Netskope LogoNetskope Logo
  • Security Services
  • AI Services
  • Networking Services
  • Analytics Services
  • Integrations
  • getting-started.svgGetting Started
    • Support
    • Community
    • Netskope.com
    © 2026 All Rights Reserved. Netskope Inc.
    Home
    Admin Console
    Administration
    Managing Administrators for RBAC V3
    Netskope Advanced Analytics and RBAC V3

    Netskope Advanced Analytics and RBAC V3

    RBAC V3 is an overarching framework that governs what an admin can do in the Netskope platform. It does not matter whether the admin is doing it via the UI or REST API.

    Product capabilities are divided up into abstract functions. Every admin who logs in is assigned a role. And it is that role that defines, for each and every function, the permission the admin has:

    • None – this role has no access to this function
    • View – this role has read access to this function and can see but not change configuration or data under this function’s jurisdiction.
    • Manage – this role has both read and write access to this function and can change configuration or data under this function’s jurisdiction
    • Manage & Apply – this role has both read and write access to this function and can change configuration or data under this function’s jurisdiction. In addition, this role can make and apply changes immediately.

    You can see Advanced Analytics permissions available in the following functional areas:

    • Access Control
    • DLP
    • Threat Protection
    • Behavioral Analytics
    • Security Posture
    • Risk Insights
    • Events and Analytics

    The following table lists the Advanced Analytics function mapping.

    FUNCTIONMAX PERMISSIONSCOPE is available for ...OBFUSCATION is available ...
    UI consoleR+W-User
    -App Instance
    -Query
    Yes
    AlertsR-User
    -App Instance
    -Query
    Yes
    Application EventsR-User
    -App Instance
    -Query
    Yes
    Audit EventsR-User
    -Query
    Yes
    Cloud Firewall EventsR-User
    -App Instance
    -Query
    Yes
    DevicesR-User
    -Query
    Yes
    Endpoint EventsR-User
    -Query
    Yes
    IncidentsR-User
    -App Instance
    -Query
    Yes
    Network EventsR-User
    -Query
    Yes
    Page EventsR-User
    -Query
    Yes
    Transaction EventsR-App Instance
    -Query
    Yes
    Scope provides addition control of a function. Scope is applied globally to all supported functions.
    Obfuscation hides fields in data records related to a function. Obfuscation is applied locally to each function.

    Data scope determines the data record access control in addition to the permissions for which the admin can access/manage. Scope provides addition control of a function. Scope is applied globally to all supported functions.

    You can perform the following functions:

    • User: include or exclude a User, User Group, or Organization Unit
    • Network Location: search for a network location to include or exclude
    • App Instance: search for an app instance to include or exclude
    • Query: type in the field to add a query

    If enabled, obfuscation will only be applied to records that match the conditions. Otherwise obfuscation is applied to all records within this function. This feature is visible for functions for which it applies, therefore, visibility may vary and performance may be impacted. Obfuscation hides fields in data records related to a function. Obfuscation is applied locally to each function.

    You can obfuscate the following fields:

    • Usernames
    • Source location information
    • User IPs
    • File and object names
    • App names, URLs, and description IPs
    In this Topic
    • Netskope Advanced Analytics and RBAC V3