Use permissions to control the access different roles have to the different functions and assets in Axonius.

Permissions are the building blocks for Axonius Role Based Access Control (RBAC). Each role consists of a collection of permissions for various elements in the system. Each user is assigned a specific role with permissions. Each role consists of the following categories and each category consists of different set of permissions.

There are two types of permissions:

  • Platform Capabilities Permissions - These permissions control access to the various functions and pages in Axonius. Some examples are Dashboards, Asset Graph, Activity Logs, Adapters, and Action Center.
  • Asset Permissions - Permissions are configured separately for each asset type in Axonius. Refer to the list of Asset Types for the full list of assets that a user needs permission to work with.

See Managing Roles for information on how to create roles and assign permissions.

The tables below lists all the system permissions and samples of some of the asset permissions:

Platform Capabilities Permissions

CategoryPermission/Permission GroupPermissions within the group
Access RequestCreate request
Action CenterView
Add and import
Edit
Duplicate
Export
Run
Delete
Action Center TasksView
Terminate
Export to CSV
Activity logsView
Saved QueriesRun
Create
Edit
Delete
Export to CSV
AdaptersView
ConnectionsCreate
Edit
Delete
Terminate
Fetch
Edit advanced settings
Saved QueriesRun
Create
Edit
Delete
Column ViewsView
Manage
Export to CSV
API AccessEnable API access
Reset API key
Asset CriticalityManage Asset Criticality
Delete Asset Criticality
Asset GraphView
Create
Edit
Add and edit for all data scopes
Load saved graph
Manage graph folders
Delete
Asset InvestigationView
Edit tracked fields
Saved QueriesRun
Create
Edit
Delete
Business ContextView
Edit
Case ManagementView
Create case
Edit case
Delete case
Cloud Asset ComplianceView
Update Benchmark settings
Exclusions and CommentsManage Exclusions and Comments
Export to CSV
CMDB Reconciliation RulesView
Manage CMDB Reconciliation Rules
Manage CMDB Reconciliation Issues
DashboardsView
ChartsAdd
Edit
Delete
DashboardsAdd and edit
Add and edit for all data scopes
Add and edit private dashboards
Import
Export
Delete
Set default dashboards for data scopes
Manage dashboard folders
Refresh
Export to CSV
Field MappingView
Add
Edit
Delete
FindingsView
Modify
AlertsView
Modify
Saved QueriesRun
Create
Edit
Delete
Global ActionsSave data analytics
Enable support center link
Identities: RulesCreate and Edit
Delete
Activation
Ingestion RulesView
Update
Managed Compute NodesView
Edit
Restart and shut down
QueriesManage query folders
Manage query calculation
Import
Export
View query history of all users
Add and edit for all data scopes
Export to CSV
ReportsView
Add
Edit
Disable email reports
Delete
Allow private reports
Export to CSV
Security Finding RulesManage Security Finding Rules
Delete Security Finding Rules
System ManagementView
Update
Manage data scopes
Move between data scopes
RolesAdd
Edit
Delete
Manage admin users
Manage gateways
View gateways
NotificationsView
Run manual discovery cycle
Export to CSV
Threat Intelligence FeedView
Configure
Users ManagementView user accounts and roles
UserAdd
Edit
Delete
Manage Service Accounts
Export to CSV
WorkspacesSet homepage dashboard
Edit homepage dashboard

Asset Permissions


📘

Note:

  • Permissions are configured separately for each asset type in Axonius. This list only contains samples of some of the Axonius Asset types. The permissions available for each asset are similar to those detailed below for Device and User assets. Refer to the list of Asset Types for the full list of assets which each need these permissions configured.
  • When you apply permissions to assets that have sub-assets the permissions apply to all related sub-assets.
AssetPermission/Permission GroupPermissions within the group
Compute: Devices
These permissions apply to all related sub-assets: Network Devices, IoT, IoMT, OT, Network Inspectors etc.
View devices
Create, delete, and link
Edit tags and custom data
Manage notes
Saved QueriesRun
Create
Edit
Delete
Edit device relationships
Column ViewsView
Manage
Export to CSV
Identity: Users
These permissions apply to all related sub-assets: Managed Identities
View users
Create, delete, and link
Edit tags and custom data
Manage notes
Saved QueriesRun
Create
Edit
Delete
Edit user relationships
Column ViewsView
Manage
Export to CSV
Exposures: Security Findings
These permissions apply to all related sub-assets: IAVM Findings
View security findings
Create, delete, and link
Edit tags and custom data
Manage notes
Saved QueriesRun
Create
Edit
Delete
Column ViewsView
Manage
Edit security finding relationships
Manage Security Findings Exceptions
Manage SLA Rules
Manage Remediation Ownership
Export to CSV
Exposures: Aggregated Security Findings
These permissions apply to all related sub-assets: Threat Intelligence Feed
View aggregated security findings
Edit tags and custom data
Saved QueriesRun
Create
Edit
Delete
Edit Excluded Aggregated Security Findings
Edit aggregated security findings relationships
Column ViewsView
Manage
Export to CSV
Exposures: Recommended ActionsView recommended actions
Edit tags and custom data
Manage notes
Saved QueriesRun
Create
Edit
Delete
Column ViewsView
Manage
Edit recommended action relationships
Export to CSV
Applications: Software
These permissions apply to all related sub-assets: Software Registry
View software
Create, delete, and link
Edit tags and custom data
Saved QueriesRun
Create
Edit
Delete
Manage Software
Edit software relationships
Column ViewsView
Manage
Export to CSV
Applications: SaaS Applications Repository
These permissions apply to all related sub-assets: SaaS Applications
View saas applications repository
Create, delete, and link
Edit tags and custom data
Manage notes
Saved QueriesRun
Create
Edit
Delete
Column ViewsView
Manage
Edit saas application repository relationships
View SaaS Application Discovery Screen
Manage SaaS Application Discovery
Export to CSV

Did this page help you?