Overview
This article explains how to manage administrator access to Netskope Data Security Posture Management (DSPM) screens and functions using Role-Based Access Control (RBAC) v3. You can grant permissions by assigning pre-defined roles or by creating custom roles with granular control over DSPM-specific functional areas.
Understand DSPM Functional Areas
Access to DSPM is divided into four functional areas. When creating a custom role, you can assign Manage or View permissions to each of these areas.
| Functional Area | Controlled DSPM Screens and Features |
|---|---|
| Reporting | Dashboard Alerts Reports User Assessment |
| Management | Data Stores > Data Store Inventory Data Stores > Configuration Analysis Data Stores > Privileges Analysis Classification > Classification Management Classification > Entity Data Types Classification > Data Tags Policies > Policy Management Policies > Policy Categories Policies > Workflows User Identity > Employee Management User Identity > User Tags |
| Administration | Administration > Infrastructure Connections Administration > Integrations Administration > Notification Settings Administration > Sidecar |
| Sampling | Controls two separate functions: - Classification Management > Fields > Fetch Samples button - Classification Management > Files > Get Snippets button |
Permissions for Pre-Defined Roles
The following table outlines the default DSPM permissions for the standard, pre-defined RBAC v3 roles.
- Manage: The administrator can view and perform all actions within the functional area.
- View: The administrator can only view information and cannot make changes.
- None: The administrator has no access to the screens within the functional area.
| Pre-Defined Role Name | Reporting | Management | Administration | Sampling |
|---|---|---|---|---|
| Tenant Admin | Manage | Manage | Manage | View |
| Delegated Admin | Manage | Manage | None | View |
| Restricted Admin | Manage | View | None | None |
| Cloud Intelligence Analyst | Manage | None | None | None |
| Application Risk Analyst | Manage | None | None | None |
| Enterprise Applications Admin | Manage | None | None | None |
| Directory Admin | Manage | None | None | None |
| Security Admin | Manage | Manage | None | View |
| InfoSec Operations Admin | Manage | Manage | None | View |
| Compliance Officer | Manage | View | None | None |
| Security Analyst | Manage | None | None | None |
| IaaS and PaaS Admin | Manage | Manage | None | None |
| NS Technical Success | Manage | View | None | None |
| NS Technical Support | View | View | View | View |
| Netskope Cloud Exchange | None | None | None | None |
Configure a Custom Role for DSPM
You can create a custom role to grant specific combinations of DSPM permissions.
- Go to Settings > Administration > Roles.
- Click New Role or select an existing custom role to edit.
- In the Permissions section, enable the parent functional area to see the DSPM permissions > Select the checkbox for Security Posture > Data.
- Scroll down to the new DSPM section > Using the dropdowns, grant Manage, View, or None for each of the four DSPM functional areas (Reporting, Management, Administration, Sampling).
- Click Save.
Non-Applicable RBAC Features
When configuring custom roles specifically for DSPM, be aware that the following RBAC v3 functionalities do not apply to DSPM permissions:
- Scope
- Obfuscation
- IP Allowlist

