Interno: Roles & Permissions Reference

Interno: Roles & Permissions Reference

Overview

Access to each part of Interno is controlled by permission scopes. Interno's own scopes all begin with defence:. This article lists the scopes that Interno checks and what each one unlocks.

This page covers Interno only. For every product's scopes in one place, see the *Zeron Platform: Complete Permissions & RBAC Reference*.


Prerequisites

  • The zitadel:iam permission, which is what gates the Admin > Management area where users, groups and policies are maintained
  • The list of scopes you intend to grant (below)

How Permissions Work

  • A scope is a single permission string, for example defence:dashboard:view.
  • Policies bundle scopes; groups bundle policies. Adding a user to a group is the recommended way to grant access, because everyone in the group stays consistent.
  • If a user does not hold the scope a page requires, Interno shows an Unauthorized screen instead of the page.
  • Users, groups and departments are maintained under Admin > Management. That whole area is visible only to users holding zitadel:iam.

Scope Reference

Dashboards

To do thisScope
Open dashboards, and the Asset Inventory pagedefence:dashboard:view
Create a dashboard, use AI dashboard/widget suggestions, import a dashboarddefence:dashboard:create
Edit a dashboard (rearrange widgets, save layout changes)defence:dashboard:update
Delete a dashboarddefence:dashboard:delete

Export Dashboard needs only defence:dashboard:view. Set As Default saves a change to the dashboard, so it requires defence:dashboard:update.

Widgets

To do thisScope
See saved widgets and the widget librarydefence:widget:view
Create or duplicate a widgetdefence:widget:create
Update a widget, or link/unlink a drill-down widgetdefence:widget:update
Delete a widgetdefence:widget:delete
Load the data behind a widgetdefence:widget:data:view or defence:dashboard:view
Get visualisation recommendationsdefence:widget:visualize or defence:dashboard:view

The User Access Coverage tables are served by the widget service, so viewing them also requires defence:widget:view.

Queries and Alerts

To do thisScope
View queries and alertsdefence:query:view
Create a query or alertdefence:query:create
Edit a query or alertdefence:query:update
Delete a query or alertdefence:query:delete
Run a query or alertdefence:query:execute

Manual Ingestion

To do thisScope
Open the Manual Ingestion page and its historydefence:manual-ingest:view
Start an uploaddefence:manual-ingest:create
Review and approve uploaded datadefence:manual-ingest:review

The import itself is executed by the query service, so users who upload also need defence:query:execute.

Integrations

To do thisScope
See the Integrations page and the connector cataloguedefence:integration:view
View saved integration credentialsdefence:integration:credentials:view
Add an integration, edit an existing one, start a scan, activate or deactivatedefence:integration:credentials:create
Delete an integrationdefence:integration:credentials:delete

Editing an integration is deliberately gated on the same scope as creating one — there is no separate "edit" scope.

Risk Register

To do thisScope
View risksdefence:risk:view
Create a riskdefence:risk:create or defence:risk:manage
Update a riskdefence:risk:update or defence:risk:manage
Delete a riskdefence:risk:delete or defence:risk:manage
Use the full four-step risk workflowdefence:risk:manage
View documents attached to a riskdefence:risk:documents:view

Evidence Queries (shared with Conformity)

To do thisScope
See the Evidence tab in the Query Librarygrc:evidence:view
Create or delete an evidence querygrc:evidence:create

Suggested Combinations

Read-only analyst defence:dashboard:view, defence:widget:view, defence:widget:data:view, defence:query:view, defence:integration:view, defence:risk:view

Full Interno user All defence:* scopes above. Add grc:evidence:view and grc:evidence:create if the person works with evidence queries.

Administrator The full Interno user set plus zitadel:iam, so they can manage users, groups and departments.


Troubleshooting

A user sees the "Unauthorized" screen on a page → Their group is missing that page's scope. Find the row above and add the scope to the group's policy.

A user can open dashboards but cannot rearrange widgets → Editing a dashboard layout requires defence:dashboard:update. Adding widgets to it also needs defence:widget:view.

A user cannot see the Create button on the Dashboard page → That button appears only if the user holds at least one of defence:dashboard:create, defence:widget:create or defence:query:create.

A user cannot add or edit an integration → Add defence:integration:credentials:create in addition to defence:integration:view.

A user can open the Manual Ingestion page but the upload fails → Grant defence:manual-ingest:create and defence:query:execute.

An administrator cannot reach Admin > Management → That area requires zitadel:iam.


Need more help? Contact support@zeron.one

    • Related Articles

    • Interno: Frequently Asked Questions (FAQ)

      Overview Answers to the questions we hear most often about Interno, the Zeron Command Center. Interno pulls data from your existing security and IT tools into one place, normalises it, and lets you build dashboards, queries, alerts and a risk ...
    • Troubleshooting Common Issues in Interno

      Overview This guide covers the issues Interno users hit most often, and how to resolve them. Most "I can't see it" and "I can't do it" problems come down to one of two things: a missing permission scope, or an organisation that has not ingested any ...
    • Getting Started with Interno

      Overview Interno is the Zeron Command Center. It pulls data out of the security and IT tools you already run, keeps it in one place, and lets you build dashboards, run queries and track risks against it. This guide takes you from first login to your ...
    • Interno: Metrics & Glossary

      Overview A reference for the terms and the standard KPI widgets you will meet in Interno, the Zeron Command Center. Prerequisites Access to Interno At least one integration connected, so the terms below have data behind them Platform and Navigation ...
    • Interno Data Sources & Fields (Data Dictionary)

      Overview When you build a widget or a query in Interno you pick a table and its fields. This guide explains how Interno organises the data that arrives from your connected tools, what the shared system fields mean, and how to find the right field ...