Netskope LogoNetskope Logo
  • Security Services
  • AI Services
  • Networking Services
  • Analytics Services
  • Integrations
  • getting-started.svgGetting Started
    • Support
    • Community
    • Netskope.com
    © 2026 All Rights Reserved. Netskope Inc.
    Home
    DataSec Command Center
    Manage DataSec Command Center Administrator Permissions (RBAC)

    Manage DataSec Command Center Administrator Permissions (RBAC)

    Netskope Role-Based Access Control (RBAC) allows you to manage administrator access to DataSec Command Center (DCC) features and screens in the Netskope tenant. You can assign default pre-defined roles or configure custom roles to grant administrators the appropriate level of visibility and management capabilities.

    DataSec Command Center Functional Area and Permissions

    The Netskope tenant UI provides the following functional area and permissions under Role-Based Access Control:

    • Functional Area: DataSec Command Center
    • Available Permissions:
      • None: Disables access to DataSec Command Center. Administrators cannot view or access DCC screens, dashboards, or assets.
      • View: Grants read-only visibility into DataSec Command Center screens, including Overview, Data Stores and Destinations, Identities, Risk Policies and Remediation, and Global Search.
      • Manage: Grants full administrative access to view all DCC screens, manage risk policies, execute remediation actions, and retrieve file snippets for SaaS applications.
    DataSec Command Center does not support Scope or Obfuscation settings in RBAC.

    Permissions for Pre-Defined Roles

    The following table outlines the default DataSec Command Center permissions for standard, pre-defined RBAC roles:

    • Manage: The administrator has full access to view, manage, and perform actions in DataSec Command Center.
    • View: The administrator has read-only access to DataSec Command Center.
    • None: The administrator has no access to DataSec Command Center.
    Pre-Defined Role NameDataSec Command Center Permission
    Tenant AdminManage
    Delegated AdminManage
    Security AdminManage
    InfoSec Operations AdminManage
    Restricted AdminView
    Compliance OfficerView
    NS Technical SuccessView
    NS Technical SupportView
    Cloud Intelligence AnalystNone
    Application Risk AnalystNone
    Enterprise Applications AdminNone
    Directory AdminNone
    Security AnalystNone
    IaaS and PaaS AdminNone
    Netskope Cloud ExchangeNone

    Additional Permissions for Integrated Features

    DataSec Command Center integrates data and actions from other Netskope platform modules. To view specific tags, scores, or execute risk remediation actions across DCC screens, administrators require additional functional permissions:

    Integrated Feature / ActionRequired Module & PermissionImpact if Missing
    App TagsCloud Confidence Index (CCI): ViewDCC displays an error when loading application tags.
    UCI Score in Identity DrawerUser Confidence Index (UCI): ViewThe UCI score does not appear in the user Identity drawer.
    Unmanaged Instance TagsSkope IT (Any): View / ReadUnmanaged instance tags do not appear in the inventory UI.
    DSPM Data Store SnippetsSecurity Posture > Data > Sampling: ViewAdministrators cannot fetch content snippets for DSPM data stores.
    SaaS Application SnippetsDataSec Command Center: ManageAdministrators cannot retrieve content snippets for SaaS applications.
    Create Risk PoliciesAPI Data Protection > Policy: ManageAdministrators cannot create new policies directly from the Risk UI.
    Apply Risk PoliciesAPI Data Protection > Policy: Manage and ApplyAdministrators cannot apply policies from the Risk UI.
    Manual Remediation ActionsAPI Data Protection > Policy: ManageAdministrators cannot trigger manual remediation actions on the Risk UI.

    To learn more about related permissions:

    • Manage DSPM Administrator Permissions (RBAC)
    • DataSec Command Center

    Configuring a Custom Role for DataSec Command Center

    To create or update a custom administrator role for DataSec Command Center:

    1. In the Netskope tenant UI, go to Settings > Administration > Administrator & Roles.
    2. Click New Role, or click the name of an existing custom role to edit it.
    3. Enter a Role Name and an optional description.
    4. Under Permissions, select one or more functional areas to display the permissions table.
    5. In the Function column, locate DataSec Command Center.
    6. Under the Permission column, select View or Manage depending on the desired level of access.
      • (Optional) Configure any additional permissions listed in the Additional Permissions for Integrated Features table if the administrator requires policy management, remediation, or snippet retrieval.
    7. Click Save.
    In this Topic
    • Manage DataSec Command Center Administrator Permissions (RBAC)