Skip to main content

Available Roles & Permissions

Service Roles

Risk Overview

Centralized view of overall organizational risk posture, trends, and top vulnerabilities.

RolePermission KeyDescription
Viewrisk.viewAllows user to view dashboards, lists, and read-only data.
Exportrisk.exportAllows exporting of scan data, reports, vulnerabilities, and analytics.

Network Perimeter

Visibility into attack surface, exposed ports, services, and network vulnerabilities.

RolePermission KeyDescription
Viewnetwork.viewAllows user to view dashboards, lists, and read-only data.
Createnetwork.createAllows creation of scans, assets, users, or resources depending on service.
Managenetwork.manageAllows modification, updates, and administrative control within a service.
Create & Managenetwork.create_manageCombined role offering both create and manage permissions.
Commentscomments
Full Accessnetwork.full_accessComplete control including create, manage, import/export, and administrative privileges.
Exportnetwork.exportAllows exporting of scan data, reports, vulnerabilities, and analytics.
Importnetwork.importAllows importing assets, scan data, configurations, and external resources.
Allow AI Usenetwork.ai_useGrants ability to query and interact with AI Agent for analysis, RCA, and security automation.

Cloud Workload Risks

Identification and analysis of cloud misconfigurations, IAM issues, and cloud security risks.

RolePermission KeyDescription
Viewcloud.viewAllows user to view dashboards, lists, and read-only data.
Createcloud.createAllows creation of scans, assets, users, or resources depending on service.
Managecloud.manageAllows modification, updates, and administrative control within a service.
Create & Managecloud.create_manageCombined role offering both create and manage permissions.
Full Accesscloud.full_accessComplete control including create, manage, import/export, and administrative privileges.
Exportcloud.exportAllows exporting of scan data, reports, vulnerabilities, and analytics.
Importcloud.importAllows importing assets, scan data, configurations, and external resources.
Allow AI Usecloud.ai_useGrants ability to query and interact with AI Agent for analysis, RCA, and security automation.

Code Security

Security analysis of source code, repositories, pipelines, secrets, and SCA/DAST findings.

RolePermission KeyDescription
Viewcode.viewAllows user to view dashboards, lists, and read-only data.
Createcode.createAllows creation of scans, assets, users, or resources depending on service.
Managecode.manageAllows modification, updates, and administrative control within a service.
Create & Managecode.create_manageCombined role offering both create and manage permissions.
Full Accesscode.full_accessComplete control including create, manage, import/export, and administrative privileges.
Developer Accesscode.developer_accessGrants developer-centric capabilities such as viewing and triaging code findings, linking fixes to repos, and CI/CD integration management.
Exportcode.exportAllows exporting of scan data, reports, vulnerabilities, and analytics.
Importcode.importAllows importing assets, scan data, configurations, and external resources.
Allow AI Usecode.ai_useGrants ability to query and interact with AI Agent for analysis, RCA, and security automation.

Cloud Security Posture Management (CSPM)

Continuous assessment of cloud infrastructure to identify misconfigurations, compliance gaps, and security risks across AWS, Azure, and GCP.

RolePermission KeyDescription
Viewcspm.viewAllows user to view dashboards, lists, and read-only data.
Createcspm.createAllows creation of scans, assets, users, or resources depending on service.
Managecspm.manageAllows modification, updates, and administrative control within a service.
Create & Managecspm.create_manageCombined role offering both create and manage permissions.
Full Accesscspm.full_accessComplete control including create, manage, import/export, and administrative privileges.
Cloud Engineer Accesscloud_engineer_access
Exportcspm.exportAllows exporting of scan data, reports, vulnerabilities, and analytics.
Importcspm.importAllows importing assets, scan data, configurations, and external resources.
Allow AI Usecspm.ai_useGrants ability to query and interact with AI Agent for analysis, RCA, and security automation.

Web Application & API Security Testing

Automated and manual security testing of web applications and APIs, including DAST, API fuzzing, authentication testing, and vulnerability discovery.

RolePermission KeyDescription
Viewweb.viewAllows user to view dashboards, lists, and read-only data.
Createweb.createAllows creation of scans, assets, users, or resources depending on service.
Manageweb.manageAllows modification, updates, and administrative control within a service.
Create & Manageweb.create_manageCombined role offering both create and manage permissions.
Full Accessweb.full_accessComplete control including create, manage, import/export, and administrative privileges.
Tester Accesstester_access
Exportweb.exportAllows exporting of scan data, reports, vulnerabilities, and analytics.
Importweb.importAllows importing assets, scan data, configurations, and external resources.
Allow AI Useweb.ai_useGrants ability to query and interact with AI Agent for analysis, RCA, and security automation.

AI Agent

AI-powered security assistant for RCA, patch scripts, analysis, and Q&A across the platform.

RolePermission KeyDescription
Viewai_agent.viewAllows user to view dashboards, lists, and read-only data.
Allow AI Useai_agent.ai_useGrants ability to query and interact with AI Agent for analysis, RCA, and security automation.
Manageai_agent.manageAllows modification, updates, and administrative control within a service.
Full Accessai_agent.full_accessComplete control including create, manage, import/export, and administrative privileges.

Integrations

Connect and manage external integrations such as GitHub, Azure, AWS, Jira, ServiceNow, Slack.

RolePermission KeyDescription
Viewintegrations.viewAllows user to view dashboards, lists, and read-only data.
Createintegrations.createAllows creation of scans, assets, users, or resources depending on service.
Manageintegrations.manageAllows modification, updates, and administrative control within a service.
Create & Manageintegrations.create_manageCombined role offering both create and manage permissions.
Full Accessintegrations.full_accessComplete control including create, manage, import/export, and administrative privileges.
Importintegrations.importAllows importing assets, scan data, configurations, and external resources.
Exportintegrations.exportAllows exporting of scan data, reports, vulnerabilities, and analytics.

Billing & Subscriptions

Manage subscriptions, invoices, usage metrics, payments, and financial configuration.

RolePermission KeyDescription
Viewbilling.viewAllows user to view dashboards, lists, and read-only data.
Managebilling.manageAllows modification, updates, and administrative control within a service.
Full Accessbilling.full_accessComplete control including create, manage, import/export, and administrative privileges.

Comments & Notes

Add, view, and manage comments and notes on vulnerabilities, scans, and findings across all security dashboards.

RolePermission KeyDescription
Viewcomments.viewAllows user to view dashboards, lists, and read-only data.
Editedit

Unified Findings

Consolidated view of security findings across code, cloud, web, API, and infrastructure scans with filtering, prioritization, and remediation context.

RolePermission KeyDescription
Viewunified.viewAllows user to view dashboards, lists, and read-only data.
Exportunified.exportAllows exporting of scan data, reports, vulnerabilities, and analytics.
Allow AI Useunified.ai_useGrants ability to query and interact with AI Agent for analysis, RCA, and security automation.

Asset Inventory

Comprehensive inventory of infrastructure, cloud resources, applications, repositories, APIs, and services with ownership, exposure, and risk context.

RolePermission KeyDescription
Viewasset.viewAllows user to view dashboards, lists, and read-only data.
Manageasset.manageAllows modification, updates, and administrative control within a service.
Exportasset.exportAllows exporting of scan data, reports, vulnerabilities, and analytics.

Quick Roles

RoleDescriptionPermissions
AuditorComplete read-only access across the platform for compliance, audit, and investigation.all.read
Billing ManagerFull access to billing, subscriptions, invoices, and payment configurations.billing.full_access
CISO/CXOTop management role with full visibility across all dashboards but without modification rights.all.read, all.export, all.ai_use
Co-AdminAdvanced admin role with high-level management access across services except billing.all.manage_except_billing
DeveloperDeveloper-focused role with access to code security, CI/CD, repos, and developer insights.code.full_access, code.ai_usage
Security AnalystCan view, triage, classify, and assign vulnerabilities but cannot modify platform settings.risk.view, cloud.view, network.view, code.view, export
Security EngineerCan remediate vulnerabilities, run scans, manage integrations, and use AI Agent.network.manage, cloud.manage, code.manage, all.ai_use, integrations.manage
Viewer (Global)Global view-only role for users needing read-only access across all modules.all.view
Read-Write Except DeleteCustom role allowing edits and creations but preventing destructive actions.create, manage