Sync Profile permissions - Configure Sync Profile permissions under Objects. - Administrator Guide - Cortex XSIAM - Cortex - Security Operations

Cortex XSIAM 3.x Documentation

Product
Cortex XSIAM
Creation date
2025-07-15
Last date published
2026-06-11
Category
Administrator Guide
Abstract

Configure Sync Profile permissions under Objects.

Controls access to case mirroring profiles configuration in SettingsConfigurationsObject SetupIssuesSync Profiles.

Sync Profiles define the parameters for case mirroring with third-party platforms such as Jira and ServiceNow. When a profile is active, updates to cases in the tenant are automatically reflected in the external system, and depending on the profile type (inbound or bidirectional), changes in the external system can update XSIAM cases.

For more information, see Create a sync profile.

Permission

Description

Roles Example

None

No access to Sync Profiles. Users cannot view, create, or select profiles for use in automation.

  • SOC Tier 1 and 2 Analyst: Mirroring configuration is typically handled by engineers.

  • Threat Hunter: Layout configuration is outside the threat hunting scope.

View

Read-only access. Users can view the Sync Profiles table and open profile details in read-only mode.

SOC Tier-3 Analyst: Should understand mirroring configurations for escalation workflows and cross-system case tracking.

View/Edit

Full read/write access to view, create, edit, and delete sync profiles.

Security Engineer: Configures and manages mirroring with external ticketing systems (Jira, ServiceNow).