---
title: Prerequisites and user roles for Security RX
source: https://docs.newrelic.com/docs/vulnerability-management/getting-started/prerequisites
---

## Prerequisites

Before you can use the Security RX capability, you must have the following:

-   A New Relic account with access to Security RX.

-   'View' permissions for the ['security' capability](https://docs.newrelic.com/docs/accounts/accounts-billing/new-relic-one-user-management/user-permissions/#security).

-   Vulnerability data through one of these sources:

    -   An Application instrumented with [New Relic's APM agent](https://docs.newrelic.com/docs/apm/new-relic-apm/getting-started/introduction-apm/)
    -   **or** a host monitored with [New Relic's Infrastructure Agent](https://docs.newrelic.com/docs/infrastructure/infrastructure-agent/new-relic-guided-install-overview/)
    -   **or** Vulnerability data sent through [one of our integrations](https://docs.newrelic.com/docs/vulnerability-management/getting-started/integrations/overview).

    For more information on Security RX pricing, see our [pricing docs](https://docs.newrelic.com/docs/licenses/license-information/usage-plans/new-relic-one-usage-plan-descriptions/#list-price).

### Capabilities used by Security RX

-   [Security](https://docs.newrelic.com/docs/accounts/accounts-billing/new-relic-one-user-management/user-permissions/#security) capability refers to the ability to view and manage security findings (vulnerabilities and misconfigurations) detected in entities.
-   [Applied Intelligence - Channels](https://docs.newrelic.com/docs/accounts/accounts-billing/new-relic-one-user-management/user-permissions/#applied-intelligence) capability is required to create new outbound alerts based on vulnerabilities detected.
-   [Applied Intelligence - Destinations](https://docs.newrelic.com/docs/accounts/accounts-billing/new-relic-one-user-management/user-permissions/#applied-intelligence) capability is required to create new outbound alerts based on vulnerabilities detected.

### Granting access to Security RX

Review the current custom roles created for your organizations. Add 'read' permissions for the 'security' capability to grant access to view Security RX. Standard roles are automatically granted this capability but custom roles need to have 'read' permissions granted.
For more information about custom roles, see [user roles](https://docs.newrelic.com/docs/accounts/accounts-billing/new-relic-one-user-management/user-management-concepts/#roles).

![An image showing the summary Vulnerability Management overview page.](https://docs.newrelic.com/images/vm_user_role.webp "Vulnerability Management overview")

### Removing user access from Security RX

Users with the ability to create/adjust roles within their organization can modify who has access to Security RX feature. You can remove access from Security RX by creating a custom role that does not have 'read' permissions for the 'security' capability. You must then apply this custom role to the users that you wish to restrict.

## What's next?

Now that you've verified your prerequisites, set up your first integration:

[Set up integrations](https://docs.newrelic.com/docs/vulnerability-management/getting-started/integrations/overview)

Configure APM agents, Infrastructure agents, or third-party security tools

[Understand prioritization](https://docs.newrelic.com/docs/vulnerability-management/getting-started/prioritization)

Learn how Security RX ranks vulnerabilities by risk

[Security RX for Applications](https://docs.newrelic.com/docs/vulnerability-management/applications/overview)

Start monitoring application vulnerabilities

[Security RX for Infrastructure](https://docs.newrelic.com/docs/vulnerability-management/infrastructure/overview)

Start monitoring infrastructure vulnerabilities
