Access to each part of Interno is controlled by permission scopes. Interno's own scopes all begin with defence:. This article lists the scopes that Interno checks and what each one unlocks.
This page covers Interno only. For every product's scopes in one place, see the *Zeron Platform: Complete Permissions & RBAC Reference*.
zitadel:iam permission, which is what gates the Admin > Management area where users, groups and policies are maintaineddefence:dashboard:view.zitadel:iam.| To do this | Scope |
|---|---|
| Open dashboards, and the Asset Inventory page | defence:dashboard:view |
| Create a dashboard, use AI dashboard/widget suggestions, import a dashboard | defence:dashboard:create |
| Edit a dashboard (rearrange widgets, save layout changes) | defence:dashboard:update |
| Delete a dashboard | defence:dashboard:delete |
Export Dashboard needs only defence:dashboard:view. Set As Default saves a change to the dashboard, so it requires defence:dashboard:update.
| To do this | Scope |
|---|---|
| See saved widgets and the widget library | defence:widget:view |
| Create or duplicate a widget | defence:widget:create |
| Update a widget, or link/unlink a drill-down widget | defence:widget:update |
| Delete a widget | defence:widget:delete |
| Load the data behind a widget | defence:widget:data:view or defence:dashboard:view |
| Get visualisation recommendations | defence:widget:visualize or defence:dashboard:view |
The User Access Coverage tables are served by the widget service, so viewing them also requires defence:widget:view.
| To do this | Scope |
|---|---|
| View queries and alerts | defence:query:view |
| Create a query or alert | defence:query:create |
| Edit a query or alert | defence:query:update |
| Delete a query or alert | defence:query:delete |
| Run a query or alert | defence:query:execute |
| To do this | Scope |
|---|---|
| Open the Manual Ingestion page and its history | defence:manual-ingest:view |
| Start an upload | defence:manual-ingest:create |
| Review and approve uploaded data | defence:manual-ingest:review |
The import itself is executed by the query service, so users who upload also need defence:query:execute.
| To do this | Scope |
|---|---|
| See the Integrations page and the connector catalogue | defence:integration:view |
| View saved integration credentials | defence:integration:credentials:view |
| Add an integration, edit an existing one, start a scan, activate or deactivate | defence:integration:credentials:create |
| Delete an integration | defence:integration:credentials:delete |
Editing an integration is deliberately gated on the same scope as creating one — there is no separate "edit" scope.
| To do this | Scope |
|---|---|
| View risks | defence:risk:view |
| Create a risk | defence:risk:create or defence:risk:manage |
| Update a risk | defence:risk:update or defence:risk:manage |
| Delete a risk | defence:risk:delete or defence:risk:manage |
| Use the full four-step risk workflow | defence:risk:manage |
| View documents attached to a risk | defence:risk:documents:view |
| To do this | Scope |
|---|---|
| See the Evidence tab in the Query Library | grc:evidence:view |
| Create or delete an evidence query | grc:evidence:create |
Read-only analyst defence:dashboard:view, defence:widget:view, defence:widget:data:view, defence:query:view, defence:integration:view, defence:risk:view
Full Interno user All defence:* scopes above. Add grc:evidence:view and grc:evidence:create if the person works with evidence queries.
Administrator The full Interno user set plus zitadel:iam, so they can manage users, groups and departments.
A user sees the "Unauthorized" screen on a page → Their group is missing that page's scope. Find the row above and add the scope to the group's policy.
A user can open dashboards but cannot rearrange widgets → Editing a dashboard layout requires defence:dashboard:update. Adding widgets to it also needs defence:widget:view.
A user cannot see the Create button on the Dashboard page → That button appears only if the user holds at least one of defence:dashboard:create, defence:widget:create or defence:query:create.
A user cannot add or edit an integration → Add defence:integration:credentials:create in addition to defence:integration:view.
A user can open the Manual Ingestion page but the upload fails → Grant defence:manual-ingest:create and defence:query:execute.
An administrator cannot reach Admin > Management → That area requires zitadel:iam.
Need more help? Contact support@zeron.one