File Inventory
The file inventory page lists all files discovered based on the Basic Inventory policies. The table grid contains the following columns:
- File Name
- Original File Name
- Product Name
- Product Version
- First Discovered
At the beginning of your policy creation process you will see many new events labeled as New Loaded Resource. This is because importing files in Privilege Manager is not the same thing as discovering information about the files. Discovery of file details is done by scheduled tasks by default, but if you want to discover file details immediately, do the following:
-
Navigate to File Inventory.
-
Select New Loaded Resource.
-
Click on a New Loaded Resource entry.
-
Check the Discover Status. The following states are available:
- New, the resource was just reported).
- Pending Assignment, the resource will soon be assigned to an agent for discovery).
- Assigned to agent, an agent was chosen to discover this resource.
Once an agent is assigned, you can click Discover Now to attempt to force the agent to immediately discover the resource. Many factors affect the agent's promptness in discovering the resource: agent up-time, current processing queue, etc. Please be patient.
-
-
Click Discover Now.
-
After the successful discovery, click View File or Create Filter as your next option to use the discovered or inventoried resource. You have the option to add it to a Policy.
Files may not be discovered if they have already been deleted from your system.
Requested Authorization DB Rights (macOS)
The Requested Authorization DB Rights section appears on the file inventory detail for a macOS application. It lists the macOS Authorization DB rights the application has requested, so you can see which privileged operations it attempts and decide which ones to turn into an action.
Authorization DB rights are only discovered and reported for applications that a policy targets. If no policy applies to an application, no rights appear in its inventory. See Monitoring Authorization DB Rights to enable discovery.
-
The section is hidden when an application has no recorded rights.
-
Rights are shown in a table with two columns: Right and Status.
-
When an application has more than five rights, the list is collapsed and can be expanded to show all of them.
-
Status shows whether each requested right was Granted or Denied:
-
Granted: The application requested the right and macOS authorized it. The user was able to complete the action without being blocked.
-
Denied: The application requested the right but macOS did not authorize it, so the user was blocked or prompted for administrator credentials. Denied rights are the usual candidates for creating an action.
-
-
The agent records the requested rights immediately, as the application requests them, and sends them to the server on the next send events cycle.



