Skip to main content

Sysdig Monitor System Roles

Admin

CategoryItemPermissionDescription
INTERNAL_UNCATEGORIZEDsecure.accessOTHERN/A
Posturecompliance.policies.adminOTHER_MUTATORN/A
INTERNAL_UNCATEGORIZEDcustomer.adminOTHER_MUTATORN/A
INTERNAL_UNCATEGORIZEDteam-admin.insightOTHERN/A
INTERNAL_ADMINonboarding.adminOTHER_MUTATORN/A
Integrationspromcat.integrations.manageMANAGEChange monitoring integration type or status
INTERNAL_SERVICEactive-secure-compliance-users-admin.readREADN/A
INTERNAL_SERVICEactive-secure-overview-users-admin.readREADN/A
INTERNAL_ADMINinactive-users-admin.readREADN/A
INTERNAL_SERVICEmetrics-data-admin.readREADAccess metrics data associated with a time series.
Reportsreports.manageMANAGEChange monitoring reports
Posturesecure.onboarding.adminOTHER_MUTATORN/A
Posturesecure.todo.adminOTHER_MUTATORN/A
INTERNAL_ADMINsystem-admin.editEDITN/A
INTERNAL_ADMINsystem-admin.readREADN/A
Explore / Metricsagent.cli.agent_internal_diagnosticsREADUse Agent Console commands which access internal diagnostics of the agent
Explore / Metricsagent.cli.agent_network_calls_to_remote_podsEXECUse Agent Console commands which make network calls to remote pods and endpoints
Explore / Metricsagent.cli.agent_statusREADUse Agent Console commands which access agent status
Explore / Metricsagent.cli.viewVIEWUse Agent Console commands
Explore / Metricsagent.cli.view_configurationVIEWUse Agent Console commands to view the configuration of the agent which does not contain sensitive information like passwords
Explore / Metricsagent.cli.view_sensitive_configurationVIEWUse Agent Console commands to view the configuration of the agent which does contain sensitive information like passwords. There are currently zero commands that implement this permission
Settingssso.configEDITN/A
INTERNAL_ADMINsso-system.configEDITN/A
Settingscustomer-admin-users.createCREATECreate new customer admin users
ROLE_MANAGEMENTcustom-team-roles.createCREATEN/A
Settingsteams.createCREATEN/A
Settingsusers.createCREATEInvite new users
ROLE_MANAGEMENTcustom-team-roles.deleteDELETEN/A
Settingsteams.deleteDELETEN/A
Settingsaccess-keys.editEDITN/A
Settingssso-active.editEDITN/A
Policiessecure.admission-controller.editEDITN/A
Scanning (Legacy)agentscanning.config.editEDITN/A
Settingsapi-token.editEDITReset users API token in scope of a team
Settingsaws-settings.editEDITN/A
Settingsbeacon-configuration.editEDITN/A
Posturesecure.benchmark.results.editEDITN/A
Settingscertman.editEDITN/A
Costscost-advisor.editEDITChange Cost Advisor pricing
Costscost-reports.editEDITChange cost reports
USERSuser-deactivation-configuration.editEDITModify user deactivation configuration
Data Access Settingsdatastream.editEDITN/A
INTERNAL_SERVICEdata-api-settings.editEDITN/A
INTERNAL_SERVICEdata-throttling-settings.editEDITN/A
Settingsdowntimes.editEDITN/A
Settingsevents-forwarder.editEDITN/A
Integrationsfile-storage-config.editEDITN/A
Settingsglobal.notification-channels.editEDITN/A
Settingsglobal.service-accounts.editEDITN/A
Settingsglobal-service-account-notification-settings.editEDITN/A
Data Access Settingsgroupings.editEDITCreate and edit custom groupings
Settingsgroup-mappings.editEDITModify mapping of users IDP groups to Sysdig teams/roles
Settingsip-filters.editEDITModify IP filter configuration
Settingslogin-banner.editEDITN/A
Settingsmemberships.editEDITInvite other users to the teams
Settingsmemberships-roles.editEDITModify team members roles
Network Securitynetsec.editEDITN/A
Get Startedonboarding.editEDITN/A
INTERNAL_ADMINservice.platform-alerts-settings.editEDITEdit platform alerts settings
Policiespolicy-tuner.editEDITN/A
Integrationspromcat.integrations.editEDITChange monitoring integration type or status
Integrationsproviders.editEDITN/A
Scanning (Legacy)scanning.retention.editEDITN/A
Scanning (Legacy)secure.images.editEDITN/A
Settingssecure-settings.editEDITModify Sysdig Secure configuration
Settingsservice-account.editEDITModify service accounts in scope of a team
Settingsservice-account-notification-settings.editEDITN/A
Settingsservice-account-role.editEDITChange service account roles
Settingssubscription.editEDITN/A
Settingssysdig-storage.editEDITN/A
INTERNAL_ADMINsystem-falco.editEDITN/A
Settingsteams.editEDITN/A
Settingsteam-agent-cli-settings.editEDITToggle access to agent console for a team
Settingsteam-capture-settings.editEDITToggle access to captures for a team
Settingsteam-rapid-response-settings.editEDITN/A
Integrationsthird-party-integrations.editEDITN/A
Ticketingticketing-customer-settings.editEDITEdit ticketing customer settings
UI Settingsui-customer-settings.editEDITN/A
UI Settingsui-inactivity-settings.editEDITN/A
UI Settingsui-settings.editEDITN/A
UI Settingsui-user-app-settings.editEDITN/A
Settingsusers.editEDITN/A
Settingsuser-list.editEDITN/A
USERSuser-password.editEDITN/A
USERSuser-profile.editEDITN/A
INTERNAL_UNCATEGORIZEDdev-task.execEXECN/A
INTERNAL_UNCATEGORIZEDes-query.execEXECN/A
Captures / Investigatesecure.rapid-response.execEXECUse rapid response
INTERNAL_ADMINprotobuf.exportOTHER_MUTATORN/A
INTERNAL_ADMINimpersonate.editEDITN/A
Data Access Settingsingest.prwsOTHERN/A
Data Access Settingsingest.prws.controlledOTHERN/A
Captures / Investigatesecure.rapid-response.killKILLN/A
INTERNAL_SERVICEmetrics-descriptors.manageMANAGEManage metrics descriptors, which are unique combinations of metrics and labels that create a time series. For example, sysdig_container_cpu_used_percenthost_hostname=foo,region=bar.
INTERNAL_UNCATEGORIZEDquartz-jobs.manageMANAGEN/A
Settingssecure.risk-spotlight-integration-tokens.manageMANAGEManage risk spotlight integration tokens from the UI
Settingsaccess-keys.readREADN/A
Scanning (Legacy)agentscanning.config.readREADN/A
Settingsagent-installation.readREADGet agent access key (required for agent installation)
Settingsagreement.readREADN/A
Settingsapi-token.readREADAccess users API token in scope of a team
INTERNAL_UNCATEGORIZEDaudit-trail-events.readREADN/A
Settingsaws-settings.readREADAccess AWS settings
Settingsazure-settings.readREADN/A
Settingsbeacon-configuration.readREADN/A
Settingscertman.readREADN/A
Settingscloud.accounts.readREADAccess cloud accounts
Costscost-advisor.readREADAccess Cost Advisor
INTERNAL_SERVICEcost-digest.readREADRead cost digest enabled customers
Costscost-explorer.readREADAccess Cost Explorer
Costscost-reports.readREADAccess cost reports
INTERNAL_SERVICEcustomer-by-accesskey.readREADN/A
Settingscustomer-plan.readREADN/A
Settingscustomer-teams.readREADAccess and list teams data
USERSuser-deactivation-configuration.readREADAccess user deactivation configuration
Eventscustom-events.readREADAccess the infrastructure and other events created by Sysdig Agent or Sysdig API
ROLE_MANAGEMENTcustom-team-roles.readREADN/A
Dashboardsdashboard-metrics-data.readREADAccess metrics data associated with a dashboard.
Data Access Settingsdatastream.readREADAccess data stream configuration
INTERNAL_SERVICEdata-api-settings.readREADN/A
INTERNAL_SERVICEdata-throttling-settings.readREADN/A
Settingsdowntimes.readREADList alert downtimes for the customer
Settingsevents-forwarder.readREADAccess event forwarding configuration
Explore / Metricsexplore.readREADMetric querying with Explore
INTERNAL_UNCATEGORIZEDexternal-links.readREADN/A
Integrationsfile-storage-config.readREADN/A
Settingsglobal.service-accounts.readREADN/A
Settingsglobal-service-account-notification-settings.readREADN/A
Data Access Settingsgroupings.readREADAccess default and custom groupings
Settingsgroup-mappings.readREADAccess mapping of users IDP groups to Sysdig teams/roles
Integrationshelmsrenderer.readREADAccess Helm-renderer component. During cloud account setup in Secure, the wizard calls the Helm Renderer to generate the Terraform snippet.
Data Access Settingshistory-data.readREADN/A
INTERNAL_UNCATEGORIZEDimpersonate.readREADN/A
Integrationsinfrastructure.readREADView discovered infrastructure
Integrationsintegrations.readREADView discovered workload integrations
Settingsip-filters.readREADAccess IP Filter configuration
Advisorkubernetes-api-commands.readREADKubernetes API feature
Advisorlive-logs.viewVIEWAccess Live Logs feature
Settingslogin-banner.readREADN/A
Data Access Settingsmds.read-metadataREADN/A
Settingsmemberships.readREADAccess team members
Data Access Settingsmetadata-defaults.readREADN/A
Data Access Settingsmetrics-data.readREADAccess metrics data associated with a time series.
Data Access Settingsmetrics-descriptors.readREADAccess metrics descriptors, which are unique combinations of metrics and labels that create a time series. For example, sysdig_container_cpu_used_percenthost_hostname=foo,region=bar.
Get Startedonboarding.readREADN/A
Advisoroverviews.readREADAccess Advisor
Settingspayment-details.readREADN/A
ROLE_MANAGEMENTpermissions.readREADN/A
INTERNAL_ADMINservice.platform-alerts-settings.readREADRead platform alerts settings
Integrationspromcat.integrations.readREADAccess monitoring integration type or status
Data Access Settingspromql-metadata.readREADAccess Prometheus metrics and labels
Integrationsproviders.readREADRelated to cloud account setups (both Metric Stream and Cost Private Pricing).
Scanning (Legacy)scanning.readREADRead scan results
Scanning (Legacy)scanning.retention.readREADN/A
Get Startedsecure.onboarding.readREADN/A
Settingssecure-settings.readREADN/A
Settingsservice-account.readREADAccess service accounts in scope of a team
Settingsservice-account-notification-settings.readREADN/A
Integrationsspotlight.readREADAccess spotlight
Settingssubscription.readREADAccess customer subscription details
Settingssysdig-storage.readREADView Sysdig storage configuration
INTERNAL_UNCATEGORIZEDteams.readREADN/A
Settingsteam-agent-cli-settings.readREADSee the agent console access settings for a team
Settingsteam-capture-settings.readREADSee the capture settings for a team
Settingsteam-rapid-response-settings.readREADN/A
INTERNAL_UNCATEGORIZEDteam-search.readREADN/A
Integrationsthird-party-integrations.readREADN/A
Ticketingticketing-customer-settings.readREADRead ticketing customer settings
UI Settingsui-customer-settings.readREADN/A
UI Settingsui-inactivity-settings.readREADN/A
UI Settingsui-settings.readREADN/A
UI Settingsui-user-app-settings.readREADN/A
Settingsusers.readREADAccess existing users data
Settingsuser-list.readREADSee the list of users for a customer
USERSuser-profile.readREADN/A
Captures / Investigatesecure.rapid-response.sessions.read.allREADN/A
Settingsagreement.signSIGNN/A
INTERNAL_UNCATEGORIZEDsystem-support.editEDITN/A
INTERNAL_ADMINagent-availability.toggleTOGGLEN/A
INTERNAL_UNCATEGORIZEDtrack.eventOTHER_MUTATORN/A
ROLE_MANAGEMENTcustom-team-roles.updateUPDATEN/A
Sagesage.execEXECSysdig Sage chat
Integrationspromcat.integrations.validateVALIDATEChange monitoring integration status to Pending Metrics