Permissions

A user can have access to a limited set of resources or to all resources depending on the permissions assigned to them.

The different roles that can be assigned to a user are:

 AuditorSecurity AdministratorSystem Administrator
AssetsReadRead and ignore CVEManage and actions on all assets (patch, reboot…)
DiscoveriesReadReadManage
Connectors ManageReadReadManage
EncyclopediasReadReadManage
ReportsReadReadRead
Settings  Partial Control

The Administrator has full rights on Cyberwatch. Permissions that are exclusively granted to them are detailed in the table titled “Permissions reserved for the Administrator”.

Changing a user’s access permissions is described here.


The permissions described in the tables below apply to the assets that users have access to. Specific details may be provided in the table dedicated to special permissions as well as in the FAQ.

User permissions (excluding administrators) can be restricted to projects. For more information, please refer to this page.

The color code used in the tables below is as follows:

  • Read: Permission to read without editing
  • Manage: Permission to Read - Create - Edit - Delete
Assets
 AuditorSecurity AdministratorSystem Administrator
Asset detailsReadReadManage
Asset vulnerabilitiesReadIgnoreIgnore
Patch listReadReadDeploy
Asset reboot  Reboot
Compliance rulesReadReadIgnore
TechnologiesReadReadUninstall
AnalysesReadRelaunchRelaunch
Declarative dataReadReadManage
Discoveries
 AuditorSecurity AdministratorSystem Administrator
DiscoveriesReadReadManage
Connector Manage
 AuditorSecurity AdministratorSystem Administrator
AgentsReadReadManage
Agentless connectionsReadReadManage
Air-gapped assetsReadReadManage
Docker imagesReadReadManage
Network targets & websitesReadManageManage
CloudReadReadManage
Encyclopedias
 AuditorSecurity AdministratorSystem Administrator
VulnerabilitiesReadReadEdit
Remediation actionsReadReadDeploy
Security flawsReadReadRead
Compliance rulesReadReadAssign
Reports
 AuditorSecurity AdministratorSystem Administrator
AlertsManageManageManage
ExportManageManageManage
User activitiesReadReadRead
Settings
 AuditorSecurity AdministratorSystem Administrator
ProjectsReadReadRead
GroupsReadReadRead
Stored credentials  Manage
Analysis/deployment/reboot policiesReadReadManage
CriticalitiesReadReadManage
Automatic exclusionsReadReadRead
Custom repositoriesReadReadManage
BenchmarksReadReadRead
Asset rulesReadReadRead
Special Permissions
ModalsAuditorSecurity AdministratorSystem Administrator
KibanaRequires explicit permissionRequires explicit permissionRequires explicit permission
Permissions reserved for the Administrator
ResourcesRights
ProjectsCreate
GroupsCreate / Assign
Custom analysis scripts and compliance rulesManage
ignoring policiesManage
BenchmarksCreate / Delete
Asset rulesManage
Security issuesManage
Cyberwatch applicationUpdate / Restart
User accounts and permissionsManage
NodesManage / Update / Restart
User activitiesComment

Back to top