Skip to content

Permissions Reference

Use this reference when configuring Settings → Groups. Permission names match the group permission editor in the UI.

Permissions are stored on groups as JSON maps of key → true. The built-in Admin group effectively has full access (* wildcard).

KeyUI module
module.dashboardDashboard
module.assetsAssets / CMDB
module.incidentsIncidents
module.post_incident_reviewsPost-incident reviews
module.service_requestsService requests
module.problemsProblems
module.changesChanges
module.releasesReleases
module.vulnerabilitiesVulnerabilities
module.knowledgeKnowledge
module.diagramsNetwork diagrams
module.maintenanceMaintenance
module.vpnVPN
module.securitySecurity
module.backupBackup
module.settingsSettings

For each resource dashboard, assets, incidents, changes, problems, vulnerabilities, knowledge, diagrams, maintenance, vpn, security, backup, service_requests, post_incident_reviews, releases, vendors:

  • {resource}.read
  • {resource}.create
  • {resource}.update
  • {resource}.delete

(dashboard only uses dashboard.read.)

KeyPurpose
settings.license.writeLicense / modules
settings.groups.read / .write / .membersGroups
settings.users.read / .users.manageUsers & invites
settings.api_keys.manageAPI keys
settings.edge_registration_keys.manageEdge registration keys
settings.retention.writeRetention policies
settings.company.writeCompany / system settings
settings.auth.manageAuthentication / Entra
settings.audit.readAudit log viewer

security.tool.ping, security.tool.arp_scan, security.tool.nmap, security.tool.rustscan, security.tool.ssh, security.tool.busybox_shell