Interno: Roles & Permissions Reference

Interno: Roles & Permissions Reference

This guide lists the permission scopes that control access to each part of Interno (the Zeron Command Center). Interno scopes use the defence: prefix.

This page covers Interno only. For the complete cross-product reference — every product's scopes, resource-level roles, groups, and common scenarios — see the Zeron Platform: Complete Permissions & RBAC Reference.

How permissions work

  • Groups bundle one or more policies (permission sets). Add users to a group and they inherit all of its permissions — the recommended approach.
  • Permissions can also be attached directly to a user.
  • Each permission is a scope string (e.g., vendor:view). If a user lacks the scope a page needs, they see an "Unauthorized" screen.

Manage user accounts and groups under Admin > Management (requires the zitadel:iam permission).

Section-by-section: what scope each page needs

To do thisRequired scope
Use ZIN Copilot, HITL approvals, agent tasksAny authenticated user with product access
View dashboards & posture overview (and Asset Inventory)defence:dashboard:view
Create new dashboardsdefence:dashboard:create
Edit dashboards, use the custom widget builderdefence:dashboard:update
Delete dashboardsdefence:dashboard:delete
View saved widgetsdefence:widget:view
Create / duplicate widgetsdefence:widget:create
Delete widgetsdefence:widget:delete
View widget underlying datadefence:widget:data:view
Render widget chartsdefence:widget:visualize
View manual ingestion page & historydefence:manual-ingest:view
Upload / import data filesdefence:manual-ingest:create
Review & approve ingested datadefence:manual-ingest:review
View queries & alertsdefence:query:view
Create / edit / delete queries & alertsdefence:query:create / :update / :delete
Execute / run a querydefence:query:execute
View evidence queries (shared with Conformity)grc:evidence:view
Create / manage evidence queriesgrc:evidence:create
View integrations & connector catalogdefence:integration:view
View / create / delete connector credentialsdefence:integration:credentials:view / :create / :delete
View risksdefence:risk:view
Create / update / delete risksdefence:risk:create / :update / :delete
Use the full 4-step risk workflowdefence:risk:manage
View risk documentsdefence:risk:documents:view
View & generate reportsreport:view

Common setups

  • Read-only Analyst: defence:dashboard:view + defence:widget:view + defence:query:view + defence:integration:view + defence:risk:view + report:view
  • Security Analyst (full Interno): all defence:* scopes + report:view (add grc:evidence:* for evidence queries).

Troubleshooting

IssueWhat to do
User sees "Unauthorized" on a pageTheir group is missing that page's scope. Add it from the table above.
Can view dashboards but cannot build widgetsThe custom widget builder needs defence:dashboard:update (plus defence:widget:create).
Cannot connect an integrationAdd defence:integration:credentials:create in addition to defence:integration:view.
Cannot see ReportsAdd report:view (shared across products).

Need more help? Contact support@zeron.one.