You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: docs/manage/users-roles/roles/role-capabilities.md
+34-26Lines changed: 34 additions & 26 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -4,11 +4,17 @@ title: Role Capabilities
4
4
description: Assign any of these capabilities when you create user roles.
5
5
---
6
6
7
-
Following are the capabilities you can assign when you [create roles](create-manage-roles.md), including the [APIs](/docs/api/about-apis/) available when you have the role.
7
+
import ApiCreateRole from '../../../reuse/api-create-role.md';
8
+
9
+
Following are the capabilities you can assign when you [create roles](create-manage-roles.md).
10
+
11
+
:::note
12
+
If you use the [createRoleV2 API](https://api.sumologic.com/docs/#operation/createRoleV2) to create a role, enter the corresponding role capability value in the `capabilities` parameter of the API.
13
+
:::
8
14
9
15
## Data Management
10
16
11
-
| Capability | Description |API|
17
+
| Capability | Description |<ApiCreateRole/>|
12
18
| :-- | :-- | :-- |
13
19
| View Collectors | View collectors and sources that have already been installed or added. |`viewCollectors`|
14
20
| Manage Collectors |[View and manage](/docs/send-data) installed and hosted collectors as well as sources. |`manageCollectors`|
@@ -43,21 +49,21 @@ Following are the capabilities you can assign when you [create roles](create-man
43
49
44
50
## Entity Management
45
51
46
-
| Capability | Description |API|
52
+
| Capability | Description |<ApiCreateRole/>|
47
53
| :-- | :-- | :-- |
48
54
| Manage Entity Type Configs | Reserved for internal use. |`manageEntityTypeConfigs`|
49
55
50
56
## Metrics
51
57
52
-
| Capability | Description | API |
58
+
| Capability | Description |Corresponding value in the *capabilities* field of the [createRoleV2 API](https://api.sumologic.com/docs/#operation/createRoleV2)|
| Manage Password Policy|Set the password policy for your Sumo Logic account. |`managePasswordPolicy`|
63
69
|Allowlist IP Addresses |[Explicitly grant access](/docs/manage/security/create-allowlist-ip-cidr-addresses) to specific IP addresses or address ranges. |`allowlistIpAddresses`|
@@ -72,27 +78,27 @@ Following are the capabilities you can assign when you [create roles](create-man
72
78
73
79
## Dashboards
74
80
75
-
| Capability | Description |API|
81
+
| Capability | Description |<ApiCreateRole/>|
76
82
| :-- | :-- | :-- |
77
83
| Share Dashboards with the World |[Share dashboards](/docs/dashboards/share-dashboard-outside-org) in view-only mode with no login required. |`shareDashboardsWithTheWorld`|
78
-
| Share Dashboards with the Allowlist |[Share dashboards](/docs/dashboards/share-dashboard-new/) in view-only mode; viewers must be on your service allowlist. |`shareDashboardsWithYourAllowlist`and `shareDashboardWhitelist`|
84
+
| Share Dashboards with the Allowlist |[Share dashboards](/docs/dashboards/share-dashboard-new/) in view-only mode; viewers must be on your service allowlist. |`shareDashboardsWithYourAllowlist`|
79
85
80
86
## User Management
81
87
82
-
| Capability | Description |API|
88
+
| Capability | Description |<ApiCreateRole/>|
83
89
| :-- | :-- | :-- |
84
90
| Manage Users And Roles | Access the UI pages to manage [users](/docs/manage/users-roles/users) and [roles](/docs/manage/users-roles/roles). |`manageUsersAndRoles`|
85
91
86
92
## Audit Event Management
87
93
88
-
| Capability | Description |API|
94
+
| Capability | Description |<ApiCreateRole/>|
89
95
| :-- | :-- | :-- |
90
96
| Access Search Audit Events | View and download audit logs of search queries executed in the UI. |`accessSearchAuditEvents`|
91
97
| Access Audit Events | View and download audit logs of admin and config events. |`accessAuditEvents`|
92
98
93
99
## Automation Service
94
100
95
-
| Capability | Description |API|
101
+
| Capability | Description |<ApiCreateRole/>|
96
102
| :-- | :-- | :-- |
97
103
| Task View|See tasks in [playbooks](/docs/platform-services/automation-service/playbooks/). |`taskView`|
98
104
| Task Access | Access your tasks in playbooks. |`taskAccess`|
@@ -111,7 +117,7 @@ Following are the capabilities you can assign when you [create roles](create-man
111
117
112
118
## Alerting
113
119
114
-
| Capability | Description |API|
120
+
| Capability | Description |<ApiCreateRole/>|
115
121
| :-- | :-- | :-- |
116
122
| View Monitors |If folder perms are enabled, view folders & monitors you have access to. |`viewMonitors`|
117
123
| Manage Monitors | Create folders & monitors, grant perms, and (with folder perms) full CRUD on folders you control. |`manageMonitors`|
@@ -123,51 +129,53 @@ Following are the capabilities you can assign when you [create roles](create-man
123
129
<!--
124
130
## Open Analytics
125
131
126
-
| Capability | Description | API |
132
+
| Capability | Description | <ApiCreateRole/> |
127
133
| :-- | :-- | :-- |
128
134
| Manage Open Analytics Endpoint | ? | ? |
129
135
-->
130
136
131
137
## Usage Management
132
138
133
-
| Capability | Description | API |
139
+
<!-- `viewBudgets` is a guess. It doesn't appear in the `capabilities` parameter list. -->
| Manage SLOs | Create, edit, and delete SLOs. |`manageSLOs`|
144
152
145
153
## Threat Intel
146
154
147
-
| Capability | Description |API|
155
+
| Capability | Description |<ApiCreateRole/>|
148
156
| :-- | :-- | :-- |
149
157
| View Threat Intel Data Store | View the [Threat Intelligence](/docs/security/threat-intelligence/about-threat-intelligence/) tab. |`viewThreatIntelDataStore`|
150
158
| Manage Threat Intel Data Store | Create, edit, and delete threat intel sources. |`manageThreatIntelDataStore`|
151
159
152
160
<!--
153
161
## Macros
154
162
155
-
| Capability | Description | API |
163
+
| Capability | Description | <ApiCreateRole/> |
156
164
| :-- | :-- | :-- |
157
165
| Manage Macros | ? | ? |
158
166
-->
159
167
160
168
<!--
161
169
## Data Masking
162
170
163
-
| Capability | Description | API |
171
+
| Capability | Description | <ApiCreateRole/> |
164
172
| :-- | :-- | :-- |
165
173
| View Unmasked Data | ? | ? |
166
174
-->
167
175
168
176
## Organizations
169
177
170
-
| Capability | Description |API|
178
+
| Capability | Description |<ApiCreateRole/>|
171
179
| :-- | :-- | :-- |
172
180
| View Organizations | View the [Organizations](/docs/manage/manage-subscription/create-and-manage-orgs/create-manage-orgs) UI. |`viewOrganizations`|
173
181
| Create Organizations | Create and provision child organizations. |`createOrganizations`|
@@ -184,7 +192,7 @@ Following are the capabilities you can assign when you [create roles](create-man
184
192
This section is for our Cloud SOAR SaaS version. If you have a legacy Cloud SOAR instance URL matching the pattern `*.soar.sumologic.com`, see [Legacy Cloud SOAR](#legacy-cloud-soar).
0 commit comments