Token scopes
What each scope allows.
A token carries one or more scopes. A route or MCP tool refuses the call (403) if its scope is missing. Grant the minimum: a ticketing connector only needs read:machines and read:netdiag, for example.
| Scope | Gives access to |
|---|---|
read:machines | Fleet: workstations and servers running the agent. |
read:netdiag | NetDiag: verdicts, measurements, events and applications of workstations. |
read:flows | Network flows, destinations, volumes, flow explorer. |
read:alerts | Open alerts and incidents. |
read:monitors | Availability: monitors, incidents, probes. |
read:inventory | Software inventory, vulnerabilities, end of life, licences. |
read:security | Security: SIEM, Active Directory authentications. |
read:databases | Databases: instances, queries, waits, sessions. |
read:dns | DNS: queries and threats. |
read:files | File access: events and shares. |
read:network | Network infrastructure: devices, links, tunnels, Wi-Fi. |
read:firewall | Firewalls and gateways: logs, traffic, threats. |
report:pdf | PDF reports (e.g. the NetDiag report of a workstation). |
write:alerts | Write: acknowledge an alert (logged with its body). |
write:netdiag | Write: NetDiag settings and diagnostic actions (logged). |
Source: · FirstSI Docs · updated 2026-10-10