Create asset scopes

Prev Next

Asset scopes determine which assets an account can access. You can define scopes based on criteria such as:

  • Asset type (for example, servers, Windows devices, network equipment)
  • Domain or subnet
  • Installation or scanning target
  • Location

If no asset scopes are configured, accounts can see all assets in their inventory. By adding scopes, you restrict the assets an account can view.

Scopes don't apply to Administrators

You can't assign asset scopes to the Administrator role, and site owners are always Administrators. Both always have access to all assets. To restrict access, assign a custom role with an asset scope. For more information, see Manage site owners.

Related reading

For more information about access management, see Access management.

Create an asset scope

  1. In your site, go to Site settings > Account management > Asset scopes.
  2. Select Create asset scope.
  3. Enter a Name for your asset scope that represents your desired scope. Optionally, enter a description.
  4. Under Conditions, select the option Asset type, Asset domain, IP location, Location, or Installation from the dropdown.
  5. Select your desired Operator and Value.
  6. Under Assigned roles, select a created role from the dropdown. To create a new role, see Manage roles.
  7. Select Create.

Next steps

After you’ve created an asset scope, you can: