Permissions reference

Every permission by module and action (view/manage), the admin-only permissions, and what each grants.

permissionsviewmanageadminreference

How permissions are named

Permissions are module.action. Most modules have view (read) and manage (create/edit/delete). Vera adds use. Administrative areas are manage-only.

Feature permissions

Module view manage
Dashboards See dashboards Create and edit dashboards
Alerts See alerts, SLOs, on-call Manage alert rules, SLOs, on-call
Inventory See software/asset inventory Manage inventory and the review queue
Network See network observability Manage network tests, agents, SNMP
Synthetics See synthetic monitors Manage synthetic monitors
RUM See real-user monitoring Manage RUM applications
APM See APM, traces, metrics, logs Manage APM services
Workbooks See workbooks and workflows Create and run workbooks/workflows
Response See incidents and the war room Manage incidents and response
Cloud Integrations See cloud integrations Connect and manage cloud accounts
Sentinel See Sentinel (AI-SRE) Manage Sentinel agents and evaluations
Notifications See notification channels Manage notification channels
Settings See organization settings (retention, ingestion, usage) Change organization settings
Billing See plan, usage and billing Manage plan and billing

Vera

  • vera.use — chat with Vera, the AI assistant.
  • vera.manage — administer Vera governance and settings (admin).

Administrative permissions

These are manage-only and grant control over sensitive areas — grant them only to administrative roles:

  • settings.manage — organization settings.
  • billing.manage — plan and billing.
  • users.manage — invite and manage users, and assign roles.
  • roles.manage — create and edit roles and permissions.
  • api_keys.manage — manage API keys.
Note: Downloadable agent installers and artifacts are available to every signed-in member regardless of role, so anyone can install an agent when asked to.