Learn more about managing access to saved queries in Cortex XDR.
Review the following:
The Query Library serves as the central repository for your team's investigation logic. By using object-level access, you can ensure that specific Cortex Query Language (XQL) queries, such as those used for sensitive internal investigations or executive reporting, are only accessible to authorized users, user groups, and API keys.
Prerequisite
Configure tenant-level settings: An administrator must first establish the sharing framework under → → → .
The configuration of these settings defines the authorized sharing workflows for saved queries in the Query Library, including the options that appear to users when clicking the three dot, vertical ellipsis (⋮) for a query in the Query Library:
Enable "Owners can Share objects they created": Grants owners the ability to share saved queries with specific users, user groups, and API keys to the query's access list. In the Query Library, this enables the Share option.
Disable "Owners can Share objects they created": Restricts owners to managing only General access (Public vs. Restricted). In the Query Library, this replaces the Share option with the Manage Access option.
For more information on these tenant-level configurations, see Manage access to objects.