The permission catalog by category: what each key allows, which permissions it carries with it, and why a few are described here rather than printed.
A permission is a fixed key — servers.view, events.cancel — with a name beside it. The key is what is stored on a role and what is checked on every request; the name is what the permissions screen shows. The same keys are also the scopes an access token can be given, so this list does two jobs.
The console renders these permission names in Hebrew in both interface languages. The English names below are for reading; the keys are identical either way.
Three rules that shape the catalog
Every key belongs to exactly one category. The categories below are in the order the permissions screen renders them.
A category carries at most one access ladder. Where there is one, choosing a level also grants every level beneath it. In most categories the ladder is view → edit. The system register has three rungs — view → edit → merge — because a merge changes the identity of the system every other screen joins to, which is a larger decision than an edit.
An implication never crosses a category. A permission can carry another permission from the same category — edit carries view, export carries view — and never one from another module. That is what stops a grant on one screen from quietly opening another.
The two roles the product ships with
Role
What it holds
System administrator
The whole catalog, including keys added in later versions. The role holds no explicit permission list at all, so an upgrade never leaves an administrator without a new permission nobody remembered to add.
Operator
The default role — a user assigned to no role gets it. It carries read access to the operational screens, export, and the day-to-day operating actions: updating an event's status, filling in a checklist, marking a server as handled.
Further roles are built on the permissions screen out of the same catalog. There is no permission that exists in the product and not there.
Events and calendar
Key
Permission
What it allows
Also carries
events.view
View events
The calendar, the event list and the history
—
events.create
Create an event
Creating an update event through the wizard
events.view
events.edit
Edit an event
Changing an existing event, including updating the calendar invitation and the ticket
—
events.cancel
Cancel an event
Cancelling an event and sending the cancellation to the invitees
—
events.delete_permanent
Delete permanently
Permanently deleting a cancelled event
—
events.status
Update event status
Marking an event completed or failed
—
events.checklist
Fill in a checklist
Completing the event checklist after the work
—
events.export
Export events
Exporting the event list to CSV or Excel
—
tasks.view
View tasks
The task list for events
—
tasks.manage
Manage tasks
Creating, editing and deleting tasks and task templates
tasks.view
Server inventory
Key
Permission
What it allows
Also carries
servers.view
View the server inventory
The server table, the systems and the system managers
—
servers.comment
Edit server comments
Writing and deleting a note in the comment column
servers.view
servers.export
Export servers
Exporting the inventory to CSV or Excel
servers.view
cmdb.view
View the server record
Opening a server's record — values, sources and field history
servers.view
cmdb.edit
Edit fields on the server record
Changing field values on the record, including setting a value that differs from a discovered source
cmdb.view
cmdb.quality
Data quality board
The completeness score of the record store and the quality findings — duplicates, contradictions between sources, records never observed and records with no owner
cmdb.view
capacity.view
View capacity management
The capacity headroom of compute clusters, racks and reclaimable capacity
servers.view
capacity.plan
Capacity planning
Running "is there room" scenarios against clusters, sites and racks
capacity.view
capacity.export
Export capacity data
Exporting capacity data to CSV or Excel
capacity.view
System register
Key
Permission
What it allows
Also carries
systems.view
View the system register
The register, the owners, patch coverage and the system record
—
systems.edit
Edit a system
Creating and editing a system record, its aliases, membership and declared dependencies
systems.view
systems.merge
Merge and split systems
Merging two records into one, splitting a record and deleting it
systems.edit
systems.attest
Answer an ownership attestation
Confirming or rejecting an ownership attestation, including correcting wrong fields
systems.view
systems.export
Export systems
Exporting the register and the attestation report to CSV or Excel
systems.view
CVE vulnerabilities
Key
Permission
What it allows
Also carries
vulnerabilities.view
View vulnerabilities
The vulnerability register and the affected servers
—
vulnerabilities.manage
Manage vulnerabilities
Adding, editing and archiving records
vulnerabilities.view
vulnerabilities.mark_host
Mark a server handled
Marking an affected server as handled in the exposure panel
vulnerabilities.view
vulnerabilities.purge
Purge legacy records
Deleting old records that carry no patch
vulnerabilities.view
vulnerabilities.export
Export vulnerabilities
Exporting the list to CSV or Excel
vulnerabilities.view
System connections
Key
Permission
What it allows
Also carries
connections.view
View system connections
The connection map between systems and the scheduling collisions
—
Databases
Key
Permission
What it allows
Also carries
databases.view
View databases
The database inventory
—
databases.edit
Edit coordination fields
Editing a database's coordination fields
databases.view
databases.export
Export databases
Exporting the inventory to CSV or Excel
databases.view
Network equipment
Key
Permission
What it allows
Also carries
equipment.view
View network equipment
The equipment list
—
equipment.edit
Edit an equipment record
Editing custom fields on an item's record — not a change to the inventory source itself
equipment.view
equipment.export
Export equipment
Exporting the list to CSV or Excel
equipment.view
Virtualization
Key
Permission
What it allows
Also carries
virt.view
View virtualization clusters
The cluster inventory, the management planes and the cluster record
—
virt.edit
Edit a cluster record
Editing custom fields on a cluster or management-plane record — not a change to the management system itself
virt.view
virt.export
Export clusters
Exporting the inventory to CSV or Excel
virt.view
Storage
Key
Permission
What it allows
Also carries
storage.view
View storage systems
The storage inventory, utilization and the system record
—
storage.edit
Edit a storage record
Editing custom fields on the record — not a change to the array itself
storage.view
storage.export
Export storage systems
Exporting the inventory to CSV or Excel
storage.view
Cloud
Key
Permission
What it allows
Also carries
cloud.view
View cloud accounts
The account inventory, the attaching circuits and the account record
—
cloud.edit
Edit a cloud record
Editing custom fields on an account or circuit record — not a change at the cloud provider
cloud.view
cloud.export
Export cloud accounts
Exporting the inventory to CSV or Excel
cloud.view
Container platforms
Key
Permission
What it allows
Also carries
containers.view
View container clusters
The cluster inventory, the versions and the cluster record
—
containers.edit
Edit a container cluster record
Editing custom fields on the record — not a change to the cluster itself
containers.view
containers.export
Export container clusters
Exporting the inventory to CSV or Excel
containers.view
Backup and protection
Key
Permission
What it allows
Also carries
backup.view
View backup services
The service inventory, protection coverage and the service record
—
backup.edit
Edit a backup record
Editing custom fields on the record — not a change to the backup system itself
backup.view
backup.export
Export backup services
Exporting the inventory to CSV or Excel
backup.view
BIA and suggestions
Key
Permission
What it allows
Also carries
bia.view
View the BIA
The BIA register and the system-to-database dependency tree
—
bia.edit
Edit a BIA record
Editing custom fields on a business-process record — not a change to the register itself
bia.view
suggestions.view
View suggestions
The update suggestions, by system
—
suggestions.send_mail
Email the system manager
Preparing the update-status email to a system manager
suggestions.view
suggestions.export
Export suggestions
Exporting the suggestions and the system reports to Excel
suggestions.view
Dashboards and alerts
Key
Permission
What it allows
Also carries
dashboards.view
View dashboards
Viewing the boards
—
dashboards.edit
Edit dashboards
Building and editing boards
dashboards.view
alerts.view
View alerts
The alert bell for vulnerabilities and collisions
—
alerts.manage
Manage alert rules
Creating and editing alert rules, delivery channels and the delivery log
alerts.view
reports.view
View scheduled reports
The list of scheduled reports and their delivery log
—
reports.manage
Manage scheduled reports
Creating, editing and test-sending a report
reports.view
System memory
Key
Permission
What it allows
Also carries
memory.view
View system memory
The contacts and notes accumulated per system
—
memory.manage
Manage system memory
Adding, editing and deleting memory records
memory.view
Activity planning
Key
Permission
What it allows
Also carries
(three keys, not printed)
Activity planning
Viewing the weekly activity calendar, approving or rejecting an activity and syncing it with the ticketing system, and recording an incident recollection
—
Settings and configuration
Key
Permission
What it allows
Also carries
settings.view
Open settings
Reaching the settings screen
—
settings.types
Update types and templates
Managing update types and message templates
settings.view
settings.contacts
Contacts and performers
Managing the standing contacts and the performer list
settings.view
settings.checklists
Checklist forms
Building the event checklist forms
settings.view
settings.system
System settings
The general settings and the integration status
settings.view
settings.access
Access management
Viewing the access-management screen; editing it stays with administrators
settings.view
settings.nav
Sidebar menu
Adjusting the order and names of the sidebar for everyone
settings.view
settings.mail
Email to the system manager
Editing the email template and the columns of the table inside it
settings.view
settings.simulate
Simulation
Running integration tests from the simulation screen
settings.view
settings.freeze
Change freeze
Managing change-freeze periods on the calendar
settings.view
settings.integrations
Integrations and connections
Managing connections to external systems and their health checks
settings.view
settings.sso
Single sign-on (SSO)
Configuring a corporate identity provider and federated login
settings.view
(one key, not printed)
Workflows
Managing the workflows synced from the ticketing system
settings.view
settings.scenarios
Memory scenarios
Managing the activity memory scenarios
settings.view
settings.fields
Custom fields
Designing the custom fields of servers, systems and equipment
settings.view
views.manage
Shared views and layouts
Saving and editing table views and column layouts shared by everyone
—
ingest.author
Custom collection sources
Defining a collection source against an internal system — an SQL query or an HTTP call the product runs against one of the organisation's systems, and the mapping of the fields it fills
settings.view
recipients.manage
Recipient groups
Creating and editing standing recipient groups
settings.view
tokens.create
Create API tokens
Creating and managing your own account's access tokens
settings.view
tokens.service
Service tokens
Creating tokens for automated systems, which do not narrow with the permissions of whoever created them
tokens.create
tokens.manage_all
Manage all tokens
Viewing, disabling and revoking every user's tokens
tokens.create
docs.api
API documentation
Viewing this installation's interactive API documentation
settings.view
Permissions and audit
Key
Permission
What it allows
Also carries
roles.view
View roles
The list of roles, their permissions and their members
—
roles.manage
Manage roles
Creating, editing and deleting roles and their permissions
roles.view
roles.assign
Assign users
Assigning users to roles and removing them
roles.view
audit.view
View the audit log
The audit log of system actions
—
Updated
This page is the file content/docs/en/v1/reference/permissions.mdx