How do I Check Scan Permissions?

This article describes how to check who does or does not have the permissions required to run scans.

To check scan permissions in the Spirion Sensitive Data Platform (SDP), you must navigate to the Role-Based Access Control (RBAC) settings within the console. Note that only users with the Admin role can manage or view these permissions.

Here is how to check and manage permissions for scans, Targets, and Tags:

1. Navigate to Role Management

  • Log into the Spirion Console as an Admin.
  • Go to the User Management section (often found under a "Settings" or "Admin" menu).
  • Select the Roles tab.

2. Inspect Role Permissions

  • Find the specific role you want to check (e.g., "Security Analyst" or a custom role).
  • Click the ellipsis (...) or "More Options" menu for that role and select Manage Permissions.
  • This page enables you to see the permissions assigned to that role for Tags, Targets, and Scan Results.

3. Check Target and Tag Scoping

Permissions in Spirion are often "scoped" by Tags or Targets. If a user cannot run a scan, it is likely because their role has restricted access to the assets involved:

  • Target Permissions: Check if the role has "None," "View," or "Full" permissions for the Targets included in the scan. If set to None, the user cannot see or execute scans against that Target.
  • Tag Permissions: Check the permissions for Agent Tags. If a user's role does not have "View" or "Manage" permissions for the Tags assigned to the Agents in a scan, they will be unable to initiate that scan.

4. Check Individual User Overrides

While roles set the baseline, individual users can have specific overrides:

  • Go to User Management -> Users tab.
  • Select a user and choose Edit Permissions.
  • Individual user permissions override role-level permissions. Check here to see if a specific user has been explicitly denied access to a scan or Target.

5. Understand the "Owner" Rule

  • Owner Permissions: Any Target or Tag created by a user automatically grants that user Full Permissions (Owner status). This override cannot be changed by an admin at the role level; the creator always has full access to what they built.

Summary of Permission Levels

Permission

Effect on Scans

None

The Target/Tag is hidden. The user cannot see or run scans involving these assets.

View

The user can see the Target/Tag and view results, but may not be able to "Run Scan Now."

Unmask View

Enables the user to see the actual sensitive data (unmasked) in the results.

Full/Manage

Allows the user to create, edit, and execute scans for those assets.

If the "Run Scan Now" button is missing: It is almost certainly because the user's role (or individual override) has the Target Permission or Tag Permission set to something less than "Manage" or "Full" for the assets in that scan.