Configuring AI Agent Permissions
Use the Limitations and RBAC settings to control what the Axonius AI Agent can see and do across your environment. For each permission, set a policy to run automatically, require your approval, or block the agent entirely.
To configure AI Agent permissions:
- From the top right corner of any page, click
(System Settings). The System Settings page opens. - In the Categories/Subcategories pane of the System Settings page, expand AI Settings, and select Limitations and RBAC.
- Expand the permission categories and use the access level icons to grant permissions.
- Click Save.
Access Level Icon Legend
Each permission row has three access options, represented by icons in the Access column.
| Icon | Access | Description |
|---|---|---|
| Always approved | The agent runs the operation immediately without requesting approval. | |
| Human-in-the-loop | The agent requests your approval before running the operation. | |
| Never (blocked) | The agent cannot run the operation. |
Needs review
A Needs review indicator appears on a permission row when the underlying operations within that permission have different saved settings. Select a policy option to apply a uniform setting to all operations in that group.
Reset to defaults
To revert all permissions to their shipped defaults, click Reset to defaults. This removes all saved choices and restores the default policy for each permission. Future product updates to shipped defaults will then apply automatically.
Permission categories
The following sections describe each category and its configurable permissions.
Access & Users
Manage users, roles, service accounts, and data scopes.
| Permission | Description |
|---|---|
| Manage Data Scope | Create, update, and delete data scopes. |
| Manage Role | Create, update, and delete roles. |
| Manage Service Account | Create, update, and delete service accounts. |
| Manage User | Create, update, and delete users. |
Action Center
Create, update, and run enforcement sets, case sets, and workflow actions.
| Permission | Description |
|---|---|
| Create Case Set | Create case sets. |
| Create Enforcement Set | Create enforcement sets. |
| Create Ticket | Create tickets from the Action Center. |
| Create Workflow | Create workflows. |
| Run Case Set | Run case sets. |
| Run Enforcement Set | Run enforcement sets on assets. |
| Run Workflow | Run workflows. |
| Manage Case Set | Update cases, add comments, and update case statuses. |
| Manage Enforcement Set | Update, delete, and set schedules for enforcement sets. |
| Manage Workflow | Update, delete, and configure webhook events for workflows. |
| Set Status | Set the status of workflow actions. |
| Test Run | Run test executions of workflows. |
Adapters & Discovery
Configure adapters, discovery rules, and data-source scan settings.
| Permission | Description |
|---|---|
| Manage Adapter Connection | Create, update, and delete adapter connections. |
| Manage Discovery Cycle | Start and stop discovery cycles. |
| Manage Enrichment Catalog | Update enrichment catalog settings. |
| Manage Field Mapping | Update field mapping configurations. |
| Trigger Connection Fetch | Trigger a data fetch for an adapter connection. |
AI Agents
Manage the AI Agent's own objects.
| Permission | Description |
|---|---|
| Manage Scheduled Insight | Create, update, and delete Scheduled Insights. |
Assets & Queries
Create, update, and organize assets, custom fields, and data labels, and create and manage saved queries.
| Permission | Description |
|---|---|
| Manage Tags | Apply and delete tags on assets. |
| Manage Custom Field Definition | Create, update, and delete custom field definitions. |
| Manage Custom Relationship | Create, update, and delete custom relationships. |
| Manage Notes | Create, update, and delete notes on assets. |
| Manage Tag Definition | Create, update, and delete tag definitions. |
| Manage Query | Create, update, and delete saved queries. |
| Update Custom Data | Update custom data values on assets. |
| Add Software | Add software records to assets. |
| Set Approval Status | Set the approval status of software records. |
Dashboards and Workspaces
Create and manage dashboards, charts, scheduled reports, and workspaces.
| Permission | Description |
|---|---|
| Create Chart/Dashboard | Create dashboard spaces and charts. |
| Create Saved Filter | Create saved filters. |
| Create Csv Export | Export asset data as a CSV file. |
| Manage CMDB Workspace | Update and delete CMDB workspace rules and issues. |
| Manage Chart/Dashboard | Update, move, and delete charts and dashboard spaces. |
| Manage Report | Create, update, and delete scheduled reports. |
Risk & Exposures
Manage vulnerability findings, risk scores, and exposure rules.
| Permission | Description |
|---|---|
| Create Vulnerability Exception | Create exceptions for vulnerability findings. |
| Manage Asset Criticality | Update and delete asset criticality records and statuses. |
| Manage Remediation Owner | Assign and update remediation owners for findings. |
| Manage Vulnerability Exception | Update and delete vulnerability exceptions. |
| Manage Risk Score | Update risk score actions, statuses, and score levels. |
| Set Security Findings Rule Status | Enable and disable security findings rules. |
| Update Findings | Update the status and details of security findings. |
| Update SLA Config | Update SLA configuration settings for findings. |
System & Settings
Modify system configuration and global platform settings.
| Permission | Description |
|---|---|
| Manage Global Variable | Create, update, and delete global variables. |
| Manage Tracked Fields | Update the list of tracked fields. |
| Update System Settings | Update global system settings. |
Updated about 4 hours ago
