Set up users, groups, and roles - Learn how to set up users and roles in Cortex XSIAM. - Administrator Guide - Cortex XSIAM - Cortex - Security Operations

Cortex XSIAM 3.x Documentation

Product
Cortex XSIAM
Creation date
2025-07-15
Last date published
2026-06-11
Category
Administrator Guide
Abstract

Learn how to set up users and roles in Cortex XSIAM.

Cortex XSIAM uses both Role-Based Access Control (RBAC) and Scope-Based Access Control (SBAC) to manage roles with specific permissions for controlling user access.

RBAC helps manage access to Cortex XSIAM components and Cortex Query Language (XQL) datasets, so that users, based on their roles, are granted minimal access required to accomplish their tasks.

SBAC refines the RBAC permissions by granting access only to the relevant data that the user requires for their designated role. Users with Access Management permission can apply scopes to limit the data and content that users can be granted access to in Cortex XSIAM, which are divided into different scoping areas. The scoping areas include Assets, Cases and Issues, Endpoints, and Datasets Rows, which can be applied as relevant to the enforcement area, entity, or dataset. For more information on user scopes, see Manage user scope.

Cortex Gateway and the tenant have different options and requirements.

Location

Details

Cortex Gateway

A centralized portal for managing roles, user groups, and users for all tenants. Any roles and user groups created in Cortex Gateway are available for all tenants.

In Cortex Gateway, on the Permissions page, you can manage users that have been added to your Customer Support Portal account or view users that have been created in the tenant using SSO (you cannot edit SSO users in Cortex Gateway). All users must have at least one role or belong to at least one user group to be saved in the Cortex Gateway. You can exclude different tenants or different Cortex products. For more information, see Cortex Gateway Administrator Guide.

Only users with the Account Admin role can manage roles, tenants, and user groups in Cortex Gateway.

Cortex XSIAM tenant

(Recommended) All permissions and roles are specific to the tenant and exist only at the tenant level. Advanced settings, such as SBAC and Dataset access management, can be defined at the tenant level.

Managing users, roles, scopes, user groups, and authentication settings in Cortex XSIAM requires View/Edit RBAC permissions for Access Management (under Configurations). Account Admin and Instance Administrator roles are granted this permission by default.

For more information, see Manage user roles.

Predefined user roles

Cortex XSIAM utilizes Role-Based Access Control (RBAC) to manage user permissions across all tenants and services. This framework ensures a secure separation of duties by granting users only the specific access required for their functional or regional responsibilities. Key features include:

  • Predefined Roles: Cortex XSIAM provides default roles with set permissions. While these cannot be edited directly, they can be copied and customized to meet your organization's specific security requirements. To view the predefined permissions for each default role, go to SettingsConfigurationsAccess ManagementRoles.

    For more information about user role-based access permissions, see Role permissions by component

  • Centralized Management: Roles can be configured globally within the Cortex Gateway or at the individual tenant level.

  • Visibility logic: Users may not see a specific feature if the feature is not supported by the license type or if they do not have access based on their assigned role or scope.

Tip

To quickly see exactly which pages and actions a role allows, click on the role name, which opens a read-only view of all checked permissions.