> For the complete documentation index, see [llms.txt](https://docs.snyk.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.snyk.io/scan-fix-and-prevent/scan-with-snyk/snyk-api-web/managing-account/understanding-permissions.md).

# Understanding permissions

Learn what actions each permission grants to better configure your custom roles.

This article provides a detailed breakdown of the high-level permissions in Snyk API & Web, explaining what actions each permission grants. Snyk groups permissions into roles, either built-in or custom. The role, along with a scope, dictates the actions a user can perform.

## Role and scope structure

Roles can be applied at three levels, dictating the scope of the actions a user can perform:

* **Account:** actions apply across the entire account.
* **Team:** actions apply only to the selected team.
* **Target:** actions apply only to the selected target.

To learn more about roles, visit [Roles and permissions](/scan-fix-and-prevent/scan-with-snyk/snyk-api-web/managing-account/roles-and-permissions.md).

## Detailed permission breakdown

The following table lists the Name, ID, and a detailed description of the actions allowed for each high-level permission:

| Permission                                                                                                  | Allowed Actions                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| ----------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>Name:</strong> Account Settings<br><strong>ID:</strong> account\_settings</p>                    | <p><strong>Manage Integrations:</strong><br>\* Create, view, change, and delete third-party account integrations (for example, Akamai, Azure DevOps, Jira Cloud, and so on).<br><br><strong>Manage Labels:</strong><br>\* Create, view, change, delete, and list Finding Labels, Target Labels, and User Labels.<br><br><strong>Manage Automation:</strong><br>\* Create, view, change, delete, and list Webhooks.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| <p><strong>Name:</strong> Audit Log<br><strong>ID:</strong> audit\_log</p>                                  | <p><strong>Review History:</strong><br>\* Obtain the Audit Log entries.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| <p><strong>Name:</strong> Billing<br><strong>ID:</strong> billing</p>                                       | <p><strong>Manage and View Billing:</strong><br>\* Manage billing and payment information.<br>\* List and download invoices.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| <p><strong>Name:</strong> Change Finding<br><strong>ID:</strong> change\_finding</p>                        | <p><strong>Modify Findings:</strong><br>\* List and view findings.<br>\* Perform bulk operations on findings.<br>\* List and assign users to a finding.<br>\* Add notes to findings.<br>\* Manually synchronize findings with integrations already configured (for example, Azure DevOps, Jira Cloud, Shortcut).<br>\* View Target Labels.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| <p><strong>Name:</strong> Change Finding State<br><strong>ID:</strong> change\_finding\_state</p>           | <p><strong>Modify Findings State:</strong><br>\* Change finding state (Accept risk, Mark as invalid, Reset).<br>\* Change finding review status (Approved, Rejected).</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| <p><strong>Name:</strong> Change risk<br><strong>ID:</strong> change\_risk</p>                              | <p><strong>Modify Risk Level:</strong><br>\* Change the risk rating associated with a finding.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| <p><strong>Name:</strong> Change Target Settings<br><strong>ID:</strong> change\_target\_settings</p>       | <p><strong>Manage Target Configuration:</strong><br>\* Manage (add, change, delete, and view) Login or Logout configuration, Navigation Sequences, Partial Scans, Scanning Agents, Extra hosts, Seeds or Reject Lists, Custom Headers or Cookies, Blackout Period, Report types, Coverage details, and Technologies.<br>\* Manage (add, change, delete, view) Scan Profiles, and assign them to the target.<br>\* Configure API Schema files.<br>\* Manage target-specific integrations (Azure DevOps, DefectDojo, Jira Cloud or Server, Shortcut, Slack).<br><br><strong>Manage Domains:</strong><br>\* Manage (add, change, list, view, and verify) Domains.<br><br><strong>Manage Labels:</strong><br>\* Create, change, delete, and list Finding Labels and Target Labels.<br><br><strong>Manage Webhooks:</strong><br>\* Configure Scope Webhooks.</p> |
| <p><strong>Name:</strong> Correlation Admin<br><strong>ID:</strong> correlation\_admin</p>                  | <p><strong>Manage SAST and DAST Integration:</strong><br>\* View and manage Snyk Code integration.<br>\* View and assign or remove Snyk Code projects to or from targets.<br>\* View correlation data in the finding details.<br>\* Provide correlation feedback.<br>\* Register correlation matches (thumbs up or thumbs down).</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| <p><strong>Name:</strong> Correlation Viewer<br><strong>ID:</strong> correlation\_viewer</p>                | <p><strong>View SAST and DAST Integration:</strong><br>\* View Snyk Code projects assigned to targets.<br>\* View correlation data in the finding details.<br>\* Provide correlation feedback.<br>\* Register correlation matches (thumbs up or thumbs down).<br>\* Disable and delete Snyk Code integration.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| <p><strong>Name:</strong> Create Target<br><strong>ID:</strong> create\_target</p>                          | <p><strong>Add Targets:</strong><br>\* Add, change, list, view, and verify Domains.<br>\* Add Targets (including uploading and downloading target files).<br>\* View and list available Scanning Agents.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| <p><strong>Name:</strong> Delete Target<br><strong>ID:</strong> delete\_target</p>                          | <p><strong>Remove Targets:</strong><br>\* Delete Targets.<br>\* Delete Domains.<br>\* Delete Webhooks.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| <p><strong>Name:</strong> Discovery<br><strong>ID:</strong> discovery</p>                                   | <p><strong>Manage Discovery:</strong><br>\* List, and view Discovery Assets.<br>\* View Discovery Scans.<br>\* View Discovery Asset Logs.<br>\* Change Discovery Assets (Mark as new or not new, Hide or Show, Rename, Manage Target Labels, Add Notes).</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| <p><strong>Name:</strong> Discovery Read-Only<br><strong>ID:</strong> discovery\_read\_only</p>             | <p><strong>View Discovery Data:</strong><br>\* List and view Discovery Assets.<br>\* View Discovery Asset Logs.<br>\* View Discovery Scans.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| <p><strong>Name:</strong> Manage Credentials<br><strong>ID:</strong> manage\_credentials</p>                | <p>This permission allows you to create, view, update, and delete <strong>credentials created by other users</strong>, depending on your assigned scope:<br>\* <strong>Team Scope:</strong> You can only manage credentials within the <strong>specific teams</strong> where you have been granted "Manage Credentials" permissions.<br>\* <strong>Account Scope:</strong> Additionally, you can assign a credential to <strong>any team</strong> within the entire account.</p>                                                                                                                                                                                                                                                                                                                                                                            |
| <p><strong>Name:</strong> Password Login Override<br><strong>ID:</strong> password\_login\_override</p>     | <p><strong>Authentication:</strong><br>\* Override SSO configuration (that is, log in with username and password when SSO is configured).</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| <p><strong>Name:</strong> Role Assignment<br><strong>ID:</strong> role\_assignment</p>                      | <p><strong>Manage User Roles:</strong><br>\* List high-level permissions.<br>\* List built-in roles.<br>\* Add, change, delete, list, and view custom-roles.<br>\* View User details.<br>\* Add, change, delete, list and view User Labels.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| <p><strong>Name:</strong> Scanning Agent Management<br><strong>ID:</strong> scanning\_agent\_management</p> | <p><strong>Manage Scanning Agents:</strong><br>\* Add, change, delete, list, and view.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| <p><strong>Name:</strong> Start re-test<br><strong>ID:</strong> start\_retest</p>                           | <p><strong>Trigger Re-tests:</strong><br>\* Initiate a re-test for a finding.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| <p><strong>Name:</strong> Start Scan<br><strong>ID:</strong> start\_scan</p>                                | <p><strong>Manage Scans:</strong><br>\* Initiate a manual Scan on a Target.<br>\* Cancel, pause, and resume ongoing Scans.<br>\* Add, change, delete, list, and view Scheduled Scans.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| <p><strong>Name:</strong> Team Management<br><strong>ID:</strong> team\_management</p>                      | <p><strong>Manage Teams:</strong><br>\* Add, change, delete, and view teams.<br>\* Move targets between teams.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| <p><strong>Name:</strong> User Management<br><strong>ID:</strong> user\_management</p>                      | <p><strong>Manage Users and Roles (Account Level):</strong><br>\* View User Roles, High-Level Permissions, and available Roles.<br>\* Add, change, list, enable or disable Users and API Keys.<br>\* Manage Users and API Keys' roles (list, view, assign, and remove role from User or API Key).<br>\* Manage User Labels.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| <p><strong>Name:</strong> View Target<br><strong>ID:</strong> view\_target</p>                              | <p><strong>View Target Data and Reports:</strong><br>\* List and view Target, Target Settings (including integration-specific settings), Scans, Scheduled Scans, and Findings.<br>\* View integration-specific links.<br>\* View Target Labels.<br>\* View User details.<br><br><strong>Manage Reports:</strong><br>\* Download Scan Reports.<br>\* Add, change, delete, list, and view Stored or Managed Reports.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                      |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.snyk.io/scan-fix-and-prevent/scan-with-snyk/snyk-api-web/managing-account/understanding-permissions.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
