RBAC V3 is an overarching framework that governs what an admin can do in the Netskope platform. It does not matter whether the admin is doing it via the UI or REST API.
Product capabilities are divided up into abstract functions. Every admin who logs in is assigned a role. And it is that role that defines, for each and every function, the permission the admin has:
- None – this role has no access to this function
- View – this role has read access to this function and can see but not change configuration or data under this function’s jurisdiction.
- Manage – this role has both read and write access to this function and can change configuration or data under this function’s jurisdiction
- Manage & Apply – this role has both read and write access to this function and can change configuration or data under this function’s jurisdiction. In addition, this role can make and apply changes immediately.
You can see Advanced Analytics permissions available in the following functional areas:
- Access Control
- DLP
- Threat Protection
- Behavioral Analytics
- Security Posture
- Risk Insights
- Events and Analytics
The following table lists the Advanced Analytics function mapping.
| FUNCTION | MAX PERMISSION | SCOPE is available for ... | OBFUSCATION is available ... |
|---|---|---|---|
| UI console | R+W | -User -App Instance -Query | Yes |
| Alerts | R | -User -App Instance -Query | Yes |
| Application Events | R | -User -App Instance -Query | Yes |
| Audit Events | R | -User -Query | Yes |
| Cloud Firewall Events | R | -User -App Instance -Query | Yes |
| Devices | R | -User -Query | Yes |
| Endpoint Events | R | -User -Query | Yes |
| Incidents | R | -User -App Instance -Query | Yes |
| Network Events | R | -User -Query | Yes |
| Page Events | R | -User -Query | Yes |
| Transaction Events | R | -App Instance -Query | Yes |
Obfuscation hides fields in data records related to a function. Obfuscation is applied locally to each function.
Data scope determines the data record access control in addition to the permissions for which the admin can access/manage. Scope provides addition control of a function. Scope is applied globally to all supported functions.
You can perform the following functions:
- User: include or exclude a User, User Group, or Organization Unit
- Network Location: search for a network location to include or exclude
- App Instance: search for an app instance to include or exclude
- Query: type in the field to add a query
If enabled, obfuscation will only be applied to records that match the conditions. Otherwise obfuscation is applied to all records within this function. This feature is visible for functions for which it applies, therefore, visibility may vary and performance may be impacted. Obfuscation hides fields in data records related to a function. Obfuscation is applied locally to each function.
You can obfuscate the following fields:
- Usernames
- Source location information
- User IPs
- File and object names
- App names, URLs, and description IPs

