Configuring AI Agent Permissions

Use the Limitations and RBAC settings to control what the Axonius AI Agent can see and do across your environment. For each permission, set a policy to run automatically, require your approval, or block the agent entirely.

To configure AI Agent permissions:

  1. From the top right corner of any page, click (System Settings). The System Settings page opens.
  2. In the Categories/Subcategories pane of the System Settings page, expand AI Settings, and select Limitations and RBAC.
  3. Expand the permission categories and use the access level icons to grant permissions.
  4. Click Save.

Access Level Icon Legend

Each permission row has three access options, represented by icons in the Access column.

IconAccessDescription
Always approvedThe agent runs the operation immediately without requesting approval.
Human-in-the-loopThe agent requests your approval before running the operation.
Never (blocked)The agent cannot run the operation.

Needs review

A Needs review indicator appears on a permission row when the underlying operations within that permission have different saved settings. Select a policy option to apply a uniform setting to all operations in that group.

Reset to defaults

To revert all permissions to their shipped defaults, click Reset to defaults. This removes all saved choices and restores the default policy for each permission. Future product updates to shipped defaults will then apply automatically.

📘

Note

Resetting to defaults also discards any unsaved changes.

Permission categories

The following sections describe each category and its configurable permissions.

Access & Users

Manage users, roles, service accounts, and data scopes.

PermissionDescription
Manage Data ScopeCreate, update, and delete data scopes.
Manage RoleCreate, update, and delete roles.
Manage Service AccountCreate, update, and delete service accounts.
Manage UserCreate, update, and delete users.

Action Center

Create, update, and run enforcement sets, case sets, and workflow actions.

PermissionDescription
Create Case SetCreate case sets.
Create Enforcement SetCreate enforcement sets.
Create TicketCreate tickets from the Action Center.
Create WorkflowCreate workflows.
Run Case SetRun case sets.
Run Enforcement SetRun enforcement sets on assets.
Run WorkflowRun workflows.
Manage Case SetUpdate cases, add comments, and update case statuses.
Manage Enforcement SetUpdate, delete, and set schedules for enforcement sets.
Manage WorkflowUpdate, delete, and configure webhook events for workflows.
Set StatusSet the status of workflow actions.
Test RunRun test executions of workflows.

Adapters & Discovery

Configure adapters, discovery rules, and data-source scan settings.

PermissionDescription
Manage Adapter ConnectionCreate, update, and delete adapter connections.
Manage Discovery CycleStart and stop discovery cycles.
Manage Enrichment CatalogUpdate enrichment catalog settings.
Manage Field MappingUpdate field mapping configurations.
Trigger Connection FetchTrigger a data fetch for an adapter connection.

AI Agents

Manage the AI Agent's own objects.

PermissionDescription
Manage Scheduled InsightCreate, update, and delete Scheduled Insights.

Assets & Queries

Create, update, and organize assets, custom fields, and data labels, and create and manage saved queries.

PermissionDescription
Manage TagsApply and delete tags on assets.
Manage Custom Field DefinitionCreate, update, and delete custom field definitions.
Manage Custom RelationshipCreate, update, and delete custom relationships.
Manage NotesCreate, update, and delete notes on assets.
Manage Tag DefinitionCreate, update, and delete tag definitions.
Manage QueryCreate, update, and delete saved queries.
Update Custom DataUpdate custom data values on assets.
Add SoftwareAdd software records to assets.
Set Approval StatusSet the approval status of software records.

Dashboards and Workspaces

Create and manage dashboards, charts, scheduled reports, and workspaces.

PermissionDescription
Create Chart/DashboardCreate dashboard spaces and charts.
Create Saved FilterCreate saved filters.
Create Csv ExportExport asset data as a CSV file.
Manage CMDB WorkspaceUpdate and delete CMDB workspace rules and issues.
Manage Chart/DashboardUpdate, move, and delete charts and dashboard spaces.
Manage ReportCreate, update, and delete scheduled reports.

Risk & Exposures

Manage vulnerability findings, risk scores, and exposure rules.

PermissionDescription
Create Vulnerability ExceptionCreate exceptions for vulnerability findings.
Manage Asset CriticalityUpdate and delete asset criticality records and statuses.
Manage Remediation OwnerAssign and update remediation owners for findings.
Manage Vulnerability ExceptionUpdate and delete vulnerability exceptions.
Manage Risk ScoreUpdate risk score actions, statuses, and score levels.
Set Security Findings Rule StatusEnable and disable security findings rules.
Update FindingsUpdate the status and details of security findings.
Update SLA ConfigUpdate SLA configuration settings for findings.

System & Settings

Modify system configuration and global platform settings.

PermissionDescription
Manage Global VariableCreate, update, and delete global variables.
Manage Tracked FieldsUpdate the list of tracked fields.
Update System SettingsUpdate global system settings.

Did this page help you?