HashiCorp Cloud Platform
Configure Vault Radar permissions
Vault Radar is initially configured by a user with the HCP IAM admin role. Any HCP IAM user with the admin role can perform all functions within Vault Radar. Admins can add a data source, trigger an on-demand scan, view events, and edit event remediation state.
You must add other HCP IAM user who do not have the HCP admin role to an HCP IAM group. The group must belong to the project configured with Vault Radar, and the group assigned one or more data sources.
Vault Radar supports both organization and project level users in the HCP Portal, and service principals for the Vault Radar CLI. Following the principle of least privilege: give each user the smallest amount of access they need. Assign Resource Viewer or Resource Contributor when a user only needs specific resources, and project or organization level roles when a user needs access to everything.
Add a user for Vault Radar
Find which RBAC role the user will require by referencing the HCP Vault Radar permissions in the table below:
Vault Radar permissions Resource Viewer Resource Contributor Viewer Contributor Admin View events ✅ (assigned resources only) ✅ (assigned resources only) ✅ ✅ ✅ Edit event remediation state ✅ ✅ ✅ Add or manage data sources ✅ Add or manage filters ✅ Add or manage event rules ✅ Add or manage custom expressions ✅ Add or manage ignore rules ✅ Configure PR checks policies ✅ Trigger on-demand scans ✅ Copy secrets to Vault ✅ ✅ ✅ Verify or create an HCP IAM group with the desired role.
Invite the user from the parent organizations IAM dashboard.
When the user accepts the invitation (and if necessary signs up for HCP), assign the user a resource or project level HCP IAM role based on their role.
Project or organization level viewer, contributor, or admin roles grant access to all services, not just Vault Radar.
Add the user to the group you created previously.
Assign resource to resource role groups
The Vault Radar resource roles (viewer and contributor) do not have any permissions by default and you must have an HCP IAM Group created. A project admin assigns the role to a specific resources in the Vault Radar UI. To assign resources to the HCP group:
Go to the Vault Radar portal.
Select /Resources.
Select the resources.

Click Assign Groups.
Select the Group.

Select Viewer or Contributor type.
Click OK.

The user can now access Vault Radar Event page so see the findings assign to their group.
Remove resources from the resource role groups
To remove a resource to a group.
Go to the Vault Radar portal.
Select /Resources.
Click on the resource.
Click on the trash icon next to the group name.
