Role-based permissions in Cortex XSOAR
Review role-based permissions available in Cortex XSOAR 8 SaaS.
When creating or editing a role, you can set permission levels (RBAC) for specific components (such as playbooks, scripts, jobs, etc.), set page access, define preset role queries, and set up shift management.
In the Cortex tenant, you can set permission levels for each role by going to Settings → Settings & Info → Access Management → Roles and editing or creating a new role.
If using Cortex Gateway, go to Permission Management → Roles.
Note
You can only create, edit, copy, or delete a role if you have administrator (Instance/Account Admin) permissions. You cannot change the predefined (Instance Administrator or Account Admin) role permissions.
Advanced permissions, such as shift management are not available in Cortex Gateway.
Each role contains the following tabs:
The Components tab
The Components tab includes the following areas where you can define permissions.
Data
Data
Sets the permission level generally for data related to investigations, dashboards, and reports. If you select none, the user role cannot view and edit incidents, indicators, dashboards, and reports.
Execute potential harmful actions
Allows executing integration commands that are marked as Potentially Harmful in the integration code/settings. Users can run these commands from the CLI. Playbook tasks that use these commands would not be affected, as they are run by the DBot user as part of playbook execution.
Edit incident properties
Allows editing an incident's fields from the layout or via the Actions menu.
Change the incident status
Allows closing or reopening an incident.
Delete incidents
Allows deleting incidents. We recommend only granting this permission to the default Admin or select Administrators.
Manage incident workplan
Allows interacting with the playbook for the incident.
Edit indicators
Allows editing indicators either from the Threat Intel pane or when viewing the indicator via its full layout or quick view tab.
Retain incidents
Allows marking an incident for permanent retention or disabling retention for an incident. Retained incidents cannot be deleted.
Incidents Table Actions
Limits table actions in the Incidents page, such as delete, command line actions, edit, close, and mark as duplicate.
Exclusion list
EXCLUSION LIST
Limits permissions when editing, creating, or deleting an indicator in an exclusion list.
Playbooks
Playbooks
Limits permissions for creating, editing, and deleting playbooks.
Scripts
Scripts
Limits permissions for managing scripts. If the role has read/write permissions, you can enable user roles to create scripts that run as a Super User.
On the Scripts page, you can define which roles are permitted to run a script, and according to which role the script executes.
Jobs
Jobs
Limits permissions for managing jobs. Roles that have read permissions to content items, retain partial read access. If you do not want to retain partial read access, set the permission to none.
Marketplace
Marketplace
You can set the following permissions for Marketplace.
None: The user role is not able to view Marketplace.
View: The user role can view, but not take any action in Marketplace.
View/Edit: The user role can install, upgrade, downgrade, and delete content packs in Marketplace.
Configurations
General Setting
Auditing
Whether a user role can access the Management Audit Logs page.
General Setting
Alert Notifications
Whether a user role can forward Management Audit Logs to an email distribution list or a syslog server.
Integrations
Public API
Whether a user role can access the API Keys page. View/Edit enables the user role to manage API keys, including creating, editing, and deleting.
Integrations
Integrations
Whether a user role can view, add, edit, or delete integration instances, pre-process rules, and classify and map incidents and indicators.
Roles that have view permissions for content items, retain partial read access. If you do not want to retain partial read access, set the permission to none.
Integrations
Integrations Permissions
Enables you to set the permissions on the Integration Permissions page. Integration permissions enable you to assign different permission levels for the same command in each instance.
None: The user role cannot view the page.
View: The user can view the page.
View/Edit: The user can view and edit permissions.
Integrations
Credentials
Whether a user role can add, edit, or delete integration credentials.
Object Setup
Fields and Types
Whether a user can add, edit, or delete fields and types for indicators, incidents, and Threat Intel Reports.
Object Setup
Layouts
Whether a user can add, edit, or delete layouts for indicators, incidents, and Threat Intel Reports.
Advanced
Propagation Labels
(Multi-tenant only) Enables the user role to determine which content items can be synced to child tenants. You can select:
None: The user role cannot select a propagation label.
View: The user role selects from existing propagation labels.
View/Edit: The user role can create new labels and select existing propagation labels.
Advanced
Administration
Limits permissions for administration tasks, such as server configurations, audit trails, and changing logos.
Advanced
Tenant Management
(Multi-Tenant Only) If you have View or View/Edit permissions, you can select whether the role can sync content to tenant accounts. If you have View/Edit permissions you can edit content (such as playbooks and scripts) in the parent tenant.
Page Access
Select the pages the user role should have access to.
Note
If you select None in the Data section, even though you allow page access, the user role cannot access those pages. For example, if you allow page access to Dashboards, but DATA is set to None, the user role cannot access the Dashboards page.
The Advanced tab
You can only access this tab when creating or editing a role in the XSOAR tenant. You can add these settings to roles created in Cortex Gateway.
DEFAULT DASHBOARDS
Select the default dashboards for each role. If a user has not modified their dashboard, these dashboards are added automatically; otherwise, users can add these dashboards to their existing dashboards. For more information, see Define dashboards.
PRE-SET ROLE QUERIES
Select the preset query for each of the available components. For more information, see Define preset role queries.
SHIFTS
Weekly shifts start on Sunday and are specified in the UTC zone. For more information about setting up shifts, see Set up shift management.
Last updated
Was this helpful?
