoping areas that you want to grant the user role access to in the tenant by clicking the chevron icon (**>**) beside the scoping area title, and make any changes required. The following table explains the options available to configure:

      <div data-gb-custom-block data-tag="hint" data-style="warning" class="hint hint-warning"><p>Before configuring, ensure that you review <strong>Understand scoping</strong> in the <a href="/pages/wnVKplCzZ4bBbl0hYUGo#UUID-071cdbb6-6c6a-6afe-3a67-1fa79991a0a8">Manage user scope</a> section.</p></div>

      | Scoping Area                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | Granular Scoping Configurations                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
      | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
      | Assets                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | <p>Set the <strong>Scope</strong> by selecting one of the following:</p><ul><li><strong>No assets</strong>: No asset is accessible.</li><li><strong>All assets</strong>: Defines access to all assets.</li><li><strong>Select asset groups</strong>: Defines access to the specific assets associated with the Asset Groups selected, and to view all their related cases, issues, and findings for these specific assets and Asset Groups. Under <strong>Select asset groups</strong>, define the specific asset groups that you want to grant access. Only Asset Groups relevant for scoping are listed, which are asset groups that are using only the asset attributes listed in <a href="/pages/9AFGTx70crw2n7sT6yFu#UUID-071cdbb6-6c6a-6afe-3a67-1fa79991a0a8_section-idm235041053079477">Manage user scope</a> (under <strong>Understand scoping</strong> → <strong>Scoping Areas</strong> → <strong>Assets</strong>).</li></ul><p>The scoping of assets also affects the scoping of cases, issues, and findings.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>Visibility of Security domain Issues that refer to assets with agents is controlled by the <strong>Endpoints</strong> scoping configuration.</p></div>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
      | Cases and Issues                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | <p>Set the <strong>Scope</strong> by selecting one of the following:</p><ul><li><strong>No cases and issues</strong>: Defines access to no cases and issues.</li><li><strong>All cases and issues</strong>: Defines access to all cases and issues. Users can view cases or issues referencing assets within their scope. Use the <strong>Assets</strong> section to define which assets are in scope.</li><li><p><strong>Select domains</strong>: Defines access to the domains selected to view their related cases and issues. Under <strong>Select domains</strong>, define the specific domains that you want to grant access.</p><p>Users can only view cases or issues referencing assets and endpoints within their scope. Use the <strong>Assets</strong> section to define which assets are in scope.</p></li></ul><p>When selecting <strong>All cases and issues</strong> or <strong>Select domains</strong>, you can separately configure access to issues and cases that lack an asset reference or where the referenced asset is not in <strong>All Assets</strong> and <strong>All Endpoints</strong> inventories. To provide access, select the <strong>Allow access to cases and issues that are not referencing known assets or endpoints</strong> checkbox. Once selected, you can specifically control which users have access to issues and cases that lack <strong>Affected Assets</strong> (as seen in the issue’s panel) and <strong>Assets</strong> (as seen in the case's panel), or where the listed assets are not part of the Asset or Endpoint inventories. When the assets listed are not part of the inventories, the asset string is typically non-clickable. In some cases, such as for identity-related issues, assets may open a dedicated <strong>User Risk View</strong>, which differs from the standard inventories panels. In the <strong>Issues</strong> and <strong>Cases</strong> tables, such items can be identified by empty values in the following columns: Asset IDs, Target Agent Identifier, and Source Agent Identifier.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
      | Endpoints                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | <p>Set the <strong>Scope</strong> by selecting one of the following:</p><ul><li><strong>No endpoints</strong>: Defines access to no endpoints with no ability to view their related agent management and enterprise policies.</li><li><strong>All endpoints</strong>: Defines access to all endpoints with the ability to view their related agent management and enterprise policies. This configuration can impact the visibility of related <strong>Security</strong> domain <strong>Cases and Issues</strong>, but will not affect asset visibility.</li><li><strong>Select specific (at least one required)</strong>: Defines specific access to all endpoint groups by selecting <strong>Endpoint Groups</strong> or all endpoint tags by selecting <strong>Endpoint Tags</strong> to view their related agent management and enterprise policies. This configuration can impact the visibility of related <strong>Security</strong> domain <strong>Cases and Issues</strong>, but will not affect asset visibility.</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
      | Datasets Rows                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           | <p>Configure a <code>filter</code> to define the specific subset of rows a user is allowed to access in each raw dataset. A raw dataset is every dataset where Palo Alto Networks data is ingested out-of-the-box or third-party data is ingested using a configured dedicated collector, also called a data source. This filter configuration does not impact the visibility of cases and issues.</p><p>Follow these steps to configure a <code>filter</code>.</p><ol><li><p>For datasets where no <code>filter</code> is defined, determine how to set the When no filter is defined option as either:</p><ul><li>No rows are accessible (default): Without a configured <code>filter</code>, no rows are accessible. Users can query the datasets in Cortex Query Language (XQL) as they have access, but the results will be empty.</li><li>All rows are accessible: Without a configured <code>filter</code>, all rows are accessible. Users can query the datasets in Cortex Query Language (XQL) as they have access, and view all results.</li></ul><p>When defining a filter for row-level scoping on raw datasets, queries based on the Cortex Data Model (XDM) are not supported. XDM queries return specific rows only when All rows are accessible is selected and no filter is defined in the Datasets Rows scoping area. Otherwise, no rows are returned.</p></li><li><p>Define any filters for the applicable datasets listed in the table:</p><ol><li>Scroll down the list of datasets to the dataset you want to apply a <code>filter</code> on, and click the Edit Scope icon.</li><li><p>In the Define what rows are accessible window, continue to write the query for the <code>filter</code> in the query box (where the syntax is a limited subset of XQL) to limit the data rows for the selected dataset according to the access permissions you want the user to have. The beginning of the query is already defined before the query box, and there is no need to include this in your query.</p><p>For optimal performance, we recommend using a single field in the <code>filter</code> definition and simple comparison operators.</p><p>Supported syntax</p><p><strong>Fields</strong></p><p>You can define the rest of the <code>filter</code> in the query box, where only the following system fields are supported: <code>\_broker\_device\_id</code>, <code>\_broker\_device\_ip</code>, <code>\_broker\_device\_name</code>, <code>\_collector\_id</code>, <code>\_collector\_ip</code>, <code>\_collector\_name</code>, <code>\_collector\_type</code>, <code>\_device\_id</code>, <code>\_final\_reporting\_device\_ip</code>, <code>\_final\_reporting\_device\_name</code>, <code>\_log\_type</code>, <code>\_product</code>, <code>\_scope</code>, <code>\_reporting\_device\_ip</code>, <code>\_reporting\_device\_name</code>, and <code>\_vendor</code>.</p><p>For more information on these fields, see the table that describes all the fields in the <code>metrics\_source</code> dataset and <code>metrics\_view</code> preset in <a href="/spaces/AEIjuYE3RXcIfmuQnBbm/pages/PSslnZ5WBjBb2Sz27RdA">Overview of data ingestion metrics</a>. For more information on the <code>\_scope</code> field (relevant when <code>\_scope</code> is defined in the Parsing Rule), see \[Scenario 3: Supported fields don't provide the necessary segmentation] in Scenarios related to Datasets Rows scoping.</p><p><strong>Comparison operators</strong></p><p>The following comparison operators are supported:</p><ul><li>Exact matches (<code>=</code>, <code>!=</code>)</li><li>Comparing numerical values (<code>></code>, <code><</code>, <code>>=</code>, <code><=</code>)</li><li>Checking membership in lists (<code>in</code>)</li><li>Querying arrays (<code>array\_contains</code>)</li><li>Partial matches (<code>contains</code>, <code>starts\_with</code>): Using this operator has additional performance overhead, and we recommend avoiding its use.</li></ul><p>If you only want a user to be able to access rows in the <code>pan\_dds\_raw</code> dataset, when the <code>\_collector\_name</code> is <code>bu2\_collector</code> , you'd have to define the <code>filter</code> in the query box as:</p><pre><code>\_collector\_name = “bu2\_collector” |
      | </code></pre></li></ol></li></ol>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
      |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
      |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
      | <p><br></p><ul><li>(Optional) Set the Time frame for the query. The default is Last 1 day.</li><li>(Optional) You can preview the query results displayed based on your defined query by clicking Preview. You can edit your query until you're satisfied with the output. By default, the query results are limited to 1000 records.</li><li><p>When you are finished, click Done.</p><p>The Scope field for the dataset that you added the filter on is updated with the query.</p><p>In the above example, the Scope field displays <code>\_collector\_name = “bu2\_collector”</code>.</p></li></ul> |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Important</h3><p>By default, <strong>Enable Scope Based Access Control</strong> is disabled in Settings → Configurations → General → <strong>Server Settings</strong>, and granular scoping is not enforced. Before enabling SBAC, we recommend that an administrator or a user with <strong>Access Management</strong> permissions first ensures that the users, user groups, and API Keys defined in Cortex XSIAM are granted the required access by assigning the relevant scopes. For more information, see <a href="/pages/9AFGTx70crw2n7sT6yFu">Manage user scope</a>.</p></div>
8. Click Save.

**Perform additional tasks**

For more information about additional tasks such as creating a custom role, modifying a user's role, or removing a user's role, see [Manage user access](/cortex-xsiam/onboard-cortex-xsiam/post-deployment/manage-user-roles-and-access-management.md#UUID-a112c99e-112f-ab8a-e5ed-e31445dee8fe).


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/deployment-steps/set-up-users-and-roles/assign-user-roles-and-groups.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
