Asset Roles configuration permissions - Configure Asset Roles permissions (under Inventory). - Administrator Guide - Cortex XSIAM - Cortex - Security Operations

Cortex XSIAM 3.x Documentation

Product
Cortex XSIAM
Creation date
2025-07-15
Last date published
2026-06-04
Category
Administrator Guide
Abstract

Configure Asset Roles permissions (under Inventory).

Asset Roles Configuration allows organizations to define and manage specific functional roles for assets across their environment (such as Admin, User, or Server). By associating specific users and endpoints with these roles, security teams can enrich security events with role context and support role-based analytics and alerting. Users access these features by going to InventoryAssetsAsset Roles Configuration.

Notice

Requires the Identity Threat Detection and Response add-on.

For more information, see Asset Roles.

The Asset Roles configuration permissions control the ability to view, create, edit, and assign endpoints to functional asset roles.

Permissions

Description

Roles Example

None

No access to the Assets Roles Configuration page.

SOC Tier-1 Analyst: The role configuration is not part of daily operations

View

Read-only access to the Assets Role Configuration page, including viewing the roles list, details, members, and searching/filtering roles.

  • SOC Tier-2 Analyst: Reference role context during investigations.

  • SOC Tier-3 Analyst: Understand role assignments for analysis,

  • Threat Hunter: Reference role context for hunting.

View/Edit

All view capabilities, plus all view/edit actions, such as add, edit, delete, and add endpoints to a role, as well as manually assign endpoints to specific roles.

Security Engineer: Configure and maintain asset roles.