Permissions List
Use permissions to control the access different roles have to the different functions and assets in Axonius.
Permissions are the building blocks for Axonius Role Based Access Control (RBAC). Each role consists of a collection of permissions for various elements in the system. Each user is assigned a specific role with permissions. Each role consists of the following categories and each category consists of different set of permissions.
There are two types of permissions:
- Platform Capabilities Permissions - These permissions control access to the various functions and pages in Axonius. Some examples are Dashboards, Asset Graph, Activity Logs, Adapters, and Action Center.
- Asset Permissions - Permissions are configured separately for each asset type in Axonius. Refer to the list of Asset Types for the full list of assets that a user needs permission to work with.
See Managing Roles for information on how to create roles and assign permissions.
The tables below lists all the system permissions and samples of some of the asset permissions:
Platform Capabilities Permissions
| Category | Permission/Permission Group | Permissions within the group |
|---|---|---|
| Access Request | Create request | |
| Action Center | View | |
| Add and import | ||
| Edit | ||
| Duplicate | ||
| Export | ||
| Run | ||
| Delete | ||
| Action Center Tasks | View | |
| Terminate | ||
| Export to CSV | ||
| Activity logs | View | |
| Saved Queries | Run | |
| Create | ||
| Edit | ||
| Delete | ||
| Export to CSV | ||
| Adapters | View | |
| Connections | Create | |
| Edit | ||
| Delete | ||
| Terminate | ||
| Fetch | ||
| Edit advanced settings | ||
| Saved Queries | Run | |
| Create | ||
| Edit | ||
| Delete | ||
| Column Views | View | |
| Manage | ||
| Export to CSV | ||
| API Access | Enable API access | |
| Reset API key | ||
| Asset Criticality | Manage Asset Criticality | |
| Delete Asset Criticality | ||
| Asset Graph | View | |
| Create | ||
| Edit | ||
| Add and edit for all data scopes | ||
| Load saved graph | ||
| Manage graph folders | ||
| Delete | ||
| Asset Investigation | View | |
| Edit tracked fields | ||
| Saved Queries | Run | |
| Create | ||
| Edit | ||
| Delete | ||
| Business Context | View | |
| Edit | ||
| Case Management | View | |
| Create case | ||
| Edit case | ||
| Delete case | ||
| Cloud Asset Compliance | View | |
| Update Benchmark settings | ||
| Exclusions and Comments | Manage Exclusions and Comments | |
| Export to CSV | ||
| CMDB Reconciliation Rules | View | |
| Manage CMDB Reconciliation Rules | ||
| Manage CMDB Reconciliation Issues | ||
| Dashboards | View | |
| Charts | Add | |
| Edit | ||
| Delete | ||
| Dashboards | Add and edit | |
| Add and edit for all data scopes | ||
| Add and edit private dashboards | ||
| Import | ||
| Export | ||
| Delete | ||
| Set default dashboards for data scopes | ||
| Manage dashboard folders | ||
| Refresh | ||
| Export to CSV | ||
| Field Mapping | View | |
| Add | ||
| Edit | ||
| Delete | ||
| Findings | View | |
| Modify | ||
| Alerts | View | |
| Modify | ||
| Saved Queries | Run | |
| Create | ||
| Edit | ||
| Delete | ||
| Global Actions | Save data analytics | |
| Enable support center link | ||
| Identities: Rules | Create and Edit | |
| Delete | ||
| Activation | ||
| Ingestion Rules | View | |
| Update | ||
| Managed Compute Nodes | View | |
| Edit | ||
| Restart and shut down | ||
| Queries | Manage query folders | |
| Manage query calculation | ||
| Import | ||
| Export | ||
| View query history of all users | ||
| Add and edit for all data scopes | ||
| Export to CSV | ||
| Reports | View | |
| Add | ||
| Edit | ||
| Disable email reports | ||
| Delete | ||
| Allow private reports | ||
| Export to CSV | ||
| Security Finding Rules | Manage Security Finding Rules | |
| Delete Security Finding Rules | ||
| System Management | View | |
| Update | ||
| Manage data scopes | ||
| Move between data scopes | ||
| Roles | Add | |
| Edit | ||
| Delete | ||
| Manage admin users | ||
| Manage gateways | ||
| View gateways | ||
| Notifications | View | |
| Run manual discovery cycle | ||
| Export to CSV | ||
| Threat Intelligence Feed | View | |
| Configure | ||
| Users Management | View user accounts and roles | |
| User | Add | |
| Edit | ||
| Delete | ||
| Manage Service Accounts | ||
| Export to CSV | ||
| Workspaces | Set homepage dashboard | |
| Edit homepage dashboard |
Asset Permissions
Note:
- Permissions are configured separately for each asset type in Axonius. This list only contains samples of some of the Axonius Asset types. The permissions available for each asset are similar to those detailed below for Device and User assets. Refer to the list of Asset Types for the full list of assets which each need these permissions configured.
- When you apply permissions to assets that have sub-assets the permissions apply to all related sub-assets.
| Asset | Permission/Permission Group | Permissions within the group |
|---|---|---|
| Compute: Devices These permissions apply to all related sub-assets: Network Devices, IoT, IoMT, OT, Network Inspectors etc. | View devices | |
| Create, delete, and link | ||
| Edit tags and custom data | ||
| Manage notes | ||
| Saved Queries | Run | |
| Create | ||
| Edit | ||
| Delete | ||
| Edit device relationships | ||
| Column Views | View | |
| Manage | ||
| Export to CSV | ||
| Identity: Users These permissions apply to all related sub-assets: Managed Identities | View users | |
| Create, delete, and link | ||
| Edit tags and custom data | ||
| Manage notes | ||
| Saved Queries | Run | |
| Create | ||
| Edit | ||
| Delete | ||
| Edit user relationships | ||
| Column Views | View | |
| Manage | ||
| Export to CSV | ||
| Exposures: Security Findings These permissions apply to all related sub-assets: IAVM Findings | View security findings | |
| Create, delete, and link | ||
| Edit tags and custom data | ||
| Manage notes | ||
| Saved Queries | Run | |
| Create | ||
| Edit | ||
| Delete | ||
| Column Views | View | |
| Manage | ||
| Edit security finding relationships | ||
| Manage Security Findings Exceptions | ||
| Manage SLA Rules | ||
| Manage Remediation Ownership | ||
| Export to CSV | ||
| Exposures: Aggregated Security Findings These permissions apply to all related sub-assets: Threat Intelligence Feed | View aggregated security findings | |
| Edit tags and custom data | ||
| Saved Queries | Run | |
| Create | ||
| Edit | ||
| Delete | ||
| Edit Excluded Aggregated Security Findings | ||
| Edit aggregated security findings relationships | ||
| Column Views | View | |
| Manage | ||
| Export to CSV | ||
| Exposures: Recommended Actions | View recommended actions | |
| Edit tags and custom data | ||
| Manage notes | ||
| Saved Queries | Run | |
| Create | ||
| Edit | ||
| Delete | ||
| Column Views | View | |
| Manage | ||
| Edit recommended action relationships | ||
| Export to CSV | ||
| Applications: Software These permissions apply to all related sub-assets: Software Registry | View software | |
| Create, delete, and link | ||
| Edit tags and custom data | ||
| Saved Queries | Run | |
| Create | ||
| Edit | ||
| Delete | ||
| Manage Software | ||
| Edit software relationships | ||
| Column Views | View | |
| Manage | ||
| Export to CSV | ||
| Applications: SaaS Applications Repository These permissions apply to all related sub-assets: SaaS Applications | View saas applications repository | |
| Create, delete, and link | ||
| Edit tags and custom data | ||
| Manage notes | ||
| Saved Queries | Run | |
| Create | ||
| Edit | ||
| Delete | ||
| Column Views | View | |
| Manage | ||
| Edit saas application repository relationships | ||
| View SaaS Application Discovery Screen | ||
| Manage SaaS Application Discovery | ||
| Export to CSV |
Updated 3 days ago
Did this page help you?
