---
name: sap-powervs-scc-wp-2-creating-instance
title: Creating an IBM Cloud&reg; Security and Compliance Center Workload Protection instance
description: To leverage the functionality offered by IBM Cloud&reg; Security and Compliance Center Workload Protection, Workload Protection instance is required required. This tutorial describes how to create one.
last-updated: 2026-06-16
---

> ## Documentation Index
> The table of contents for this documentation set is at https://cloud.ibm.com/docs/sap?format=markdown
> The index for all IBM Cloud docs is at: https://cloud.ibm.com/docs/llms.txt
> Use these files to discover more information as needed.

# Creating an IBM Cloud&reg; Security and Compliance Center Workload Protection instance
{: #powervs-scc-wp-create-instance}
{: toc-content-type="tutorial"}
{: toc-completion-time="10m"}



To leverage the functionality offered by IBM Cloud&reg; Security and Compliance Center Workload Protection, Workload Protection instance is required required. This tutorial describes how to create one.
{: shortdesc}

## Before you begin
{: #getting-started-prereqs}

- You must have a user ID that is a member or an owner of an IBM Cloud account. To get an IBM Cloud user ID, go to: [Registration](https://cloud.ibm.com/login){: external}.

- Check the regions where the service is available. [Learn more](https://cloud.ibm.com/docs/workload-protection?topic=workload-protection-regions&format=markdown). You can complete the steps in any of the supported regions.


## Manage user access
{: #getting-started-step1}
{: step}

Every user that accesses the IBM Cloud Security and Compliance Center Workload Protection service in your account must be assigned an access policy with an IAM user role defined. The policy determines the actions that the user can run within the context of the service or instance you selected. The allowable actions are customized and defined as operations that are allowed to be run on the service. The actions are then mapped to IAM user roles. For more information, see [Managing user access in the IBM Cloud](https://cloud.ibm.com/docs/workload-protection?topic=workload-protection-iam&format=markdown).

When a user is granted permissions in the IBM Cloud to work with the IBM Cloud Security and Compliance Center Workload Protection service, the user is automatically granted a service role. This role determines the actions that a user has permissions to run. For more information, see [Controlling access through IAM](https://cloud.ibm.com/docs/workload-protection?topic=workload-protection-iam&format=markdown).

Before you can provision an instance, you need to understand:
* The account owner can create, view, and delete an instance of a service in the IBM Cloud, and can grant permissions to other users to work with the IBM Cloud Security and Compliance Center Workload Protection service.
* You must have permissions to create resources in the *Default* resource group.
* Other IBM Cloud users with `administrator` or `editor` permissions can manage the IBM Cloud Security and Compliance Center Workload Protection service in the IBM Cloud. These users must also have platform permissions to create resources within the context of the resource group where they plan to provision the instance.

To grant a user the administrator role for the service and to manage instances within a resource group in the account, the user must have an IAM policy for the IBM Cloud Security and Compliance Center Workload Protection service. For more information, see [Granting permissions to work with the IBM Cloud Security and Compliance Center Workload Protection service](https://cloud.ibm.com/docs/workload-protection?topic=workload-protection-iam&format=markdown).

By default, users are automatically added as members of the **Secure Operations** team that is predefined for each IBM Cloud Security and Compliance Center Workload Protection instance. Users have full permissions to see all the data in the web UI.


## Provision an instance
{: #getting-started-step2}
{: step}

To add monitoring features with IBM Cloud Security and Compliance Center Workload Protection in the IBM Cloud, you must provision an instance of the IBM Cloud Security and Compliance Center Workload Protection service.

Instances are provisioned in the context of a resource group. A resource group organizes your services for access control and billing purposes. You can provision the IBM Cloud Security and Compliance Center Workload Protection instance in the *default* resource group or in a custom resource group.

To provision an instance through the IBM Cloud UI, complete the following steps:

1. Log in to your IBM Cloud account.

   Open the [IBM Cloud dashboard](https://cloud.ibm.com/login){: external}.

   After you log in with your user ID and password, the IBM Cloud UI opens.

1. Click **Catalog**. The list of the services that are available in IBM Cloud opens.

1. To filter the list of services that is displayed, select the **Security** category.

1. Click the **IBM Cloud Security and Compliance Center Workload Protection** tile.

1. Select the location.

1. Select a service plan.

   For more information about the service plans, see [Service plans](https://cloud.ibm.com/docs/workload-protection?topic=workload-protection-pricing&format=markdown).

1. Enter a service name.

1. Select a resource group. By default, the **Default** resource group is set.

1. Click **Create** to provision an instance.

The service UI opens.

To provision an instance through the CLI, see [Provisioning a Monitoring instance through the IBM Cloud CLI](https://cloud.ibm.com/docs/workload-protection?topic=workload-protection-provision&interface=cli&format=markdown#provision_cli).
{: tip}


## Access the Workload Protection Dashboard
{: #scc-wp-create-instance-access-dashboard}
{: step}

The last step should have taken you to the Overview page of the Workload Protection you just created. From there, you can just click on "Open dashboard". In case you closed the page and want to get back, follow these steps to access the dashboard:

1. Open the [IBM Cloud dashboard](https://cloud.ibm.com/login){: external}.

1.  Click the **Navigation menu** icon ![Navigation menu icon](../../icons/icon_hamburger.svg "Menu") > **Security** > **Resources**

1. From the list, select your Workload Protection instance and click on it.

1. In the instance, click on **Open Dashboard**

## Next step: Configure the agent
{: #scc-wp-create-instance-next-step}
{: step}

You've successfully created a Workload Protection instance. Proceed to [Workload Protection agent setup](https://cloud.ibm.com/docs/sap?topic=sap-scc-wp-agent-setup&format=markdown) to learn how to install and configure the agent on your Power Virtual Server instances and Virtual Servers for VPC.