---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# MISP user roles and permissions

# MISP user roles and permissions {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Review the user roles that are required in the MISP integration for Security Operations
integration.
{#misp-user-roles-and-permissions__table_ft2_1cv_fvb__entry__3}

| MISP capability | Tagger | Tag editor |
|-|-|-|
| Observable Enrichment (Read-only) | ✓ | ✓ |
| Sighting Search (Read-only) | ✓ | ✓ |
[Table 1. Observable Enrichment and Sighting Search Permissions Note:
* All ServiceNow MISP integration capabilities need the basic permissions to Manage Organization Events and Auth key access. Ensure that you have these basic permissions before you proceed.
* To add local galaxies, the user that configures the integration should belong to the host organization of the corresponding MISP server.
{#misp-user-roles-and-permissions__ul_lf3_ndv_fvb}]

{#misp-user-roles-and-permissions__table_ft2_1cv_fvb} {#misp-user-roles-and-permissions__table_ilx_qcv_fvb__entry__2}

| MISP capability | Sighting creator |
|-|-|
| Report Sighting | ✓ |
[Table 2. Report Sighting Permissions]

{#misp-user-roles-and-permissions__table_ilx_qcv_fvb} {#misp-user-roles-and-permissions__table_xqn_zcv_fvb__entry__3}

| MISP capability | Tagger | Tag editor |
|-|-|-|
| Edit Event/Attribute Tags | ✓ | ✓ |
| Edit Event/Attribute Galaxies | ✓ | ✓ |
| Edit Attribute Comments | ✓ | ✓ |
| Add New Attribute to event | ✓ | ✓ |
| Create Event in MISP | ✓ | ✓ |
[Table 3. Attribute and Event Permissions]

{#misp-user-roles-and-permissions__table_xqn_zcv_fvb}

