Tenable-Provided Role Privileges

This topic describes the performance of or functionality for a new feature in Tenable.io Key Enhancements. For more information, see Tenable.io Key Enhancements.

The following tables describe privileges associated with each Tenable-provided user role, organized by function in Tenable.io.

Area   Tenable.io Vulnerability Management-Provided Roles and Privileges

Administrator

Scan Manager Standard Scan Operator Basic
API Keys view, modify view, modify view, modify view, modify view, modify
Account Settings view, modify view, modify view, modify view, modify view, modify
Agents view, delete view, delete - - -
Agent Freeze Windows view, create, modify, delete view, create, modify, delete - - -
Agent Groups view, create, modify, delete view, create, modify, delete - - -
Agent Settings view, modify view, modify - - -
Assets view, modify, delete view, modify, delete view, modify, delete view, modify, delete view
Connectors view, create, modify, delete - - - -
Dashboards view, create, modify, delete view, create, modify, delete view, create, modify, delete view, create, modify, delete view, create, modify, delete
Exclusions view, import, export, delete view, import, export, delete - - -
General Settings view, modify - - - -
Health and Status view - - - -
Managed Credentials view, create, modify, delete view, create, modify, delete view, create, modify, delete view, create, modify, delete view, create, modify, delete
PCI Managing view, import, export, create, modify, delete - - - -
Recast Rules view, create, modify, delete - - - -
Reports view, run, create, modify, delete view, run, create, modify, delete view, run, create, modify, delete view, run, create, modify, delete view
Report Results view, delete view, delete view, delete view, delete view
Scans1 view, import, run, create, modify, delete view, import, run, create, modify, delete view, import, run, create, modify, delete view, import, run, create2, modify, delete view3, import
Scan Results view, delete view, delete view, delete view, delete view, delete
Sensors view, add, modify, delete view, add, modify, delete - - -
Scanner Groups view, create, modify, delete view, create, modify, delete - - -
Tags4 view, create tag category, create tag value, delete, assign, unassign view, create tag value, delete, assign, unassign view, delete, assign, unassign view, delete, assign, unassign view, assign, unassign
User Groups view, create, modify, delete - - - -
User-Defined Scan Templates view, import, export, create, modify, delete view, import, export, create, modify, delete view, import, export, create, modify, delete - -
Users view, create, modify, delete - - - -
Vulnerabilities view, export view, export view, export view, export view, export
Area    Tenable.io Web Application Scanning-Provided Roles and Privileges

Administrator

Scan Manager Standard Scan Operator Basic
Dashboards view, create, modify, delete view, create, modify, delete view, create, modify, delete view, create, modify, delete view
Tenable-Provided Scan Templates view view view - -
User-Defined Templates view, create, modify, delete view, create, modify, delete view - -

Scans

(also requires scan permissions)

view, create, modify, run, delete view, create, modify, run, delete view, create, modify, run, delete view, import, create5, modify, run, delete, move to trash view
Managed Credentials view, create, modify, delete view, create, modify, delete view, create, modify, delete view, create, modify, delete view, create, modify, delete

Scan Permissions

view, create, modify, delete6 view, create, modify, delete7 view, create, modify, delete8 view, create, modify, delete9 -

Scan Results

(also requires scan permissions)

view, delete view, delete view, delete view, delete view, delete
  Area Tenable.io Container Security-Provided Roles and Privileges
Administrator Scan Manager Standard Scan Operator Basic

Dashboards

view view view view view
Usage Data view 10 view view view view
Images view, push to Tenable.io, delete 11 view, push to Tenable.io, delete view, push to Tenable.io, delete view, push to Tenable.io, delete -
Image Repository view, search, delete view, search, delete view, search, delete view, search, delete view, search
Containers view view view view view
Policies create, view, edit, set permissions, delete create, view, edit, set permissions, delete view view view
Connectors create, configure, view, delete - - - -
CS Scanner download, view, configure, run download, view, configure, run download, view, configure, run download, view, configure, run download
Scan Results view, search view, search view, search view, search view, search