Role Reference

Role Reference (Complete Matrix)

The following table maps every significant action in the system to the roles that can perform it. Actions are grouped by feature area.

ActionViewerAnalystApproverAdmin
Dashboard
View dashboard KPI cardsYesYesYesYes
View recent activityYesYesYesYes
Findings
View findings listYesYesYesYes
View finding detailYesYesYesYes
Create finding (manual)NoYesYesYes
Create finding (Report Finding page action)Yes*YesYesYes
Update finding statusNoYesYesYes
Import findings via CSVNoYesYesYes
Export findings as PDFYesYesYesYes
Bulk update finding statusNoYesYesYes
Create Jira issue from findingNoYesYesYes
Cases
View cases listYesYesYesYes
View case detailYesYesYesYes
Create caseNoYesYesYes
Update case statusNoYesYesYes
Assign caseNoYesYesYes
Add comment to caseNoYesYesYes
Link finding to caseNoYesYesYes
Bulk update casesNoYesYesYes
Export case evidence bundleNoYesYesYes
Export cases as PDFYesYesYesYes
Create Jira issue from caseNoYesYesYes
Request risk exceptionNoYesYesYes
Approve risk exceptionNoNoYesYes
Revoke risk exceptionNoNoNoYes
Access Explorer
Analyze page accessYesYesYesYes
View exposure scoreYesYesYesYes
View principal list (groups, users)YesYesYesYes
Expand group to individual usersNoYesYesYes
Explain access for a specific userNoYesYesYes
Invalidate access cacheNoYesYesYes
Scanning
View scan status and historyYesYesYesYes
Start content scan (full / incremental / space)NoYesYesYes
Pause / abort scanNoYesYesYes
View scan hit detailsYesYesYesYes
Alerts
View alert rulesYesYesYesYes
Create/edit/delete alert rulesNoNoNoYes
View triggered alertsYesYesYesYes
Acknowledge alertNoYesYesYes
Resolve alertNoYesYesYes
Audit Log
View audit logYesYesYesYes
Filter audit logYesYesYesYes
Export audit logYesYesYesYes
Notifications
View own notificationsYesYesYesYes
Mark notification read/dismissedYesYesYesYes
Mark all notifications readYesYesYesYes
Admin Settings
Access Admin Settings pageNoNoNoYes
Assign/change/remove rolesNoNoNoYes
Set classificationsNoNoNoYes
Remove classificationsNoNoNoYes
Enable/disable detectorsNoNoNoYes
Create/edit/delete custom detectorsNoNoNoYes
Update score weightsNoNoNoYes
Update SLA policyNoNoNoYes
Configure access expansionNoNoNoYes
Manage notification channelsNoNoNoYes
Configure Jira integrationNoNoNoYes
Update retention policyNoNoNoYes
Run retention purgeNoNoNoYes
Rebuild entity count cacheNoNoNoYes
View job health / run historyNoNoNoYes

*Any authenticated Confluence user can use the “Report Security Finding” page action regardless of Aegis role.