Skip to main content

Role Capabilities

Following are the capabilities you can assign when you create roles.

note

If you use the createRoleV2 API to create a role, enter the corresponding role capability value in the capabilities parameter of the API as indicated in the tables below.

Data Management

CapabilityDescription

Value in capabilities parameter of createRoleV2 API

View CollectorsView collectors and sources that have already been installed or added.viewCollectors
Manage CollectorsView and manage installed and hosted collectors as well as sources.manageCollectors
Manage Ingest BudgetsAllows you to manage ingest budgets. Enabling this will automatically enable the Manage Collectors capability. The Manage Collectors capability on its own permits the re-assignment of budgets to different collectors, but not creating or deleting them.manageBudgets
Manage Data Volume FeedEnable and manage the data volume index for your account to avoid exceeding your data limits, and to determine when you need to upgrade your account.manageDataVolumeFeed
View Field Extraction RulesView field extraction rules, which accelerate your search process by automatically parsing fields as log messages are ingested.viewFieldExtraction
View FieldsView fields, which are custom metadata fields you can assign to logs.viewFields
Manage FieldsManage fields. Note that if you grant a role the Manage Fields capability, users with that role will also have the View Fields and View Field Extraction Rules capabilities.manageFields
Manage Field Extraction RulesManage field extractions, which speed the search process by automatically parsing fields as log messages are ingested. Note that if you grant a role the Manage Field Extraction Rules capability, users with that role will also have the Manage Fields, View Fields, and View Field Extraction Rules capabilities.manageFieldExtractionRules
Manage S3 Data ForwardingManage S3 data forwarding from Sumo Logic to an S3 bucket.manageS3DataForwarding
Manage ContentManage the content for your organization. This provides access to Admin Mode in the Library.manageContent
Manage AppsInstall and manage apps.manageApps
Manage ConnectionsManage the connections that allow you to send alerts to other tools.manageConnections
View ConnectionsView connections on the Connections page.viewConnections
View ViewsView Scheduled Views.viewScheduledViews
Manage ViewsView, create, edit, and delete Scheduled Views. Note that if you grant a role the Manage Scheduled Views capability, users with that role will also have View Scheduled Views capability.manageScheduledViews
View PartitionsView partitions.viewPartitions
Manage PartitionsView, create, edit, and delete partitions. Note that if you grant a role the Manage Partitions capability, users with that role will also have View Partitions and Manage S3 Data Forwarding capabilities.managePartitions
View Account OverviewView the Account Overview page.viewAccountOverview
Manage TokensManage Installation Tokens.manageTokens
View ParsersView parsers.viewParsers
Download Search ResultsExport log query results to a .csv file.downloadSearchResults
Access Data Volume IndexAccess the sumologic_volume index.dataVolumeIndex

Entity Management

CapabilityDescription

Value in capabilities parameter of createRoleV2 API

Manage Entity Type ConfigsReserved for internal use.manageEntityTypeConfig

Metrics

CapabilityDescriptionCorresponding value in the capabilities field of the createRoleV2 API
Manage Metrics Transformation RulesCreate, edit, or delete metrics transformation rules.metricsTransformation
Manage Logs-to-MetricsCreate, edit, or delete Logs-to-Metrics rules.metricsExtraction
Manage Metrics RulesCreate, edit, or delete metrics rules.metricsRules

Security

CapabilityDescription

Value in capabilities parameter of createRoleV2 API

Manage Password PolicySet the password policy for your Sumo Logic account.managePasswordPolicy
Allowlist IP AddressesExplicitly grant access to specific IP addresses or address ranges.ipAllowlisting
Create Access KeysCreate your own access keys.createAccessKeys
Manage Access KeysSet up, activate, deactivate, or delete access keys for your organization.manageAccessKeys
Manage Support Account AccessEnable management of the Sumo Logic support account for your organization.manageSupportAccountAccess
Manage Audit Data FeedEnable and manage the Audit Index, which provides information on internal events.manageAuditDataFeed
Manage SAMLProvision and manage SAML for single sign-on.manageSAML
Manage Share Dashboards Outside OrganizationShare a dashboard with users who do not have Sumo Logic access.shareDashboardOutsideOrg
Manage Organization SettingsConfigure concurrent session limits and the Data Access Level for Shared Dashboards security policy.manageOrgSettings
Change Data Access LevelChange the data access level of dashboards or scheduled searches.changeDataAccessLevel

Dashboards

CapabilityDescription

Value in capabilities parameter of createRoleV2 API

Share Dashboards with the WorldShare dashboards in view-only mode with no login required.shareDashboardWorld
Share Dashboards with the AllowlistShare dashboards in view-only mode; viewers must be on your service allowlist.shareDashboardAllowlist

User Management

CapabilityDescription

Value in capabilities parameter of createRoleV2 API

Manage Users And RolesAccess the UI pages to manage users and roles.manageUsersAndRoles

Audit Event Management

CapabilityDescription

Value in capabilities parameter of createRoleV2 API

Access Search Audit EventsView and download audit logs of search queries executed in the UI.searchAuditIndex
Access Audit EventsView and download audit logs of admin and config events.auditEventIndex

Automation Service

CapabilityDescription

Value in capabilities parameter of createRoleV2 API

Task ViewSee tasks in playbooks.cloudSoarIncidentTaskView
Task AccessAccess your tasks in playbooks.cloudSoarIncidentTaskAccess
Task Access AllAccess all user tasks in playbooks.cloudSoarIncidentTaskAccessAll
Task EditConfigure tasks in playbooks.cloudSoarIncidentTaskEdit
Task ReassignAssign tasks in playbooks to users.cloudSoarIncidentTaskReassign
App Central AccessView App Central.cloudSoarAppCentralAccess
App Central ExportExport integrations and playbooks from App Central.cloudSoarAppCentralExport
Integrations AccessView integrations.cloudSoarIntegrationsAccess
Integrations ConfigureCreate and edit integrations.cloudSoarIntegrationsConfigure
Playbooks AccessView playbooks.cloudSoarPlaybooksAccess
Playbooks ConfigureCreate and edit playbooks.cloudSoarPlaybooksConfigure
Bridge Monitoring AccessMonitor Bridge operations.cloudSoarBridgeMonitoringAccess
Observability AccessAccess automation in the SaaS Log UI.cloudSoarObservabilityAccess
Observability ConfigureCreate and edit automation in the Sumo Logic SaaS Log Analytics Platform.cloudSoarObservabilityManagement

Alerting

CapabilityDescription

Value in capabilities parameter of createRoleV2 API

View MonitorsIf folder perms are enabled, view folders & monitors you have access to.viewMonitorsV2
Manage MonitorsCreate folders & monitors, grant perms, and (with folder perms) full CRUD on folders you control.manageMonitorsV2
Admin MonitorsWith folder perms, full CRUD & grant on all folders & monitors.adminMonitorsV2
View AlertsView alerts on the Alert page.viewAlerts
View Muting SchedulesView Muting Schedules.viewMutingSchedules
Manage Muting SchedulesCreate, edit, and delete Muting Schedules.manageMutingSchedules

Usage Management

CapabilityDescription

Value in capabilities parameter of createRoleV2 API

View Usage ManagementView usage management.viewUsageManagement
Manage Usage ManagementManage usage management.manageBudgets

Reliability Management

CapabilityDescription

Value in capabilities parameter of createRoleV2 API

View SLOsView Service Level Objectives (SLOs).viewSlos
Manage SLOsCreate, edit, and delete SLOs.manageSlos

Threat Intel

CapabilityDescription

Value in capabilities parameter of createRoleV2 API

View Threat Intel Data StoreView the Threat Intelligence tab.viewThreatIntelDataStore
Manage Threat Intel Data StoreCreate, edit, and delete threat intel sources.manageThreatIntelDataStore

Organizations

CapabilityDescription

Value in capabilities parameter of createRoleV2 API

View OrganizationsView the Organizations UI.viewOrganizations
Create OrganizationsCreate and provision child organizations.createOrganizations
Change Credits AllocationChange the credits allocation for a child organization.changeCreditsAllocation
Create Trial OrganizationsCreate trial organizations (Service Providers only).createTrialOrganizations
Upgrade Trial OrganizationsUpgrade trial organizations (Service Providers only).upgradeTrialOrganizations
Deactivate OrganizationsDeactivate trial organizations (Service Providers only).deactivateOrganizations

Cloud SOAR

Cloud SOAR capabilities appear in the roles UI only if Cloud SOAR has been enabled for your account.

info

This section is for our Cloud SOAR SaaS version. If you have a legacy Cloud SOAR instance URL matching the pattern *.soar.sumologic.com, see Legacy Cloud SOAR.

Capability categoryCapabilityDescription

Value in capabilities parameter of createRoleV2 API

View Cloud SOARShow “Cloud SOAR” link in nav.viewCloudSoar
IncidentViewView all incidents.cloudSoarIncidentView
IncidentAccessAccess your incidents.cloudSoarIncidentAccess
IncidentAccess AllAccess all incidents.cloudSoarIncidentAccessAll
IncidentEditCreate, edit, delete incidents.cloudSoarIncidentEdit
IncidentBulk OperationsManage incident bulk operations.cloudSoarIncidentBulkOperations
IncidentManage InvestigatorsAssign/remove investigators.cloudSoarIncidentManageInvestigators
IncidentChange OwnershipChange incident ownership.cloudSoarIncidentChangeOwnership
TriageViewView all triage.cloudSoarIncidentTriageView
TriageAccessAccess your triage events.cloudSoarIncidentTriageAccess
TriageAccess AllAccess all triage events.cloudSoarIncidentTriageAccessAll
TriageChange OwnershipChange triage ownership.cloudSoarIncidentTriageChangeOwnership
TriageEditCreate, edit, delete triage events.cloudSoarIncidentTriageEdit
TriageBulk Physical DeleteBulk-delete triage events.cloudSoarIncidentTriageBulkPhysicalDelete
FoldersEditCreate, edit, delete playbook folders.cloudSoarIncidentFoldersEdit
AttachmentsAccessView attachments.cloudSoarIncidentAttachmentsAccess
AttachmentsEditCreate, edit, delete attachments.cloudSoarIncidentAttachmentsEdit
Incident PlaybookAccessView playbooks.cloudSoarIncidentPlaybooksAccess
Incident PlaybookEditCreate, edit, delete playbooks.cloudSoarIncidentPlaybooksEdit
Incident PlaybookManageManage playbook lifecycle.cloudSoarIncidentPlaybooksManage
NoteAccessView notes.cloudSoarIncidentNotesAccess
NoteEditCreate, edit, delete notes.cloudSoarIncidentNotesEdit
War RoomUseParticipate in War Room.cloudSoarIncidentWarRoomUse
Settings GeneralConfigureConfigure global settings.cloudSoarGeneralConfigure
User ManagementGroupsManage groups.cloudSoarUserManagementGroups
NotificationConfigureConfigure notifications.cloudSoarNotificationConfigure
CustomizationLogoCustomize logo.cloudSoarCustomizationLogo
CustomizationFieldsCustomize fields.cloudSoarCustomizationFields
CustomizationIncident LabelsCustomize incident labels.cloudSoarCustomizationIncidentLabels
CustomizationTriageCustomize triage UI.cloudSoarNotificationTriage
Audit & InfoLicense InformationView license audit info.cloudSoarAuditAndInformationLicenseInformation
Audit & InfoAudit TrailView audit trail.cloudSoarAuditAndInformationAuditTrail
Audit & InfoConfigure Audit TrailConfigure audit trail.cloudSoarAuditAndInformationConfigureAuditTrail
APIUseUse the Cloud SOAR API.cloudSoarAPIUse
APIAPI AdminAdminister Cloud SOAR API.cloudSoarAPIAdmin
APIEmail ReadRead email artifacts.cloudSoarAPIEmailRead
APIEmail EditCreate, edit, delete email artifacts.cloudSoarAPIEmailEdit
Incident TemplatesAccessView incident templates.cloudSoarIncidentTemplatesAccess
Incident TemplatesConfigureConfigure incident templates.cloudSoarIncidentTemplatesConfigure
Automation RulesAccessView automation rules.cloudSoarAutomationRulesAccess
Automation RulesConfigureConfigure automation rules.cloudSoarAutomationRulesConfigure
EntitiesAccessView entities.cloudSoarEntitiesAccess
EntitiesManageCreate, edit, delete entities.cloudSoarEntitiesManage
EntitiesBulk Physical DeleteBulk-delete entities.cloudSoarEntitiesBulkPhysicalDelete
ReportAccessView reports.cloudSoarReportAccess
ReportAccess AllAccess all reports.cloudSoarReportAll
DashboardAccessView dashboards.cloudSoarDashboardAccess
DashboardAccess AllAccess all dashboards.cloudSoarDashboardAll
WidgetsUse AllUse all widgets.cloudSoarWidgetsAll

Legacy Cloud SOAR

CapabilityDescription
View Cloud SOARShow “Cloud SOAR” link in nav (legacy URL).
Settings GeneralConfigure legacy settings.
ConfigureUpdate legacy configuration.

Cloud SIEM

Cloud SIEM features only show if enabled.

CapabilityDescription

Value in capabilities parameter of createRoleV2 API

View Cloud SIEMShow “Cloud SIEM” link in nav.viewCse

Insights

CapabilityDescription

Value in capabilities parameter of createRoleV2 API

Comment on InsightsAdd comments to Insights.cseCommentOnInsights
Create InsightsCreate new Insights.cseCreateInsights
Delete InsightsDelete existing Insights.cseDeleteInsights
Invoke Insights ActionsRun an Action on an Insight.cseInvokeInsights
Manage Insight AssigneeChange who’s assigned to an Insight.cseManageInsightAssignee
Manage Insight SignalsAdd/remove Signals on an Insight.cseManageInsightSignals
Manage Insight StatusChange an Insight’s status.cseManageInsightStatus
Manage Insight TagsAdd/delete tags.cseManageInsightTags

Content

CapabilityDescription

Value in capabilities parameter of createRoleV2 API

View RulesView rules.cseViewRules
Manage RulesCreate, edit, delete rules.cseManageRules
View Threat IntelligenceView threat intel sources.cseViewThreatIntelligence
Manage Threat IntelligenceCreate, edit, delete threat intel sources.cseManageThreatIntelligence
View Match ListsView Match Lists.cseViewMatchLists
Manage Match ListsCreate, edit, delete Match Lists.cseManageMatchLists
View File AnalysisView YARA rules.cseViewFileAnalysis
Manage File AnalysisCreate, edit, delete YARA rules.cseManageFileAnalysis
View Custom InsightsView custom Insights.cseViewCustomInsights
Manage Custom InsightsCreate, edit, delete custom insights.cseManageCustomInsights
View Network BlocksView network blocks.cseViewNetworkBlocks
Manage Network BlocksCreate, edit, delete network blocks.cseManageNetworkBlocks
View Suppressed EntitiesView suppressed entities.cseViewSuppressedEntities
Manage Suppressed EntitiesSuppress/unsuppress entities.cseManageSuppressedEntities

Configuration

CapabilityDescription

Value in capabilities parameter of createRoleV2 API

View MappingsView mappings.cseViewMappings
Manage MappingsCreate, edit, delete mappings.cseManageMappings
View WorkflowView detection settings, statuses, resolutions, tag schemas.cseViewCustomInsightStatuses
Manage WorkflowCreate, edit, delete detection settings, statuses, resolutions, tag schemas.cseManageCustomInsightStatuses
View Context ActionsView Context Actions.cseViewContextActions
Manage Context ActionsCreate, edit, delete Context Actions.cseManageContextActions
View ActionsView Actions.cseViewActions
Manage ActionsCreate, edit, delete Actions.cseManageActions
View EnrichmentsView enrichments.cseViewEnrichments
Manage EnrichmentsUpload enrichment data via API.cseManageEnrichments
View Custom Entity TypesView custom entity types.cseViewCustomEntityType
Manage Custom Entity TypesCreate, edit, delete custom entity types.cseManageCustomEntityType
View EntityView Entities.cseViewEntity
Manage EntityCreate, edit, delete entities.cseManageEntity
View Entity NormalizationView Domain Normalization settings.cseViewEntityConfiguration
Manage Entity NormalizationUpdate Domain Normalization settings.cseManageEntityConfiguration
View Entity CriticalityView Entity Criticalities.cseViewEntityCriticality
Manage Entity CriticalityCreate, edit, delete entity criticalities.cseManageEntityCriticality
View Tag SchemasView tag schemas.cseViewTagSchemas
Manage Tag SchemasCreate, edit, delete tag schemas.cseManageTagSchemas
Manage Favorite FieldsAdd/remove favorite fields in Records UI.cseManageFavoriteFields
View Entity GroupsView Entity Groups.cseViewEntityGroups
Manage Entity GroupsCreate, edit, delete entity groups.cseManageEntityGroups
View AutomationsView automations.cseViewAutomations
Manage AutomationsCreate, edit, delete automations.cseManageAutomations
Execute AutomationsRun automations.cseExecuteAutomations
Status
Legal
Privacy Statement
Terms of Use
CA Privacy Notice

Copyright © 2025 by Sumo Logic, Inc.