Cloud Security Posture Management (CSPM) service roles
With CSPM service roles, you can manage user access to the CSPM resources and their settings, as well as to the results of configuration compliance checks with security standards.
cspm.worker
The cspm.worker role allows the user to view the organization info, view the list of clouds and folders and their info as controlled resources of a Security Deck workspace.
The role is issued to the service account to perform checks for compliance with security standards configured in CSPM settings and extends to an organization, cloud, or folder.
cspm.auditor
The cspm.auditor role enables viewing info on cloud infrastructure checks for compliance with security standards, as well as on jobs for such checks configured in the CSPM settings.
cspm.viewer
The cspm.viewer role enables viewing info on cloud infrastructure checks for compliance with security standards and their results, as well as on jobs for such checks and exceptions from check rules configured in the CSPM settings.
This role includes the cspm.auditor permissions.
cspm.editor
The cspm.editor role enables managing jobs for cloud infrastructure checks for compliance with CSPM security standards and exceptions from related rules, as well as running such checks manually.
Users with this role can:
- View info on cloud infrastructure checks for compliance with security standards configured in the CSPM settings, as well as delete checks.
- View info on CSPM check jobs.
- Manually run checks for compliance with CSPM security standards.
- View CSPM check results.
- Create, suspend, resume, modify, and delete CSPM check jobs.
- View exceptions from CSPM check rules, as well as create and delete such exceptions.
This role includes the cspm.viewer permissions.
cspm.admin
The cspm.admin role enables managing jobs for cloud infrastructure checks for compliance with CSPM security standards and exceptions from check rules, as well as running such checks manually.
Users with this role can:
- View info on cloud infrastructure checks for compliance with security standards configured in the CSPM settings, as well as delete checks.
- View info on CSPM check jobs.
- Manually run checks for compliance with CSPM security standards.
- View CSPM check results.
- Create, suspend, resume, modify, and delete CSPM check jobs.
- View exceptions from CSPM check rules, as well as create and delete such exceptions.
This role includes the cspm.editor permissions.