Overview of cases - Understand how cases work in Cortex XDR. - Administrator Guide - Cortex XDR - Cortex - Security Operations

Cortex XDR 5.x Documentation

Product
Cortex XDR
License
XDR + Cloud
Creation date
2025-07-13
Last date published
2026-06-04
Category
Administrator Guide
Abstract

Understand how cases work in Cortex XDR.

Understand how cases work in Cortex XDR.

Prerequisite

To work with cases, an administrator must configure your user role with specific RBAC permissions. Permissions must be enabled in the following order:

  1. Playbooks: This component (under Investigation & ResponseAutomations) must be set to Enabled first. Role-level permissions determine your ability to create new playbooks or edit those marked as Public. Specific access to individual custom playbooks and scripts is managed at the object level. For detailed information on the access model, see Access to playbooks.

  2. Cases and Issues: Once Playbooks are enabled, you can set Cases and Issues (under Cases & Issues) to View or View/Edit. This is also required to view the results of playbooks executed within a case.