Skip to main content

Custom user roles

We provide predefined user roles that Administrators can assign to user accounts. Each role comprises one or more permissions that enable users to perform specific Veracode tasks. Administrators can create custom roles comprised of specific permissions.

To create and assign custom roles, Administrators can use the Identity REST API and specify the permission names in this section.

Before creating and assigning user roles, we recommend reviewing User roles assignment planning.

Administrators can also assign roles when creating users or editing users in the Veracode Platform. If your organization uses SAML and just-in-time (JIT) provisioning, you can assign roles, including the Administrator role, automatically through SAML assertions. Users that are members of a team are limited to team-assigned resources, such as the application profile and scan results for a specific application.

note

In the tables in this section, the Scope column indicates the breadth of access granted by each permission:

  • Organization-wide — Grants access to organizational settings and resources across all teams.
  • Team-level — Grants access only to resources assigned to the user's teams. For most roles, visibility is limited to applications assigned to the user's teams. To grant a user visibility across all applications without team assignments, you must set the ignore_team_restrictions:true property.
  • Workspace-level — Grants access only to resources within a specific Software Composition Analysis (SCA) workspace.
  • Individual — Grants access to user-specific features or settings.
  • Variable — Scope depends on the permission type assigned; can be organization-wide, team-level, or individual based on the qualifier (e.g., retrieveOrg vs. retrieveTeamOnly).

API users not assigned to a team have no team restrictions and can access all resources across the entire organization. To limit an API user's access to specific teams, assign the user to one or more teams when creating or editing their account.

Veracode Platform​

The following tables list the roles for administrative and general Veracode Platform tasks.

Veracode Fix availability

Users with the Submitter role (UI) or Upload and Scan API role (API) can use Veracode Fix to generate and apply security patches for SAST and SCA findings.

Administer the organization​

Some administrator permissions include permission types. The permission type assigned to a user controls whether they have team-restricted or organization-wide access. Assigning a permission with an Org-scoped type (like retrieveOrg) gives organization-wide access regardless of the permission's base scope designation. This is how you control whether custom roles respect team restrictions or bypass them.

Important

Permission types allow users to perform specific tasks granted by certain permissions. For custom roles, you must specify the types when assigning those permissions to a role.

Permission type qualifiers control access scope:

  • retrieve — Individual or team-level access
  • retrieveTeamOnly — Team-level access only (used by Team Admins)
  • retrieveOrg — Organization-wide access
  • create, update, delete — With corresponding scope qualifiers

Example: The ManageUser permission has different types (retrieve, retrieveTeamOnly, retrieveOrg). A Team Admin might have retrieveTeamOnly (see users on their teams only), while an Administrator would have retrieveOrg (see all users organization-wide).

To use the following permissions, you must have a base Veracode Platform subscription.

PermissionPermission namePermission typeScopeUI userAPI userImportant notes
Manage organizationsManageOrganizationretrieve, updateOrganization-wideYesYesControls organization-wide settings. Combine with other permissions to create full administrator roles.
Manage business unitsManageBusinessUnitcreate, retrieve, update, deleteOrganization-wideYesYesNone
Edit account SAML settingseditsamlsettingsOrganization-wideYesNoSAML must be configured for your organization.
View details for an accountviewAccountDetailsOrganization-wideYesNoNone
Manage vendor contact requestsmanageVendorContactOrganization-wideYesNoRequires third-party scanning to be configured.
Create a teamcreateTeamVariableYesYesNone
Delete a teamdeleteTeamVariableYesYesNone
Edit teameditTeamVariableYesYesNone
Manage teamsManageTeamcreate, retrieve, update, delete, retrieveTeamOnly, updateTeamOnlyVariableYesYesNone
Retrieve a team as Team AdminretrieveTeamAsTeamAdminTeam-levelYesNoCan only manage teams assigned to user with the Team Admin role.
Update team as Team AdminupdateTeamAsTeamAdminTeam-levelYesNoCan only manage teams assigned to user with the Team Admin role.
Create a login accountcreateLoginAccountVariableYesYesNone
Delete login accountdeleteLoginAccountVariableYesYesNone
Edit login accounteditLoginAccountVariableYesYesNone
Manage usersManageUsercreate, createTeamOnly, retrieve, retrieveOrg, retrieveTeamOnly, update, updateOrg, updateTeamOnly, delete, deleteTeamOnlyVariableYesYesUse Org permission types (retrieveOrg, updateOrg) to bypass team restrictions. Choose types carefully to control organizational vs. team-level access.
Create user for teamcreateUserForTeamTeam-levelYesNoCan only create users on assigned teams.
Delete a user for teamdeleteUserForTeamTeam-levelYesNoCan only delete users from assigned teams.
Retrieve a user for teamretrieveUserForTeamTeam-levelYesNoCan only view users on assigned teams.
Update user for teamupdateUserForTeamTeam-levelYesNoTeam Admins can't edit users with Administrator, Executive, Policy Administrator, Security Lead, or Team Admin roles.
Navigation for external AdministratornavExternalAdminIndividualYesNoFor external administrator partners. Combine with other permissions based on intended access level.
Navigation for external ExecutivenavExternalExecutiveIndividualYesNoFor external executive stakeholders. Provides organization-wide visibility. Combine with reporting or analytics permissions.
Navigation for Security Insight onlynavSecurityInsightOnlyIndividualYesNoRestricts users to the Security Insights page in the Veracode Platform. Useful for limiting access to read-only security metrics.
Access Admin APIadminApiOrganization-wideNoYesGrants unrestricted organization-wide access. Should be assigned to dedicated automation accounts only.
Enable the Reporting APIreportingApiOrganization-wideYesYesNone
Access Results APIresultsApiOrganization-wideNoYesCompanion roles: Pair with team assignments for scoped access. Combine with other functional API roles.
Manage API credentialsManageApiCredentialsgenerate, retrieve, retrieveOrg, retrieveTeamOnly, revoke, revokeOrg, revokeTeamOnlyVariableYesYesUse Org types (retrieveOrg, revokeOrg) for organization-wide credential management. Team-level types restrict to assigned teams.
Expire another user's API credentialsexpireApiCredentialsOrganization-wideYesNoNone
Expire another user's API credentials if on a managed teamexpireApiCredentialsForTeamTeam-levelYesNoCan only expire credentials for users on assigned teams.
View another user's API ID and status if on a managed teamretrieveApiCredentialsForTeamTeam-levelYesNoCan only view credentials for users on assigned teams.

Manage application profiles​

PermissionPermission nameScopeLicensingUI userAPI userImportant notes
Application portfolioappPortfolioTeam-levelBase Veracode Platform subscriptionYesYesRequired foundation for all application access. Companion roles: Pair with scan-specific permissions and viewResults for complete access.
Create a new applicationcreateApplicationProfileTeam-levelBase Veracode Platform subscriptionYesYesCompanion roles: Requires appPortfolio and at least one submission permission (e.g., submitPolicyScan, requestDynamicAnalysis).
Delete an applicationdeleteApplicationProfileTeam-levelBase Veracode Platform subscriptionYesYesIrreversible action; assign carefully to prevent accidental application removal.
Change application assurance levelchangeAppAssuranceLevelTeam-levelBase Veracode Platform subscriptionYesYesAffects policy compliance scoring. Limit to trusted security roles.
Change the Archer name of an applicationchangeArcherNameTeam-levelVeracode for Archer GRC integration licenseYesYesRequires Archer integration to be configured. Synchronizes with Archer GRC system.
Assign application to any teamassignAppToAnyTeamTeam-levelBase Veracode Platform subscriptionYesYesBroader than assignAppToTeam; allows assignment to any organization team regardless of user's teams.
Assign application to teamassignAppToTeamTeam-levelBase Veracode Platform subscriptionYesYesRestricted to teams the user is assigned to. Use with assignAppToAnyTeam for flexible team management.
Import application profilesimportApplicationProfilesTeam-levelBase Veracode Platform subscriptionYesNoBulk import via UI only. API users use create or update endpoints individually.
Link to applicationlinkAppTeam-levelBase Veracode Platform subscriptionYesNoAssociates scan results to an existing application profile from third-party tools.
Maintain DAST applicationmaintainDynamicApplicationTeam-levelVeracode Dynamic Analysis subscriptionYesNoRequired for configuring DAST scan templates, URLs, and scan schedules.

Manage collections​

To use the following permissions, you must have a base Veracode Platform subscription.

PermissionPermission nameScopeUI userAPI userImportant notes
Create a collectioncreateCollectionTeam-levelYesYesNone
Delete collectiondeleteCollectionTeam-levelYesYesNone
Read collectionsreadCollectionTeam-levelYesYesNone
Export custom dataexportCustomDataTeam-levelYesYesNone

Manage scan results, reports, and analytics​

PermissionPermission nameScopeLicensingUI userAPI userImportant notes
View reportsviewReportsTeam-levelBase Veracode Platform subscriptionYesYesFoundation permission for reviewing scan data. Combine with specific scan type permissions.
View resultsviewResultsTeam-levelBase Veracode Platform subscriptionYesYesRequired for accessing scan findings, flaws, and vulnerability details. Essential for most review roles.
Publish results to enterprisepublishResultsEnterpriseTeam-levelBase Veracode Platform subscriptionYesNoBroadcasts scan results across the organization. Restrict to authorized personnel only.
Custom reportcustomReportTeam-levelBase Veracode Platform subscriptionYesNoAllows creation of custom security reports. Combine with viewReports for full reporting capability.
View third-party components (SCA or VAST)viewThirdPartyDetailsIndividualBase Veracode Platform subscriptionYesNoThird-party scanning must be enabled. Required for displaying the Third-Party Components tab in the Veracode Platform for SCA scan results, and for enterprise customers to view the scan results of applications from third-party vendors using VAST.
Run Archer reportsarcherReportsTeam-levelVeracode for Archer GRC integration licenseYesYesRequires Archer integration to be configured.
Download scan reportsdownloadScanReportTeam-levelBase Veracode Platform subscriptionYesNoNone
Download scan reports as XMLdownloadScanReportXMLTeam-levelBase Veracode Platform subscriptionYesNoNone
Download crawl and login scriptdownloadScriptTeam-levelVeracode Dynamic Analysis subscriptionYesNoNone
Download the site list for the scandownloadSiteListTeam-levelVeracode Dynamic Analysis subscriptionYesNoNone
Retrieve cross-profile flaw identifiers in XML reportsportableScopeResultsAggregationTeam-levelBase Veracode Platform subscriptionYesYesAdvanced feature for cross-application flaw correlation. Typically for security leads and analysts.
Update resultsupdateResultsTeam-levelBase Veracode Platform subscriptionYesYesCompanion roles: Requires viewResults and approveMitigations for safe flaw management workflows.
View asset inventory resultsviewAssetInventoryResultsTeam-levelVeracode EASM subscriptionYesNoNone
View open sourceviewOpenSourceTeam-levelVeracode SCA subscriptionYesNoNone
Analytics creatorlookerAnalyticsCreatorTeam-levelVeracode Analytics subscriptionYesNoNone
Analytics viewerlookerAnalyticsViewerTeam-levelVeracode Analytics subscriptionYesNoNone
Analytics dashboarddashboardTeam-levelVeracode Analytics subscriptionYesNoNone

Manage security policies​

PermissionPermission nameScopeLicensingUI userAPI userImportant notes
Manage security policiespolicyManagementOrganization-wideBase Veracode Platform subscriptionYesYesControls organization-wide policy enforcement. Central to governance and compliance scoring.
View policy custom severity settingviewCustomSeverityOrganization-wideBase Veracode Platform subscriptionYesNoCustom severity levels configured.
Manage SCA component blacklist for policymanageScaBlacklistOrganization-wideVeracode SCA subscriptionYesNoNone

Manage support consultations​

To use the following permissions, you must have a base Veracode Consulting Services subscription.

PermissionPermission nameScopeUI userAPI userImportant notes
Enable applications for next-day consultations for creation and updateenableNextDayConsultationTeam-levelYesYesNone
Allow user to schedule remediation consultationsenableRemediationConsultationTeam-levelYesNoNone
Allow user to schedule upload consultationsenableUploadConsultationTeam-levelYesNoNone

Mitigate findings​

To use the following permissions, you must have a base Veracode Platform subscription.

PermissionPermission nameScopeUI userAPI userImportant notes
Approve or reject proposed mitigationsapproveMitigationsTeam-levelYesYesCritical security gate. Combine with viewResults to review proposed mitigations before approval.
Publish applications with mitigationspublishMitigatedRatingsTeam-levelYesNoNone
Change mitigation behavior for flaws mitigated by custom cleansermanageCustomCleanserManagementTeam-levelYesNoCustom cleansers must be configured.

Use File Exchange​

PermissionPermission nameScopeLicensingUI userAPI userImportant notes
Access File ExchangefileExchangeTeam-levelBase Veracode Platform subscriptionYesNoFile Exchange feature must be enabled.

Veracode Container Security​

PermissionPermission nameScopeLicensingUI userAPI userImportant notes
Submit a container scan and view resultssubmitContainerScanTeam-levelVeracode Container Security subscriptionYesNoCompanion roles: Requires appPortfolio. Pair with viewContainerResults for complete container workflow.
Review container scan resultsviewContainerResultsTeam-levelVeracode Container Security subscriptionYesNoCompanion roles: Requires appPortfolio. Pair with submitContainerScan for container security workflows.
Submit an IaC scan and view resultssubmitIaCScanTeam-levelVeracode Infrastructure-as-Code subscriptionYesNoCompanion roles: Requires appPortfolio. Pair with viewIaCResults for Infrastructure-as-Code security.
Review IaC scan resultsviewIaCResultsTeam-levelVeracode Infrastructure-as-Code subscriptionYesNoCompanion roles: Requires appPortfolio. Pair with submitIaCScan for IaC workflows.

Veracode DAST​

To use the following permissions, you must have a Veracode DAST subscription.

PermissionPermission nameScopeUI userAPI userImportant notes
Approve scansapproveDynamicScansTeam-levelYesNoCritical quality gate for DAST results. Pair with requestDynamicAnalysis for complete scan workflow.
Approve scansapproveDynamicScansTeam-levelYesNoCritical quality gate for DAST results. Pair with requestDynamicAnalysis for complete scan workflow.
Request an analysisrequestDynamicAnalysisTeam-levelYesYesInitiates DAST scans. Should be paired with approveDynamicScans for approval workflows.
Delete an analysisdeleteDynamicAnalysisTeam-levelYesNoNone
Import analysis results to an application profiledynamicAnalysisResultImportTeam-levelYesYesNone
Change application profile options for auto-linkingeditDynamicAnalysisAutoLinkAppOptionsTeam-levelYesNoNone
View application profile options for auto-linkingviewDynamicAnalysisAutoLinkAppOptionsTeam-levelYesNoNone
View analysis resultsviewDynamicAnalysisResultTeam-levelYesNoNone
View analysis statusviewDynamicAnalysisStatusTeam-levelYesNoNone
View the URL configuration for an analysisviewDynamicAnalysisURLConfigurationTeam-levelYesNoNone
Edit an ISM gatewayeditMVSAGatewayTeam-levelYesNoRequires ISM (Internal Scanning Management) gateway to be configured.
View an ISM gatewayviewMVSAGatewayTeam-levelYesNoRequires ISM gateway to be configured.
Generate WAF rulesgenerateWafRulesTeam-levelYesNoNone

Veracode eLearning​

To use the following permissions, you must have a Veracode eLearning subscription.

PermissionPermission nameScopeUI userAPI userImportant notes
Create an eLearning curriculumcreateCurriculumIndividualYesYesNone
Manage account-level eLearningmanageElearningIndividualYesYesNone
Access eLearning mentor contenteLearningMentorIndividualYesNoConsumes a purchased seat.
Access eLearning professor contenteLearningProfessorIndividualYesNoConsumes a purchased seat.
Navigation for external eLearningnavExternalELearnIndividualYesNoNone

Veracode Package Firewall​

To use the following permissions, you must have a Veracode Package Firewall subscription.

PermissionPermission nameScopeUI userAPI userImportant notes
Create a firewallcreateFirewallOrganization-wideYesNoNone
Delete a firewalldeleteFirewallOrganization-wideYesNoNone
Modify firewall policiesmanageFirewallPoliciesOrganization-wideYesNoNone
Modify firewall exceptionsmanageFirewallExceptionsTeam-levelYesNoNone
View firewall resultsviewFirewallResultsTeam-levelYesNoNone
Access Package Firewall UIaccessPackageFirewallTeam-levelYesNoNone

Veracode SAST​

To use the following permissions, you must have a Veracode Static Analysis subscription. The Scan with Greenlight permission requires a Veracode Greenlight subscription.

PermissionPermission nameScopeUI userAPI userImportant notes
Create a policy scan for an applicationcreatePolicyScanTeam-levelYesYesPolicy scans are evaluated against organization-wide security policies. Typically paired with submission and review permissions.
Delete a policy scandeletePolicyScanTeam-levelYesYesCompanion roles: Pair with scan submission and review permissions. Destructive action; restrict carefully.
Submit a manual policy scansubmitPolicyManualScanTeam-levelYesYesCompanion roles: Requires viewResults to review results. Pair with approveMitigations for complete workflow.
Submit a static policy scansubmitPolicyStaticScanTeam-levelYesYesCompanion roles: Pair with appPortfolio and viewResults for full SAST workflow.
Create a sandbox in an applicationcreateSandboxTeam-levelYesYesCompanion roles: Requires appPortfolio and viewSandbox. Works with createSandboxScan for scan submission.
Delete a sandbox in an applicationdeleteSandboxTeam-levelYesYesCompanion roles: Requires appPortfolio and viewSandbox. Destructive action; restrict to sandbox owners administrators.
View the list of sandboxes in an applicationviewSandboxTeam-levelYesYesCompanion roles: Requires appPortfolio. Pair with createSandboxScan and viewResults for development workflows.
Create a sandbox scan for an applicationcreateSandboxScanTeam-levelYesYesNone
Delete a sandbox scandeleteSandboxScanTeam-levelYesYesNone
Submit a manual sandbox scansubmitSandboxManualScanTeam-levelYesYesNone
Submit a static sandbox scansubmitSandboxStaticScanTeam-levelYesYesNone
Promote scan to policy sandboxpromoteScansTeam-levelYesYesCompanion roles: Requires viewSandbox and createSandboxScan. Counts toward compliance scoring.
Scan with GreenlightscanWithGreenlightTeam-levelYesYesVeracode Greenlight is deprecated; use Veracode Scan IDE plugins.
Delete module scan resultsdeleteModuleScanTeam-levelYesNoNone

Veracode SCA​

To use the following permissions, you must have a Veracode Software Composition Analysis (SCA) subscription.

PermissionPermission nameScopeUI userAPI userImportant notes
Enable SCA Agent-based ScanviewSourceClearScaTeam-levelYesNoCompanion roles: Pair with viewScaPortfolio and srcclrAccessAllWorkspaces for full SCA access.
View portfolio for third-party componentsviewScaPortfolioTeam-levelYesNoCompanion roles: Pair with viewSourceClearSca and srcclrListPortfolioPage for SCA portfolio visibility.
Set allow dependencies as top-level modulessetAllowDepAsTopLevelModulesTeam-levelYesNoNone
Navigate to all workspaces in SCA Agent-based ScansrcclrAccessAllWorkspacesOrganization-wideYesNoNone
Create workspace in SCA Agent-based ScansrcclrCreateWorkspaceOrganization-wideYesNoNone
View portfolio list page in SCA Agent-based ScansrcclrListPortfolioPageTeam-levelYesNoCompanion roles: Requires viewScaPortfolio and viewSourceClearSca. Foundation for SCA portfolio visibility.
Manage agents in SCA Agent-based Scan workspacesrcclrManageAgentsWorkspace-levelYesNoCompanion roles: Requires srcclrManageWorkspaces and viewSourceClearSca. Workspace-scoped permission.
Manage integration, agents, usage, and library catalog in SCA Agent-based ScansrcclrManageOrgOrganization-wideYesNoCompanion roles: Organization-wide permission. Pair with workspace-level permissions for complete SCA administrator access.
Manage SCA Agent-based Scan workspacessrcclrManageWorkspacesWorkspace-levelYesNoNone
Comment on issues in SCA Agent-based Scan workspacesrcclrWorkspaceCommentIssuesWorkspace-levelYesNoNone
Create third-party issues in SCA Agent-based Scan workspacesrcclrWorkspaceCreateThirdPartyIssueWorkspace-levelYesNoNone
Ignore and unignore issues in SCA Agent-based Scan workspacesrcclrWorkspaceIssuesVisibilityWorkspace-levelYesNoNone
Manage project settings in SCA Agent-based Scan workspacesrcclrWorkspaceManageProjectSettingsWorkspace-levelYesNoNone
Manage rules in SCA Agent-based Scan workspacesrcclrWorkspaceManageRulesWorkspace-levelYesNoNone
Manage workspace settings in SCA Agent-based ScansrcclrWorkspaceManageWebhooksWorkspace-levelYesNoNone
View projects in SCA Agent-based Scan workspacesrcclrWorkspaceViewProjectsWorkspace-levelYesNoNone
View issues, vulnerabilities, libraries, and licenses in an SCA Agent-based Scan workspacesrcclrWorkspaceViewReportsWorkspace-levelYesNoNone
View teams in SCA Agent-based Scan workspacesrcclrWorkspaceViewTeamsWorkspace-levelYesNoNone

Veracode Security Labs​

To use the following permissions, you must have a Veracode Security Labs subscription.

PermissionPermission nameScopeUI userAPI userImportant notes
Create and manage Security Labs learning for all Security Labs userssecurityLabsAdminOrganization-wideYesYesOrganization-wide adminstrator role for Security Labs. Controls learning paths for all users.
Create and manage Security Labs learning for users on their teamsecurityLabsManagerTeam-levelYesYesNone
Access Security LabssecurityLabsIndividualYesNoGrants access to Security Labs. Each assignment consumes one purchased seat. Plan assignments accordingly.

Veracode VAST​

To use the following permissions, you must have a base Veracode Platform subscription.

PermissionPermission nameScopeUI userAPI userImportant notes
Share your results in vendor directoryoptIntoVendorDirectoryIndividualYesNoOpt-in feature for vendor visibility.
View vendor listviewVendorListIndividualYesNoThird-party scanning must be enabled.