> ## Documentation Index
> Fetch the complete documentation index at: https://developer.kyberis.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Splunk permissions and roles

> Required capabilities, the admin-only cache ACL, and what runs where.

## Capability requirements at a glance

| Action | Who | Needs |
| - | - | - |
| Install the app, use the setup page | Admins | An admin role: saving profiles writes `storage/passwords` and `kyberis.conf` and reloads the app |
| Run `\| kyberis` or `\| kyberischeck` | Any role that runs Kyberis searches | The `list_storage_passwords` capability, to read the API key from secure storage |
| Own an alert with the Kyberis enrichment action | The role the alert runs as | `list_storage_passwords` **and** write access to the action's destination index |
| Write to the enrichment cache | Admins only, by design | Write access to the `kyberis_ioc_cache` collection — do not broaden it (see below) |

`list_storage_passwords` is the one capability most deployments need to grant:
admins have it by default, ordinary user roles do not. Without it, searches fail
with the missing-key error even when a key is stored, and the message says so.

<Warning>
  `list_storage_passwords` exposes all of secure storage to the role, not only
  Kyberis keys. Grant it to purpose-built roles rather than broadly.
</Warning>

## App object permissions

The app's objects — commands, alert action, eventtype, lookups — are exported
system-wide and readable by all roles. Write access to app objects and
configuration is admin-only (`admin`, and `sc_admin` on Splunk Cloud). The setup
page is therefore effectively admin-only; see
[Credential setup](/integrations/splunk/credentials).

## The cache collection ACL — do not broaden it

Cache writes go to the `kyberis_ioc_cache` KV Store collection, whose write ACL
is admin-only by app default. This is a **security property, not a convenience
default**: cached documents are trusted as authentic Kyberis verdicts, so any
role that can write the collection could plant benign-looking results for
malicious indicators — cache poisoning — that later searches, including other
users' searches, would serve as truth.

Leave the write ACL alone. Non-admin searches degrade gracefully: they still get
read-side cache hits and full enrichment results, and only the write-back is
skipped, with one warning in the search log. If you want broader cache warming,
schedule the warming search as an admin instead of widening the ACL.

## What runs where

Everything runs on the search head. Both commands are search-head only
(`distributed = false`), and the alert action executes on the search head that
ran the alert. No role needs any permission on indexers beyond normal search, and
only the alert action writes events, to its configured destination index.
