Per-Feature Access Control Details¶
ASM (Assets)¶
- Assets are bound to 0 (global assets) or many (project assets) projects.
- To create, edit, or delete an asset, the user must have the "Edit Assets" permission on the project(s) the asset is bound to.
- To edit the projects an asset is bound to, the user must have a global "Admin" permission as this operation alters the access control of the asset.
Tags¶
- Tags are global and can be attached to assets.
- To attach a tag to a resource, the user must have the relevant resource-edit permission on the project the resource is bound to (for example, "Edit Assets" for an asset).
- To create, edit, or delete a tag itself, the user must have the "Tag Edition" permission.
Warning
Tags organize resources. Access permissions come from role bindings and project membership, independently of tags.
Business Logic Aware DAST (Profiles, Scans, Custom Rules)¶
- Profiles are bound to the projects the assets they are linked to are bound to.
- To create or edit an individual profile, the user must have "Edit Profiles" or "Edit Assets" on its scope.
- Bulk updates to profile tags or schedules require "Edit Assets" on the profiles' scope.
- Deleting profiles requires "Admin" on the profiles' scope.
- To create, edit, or delete a custom rule, the user must have the "Edit Custom Rules" permission.
- To edit the projects a profile is bound to, the user must have "Admin" scoped to the destination projects or a global "Admin" binding. Clearing the project list requires global "Admin".
Issues¶
- Changing issue status, severity, or tags requires "Edit Assets" on the issues' scope.
Scans¶
- Running a scan requires "Edit Profiles" on the profile's scope.
Private Locations¶
- Creating or deleting a Private Location requires global "Admin".
Saved Views¶
- Managing saved integration views requires "Edit Integrations". Other saved views require "Edit Assets".
Vault Variables¶
- Creating, editing, or deleting vault variables and linking vaults requires "Manage Vault Variables" or "Admin" through a global role binding.
Reporting¶
- Reporting is global and can be viewed by any user.
- The data we gather to generate the report depends on the projects the user has access to.
- To manage reporting settings, the user must have a global "Manage Reporting" permission.
- Creating a report export requires a role in the organization; the report respects the user's resource access.
Workflows¶
- Workflows are global and can be viewed by any user.
- To create, edit, or delete a workflow, the user must have the "Edit Workflows" permission on the project(s) the workflow is bound to.
- To edit the projects a workflow is bound to, the user must hold "Edit Workflows" or "Admin" through a global role binding.
Warning
Attaching a workflow to a project will impact the resources against which the workflow will be executed. Workflows in a project will only apply to resources located in the project.
Integrations¶
- Integrations are bound to 0 (global integrations) or many (project integrations) projects.
- To create, edit, or delete an integration, the user must have the "Edit Integrations" permission on the project(s) the integration is bound to.
- To edit the projects an integration is bound to, the user must hold "Edit Integrations" or "Admin" through a global role binding.
Warning
Attaching an integration to a project will impact the resources that will be discovered by the integration. Resources discovered by an integration in a project will automatically be bound to the project. Integrations in a project can only be used by workflows in the same project.