Configure role based access control inside Splunk apps
Splunk SOAR (On-premises) supports granular asset access control inside of Splunk SOAR (On-premises) apps to ensure that only authorized access to the app is allowed. Asset access control works on an authorized basis, with a default-deny policy.
When granular asset access control is enabled, only users or groups with explicit permissions are able to perform actions in a Splunk SOAR (On-premises) app. Configure user and group permissions on all configured apps before enabling granular asset access control.
To set up a single user to have access the "lookup domain" action on the Google DNS asset:
- From the Home menu, select Apps.
 - Click 1 configured asset to expand the section.
 - Click Google DNS to edit the asset.
 - Click the Access Control tab.
 - Click Edit.
 - Select lookup domain from the App Action drop-down list.
 - Select the user desired user name then click the right arrow in order to move the user from the Users and Roles list into the Approved Users and Roles list.
 - Click Save.
 
Now enable granular asset access control so that the permission set above takes effect.
- From the Home menu, select Administration.
 - Select User Management > Asset Permissions.
 - Check the Enable granular Asset Access Control checkbox.
 - Confirm that you want to change global asset permissions.
 - Click Save Changes.