Roles in AI Agent Monitoring
Splunk Observability Cloud lets you restrict access to certain features to specific groups of users using role-based access control (RBAC). You assign roles to users. A role contains a set of capabilities. These capabilities define what actions are available to roles.
This topic describes roles and capabilities related to AI Agent Monitoring. For complete documentation on roles and capabilities in Splunk Observability Cloud, see About roles in Splunk Observability Cloud and Splunk Observability Cloud matrix of roles and capabilities.
Pre-defined roles in Splunk Observability Cloud
Splunk Observability Cloud includes the following predefined roles. To assign a role to a user, see Assign roles to users in Splunk Observability Cloud.
|
Role |
Description |
|---|---|
|
admin |
This role has the most capabilities assigned to it. An admin user has full privileges across Splunk Observability Cloud. |
|
power |
This role can access all components in Splunk Observability Cloud, access a subset of settings, and create, delete, and update charts, dashboards and detectors. This is the default role assigned to users. |
|
usage |
This role allows a user to view the subscription usage page without being an admin. This role also has read_only privileges. |
|
read_only |
This role can access all pages and objects that a power user can, but cannot create, edit, or delete objects. They have limited access to the Settings pages. |
| ai_monitoring | This role can view AI conversation details, such as AI inputs, outputs, and system prompts. AI conversation details are displayed on the AI trace data page in AI Agent Monitoring. |
Matrix of roles and permissions for AI Agent Monitoring
| Permission | admin | power | usage | read_only | ai_monitoring |
|---|---|---|---|---|---|
| View AI agent conversation details (AI inputs, outputs, and system prompts) | Yes | No | No | No | Yes |
read_apm_ai_conversation capability. This capability is included in the admin and ai_monitoring roles. If you're an admin and want to grant the ai_monitoring rule to a user, see Assign roles to users in Splunk Observability Cloud.