This page lists the IAM roles and permissions for Security Posture API. To search through all roles and permissions, see the role and permission index.
Security Posture API roles
| Role | Permissions | 
|---|---|
Security Posture Admin( Full access to Security Posture service APIs. Lowest-level resources where you can grant this role: 
  | 
   
       
 
 
       
 
       
 
 
 
 
 
 
       
  | 
Security Posture Deployer( Mutate and read permissions to the Posture Deployment resource.  | 
   
       
 
 
       
 
 
 
 
 
       
  | 
Security Posture Deployments Viewer( Read only access to the Posture Deployment resource.  | 
   
 
 
 
  | 
Security Posture Resource Editor( Mutate and read permissions to the Posture resource.  | 
   
 
       
  | 
Security Posture Resource Viewer( Read only access to the Posture resource.  | 
   
 
 
 
  | 
Security Posture Shift-Left Validator( Create access for Reports, e.g. IaC Validation Report.  | 
   
 
       
  | 
Security Posture Viewer( Read only access to all the SecurityPosture Service resources.  | 
   
 
 
 
 
       
 
 
  | 
Security Posture API permissions
| Permission | Included in roles | 
|---|---|
        
       | 
      
         
          Owner ( 
          Editor ( 
          Viewer ( 
          Support User ( 
          Security Posture Admin (  | 
    
        
       | 
      
         
          Owner ( 
          Editor ( 
          Viewer ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( 
          Security Posture Admin (  | 
    
        
       | 
      
         
          Owner ( 
          Editor ( 
          Security Posture Admin (  | 
    
        
       | 
      
         
          Owner ( 
          Editor ( 
          Viewer ( 
          Security Auditor ( 
          Support User ( 
          Security Center Admin ( 
          Security Center Admin Editor ( 
          Security Center Admin Viewer ( 
          Security Posture Admin ( 
          Security Posture Deployer ( 
          Security Posture Deployments Viewer ( 
          Security Posture Resource Editor ( 
          Security Posture Resource Viewer ( 
          Security Posture Shift-Left Validator ( 
          Security Posture Viewer ( Service agent roles 
  | 
    
        
       | 
      
         
          Owner ( 
          Editor ( 
          Viewer ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( 
          Security Posture Admin (  | 
    
        
       | 
      
         
          Owner ( 
          Editor ( 
          Security Posture Admin ( 
          Security Posture Deployer ( Service agent roles 
  | 
    
        
       | 
      
         
          Owner ( 
          Editor ( 
          Security Posture Admin ( 
          Security Posture Deployer ( Service agent roles 
  | 
    
        
       | 
      
         
          Owner ( 
          Editor ( 
          Viewer ( 
          Security Auditor ( 
          Support User ( 
          Security Center Admin ( 
          Security Center Admin Editor ( 
          Security Center Admin Viewer ( 
          Security Posture Admin ( 
          Security Posture Deployer ( 
          Security Posture Deployments Viewer ( 
          Security Posture Viewer ( Service agent roles 
  | 
    
        
       | 
      
         
          Owner ( 
          Editor ( 
          Viewer ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( 
          Security Center Admin ( 
          Security Center Admin Editor ( 
          Security Center Admin Viewer ( 
          Security Posture Admin ( 
          Security Posture Deployer ( 
          Security Posture Deployments Viewer ( 
          Security Posture Viewer ( Service agent roles 
  | 
    
        
       | 
      
         
          Owner ( 
          Editor ( 
          Security Posture Admin ( 
          Security Posture Deployer (  | 
    
        
       | 
      
         
          Owner ( 
          Editor ( 
          Viewer ( 
          Security Auditor ( 
          Support User ( 
          Security Center Admin ( 
          Security Center Admin Editor ( 
          Security Center Admin Viewer ( 
          Security Posture Admin ( 
          Security Posture Viewer (  | 
    
        
       | 
      
         
          Owner ( 
          Editor ( 
          Viewer ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( 
          Security Center Admin ( 
          Security Center Admin Editor ( 
          Security Center Admin Viewer ( 
          Security Posture Admin ( 
          Security Posture Viewer (  | 
    
        
       | 
      
         
          Owner ( 
          Editor ( 
          Security Posture Admin ( 
          Security Posture Resource Editor ( Service agent roles 
  | 
    
        
       | 
      
         
          Owner ( 
          Editor ( 
          Security Posture Admin ( 
          Security Posture Resource Editor (  | 
    
        
       | 
      
         
          Owner ( 
          Editor ( 
          Security Posture Admin ( 
          Security Posture Resource Editor (  | 
    
        
       | 
      
         
          Owner ( 
          Editor ( 
          Viewer ( 
          Security Auditor ( 
          Support User ( 
          Security Center Admin ( 
          Security Center Admin Editor ( 
          Security Center Admin Viewer ( 
          Security Posture Admin ( 
          Security Posture Resource Editor ( 
          Security Posture Resource Viewer ( 
          Security Posture Viewer ( Service agent roles 
  | 
    
        
       | 
      
         
          Owner ( 
          Editor ( 
          Viewer ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( 
          Security Center Admin ( 
          Security Center Admin Editor ( 
          Security Center Admin Viewer ( 
          Security Posture Admin ( 
          Security Posture Resource Editor ( 
          Security Posture Resource Viewer ( 
          Security Posture Viewer (  | 
    
        
       | 
      
         
          Owner ( 
          Editor ( 
          Security Posture Admin ( 
          Security Posture Resource Editor (  | 
    
        
       | 
      
         
          Owner ( 
          Editor ( 
          Security Posture Admin ( 
          Security Posture Shift-Left Validator (  | 
    
        
       | 
      
         
          Owner ( 
          Editor ( 
          Viewer ( 
          Support User ( 
          Security Posture Admin ( 
          Security Posture Shift-Left Validator (  | 
    
        
       | 
      
         
          Owner ( 
          Editor ( 
          Viewer ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( 
          Security Posture Admin ( 
          Security Posture Shift-Left Validator (  |