> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/gateway-guide/roles-management/predefined-roles-in-cortex-gateway.md).

# Predefined roles in Cortex Gateway

Review the predefined roles for the relevant Cortex product:

<details>

<summary>Predefined roles for XSOAR</summary>

Cortex XSOAR includes the following out-of-the-box roles:

| Role                   | Type       | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| ---------------------- | ---------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Account Admin          | Predefined | <p>A super user role that is assigned directly to the user in Cortex Gateway or tenant and has full access to all Cortex products in your account, including all tenants added in the future. In Cortex Gateway, the Account Admin can assign roles for Cortex instances, and can also activate Cortex tenants specific to the product. This user has the same view/edit permissions in the tenant as the Instance Administrator.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>The user who activated the Cortex product is assigned the Account Admin role.</p><p>You can add the role to a user in Cortex Gateway or the tenant. If you need to remove the Account Admin role from a user, this can only be done in Cortex Gateway.</p><p>Only users with the Account Admin role can add or remove another Account Admin user role.</p></div><p>You cannot edit this role. You can copy the role by saving it as a new role and then change permissions.</p> |
| Instance Administrator | Predefined | <p>View/edit permissions for all components and access to all pages in the Cortex tenant. The Instance Administrator can also assign the Instance Administrator role to other users on the tenant. If the application has predefined or custom roles, the Instance Administrator can assign those roles to other users.</p><p>You cannot edit this role. You can copy the role by saving it as a new role and then change permissions.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| Analyst                | Custom     | <p>A mix of view and view/edit permissions for all components and access to all pages in the Cortex tenant.</p><p>Cortex products comes out-of-the-box with the following Analyst roles:</p><ul><li><p><img src="/files/wcqyFoSqkRZQs5f2w0wc" alt="gateway-analyst.png"> Analyst role created in Cortex Gateway.</p><p>This role applies to all tenants.</p><p>In the Cortex tenant, you cannot edit this role, apart from changing advanced settings such as default dashboards.</p><p>In Cortex Gateway, you can change permissions, apart from advanced settings. You can also delete the role (if not assigned to a user).</p></li><li><p><img src="/files/rWA4hix4J01jKv13BAX9" alt="tenant-analyst.png"> Analyst role created in the tenant.</p><p>This role is specific to the tenant. You can edit all permissions and delete the role (if not assigned to a user) in the tenant and Cortex Gateway. In Cortex Gateway, you cannot change advanced settings.</p></li></ul>                                                     |
| Read-Only              | Custom     | <p>Read permissions for all components and pages in the Cortex tenant.</p><p>Cortex products comes out-of-the-box with the following Read-Only roles:</p><ul><li><p><img src="/files/wcqyFoSqkRZQs5f2w0wc" alt="gateway-analyst.png"> Read-Only role created in Cortex Gateway.</p><p>This role applies to all tenants.</p><p>In the Cortex tenant, you cannot edit this role, apart from changing advanced settings such as default dashboards.</p><p>In Cortex Gateway, you can change permissions, apart from advanced settings. You can also delete the role (if not assigned to a user).</p></li><li><p><img src="/files/rWA4hix4J01jKv13BAX9" alt="tenant-analyst.png"> Read-Only role created in the tenant.</p><p>This role is specific to the tenant. You can edit all permissions and delete the role (if not assigned to a user) in the tenant and Cortex Gateway. In Cortex Gateway, you cannot change advanced settings.</p></li></ul>                                                                                    |

{% hint style="info" %}

### Note

By default, users do not have roles assigned. If no direct or user group role has been assigned, users have no permission to view or edit data in the Cortex tenant.
{% endhint %}

</details>

<details>

<summary>Predefined roles for XDR/XSIAM</summary>

Role-based access control (RBAC) enables you to use predefined Cortex XDR/XSIAM roles to assign access rights to Cortex XDR/XSIAM users. You can manage roles for all Cortex XDR/XSIAM tenants and services in the Gateway or in the Cortex XDR/XSIAM tenant. By assigning roles, you enforce the separation of access among functional or regional areas of your organization.

Each role extends specific privileges to users. The way you configure administrative access depends on the security requirements of your organization. Use roles to assign specific access privileges to administrative user accounts.

You can manage role permissions in Cortex XDR/XSIAM, which are listed by the various components according to the sidebar navigation in Cortex XDR/XSIAM. Some components include additional action permissions, such as pivot (right-click) options, to which you can also assign access, but only when you’ve given the user **View/Edit** permissions to the applicable component.

The default Cortex XDR/XSIAM roles provide a specific set of access rights to each role. You cannot edit the default roles directly, but you can save them as new roles and edit the permissions of the new roles. To view the predefined permissions for each default role, go to **Settings** → **Configurations** → **Access Management** → **Roles**.

{% hint style="info" %}

### Note

Some features are license-dependent. Accordingly, users may not see a specific feature if the feature is not supported by the license type or if they do not have access based on their assigned role.
{% endhint %}

| Default Role              | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| ------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Account Admin             | <p>A Super User role that is assigned directly to the user in Cortex Gateway and has full access to all Cortex products in your account, including all tenants added in the future. The Account Admin can assign roles for Cortex instances and activate Cortex tenants specific to the product.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>The user who activated the Cortex product is assigned the Account Admin role. You cannot create additional Account Admin roles in the Cortex XDR/XSIAM tenant. If you do not want the user to have Account Admin permission, you need to remove the Account Admin role in Cortex Gateway.</p></div> |
| Instance Administrator    | View and edit permissions for all components and access all pages in the Cortex XDR/XSIAM tenant. The Instance Administrator can also make other users an Instance Administrator for the tenant. If the tenant has predefined or custom roles, the Instance Administrator can assign those roles to other users.                                                                                                                                                                                                                                                                                                                                                                                                          |
| Deployment Admin          | Manage and control endpoints and installations, and configure Broker VMs.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| Investigator              | View and triage alerts and incidents.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| Investigation Admin       | View and triage alerts and incidents, configure rules, view endpoint profiles and policies, and analytics management screens.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| Responder                 | View and triage alerts, and access all response capabilities excluding Live Terminal.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| Privileged Investigator   | View and triage alerts, incidents, and rules, view endpoint profiles and policies, and analytics management screens.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| Privileged Responder      | View and triage alerts and incidents, access all response capabilities, and configure rules, policies, and profiles.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| IT Admin                  | Manage and control endpoints and installations, configure Broker VMs, view endpoint profiles and policies, and view alerts.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| Privileged IT Admin       | Manage and control endpoints and installations, configure Broker VMs, create profiles and policies, view alerts, and initiate Live Terminal.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| Privileged Security Admin | Triage and investigate alerts and incidents, and respond to and edit profiles and policies.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| Viewer                    | View the majority of the features for this instance and can edit reports.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| Scoped Endpoint Admin     | Can only access product areas that support endpoint scoped-based access control (SBAC) - Endpoint Administration, Action Center, Response, Dashboards and Reports.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| Security Admin            | Can triage and investigate alerts and incidents, respond (excluding Live Terminal), and edit profiles and policies.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |

</details>

<details>

<summary>Predefined roles for XSIAM Platform</summary>

Role-based access control (RBAC) enables you to use predefined Cortex XSIAM Platform roles to assign access rights to Cortex XSIAM Platform users. You can manage roles for all tenants and services in the Gateway or directly in the tenant. By assigning roles, you enforce the separation of access among functional or regional areas of your organization.

Each role extends specific privileges to users. The way you configure administrative access depends on the security requirements of your organization. Use roles to assign specific access privileges to administrative user accounts.

You can manage role permissions in Cortex XSIAM Platform, which are listed by the various components according to the sidebar navigation in Cortex XSIAM Platform. Some components include additional action permissions, such as pivot (right-click) options, to which you can also assign access, but only when you’ve given the user **View/Edit** permissions to the applicable component.

The default Cortex XSIAM Platform roles provide a specific set of access rights to each role. You cannot edit the default roles directly, but you can save them as new roles and edit the permissions of the new roles. To view the predefined permissions for each default role, in the tenant go to **Settings** → **Configurations** → **Access Management** → **Roles**.

{% hint style="info" %}

### Note

Some features are license-dependent. Accordingly, users may not see a specific feature if the feature is not supported by the license type or if they do not have access based on their assigned role.
{% endhint %}

| Default Role              | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Account Admin             | <p>A Super User role that is assigned directly to the user in Cortex Gateway and has full access to all Cortex products in your account, including all tenants added in the future. The Account Admin can assign roles for Cortex instances and activate Cortex tenants specific to the product.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>The user who activated the Cortex product is assigned the Account Admin role. You cannot create additional Account Admin roles in the Cortex tenant. If you do not want the user to have Account Admin permission, you need to remove the Account Admin role in Cortex Gateway.</p></div> |
| Instance Administrator    | View and edit permissions for all components and access all pages in the tenant. The Instance Administrator can also make other users an Instance Administrator for the tenant. If the tenant has predefined or custom roles, the Instance Administrator can assign those roles to other users.                                                                                                                                                                                                                                                                                                                                                                                                                 |
| Deployment Admin          | Manage and control endpoints and installations, and configure Broker VMs.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Investigator              | View and triage issues and cases.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| Investigation Admin       | View and triage issues and cases, configure rules, view endpoint profiles and policies, and analytics management screens.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Responder                 | View and triage issues, and access all response capabilities excluding Live Terminal.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| Privileged Investigator   | View and triage issues, cases, and rules, view endpoint profiles and policies, and analytics management screens.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| Privileged Responder      | View and triage issues and cases, access all response capabilities, and configure rules, policies, and profiles.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| IT Admin                  | Manage and control endpoints and installations, configure Broker VMs, view endpoint profiles and policies, and view issues.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| Privileged IT Admin       | Manage and control endpoints and installations, configure Broker VMs, create profiles and policies, view issues, and initiate Live Terminal.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| Privileged Security Admin | Triage and investigate issues and cases, and respond to and edit profiles and policies.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| Viewer                    | View the majority of the features for this instance.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| Compliance Administrator  |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| Developer                 | Have limited permissions primarily focused on viewing and monitoring security information. Access and analyze scan results, track progress, and collaborate with security teams. Does not include ability to modify detection rules, enforcements, or directly address security issues.                                                                                                                                                                                                                                                                                                                                                                                                                         |
| CLI Read Only Role        | View scripts, playbooks, credentials, and CLI tool.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| CLI Role                  | View scripts, playbooks, and credentials. View and edit permission for CLI tool.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| AppSec Admin              | Full permissions for all Cloud Application Security related activities. Create and modify detection rules within the Code/Build domain, track progress, and adjust enforcements as needed. Additionally, triage and investigate findings, issues, and cases spanning from code to cloud. The role also includes complete visibility into all cloud assets.                                                                                                                                                                                                                                                                                                                                                      |
| Scoped Agent Admin        | Can only access product areas that support endpoint scoped-based access control (SBAC) - Agent Administration, Action Center, Response, Dashboards and Reports.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| Security Admin            | Can triage and investigate issues and cases, respond (excluding Live Terminal), and edit profiles and policies.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| App Service Account       | View and triage issues, cases, and rules, and support public APIs relevant for apps.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |

</details>

<details>

<summary>Predefined roles for Cortex Cloud</summary>

Role-based access control (RBAC) enables you to use predefined Cortex Cloud roles to assign access rights to Cortex Cloud users. You can manage roles for all tenants and services in the Gateway or directly in the tenant. By assigning roles, you enforce the separation of access among functional or regional areas of your organization.

Each role extends specific privileges to users. The way you configure administrative access depends on the security requirements of your organization. Use roles to assign specific access privileges to administrative user accounts.

You can manage role permissions in Cortex Cloud, which are listed by the various components according to the sidebar navigation in Cortex Cloud. Some components include additional action permissions, such as pivot (right-click) options, to which you can also assign access, but only when you’ve given the user **View/Edit** permissions to the applicable component.

The default Cortex Cloud roles provide a specific set of access rights to each role. You cannot edit the default roles directly, but you can save them as new roles and edit the permissions of the new roles. To view the predefined permissions for each default role, in the tenant go to **Settings** → **Configurations** → **Access Management** → **Roles**.

{% hint style="info" %}

### Note

Some features are license-dependent. Accordingly, users may not see a specific feature if the feature is not supported by the license type or if they do not have access based on their assigned role.
{% endhint %}

| Default Role           | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| ---------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Account Admin          | <p>A Super User role that is assigned directly to the user in Cortex Gateway and has full access to all Cortex products in your account, including all tenants added in the future. The Account Admin can assign roles for Cortex instances and activate Cortex tenants specific to the product.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>The user who activated the Cortex product is assigned the Account Admin role. You cannot create additional Account Admin roles in the Cortex tenant. If you do not want the user to have Account Admin permission, you need to remove the Account Admin role in Cortex Gateway.</p></div> |
| Instance Administrator | View and edit permissions for all components and access all pages in the tenant. The Instance Administrator can also make other users an Instance Administrator for the tenant. If the tenant has predefined or custom roles, the Instance Administrator can assign those roles to other users.                                                                                                                                                                                                                                                                                                                                                                                                                 |
| Viewer                 | View the majority of the features for this instance.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| Developer              | Have limited permissions primarily focused on viewing and monitoring security information. Access and analyze scan results, track progress, and collaborate with security teams. Does not include ability to modify detection rules, enforcements, or directly address security issues.                                                                                                                                                                                                                                                                                                                                                                                                                         |
| CLI Read Only Role     | View scripts, playbooks, credentials, and CLI tool.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| CLI Role               | View scripts, playbooks, and credentials. View and edit permission for CLI tool.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| AppSec Admin           | Full permissions for all Cloud Application Security related activities. Create and modify detection rules within the Code/Build domain, track progress, and adjust enforcements as needed. Additionally, triage and investigate findings, issues, and cases spanning from code to cloud. The role also includes complete visibility into all cloud assets.                                                                                                                                                                                                                                                                                                                                                      |
| Security Admin         | Can triage and investigate issues and cases, respond (excluding Live Terminal), and edit profiles and policies.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |

</details>

<details>

<summary>Role-based permission levels for Cortex XPANSE</summary>

**Predefined User Roles for Cortex Xpanse**

Cortex Xpanse provides a set of predefined user roles that you can use to assign View and Edit permission to Cortex Xpanse users. Each predefined role extends a specific set of privileges to users. The permissions defined in the predefined roles cannot be changed, but you can save a predefined role as a new role and edit it as needed.

The following tables describe the permissions defined for each of the predefined roles.

[Account Admin](#UUID-a460cba2-7f04-24a2-ded5-6f41013d8f7c_section-idm143400150018128_body)

The following table shows the permissions for the predefined role **Account Admin**.

| Section                  | Component               | Permissions |                                                                                    |                                                                                    |
| ------------------------ | ----------------------- | :---------: | :--------------------------------------------------------------------------------: | :--------------------------------------------------------------------------------: |
|                          |                         |   **None**  |                                      **View**                                      |                                    **View/Edit**                                   |
| **Dashboards & Reports** | Dashboards              |      -      |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |
|                          | Reports                 |      -      |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |
| **Incident Response**    | Alerts & Incidents      |      -      |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |
|                          | Query Center            |      -      |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |
|                          | Personal Query Library  |      -      |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |
|                          | Playbooks               |      -      |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |
|                          | Remediation Path Rules  |      -      |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |
|                          | Attack Surface Rules    |      -      |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |
| **Assets**               | Network Configuration   |      -      |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |
|                          | Asset Inventory         |      -      |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |
|                          | Business Unit Overrides |      -      |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |
|                          | Websites                |      -      | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |                                          -                                         |
| **Marketplace**          | Browse                  |      -      |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |
| **Configurations**       | Auditing                |      -      | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |                                          -                                         |
|                          | General Configuration   |      -      |                                         --                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |
|                          | Alert Notifications     |      -      |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |
|                          | Integrations            |      -      |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |
|                          | Public API              |      -      |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |

[Instance Admin](#UUID-a460cba2-7f04-24a2-ded5-6f41013d8f7c_section-idm452718510969763327740572223_body)

The following table shows the permissions for the predefined role **Instance Admin**.

| Section                        | Component              |                                     Permissions                                    |                                                                                    |                                                                                    |
| ------------------------------ | ---------------------- | :--------------------------------------------------------------------------------: | :--------------------------------------------------------------------------------: | :--------------------------------------------------------------------------------: |
|                                |                        |                                      **None**                                      |                                      **View**                                      |                                    **View/Edit**                                   |
| **Dashboards & Reports**       | Dashboards             |                                          -                                         |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |
|                                | Reports                |                                          -                                         |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |
| **Incident Response**          | Incidents and Alerts   |                                          -                                         |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |
|                                | Query Center           | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |                                          -                                         |                                          -                                         |
|                                | Personal Query Library | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |                                          -                                         |                                          -                                         |
|                                | Playbooks              |                                          -                                         |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |
| **Detection and Threat Intel** | Attack Surface Rules   |                                          -                                         |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |
| **Assets**                     | Network Configuration  | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |                                          -                                         |                                          -                                         |
|                                | Compliance             | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |                                          -                                         |                                          -                                         |
| **Assets**                     | Websites               |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |                                          -                                         |
|                                | Asset Inventory        |                                          -                                         |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |
| **Marketplace**                | Browse                 |                                          -                                         |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |
| **Settings**                   | Auditing               |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |                                          -                                         |
|                                | General Configuration  |                                          -                                         |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |
|                                | Alert Notifications    |                                          -                                         |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |
|                                | Integrations           |                                          -                                         |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |
|                                | Public API             |                                          -                                         |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |

[Analyst](#UUID-a460cba2-7f04-24a2-ded5-6f41013d8f7c_section-idm45220633476352333260203094_body)

The following table shows the permissions for the predefined role **Analyst**.

| Section                        | Component              |                                     Permissions                                    |                                                                                    |                                                                                    |
| ------------------------------ | ---------------------- | :--------------------------------------------------------------------------------: | :--------------------------------------------------------------------------------: | :--------------------------------------------------------------------------------: |
|                                |                        |                                        None                                        |                                        View                                        |                                      View/Edit                                     |
| **Dashboards & Reports**       | Dashboards             |                                          -                                         |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |
|                                | Reports                |                                          -                                         |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |
| **Incident Response**          | Incidents and Alerts   |                                          -                                         |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |
|                                | Query Center           |                                          -                                         |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |
|                                | Personal Query Library |                                          -                                         |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |
| **Detection and Threat Intel** | Attack Surface Rules   |                                          -                                         |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |
| **Assets**                     | Websites               |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |                                          -                                         |
|                                | Asset Inventory        |                                          -                                         |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |
| **Marketplace**                | Browse                 |                                          -                                         |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |
| **Settings**                   | Auditing               | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |                                          -                                         |                                          -                                         |
|                                | General Configuration  | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |                                          -                                         |                                          -                                         |
|                                | Alert Notifications    | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |                                          -                                         |                                                                                    |
|                                | Integrations           |                                          -                                         |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |
|                                | Public API             |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |                                          -                                         |

[Security Engineer](#UUID-a460cba2-7f04-24a2-ded5-6f41013d8f7c_section-idm4654583494377633326029782765_body)

The following table shows the permissions for the predefined role **Security Engineer**.

| Section                        | Component              |                                     Permissions                                    |                                                                                    |                                                                                    |
| ------------------------------ | ---------------------- | :--------------------------------------------------------------------------------: | :--------------------------------------------------------------------------------: | :--------------------------------------------------------------------------------: |
|                                |                        |                                        None                                        |                                        View                                        |                                      View/Edit                                     |
| **Dashboards & Reports**       | Dashboards             |                                          -                                         |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |
|                                | Reports                |                                          -                                         |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |
| **Incident Response**          | Incidents and Alerts   |                                          -                                         |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |
|                                | Query Center           |                                          -                                         |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |
|                                | Personal Query Library |                                          -                                         |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |
|                                | Playbooks              |                                          -                                         |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |
| **Detection and Threat Intel** | Attack Surface Rules   |                                          -                                         |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |
| **Assets**                     | Websites               |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |                                          -                                         |
|                                | Asset Inventory        |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |                                          -                                         |
| **Marketplace**                | Browse                 |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |                                                                                    |
| **Settings**                   | Auditing               | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |                                          -                                         |                                          -                                         |
|                                | General Configuration  |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |                                          -                                         |
|                                | Alert Notifications    | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |                                          -                                         |                                          -                                         |
|                                | Integrations           |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |                                          -                                         |
|                                | Public API             |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |                                          -                                         |

[Privileged IT Admin](#UUID-a460cba2-7f04-24a2-ded5-6f41013d8f7c_section-idm4522063318030433326057430531_body)

The following table shows the permissions for the predefined role **Privileged IT Admin**.

| Section                        | Component              |                                     Permissions                                    |          |                                                                                    |
| ------------------------------ | ---------------------- | :--------------------------------------------------------------------------------: | :------: | :--------------------------------------------------------------------------------: |
|                                |                        |                                      **None**                                      | **View** |                                    **View/Edit**                                   |
| **Dashboards & Reports**       | Dashboards             | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |     -    |                                          -                                         |
|                                | Reports                | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |     -    |                                          -                                         |
| **Incident Response**          | Incidents and Alerts   | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |     -    |                                          -                                         |
|                                | Query Center           | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |     -    |                                          -                                         |
|                                | Personal Query Library | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |     -    |                                          -                                         |
|                                | Playbooks              |                                          -                                         |     -    | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |
| **Detection and Threat Intel** | Attack Surface Rules   | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |     -    |                                          -                                         |
| **Assets**                     | Websites               | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |     -    |                                          -                                         |
|                                | Asset Inventory        | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |     -    |                                          -                                         |
| **Marketplace**                | Browse                 |                                          -                                         |     -    | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |
| **Settings**                   | Auditing               | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |     -    |                                          -                                         |
|                                | General Configuration  |                                          -                                         |     -    | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |
|                                | Alert Notifications    | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |     -    |                                          -                                         |
|                                | Integrations           |                                          -                                         |     -    | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |
|                                | Public API             |                                          -                                         |     -    | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |

[Viewer](#UUID-a460cba2-7f04-24a2-ded5-6f41013d8f7c_section-idm4659587477665633326065697214_body)

The following table shows the permissions for the predefined role **Viewer**.

| Section                        | Component              |                                     Permissions                                    |                                                                                    |                                                                                    |
| ------------------------------ | ---------------------- | :--------------------------------------------------------------------------------: | :--------------------------------------------------------------------------------: | :--------------------------------------------------------------------------------: |
|                                |                        |                                      **None**                                      |                                      **View**                                      |                                    **View/Edit**                                   |
| **Dashboards & Reports**       | Dashboards             |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |                                          -                                         |
|                                | Ingestion Monitoring   | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |                                          -                                         |                                          -                                         |
|                                | Reports                |                                          -                                         |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |
| **Incident Response**          | Incidents and Alerts   |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |                                          -                                         |
|                                | Query Center           |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |                                          -                                         |
|                                | Personal Query Library |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |                                          -                                         |
|                                | Playbooks              |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |                                          -                                         |
| **Detection and Threat Intel** | Attack Surface Rules   |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |                                          -                                         |
|                                | Threat Intel           | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |                                          -                                         |                                          -                                         |
|                                | Asset Inventory        |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |                                          -                                         |
| **Marketplace**                | Browse                 |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |                                          -                                         |
| **Settings**                   | Auditing               |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |                                          -                                         |
|                                | General Configuration  |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |                                          -                                         |
|                                | Alert Notifications    |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |                                          -                                         |
|                                | Integrations           |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |                                          -                                         |
|                                | Public API             |                                          -                                         | <img src="/files/JcwXYRoJ1nozrlM3wBRv" alt="checkmark-n.png" data-size="original"> |                                          -                                         |

</details>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/gateway-guide/roles-management/predefined-roles-in-cortex-gateway.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
