> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/cases-and-issues-permissions.md).

# Cases and Issues permissions

The Cases & Issues section is the heartbeat of SOC operations. It is the primary workspace where alerts are aggregated into issues, and issues are escalated into cases for full-scale investigation.

Limits permissions to the **Cases**, **Issues**, and **Case Configuration** pages. It controls how analysts interact with security events, from the initial triage of a single issue to the coordinated response to a multi-stage attack.

{% hint style="warning" %}

### Caution

* To set Cases & Issues to View or View/Edit, you must first set the Scripts and Playbooks permissions to **Enabled**.
* When SBAC is set to **Restrictive** mode, users who don't have all the required tags shouldn't be able to read or edit the parent case (fields or context). For more information on setting restrictive mode, see [Configure server settings](/cortex-xsiam/onboard-cortex-xsiam/post-deployment/configure-server-settings.md).
* If users are assigned all tags on a child issue and have **View/Edit** permissions on **Cases and Issues** and **Run Playbooks**, they can trigger a playbook that could potentially change the parent case (even though users should not be able to do so according to SBAC). In this case, you can grant **Add Trigger Playbook** permissions, so users can bypass SBAC on the parent case fields and context data. For more information about updating fields in a playbook, see [Update case fields](/cortex-xsiam/configure-cortex-xsiam/customize-cases-and-issues/customize-case-fields-and-layouts/case-fields/update-case-fields.md).
* Users with **View** access to **Cases and Issues** can also view and edit Lists (under **Settings** → **Configurations** → **Object Setup** → **Lists**), provided they also have Script permissions.
  {% endhint %}

| Permission | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | Roles Example                                                                                                                                                                                          |
| ---------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| None       | Users cannot access **Cases**, **Issues**, and **Case Configuration** pages.                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |                                                                                                                                                                                                        |
| View       | Users can view cases and issues, see details, review investigation data, and view the **Case Configuration** page. Users cannot modify or take actions.                                                                                                                                                                                                                                                                                                                                                                                                  |                                                                                                                                                                                                        |
| View/Edit  | <p>Full access to cases, issues, and case configuration. Users can view, modify, investigate, and take actions. Additional sub-permissions become available:</p><ul><li><strong>Run Playbooks</strong>: Allows users to attach and trigger playbooks on issues for automated response</li><li><strong>Create Case</strong>: Allows users to manually create new cases from issues or other sources.</li><li><strong>Restrict Case Access:</strong> Allows users to change access to the case from the default scope to the assigned team only.</li></ul> | Most analyst roles should include View/Edit permissions to enable deeper investigation and case management. **Run Playbooks** and R**estrict Case Access** are not selected by default for most roles. |

**Required and recommended permissions**

For a Power User, the following permissions are essential for a complete investigation:

{% hint style="info" %}

### Note

Some roles require specific permissions. For example, a Security Engineer may require View/Edit for Playbooks, but a SOC Tier-1 Analyst does not.
{% endhint %}

| Permission          | Permission Level                            | Reason                                                                                                                                                                                                                                                                                                                                                                                                                |
| ------------------- | ------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Query Center        | View/Edit                                   | XQL query results embedded in cases show errors without this. All roles need to view the query output for the case context. Required.                                                                                                                                                                                                                                                                                 |
| Query Library       | Enabled                                     | Strongly recommended/recommended. Allows saving and organizing personal XQL queries for reuse across investigations and rule development.                                                                                                                                                                                                                                                                             |
| Playbooks           | Enabled or Enabled with checkboxes selected | <ul><li>Enabled: Required. All roles need to be able to see the automated response history and playbook outputs.</li><li>Enabled with checkboxes selected: Required/strongly recommended. Create/modify playbooks for automated investigation and response workflows. Core for SOC Tier-3 Analysts and Security Engineers.</li></ul>                                                                                  |
| Scripts             | Enabled or Enabled with checkboxes selected | <ul><li>Enabled: Required for most roles. Script output sections in cases are hidden without this. Needed to review automated enrichment and remediation results.</li><li>Enabled with checkboxes selected: Required for Security Engineers/Strongly recommended for SOC Tier-3, Threat Hunters, and Security Admins. Create/edit scripts for custom automation logic and specialized investigation tasks.</li></ul>  |
| Asset Inventory     | View or View/Edit                           | <ul><li>View: Required for most roles. The assets section in the case details is hidden without this. Need to see which hosts/users are involved in a case.</li><li>View/Edit: Strongly recommended/recommended for SOC Tier-3 Analysts, Threat Hunters, and Security Admins. Allows tagging and annotating assets during investigations.</li></ul>                                                                   |
| Threat Intelligence | View or View/Edit                           | <ul><li>View: Required/Strongly recommended/recommended for all roles. Indicator enrichment data in cases is hidden without this. Needed for IOC context (reputation, WHOIS) during triage.</li><li>View/Edit: Strongly recommended/recommended for SOC Tier-3 Analysts, Threat Hunters, Security Admins, and Engineers. Create/edit IOCs. Hunters need to add custom indicators discovered during hunting.</li></ul> |
| Actions Center      | View or View/Edit                           | <ul><li>View: Required/Strongly recommended for most roles. Response action history is not visible without this. Needed to see containment actions taken and their status.</li><li>View/Edit: Required for SOC Tier-3 Analysts, Threat Hunters, and Security Admins. Execute response actions (isolate, quarantine, block) during active case response.</li></ul>                                                     |
| Forensics           | View or View/Edit                           | <ul><li>View: Recommended for SOC Tier-2 Analyst. Access host vulnerability and configuration data to assess the attack surface during investigations.</li><li>View/Edit: Required for SOC Tier 3 Analysts and Threat Hunters. Strongly recommended for Security Admins. Initiate host scans and file searches from host insights during investigations.</li></ul>                                                    |
| Host Insights       | View or View/Edit                           | <ul><li>View: Required for SOC Tier-3 Analyst and Threat Hunter. Strongly recommended for Security Admin. Access host vulnerability and configuration data to assess the attack surface during investigations.</li><li>View/Edit: Strongly recommended for SOC Tier-3 Analysts, Threat Hunters, and Security Admins. Initiating host scans and file searches from host insights during investigations.</li></ul>      |
| Graph Search        | View or View/Edit                           | <ul><li>View: Visual investigation of entity relationships. Hunters use graph search to discover lateral movement and attack paths.</li><li>View/Edit: Save and share graph search queries for team collaboration.</li></ul><p>Strongly recommended for SOC Tier-3 Analysts and Threat Hunters. Recommended for Security Admins.</p>                                                                                  |
| Dashboards          | Enabled or Enabled with checkboxes selected | <ul><li>Enabled: Used for queue prioritization and security posture assessment. Recommended for all roles.</li><li>Enabled with checkboxes selected: Create custom dashboards for hunting campaigns, rule monitoring, and investigation tracking. Recommended/Strongly recommended for SOC Tier-3 Analysts, Threat Hunters, Security Engineers, and Security Admins.</li></ul>                                        |
| Reports             | Enabled or Enabled with checkboxes selected | <ul><li>Enabled: View pre-built reports for shift handoff, trend analysis, and compliance evidence. Recommended for all roles.</li><li>Enabled with checkboxes selected: Create custom reports for hunting findings, rule performance, and executive briefings. Recommended/Strongly recommended for SOC Tier-3 Analysts, Threat Hunters, Security Engineers, and Security Admins.</li></ul>                          |
| Integrations        | View                                        | Integration data in cases is hidden without this. Useful for seeing third-party enrichment results (VirusTotal, MISP). Recommended for all roles.                                                                                                                                                                                                                                                                     |
| Detection Rules     | View or View/Edit                           | <ul><li>View: View detection rules to understand issue generation logic. Recommended/Strongly recommended for SOC Tier-3 Analysts, Threat Hunters, and Security Admins.</li><li>View/Edit: Create and modify BIOC, IOC, and correlation rules. Core for Security Engineers and strongly recommended for Security Admins.</li></ul>                                                                                    |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/cases-and-issues-permissions.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
