curl --request PUT \
--url "https://au.api.plerion.com/v1/organization/user-groups/90355263-ff80-4066-b947-244e1b01907a/preferences/navigation?tenantId=65a72929-0e61-4c9c-b7a8-8abe6886fd6c" \
--header "Authorization: Bearer $PLERION_ORGANIZATION_API_KEY" \
--header "Content-Type: application/json" \
--data '{"order": ["home", "findings", "risks", "assets", "alerts", "threat-map"], "hidden": ["threat-map"]}'import requests
url = "https://{region}.api.plerion.com/v1/organization/user-groups/{groupId}/preferences/navigation"
payload = {
"order": ["home", "findings", "risks", "assets", "alerts", "threat-map"],
"hidden": ["threat-map"]
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.put(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PUT',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
order: ['home', 'findings', 'risks', 'assets', 'alerts', 'threat-map'],
hidden: ['threat-map']
})
};
fetch('https://{region}.api.plerion.com/v1/organization/user-groups/{groupId}/preferences/navigation', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://{region}.api.plerion.com/v1/organization/user-groups/{groupId}/preferences/navigation",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PUT",
CURLOPT_POSTFIELDS => json_encode([
'order' => [
'home',
'findings',
'risks',
'assets',
'alerts',
'threat-map'
],
'hidden' => [
'threat-map'
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://{region}.api.plerion.com/v1/organization/user-groups/{groupId}/preferences/navigation"
payload := strings.NewReader("{\n \"order\": [\n \"home\",\n \"findings\",\n \"risks\",\n \"assets\",\n \"alerts\",\n \"threat-map\"\n ],\n \"hidden\": [\n \"threat-map\"\n ]\n}")
req, _ := http.NewRequest("PUT", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.put("https://{region}.api.plerion.com/v1/organization/user-groups/{groupId}/preferences/navigation")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"order\": [\n \"home\",\n \"findings\",\n \"risks\",\n \"assets\",\n \"alerts\",\n \"threat-map\"\n ],\n \"hidden\": [\n \"threat-map\"\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://{region}.api.plerion.com/v1/organization/user-groups/{groupId}/preferences/navigation")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Put.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"order\": [\n \"home\",\n \"findings\",\n \"risks\",\n \"assets\",\n \"alerts\",\n \"threat-map\"\n ],\n \"hidden\": [\n \"threat-map\"\n ]\n}"
response = http.request(request)
puts response.read_body{
"data": {
"tenantId": "65a72929-0e61-4c9c-b7a8-8abe6886fd6c",
"order": [
"home",
"findings",
"risks",
"assets",
"alerts",
"threat-map"
],
"hidden": [
"threat-map"
],
"updatedAt": "2026-10-05T04:12:00.000Z"
}
}{
"errors": [
{
"code": "ReportNotFound",
"message": "Custom report 3f1c7d2e-5a6b-4c8d-9e0f-1a2b3c4d5e6f was not found in tenant 65a72929-0e61-4c9c-b7a8-8abe6886fd6c"
}
]
}{
"errors": [
{
"code": "<string>",
"message": "<string>",
"field": "<string>"
}
]
}{
"errors": [
{
"code": "<string>",
"message": "<string>",
"field": "<string>"
}
]
}{
"errors": [
{
"code": "RoleNotFound",
"message": "role not found"
}
]
}Set a user group's navigation
Replaces the user group’s sidebar arrangement in the tenant. order is the whole arrangement, hidden entries included, and hidden names the entries in order that are tucked away. home is always first and never hidden; the server moves or shows it if a request says otherwise. Keys must come from the sidebar catalog, and an unknown key answers 400 with the allowed keys in the message.
Requires an organization API key with read and write access.
curl --request PUT \
--url "https://au.api.plerion.com/v1/organization/user-groups/90355263-ff80-4066-b947-244e1b01907a/preferences/navigation?tenantId=65a72929-0e61-4c9c-b7a8-8abe6886fd6c" \
--header "Authorization: Bearer $PLERION_ORGANIZATION_API_KEY" \
--header "Content-Type: application/json" \
--data '{"order": ["home", "findings", "risks", "assets", "alerts", "threat-map"], "hidden": ["threat-map"]}'import requests
url = "https://{region}.api.plerion.com/v1/organization/user-groups/{groupId}/preferences/navigation"
payload = {
"order": ["home", "findings", "risks", "assets", "alerts", "threat-map"],
"hidden": ["threat-map"]
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.put(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PUT',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
order: ['home', 'findings', 'risks', 'assets', 'alerts', 'threat-map'],
hidden: ['threat-map']
})
};
fetch('https://{region}.api.plerion.com/v1/organization/user-groups/{groupId}/preferences/navigation', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://{region}.api.plerion.com/v1/organization/user-groups/{groupId}/preferences/navigation",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PUT",
CURLOPT_POSTFIELDS => json_encode([
'order' => [
'home',
'findings',
'risks',
'assets',
'alerts',
'threat-map'
],
'hidden' => [
'threat-map'
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://{region}.api.plerion.com/v1/organization/user-groups/{groupId}/preferences/navigation"
payload := strings.NewReader("{\n \"order\": [\n \"home\",\n \"findings\",\n \"risks\",\n \"assets\",\n \"alerts\",\n \"threat-map\"\n ],\n \"hidden\": [\n \"threat-map\"\n ]\n}")
req, _ := http.NewRequest("PUT", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.put("https://{region}.api.plerion.com/v1/organization/user-groups/{groupId}/preferences/navigation")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"order\": [\n \"home\",\n \"findings\",\n \"risks\",\n \"assets\",\n \"alerts\",\n \"threat-map\"\n ],\n \"hidden\": [\n \"threat-map\"\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://{region}.api.plerion.com/v1/organization/user-groups/{groupId}/preferences/navigation")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Put.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"order\": [\n \"home\",\n \"findings\",\n \"risks\",\n \"assets\",\n \"alerts\",\n \"threat-map\"\n ],\n \"hidden\": [\n \"threat-map\"\n ]\n}"
response = http.request(request)
puts response.read_body{
"data": {
"tenantId": "65a72929-0e61-4c9c-b7a8-8abe6886fd6c",
"order": [
"home",
"findings",
"risks",
"assets",
"alerts",
"threat-map"
],
"hidden": [
"threat-map"
],
"updatedAt": "2026-10-05T04:12:00.000Z"
}
}{
"errors": [
{
"code": "ReportNotFound",
"message": "Custom report 3f1c7d2e-5a6b-4c8d-9e0f-1a2b3c4d5e6f was not found in tenant 65a72929-0e61-4c9c-b7a8-8abe6886fd6c"
}
]
}{
"errors": [
{
"code": "<string>",
"message": "<string>",
"field": "<string>"
}
]
}{
"errors": [
{
"code": "<string>",
"message": "<string>",
"field": "<string>"
}
]
}{
"errors": [
{
"code": "RoleNotFound",
"message": "role not found"
}
]
}Authorizations
Plerion organization API key (plerion_oak_…), created by an organization admin in the Plerion app.
Path Parameters
The user group id.
Query Parameters
The tenant the preference applies in. A PUT checks it belongs to the key's organization and answers 400 TenantNotFound otherwise; a GET or DELETE for a tenant outside the organization finds no row and answers 404 PreferenceNotFound.
Body
The sidebar arrangement. Entries not listed are appended by the Plerion app in catalog order.
home, alerts, risks, findings, assets, agent-security, dspm, cwpp, compliance, ciem, threat-map, code-security, settings, well-architected, pinned-custom-reports [
"home",
"findings",
"risks",
"assets",
"alerts",
"threat-map"
]
Entries from order to tuck away. Must be a subset of order.
home, alerts, risks, findings, assets, agent-security, dspm, cwpp, compliance, ciem, threat-map, code-security, settings, well-architected, pinned-custom-reports ["threat-map"]
Response
The stored preference, after normalisation.
Show child attributes
Show child attributes
Was this page helpful?