Netskope LogoNetskope Logo
  • Security Services
  • AI Services
  • Networking Services
  • Analytics Services
  • Integrations
  • getting-started.svgGetting Started
    • Support
    • Community
    • Netskope.com
    © 2026 All Rights Reserved. Netskope Inc.
    Home
    Data Security Posture Management (DSPM)
    Using The DSPM Platform
    Platform Administration & Identity
    Manage DSPM Administrator Permissions (RBAC)

    Manage DSPM Administrator Permissions (RBAC)

    Overview

    This article explains how to manage administrator access to Netskope Data Security Posture Management (DSPM) screens and functions using Role-Based Access Control (RBAC) v3. You can grant permissions by assigning pre-defined roles or by creating custom roles with granular control over DSPM-specific functional areas.

    Understand DSPM Functional Areas

    Access to DSPM is divided into four functional areas. When creating a custom role, you can assign Manage or View permissions to each of these areas.

    Functional AreaControlled DSPM Screens and Features
    ReportingDashboard
    Alerts
    Reports
    User Assessment
    ManagementData Stores > Data Store Inventory
    Data Stores > Configuration Analysis
    Data Stores > Privileges Analysis
    Classification > Classification Management
    Classification > Entity Data Types
    Classification > Data Tags
    Policies > Policy Management
    Policies > Policy Categories
    Policies > Workflows
    User Identity > Employee Management
    User Identity > User Tags
    AdministrationAdministration > Infrastructure Connections
    Administration > Integrations
    Administration > Notification Settings
    Administration > Sidecar
    SamplingControls two separate functions:
    - Classification Management > Fields > Fetch Samples button
    - Classification Management > Files > Get Snippets button
    Screens not explicitly listed above (e.g., Licensing, Support) are accessible by any role that has general access to the DSPM module.

    Permissions for Pre-Defined Roles

    The following table outlines the default DSPM permissions for the standard, pre-defined RBAC v3 roles.

    • Manage: The administrator can view and perform all actions within the functional area.
    • View: The administrator can only view information and cannot make changes.
    • None: The administrator has no access to the screens within the functional area.
    Pre-Defined Role NameReportingManagementAdministrationSampling
    Tenant AdminManageManageManageView
    Delegated AdminManageManageNoneView
    Restricted AdminManageViewNoneNone
    Cloud Intelligence AnalystManageNoneNoneNone
    Application Risk AnalystManageNoneNoneNone
    Enterprise Applications AdminManageNoneNoneNone
    Directory AdminManageNoneNoneNone
    Security AdminManageManageNoneView
    InfoSec Operations AdminManageManageNoneView
    Compliance OfficerManageViewNoneNone
    Security AnalystManageNoneNoneNone
    IaaS and PaaS AdminManageManageNoneNone
    NS Technical SuccessManageViewNoneNone
    NS Technical SupportViewViewViewView
    Netskope Cloud ExchangeNoneNoneNoneNone

    Configure a Custom Role for DSPM

    You can create a custom role to grant specific combinations of DSPM permissions.

    1. Go to Settings > Administration > Roles.
    2. Click New Role or select an existing custom role to edit.
    3. In the Permissions section, enable the parent functional area to see the DSPM permissions > Select the checkbox for Security Posture > Data.
    4. Scroll down to the new DSPM section > Using the dropdowns, grant Manage, View, or None for each of the four DSPM functional areas (Reporting, Management, Administration, Sampling).
    5. Click Save.

    Non-Applicable RBAC Features

    When configuring custom roles specifically for DSPM, be aware that the following RBAC v3 functionalities do not apply to DSPM permissions:

    • Scope
    • Obfuscation
    • IP Allowlist

    In this Topic
    • Manage DSPM Administrator Permissions (RBAC)