Connect Grafana to Black Cat SSPM
Connect your Grafana instance so Black Cat can review users, service accounts and their tokens, data sources, dashboard sharing, folders, alert rules and plugins.
≈ 10 min · audit access · no write-capable permission
What Black Cat reads, and why
| Permission | What it lets Black Cat do | Status |
|---|---|---|
org.users:read | Lets Black Cat list users, their roles and last activity. | Required |
serviceaccounts:read | Lets Black Cat list service accounts, their roles and token expiry. | Required |
datasources:read | Lets Black Cat review data sources, their access mode and whether certificate checks are skipped. | Required |
dashboards:read | Lets Black Cat see which dashboards exist and which of them are published publicly. | Required |
dashboards.permissions:read | Lets Black Cat see who can view and edit each dashboard. | Required |
folders:read | Lets Black Cat review folder permissions and spot folders without their own access list. | Required |
alert.rules:read | Lets Black Cat review alert rules, their state and the contact points they notify. | Required |
plugins:read | Lets Black Cat list installed plugins and whether they are signed and up to date. | Required |
settings:read | Lets Black Cat review instance settings such as single sign-on and basic authentication. | Optional |
What you'll need
- Grafana address Required — The address you use to reach Grafana, for example https://grafana.acme.com.
- Service account token Required — Created on a read-only service account in your Grafana administration settings.