Account → Roles & Permissions
A read-only view of your assigned roles and the permissions available to your account. Every user can view their own assignments. Contact an administrator to request changes.
My Roles
The role chips show the names of your assigned roles. Administrators manage assignments and location restrictions in Settings → Users & Roles. The permission summary combines your roles; role names alone do not determine access.
My Permissions
The grid lists permission areas, such as Resources and FactPolicies, in rows, with Read, Write, Delete and Execute as columns. Each cell shows a readable action description and an access badge. A dash (—) means that action does not exist for the area. All areas appear in one table; on narrow screens, scroll horizontally while the area column stays visible.
| Badge | Meaning |
|---|---|
| Full access | The permission applies globally for this action. |
| Partial access | The permission applies to the listed location branches and their descendants. Expand the badge to read every allowed branch path. |
| No access | The permission is absent, or its location restriction allows no operational locations. |
| Access unavailable | The current permission summary is missing or could not be loaded. This does not mean access was denied. |
Hover over Partial access to read the allowed paths in a tooltip beside the mouse cursor, or focus the badge with the keyboard. Expand the list with a click, a tap, or by pressing Enter or Space. Long branch lists scroll. Only allowed branches are listed, using full paths such as /EMEA/France/Paris; unrelated or denied branches are not listed.
Ancestors appear in a path to identify the branch. A path ending at Paris does not grant operations at France or EMEA. Overlapping grants from several roles are combined before display.
Global configuration and administration actions can show Full access even when granted by a role with location restrictions, because those actions do not apply a location restriction. A feature without a dedicated permission is identified separately.
Collector separates policy viewing under Read from collected-log visibility under Execute. Log visibility follows the allowed location branches. Sensors similarly separates IDS policy viewing under Read from retained IDS alerts under Execute, with alert visibility restricted to the allowed branches.
Understanding an action’s requirements
Each badge describes one permission for its labelled use. Some operations require several permissions together. For example, AI chat uses the AI permission globally; Quick Assist requires both its AI permission and resource-read access in the relevant context. Both uses are labelled separately inside the Execute cell so the chat badge does not imply access to every resource.
Licence, ownership, supported resource types, session state, and policy checks can also affect whether an action succeeds. A Full access badge does not bypass these checks.
The page refreshes your account information when opened or refreshed. Existing account and sign-in refreshes also update the displayed roles, badges, and paths. Location names and branches reflect the last successful account response; the server checks current permissions whenever you perform an operation.