AI Prompts - Configure access to AI Prompts when using the Cortex Agentic Assistant. - Administrator Guide - Cortex XSIAM - Cortex - Security Operations

Cortex XSIAM 3.x Documentation

Product
Cortex XSIAM
Creation date
2025-07-15
Last date published
2026-06-11
Category
Administrator Guide
Abstract

Configure access to AI Prompts when using the Cortex Agentic Assistant.

Controls access to the AI Prompts Library (Investigation & ResponseAutomationAI Prompts), where users create and manage reusable prompt templates (including system instructions and few-shot examples) used to guide the LLM's behavior.

Caution

To effectively embed AI Prompts directly into playbook workflows, users must be granted the Manage prompts in playbook editor checkbox, and they must also hold View/Edit permissions for the Playbooks module.

For more information, see AI prompts role-based access control.

Permission

Description

Roles Example

None

No access to the AI Prompts page and can't see prompts in the Playbook editor.

SOC Tier-1 Analyst: No need to access AI prompts. They consume agent capabilities through the Agentic Assistant chat interface, not through prompt management.

View

Read-only access to the AI Prompts page and can view prompts in the Playbook editor.

SOC Tier-2, Tier-3 Analysts and Threat Hunters: Need visibility to understand the capabilities and logic of the AI assistants they use

View/Edit

Users can do everything in View. When set to View/Edit, the following action checkboxes become available:

  • Manage prompts library

  • Manage prompts in playbook editor

Security Engineer: Full View/Edit with both checkboxes enabled. They are the primary builders of AI prompts and playbook AI tasks. They create, test, and maintain the prompt library and embed AI tasks into playbook workflows.

AI Prompt Sub-permissions

Sub-permission

Description

Manage prompts library

Controls whether users can create, view, edit, duplicate, and delete prompts on the AI Prompts page.

  • Checked: The user has full edit access to the AI Prompts page, such as create, edit, delete, edit, and save prompts. All management buttons and menu options are visible and functional.

  • Unchecked: The user has read-only access to the AI Prompts page (equivalent to View level).

Manage prompts in playbook editor

Controls the ability to use and manage AI prompts directly within the playbook editor, enabling inline AI task configuration in playbook workflows.

  • Checked: The user has full edit access to AI prompt tasks in the Playbook editor, such as adding AI tasks to playbooks, configuring AI task arguments, outputs, and timeout settings.

  • Unchecked: The user has read-only access to prompts in the Playbook editor. The user can't create, edit, save, or delete AI prompt tasks.

Note

You need to add Playbooks View/Edit permission to edit playbooks.