Custom user roles
We provide predefined user roles that Administrators can assign to user accounts. Each role comprises one or more permissions that enable users to perform specific Veracode tasks. Administrators can create custom roles comprised of specific permissions.
To create and assign custom roles, Administrators can use the Identity REST API and specify the permission names in this section.
Before creating and assigning user roles, we recommend reviewing User roles assignment planning.
Administrators can also assign roles when creating users or editing users in the Veracode Platform. If your organization uses SAML and just-in-time (JIT) provisioning, you can assign roles, including the Administrator role, automatically through SAML assertions. Users that are members of a team are limited to team-assigned resources, such as the application profile and scan results for a specific application.
In the tables in this section, the Scope column indicates the breadth of access granted by each permission:
- Organization-wide — Grants access to organizational settings and resources across all teams.
- Team-level — Grants access only to resources assigned to the user's teams. For most roles, visibility is limited to applications assigned to the user's teams. To grant a user visibility across all applications without team assignments, you must set the
ignore_team_restrictions:trueproperty. - Workspace-level — Grants access only to resources within a specific Software Composition Analysis (SCA) workspace.
- Individual — Grants access to user-specific features or settings.
- Variable — Scope depends on the permission type assigned; can be organization-wide, team-level, or individual based on the qualifier (e.g.,
retrieveOrgvs.retrieveTeamOnly).
API users not assigned to a team have no team restrictions and can access all resources across the entire organization. To limit an API user's access to specific teams, assign the user to one or more teams when creating or editing their account.
Veracode Platform
The following tables list the roles for administrative and general Veracode Platform tasks.
Users with the Submitter role (UI) or Upload and Scan API role (API) can use Veracode Fix to generate and apply security patches for SAST and SCA findings.
Administer the organization
Some administrator permissions include permission types. The permission type assigned to a user controls whether they have team-restricted or organization-wide access.
Assigning a permission with an Org-scoped type (like retrieveOrg) gives organization-wide access regardless of the permission's base scope designation.
This is how you control whether custom roles respect team restrictions or bypass them.
Permission types allow users to perform specific tasks granted by certain permissions. For custom roles, you must specify the types when assigning those permissions to a role.
Permission type qualifiers control access scope:
retrieve— Individual or team-level accessretrieveTeamOnly— Team-level access only (used by Team Admins)retrieveOrg— Organization-wide accesscreate,update,delete— With corresponding scope qualifiers
Example: The ManageUser permission has different types (retrieve, retrieveTeamOnly, retrieveOrg). A Team Admin might have retrieveTeamOnly (see users on their teams only), while an Administrator would have retrieveOrg (see all users organization-wide).
To use the following permissions, you must have a base Veracode Platform subscription.
| Permission | Permission name | Permission type | Scope | UI user | API user | Important notes |
|---|---|---|---|---|---|---|
| Manage organizations | ManageOrganization | retrieve, update | Organization-wide | Yes | Yes | Controls organization-wide settings. Combine with other permissions to create full administrator roles. |
| Manage business units | ManageBusinessUnit | create, retrieve, update, delete | Organization-wide | Yes | Yes | None |
| Edit account SAML settings | editsamlsettings | Organization-wide | Yes | No | SAML must be configured for your organization. | |
| View details for an account | viewAccountDetails | Organization-wide | Yes | No | None | |
| Manage vendor contact requests | manageVendorContact | Organization-wide | Yes | No | Requires third-party scanning to be configured. | |
| Create a team | createTeam | Variable | Yes | Yes | None | |
| Delete a team | deleteTeam | Variable | Yes | Yes | None | |
| Edit team | editTeam | Variable | Yes | Yes | None | |
| Manage teams | ManageTeam | create, retrieve, update, delete, retrieveTeamOnly, updateTeamOnly | Variable | Yes | Yes | None |
| Retrieve a team as Team Admin | retrieveTeamAsTeamAdmin | Team-level | Yes | No | Can only manage teams assigned to user with the Team Admin role. | |
| Update team as Team Admin | updateTeamAsTeamAdmin | Team-level | Yes | No | Can only manage teams assigned to user with the Team Admin role. | |
| Create a login account | createLoginAccount | Variable | Yes | Yes | None | |
| Delete login account | deleteLoginAccount | Variable | Yes | Yes | None | |
| Edit login account | editLoginAccount | Variable | Yes | Yes | None | |
| Manage users | ManageUser | create, createTeamOnly, retrieve, retrieveOrg, retrieveTeamOnly, update, updateOrg, updateTeamOnly, delete, deleteTeamOnly | Variable | Yes | Yes | Use Org permission types (retrieveOrg, updateOrg) to bypass team restrictions. Choose types carefully to control organizational vs. team-level access. |
| Create user for team | createUserForTeam | Team-level | Yes | No | Can only create users on assigned teams. | |
| Delete a user for team | deleteUserForTeam | Team-level | Yes | No | Can only delete users from assigned teams. | |
| Retrieve a user for team | retrieveUserForTeam | Team-level | Yes | No | Can only view users on assigned teams. | |
| Update user for team | updateUserForTeam | Team-level | Yes | No | Team Admins can't edit users with Administrator, Executive, Policy Administrator, Security Lead, or Team Admin roles. | |
| Navigation for external Administrator | navExternalAdmin | Individual | Yes | No | For external administrator partners. Combine with other permissions based on intended access level. | |
| Navigation for external Executive | navExternalExecutive | Individual | Yes | No | For external executive stakeholders. Provides organization-wide visibility. Combine with reporting or analytics permissions. | |
| Navigation for Security Insight only | navSecurityInsightOnly | Individual | Yes | No | Restricts users to the Security Insights page in the Veracode Platform. Useful for limiting access to read-only security metrics. | |
| Access Admin API | adminApi | Organization-wide | No | Yes | Grants unrestricted organization-wide access. Should be assigned to dedicated automation accounts only. | |
| Enable the Reporting API | reportingApi | Organization-wide | Yes | Yes | None | |
| Access Results API | resultsApi | Organization-wide | No | Yes | Companion roles: Pair with team assignments for scoped access. Combine with other functional API roles. | |
| Manage API credentials | ManageApiCredentials | generate, retrieve, retrieveOrg, retrieveTeamOnly, revoke, revokeOrg, revokeTeamOnly | Variable | Yes | Yes | Use Org types (retrieveOrg, revokeOrg) for organization-wide credential management. Team-level types restrict to assigned teams. |
| Expire another user's API credentials | expireApiCredentials | Organization-wide | Yes | No | None | |
| Expire another user's API credentials if on a managed team | expireApiCredentialsForTeam | Team-level | Yes | No | Can only expire credentials for users on assigned teams. | |
| View another user's API ID and status if on a managed team | retrieveApiCredentialsForTeam | Team-level | Yes | No | Can only view credentials for users on assigned teams. |
Manage application profiles
| Permission | Permission name | Scope | Licensing | UI user | API user | Important notes |
|---|---|---|---|---|---|---|
| Application portfolio | appPortfolio | Team-level | Base Veracode Platform subscription | Yes | Yes | Required foundation for all application access. Companion roles: Pair with scan-specific permissions and viewResults for complete access. |
| Create a new application | createApplicationProfile | Team-level | Base Veracode Platform subscription | Yes | Yes | Companion roles: Requires appPortfolio and at least one submission permission (e.g., submitPolicyScan, requestDynamicAnalysis). |
| Delete an application | deleteApplicationProfile | Team-level | Base Veracode Platform subscription | Yes | Yes | Irreversible action; assign carefully to prevent accidental application removal. |
| Change application assurance level | changeAppAssuranceLevel | Team-level | Base Veracode Platform subscription | Yes | Yes | Affects policy compliance scoring. Limit to trusted security roles. |
| Change the Archer name of an application | changeArcherName | Team-level | Veracode for Archer GRC integration license | Yes | Yes | Requires Archer integration to be configured. Synchronizes with Archer GRC system. |
| Assign application to any team | assignAppToAnyTeam | Team-level | Base Veracode Platform subscription | Yes | Yes | Broader than assignAppToTeam; allows assignment to any organization team regardless of user's teams. |
| Assign application to team | assignAppToTeam | Team-level | Base Veracode Platform subscription | Yes | Yes | Restricted to teams the user is assigned to. Use with assignAppToAnyTeam for flexible team management. |
| Import application profiles | importApplicationProfiles | Team-level | Base Veracode Platform subscription | Yes | No | Bulk import via UI only. API users use create or update endpoints individually. |
| Link to application | linkApp | Team-level | Base Veracode Platform subscription | Yes | No | Associates scan results to an existing application profile from third-party tools. |
| Maintain DAST application | maintainDynamicApplication | Team-level | Veracode Dynamic Analysis subscription | Yes | No | Required for configuring DAST scan templates, URLs, and scan schedules. |
Manage collections
To use the following permissions, you must have a base Veracode Platform subscription.
| Permission | Permission name | Scope | UI user | API user | Important notes |
|---|---|---|---|---|---|
| Create a collection | createCollection | Team-level | Yes | Yes | None |
| Delete collection | deleteCollection | Team-level | Yes | Yes | None |
| Read collections | readCollection | Team-level | Yes | Yes | None |
| Export custom data | exportCustomData | Team-level | Yes | Yes | None |
Manage scan results, reports, and analytics
| Permission | Permission name | Scope | Licensing | UI user | API user | Important notes |
|---|---|---|---|---|---|---|
| View reports | viewReports | Team-level | Base Veracode Platform subscription | Yes | Yes | Foundation permission for reviewing scan data. Combine with specific scan type permissions. |
| View results | viewResults | Team-level | Base Veracode Platform subscription | Yes | Yes | Required for accessing scan findings, flaws, and vulnerability details. Essential for most review roles. |
| Publish results to enterprise | publishResultsEnterprise | Team-level | Base Veracode Platform subscription | Yes | No | Broadcasts scan results across the organization. Restrict to authorized personnel only. |
| Custom report | customReport | Team-level | Base Veracode Platform subscription | Yes | No | Allows creation of custom security reports. Combine with viewReports for full reporting capability. |
| View third-party components (SCA or VAST) | viewThirdPartyDetails | Individual | Base Veracode Platform subscription | Yes | No | Third-party scanning must be enabled. Required for displaying the Third-Party Components tab in the Veracode Platform for SCA scan results, and for enterprise customers to view the scan results of applications from third-party vendors using VAST. |
| Run Archer reports | archerReports | Team-level | Veracode for Archer GRC integration license | Yes | Yes | Requires Archer integration to be configured. |
| Download scan reports | downloadScanReport | Team-level | Base Veracode Platform subscription | Yes | No | None |
| Download scan reports as XML | downloadScanReportXML | Team-level | Base Veracode Platform subscription | Yes | No | None |
| Download crawl and login script | downloadScript | Team-level | Veracode Dynamic Analysis subscription | Yes | No | None |
| Download the site list for the scan | downloadSiteList | Team-level | Veracode Dynamic Analysis subscription | Yes | No | None |
| Retrieve cross-profile flaw identifiers in XML reports | portableScopeResultsAggregation | Team-level | Base Veracode Platform subscription | Yes | Yes | Advanced feature for cross-application flaw correlation. Typically for security leads and analysts. |
| Update results | updateResults | Team-level | Base Veracode Platform subscription | Yes | Yes | Companion roles: Requires viewResults and approveMitigations for safe flaw management workflows. |
| View asset inventory results | viewAssetInventoryResults | Team-level | Veracode EASM subscription | Yes | No | None |
| View open source | viewOpenSource | Team-level | Veracode SCA subscription | Yes | No | None |
| Analytics creator | lookerAnalyticsCreator | Team-level | Veracode Analytics subscription | Yes | No | None |
| Analytics viewer | lookerAnalyticsViewer | Team-level | Veracode Analytics subscription | Yes | No | None |
| Analytics dashboard | dashboard | Team-level | Veracode Analytics subscription | Yes | No | None |
Manage security policies
| Permission | Permission name | Scope | Licensing | UI user | API user | Important notes |
|---|---|---|---|---|---|---|
| Manage security policies | policyManagement | Organization-wide | Base Veracode Platform subscription | Yes | Yes | Controls organization-wide policy enforcement. Central to governance and compliance scoring. |
| View policy custom severity setting | viewCustomSeverity | Organization-wide | Base Veracode Platform subscription | Yes | No | Custom severity levels configured. |
| Manage SCA component blacklist for policy | manageScaBlacklist | Organization-wide | Veracode SCA subscription | Yes | No | None |
Manage support consultations
To use the following permissions, you must have a base Veracode Consulting Services subscription.
| Permission | Permission name | Scope | UI user | API user | Important notes |
|---|---|---|---|---|---|
| Enable applications for next-day consultations for creation and update | enableNextDayConsultation | Team-level | Yes | Yes | None |
| Allow user to schedule remediation consultations | enableRemediationConsultation | Team-level | Yes | No | None |
| Allow user to schedule upload consultations | enableUploadConsultation | Team-level | Yes | No | None |
Mitigate findings
To use the following permissions, you must have a base Veracode Platform subscription.
| Permission | Permission name | Scope | UI user | API user | Important notes |
|---|---|---|---|---|---|
| Approve or reject proposed mitigations | approveMitigations | Team-level | Yes | Yes | Critical security gate. Combine with viewResults to review proposed mitigations before approval. |
| Publish applications with mitigations | publishMitigatedRatings | Team-level | Yes | No | None |
| Change mitigation behavior for flaws mitigated by custom cleanser | manageCustomCleanserManagement | Team-level | Yes | No | Custom cleansers must be configured. |
Use File Exchange
| Permission | Permission name | Scope | Licensing | UI user | API user | Important notes |
|---|---|---|---|---|---|---|
| Access File Exchange | fileExchange | Team-level | Base Veracode Platform subscription | Yes | No | File Exchange feature must be enabled. |
Veracode Container Security
| Permission | Permission name | Scope | Licensing | UI user | API user | Important notes |
|---|---|---|---|---|---|---|
| Submit a container scan and view results | submitContainerScan | Team-level | Veracode Container Security subscription | Yes | No | Companion roles: Requires appPortfolio. Pair with viewContainerResults for complete container workflow. |
| Review container scan results | viewContainerResults | Team-level | Veracode Container Security subscription | Yes | No | Companion roles: Requires appPortfolio. Pair with submitContainerScan for container security workflows. |
| Submit an IaC scan and view results | submitIaCScan | Team-level | Veracode Infrastructure-as-Code subscription | Yes | No | Companion roles: Requires appPortfolio. Pair with viewIaCResults for Infrastructure-as-Code security. |
| Review IaC scan results | viewIaCResults | Team-level | Veracode Infrastructure-as-Code subscription | Yes | No | Companion roles: Requires appPortfolio. Pair with submitIaCScan for IaC workflows. |
Veracode DAST
To use the following permissions, you must have a Veracode DAST subscription.
| Permission | Permission name | Scope | UI user | API user | Important notes |
|---|---|---|---|---|---|
| Approve scans | approveDynamicScans | Team-level | Yes | No | Critical quality gate for DAST results. Pair with requestDynamicAnalysis for complete scan workflow. |
| Approve scans | approveDynamicScans | Team-level | Yes | No | Critical quality gate for DAST results. Pair with requestDynamicAnalysis for complete scan workflow. |
| Request an analysis | requestDynamicAnalysis | Team-level | Yes | Yes | Initiates DAST scans. Should be paired with approveDynamicScans for approval workflows. |
| Delete an analysis | deleteDynamicAnalysis | Team-level | Yes | No | None |
| Import analysis results to an application profile | dynamicAnalysisResultImport | Team-level | Yes | Yes | None |
| Change application profile options for auto-linking | editDynamicAnalysisAutoLinkAppOptions | Team-level | Yes | No | None |
| View application profile options for auto-linking | viewDynamicAnalysisAutoLinkAppOptions | Team-level | Yes | No | None |
| View analysis results | viewDynamicAnalysisResult | Team-level | Yes | No | None |
| View analysis status | viewDynamicAnalysisStatus | Team-level | Yes | No | None |
| View the URL configuration for an analysis | viewDynamicAnalysisURLConfiguration | Team-level | Yes | No | None |
| Edit an ISM gateway | editMVSAGateway | Team-level | Yes | No | Requires ISM (Internal Scanning Management) gateway to be configured. |
| View an ISM gateway | viewMVSAGateway | Team-level | Yes | No | Requires ISM gateway to be configured. |
| Generate WAF rules | generateWafRules | Team-level | Yes | No | None |
Veracode eLearning
To use the following permissions, you must have a Veracode eLearning subscription.
| Permission | Permission name | Scope | UI user | API user | Important notes |
|---|---|---|---|---|---|
| Create an eLearning curriculum | createCurriculum | Individual | Yes | Yes | None |
| Manage account-level eLearning | manageElearning | Individual | Yes | Yes | None |
| Access eLearning mentor content | eLearningMentor | Individual | Yes | No | Consumes a purchased seat. |
| Access eLearning professor content | eLearningProfessor | Individual | Yes | No | Consumes a purchased seat. |
| Navigation for external eLearning | navExternalELearn | Individual | Yes | No | None |
Veracode Package Firewall
To use the following permissions, you must have a Veracode Package Firewall subscription.
| Permission | Permission name | Scope | UI user | API user | Important notes |
|---|---|---|---|---|---|
| Create a firewall | createFirewall | Organization-wide | Yes | No | None |
| Delete a firewall | deleteFirewall | Organization-wide | Yes | No | None |
| Modify firewall policies | manageFirewallPolicies | Organization-wide | Yes | No | None |
| Modify firewall exceptions | manageFirewallExceptions | Team-level | Yes | No | None |
| View firewall results | viewFirewallResults | Team-level | Yes | No | None |
| Access Package Firewall UI | accessPackageFirewall | Team-level | Yes | No | None |
Veracode SAST
To use the following permissions, you must have a Veracode Static Analysis subscription. The Scan with Greenlight permission requires a Veracode Greenlight subscription.
| Permission | Permission name | Scope | UI user | API user | Important notes |
|---|---|---|---|---|---|
| Create a policy scan for an application | createPolicyScan | Team-level | Yes | Yes | Policy scans are evaluated against organization-wide security policies. Typically paired with submission and review permissions. |
| Delete a policy scan | deletePolicyScan | Team-level | Yes | Yes | Companion roles: Pair with scan submission and review permissions. Destructive action; restrict carefully. |
| Submit a manual policy scan | submitPolicyManualScan | Team-level | Yes | Yes | Companion roles: Requires viewResults to review results. Pair with approveMitigations for complete workflow. |
| Submit a static policy scan | submitPolicyStaticScan | Team-level | Yes | Yes | Companion roles: Pair with appPortfolio and viewResults for full SAST workflow. |
| Create a sandbox in an application | createSandbox | Team-level | Yes | Yes | Companion roles: Requires appPortfolio and viewSandbox. Works with createSandboxScan for scan submission. |
| Delete a sandbox in an application | deleteSandbox | Team-level | Yes | Yes | Companion roles: Requires appPortfolio and viewSandbox. Destructive action; restrict to sandbox owners administrators. |
| View the list of sandboxes in an application | viewSandbox | Team-level | Yes | Yes | Companion roles: Requires appPortfolio. Pair with createSandboxScan and viewResults for development workflows. |
| Create a sandbox scan for an application | createSandboxScan | Team-level | Yes | Yes | None |
| Delete a sandbox scan | deleteSandboxScan | Team-level | Yes | Yes | None |
| Submit a manual sandbox scan | submitSandboxManualScan | Team-level | Yes | Yes | None |
| Submit a static sandbox scan | submitSandboxStaticScan | Team-level | Yes | Yes | None |
| Promote scan to policy sandbox | promoteScans | Team-level | Yes | Yes | Companion roles: Requires viewSandbox and createSandboxScan. Counts toward compliance scoring. |
| Scan with Greenlight | scanWithGreenlight | Team-level | Yes | Yes | Veracode Greenlight is deprecated; use Veracode Scan IDE plugins. |
| Delete module scan results | deleteModuleScan | Team-level | Yes | No | None |
Veracode SCA
To use the following permissions, you must have a Veracode Software Composition Analysis (SCA) subscription.
| Permission | Permission name | Scope | UI user | API user | Important notes |
|---|---|---|---|---|---|
| Enable SCA Agent-based Scan | viewSourceClearSca | Team-level | Yes | No | Companion roles: Pair with viewScaPortfolio and srcclrAccessAllWorkspaces for full SCA access. |
| View portfolio for third-party components | viewScaPortfolio | Team-level | Yes | No | Companion roles: Pair with viewSourceClearSca and srcclrListPortfolioPage for SCA portfolio visibility. |
| Set allow dependencies as top-level modules | setAllowDepAsTopLevelModules | Team-level | Yes | No | None |
| Navigate to all workspaces in SCA Agent-based Scan | srcclrAccessAllWorkspaces | Organization-wide | Yes | No | None |
| Create workspace in SCA Agent-based Scan | srcclrCreateWorkspace | Organization-wide | Yes | No | None |
| View portfolio list page in SCA Agent-based Scan | srcclrListPortfolioPage | Team-level | Yes | No | Companion roles: Requires viewScaPortfolio and viewSourceClearSca. Foundation for SCA portfolio visibility. |
| Manage agents in SCA Agent-based Scan workspace | srcclrManageAgents | Workspace-level | Yes | No | Companion roles: Requires srcclrManageWorkspaces and viewSourceClearSca. Workspace-scoped permission. |
| Manage integration, agents, usage, and library catalog in SCA Agent-based Scan | srcclrManageOrg | Organization-wide | Yes | No | Companion roles: Organization-wide permission. Pair with workspace-level permissions for complete SCA administrator access. |
| Manage SCA Agent-based Scan workspaces | srcclrManageWorkspaces | Workspace-level | Yes | No | None |
| Comment on issues in SCA Agent-based Scan workspace | srcclrWorkspaceCommentIssues | Workspace-level | Yes | No | None |
| Create third-party issues in SCA Agent-based Scan workspace | srcclrWorkspaceCreateThirdPartyIssue | Workspace-level | Yes | No | None |
| Ignore and unignore issues in SCA Agent-based Scan workspace | srcclrWorkspaceIssuesVisibility | Workspace-level | Yes | No | None |
| Manage project settings in SCA Agent-based Scan workspace | srcclrWorkspaceManageProjectSettings | Workspace-level | Yes | No | None |
| Manage rules in SCA Agent-based Scan workspace | srcclrWorkspaceManageRules | Workspace-level | Yes | No | None |
| Manage workspace settings in SCA Agent-based Scan | srcclrWorkspaceManageWebhooks | Workspace-level | Yes | No | None |
| View projects in SCA Agent-based Scan workspace | srcclrWorkspaceViewProjects | Workspace-level | Yes | No | None |
| View issues, vulnerabilities, libraries, and licenses in an SCA Agent-based Scan workspace | srcclrWorkspaceViewReports | Workspace-level | Yes | No | None |
| View teams in SCA Agent-based Scan workspace | srcclrWorkspaceViewTeams | Workspace-level | Yes | No | None |
Veracode Security Labs
To use the following permissions, you must have a Veracode Security Labs subscription.
| Permission | Permission name | Scope | UI user | API user | Important notes |
|---|---|---|---|---|---|
| Create and manage Security Labs learning for all Security Labs users | securityLabsAdmin | Organization-wide | Yes | Yes | Organization-wide adminstrator role for Security Labs. Controls learning paths for all users. |
| Create and manage Security Labs learning for users on their team | securityLabsManager | Team-level | Yes | Yes | None |
| Access Security Labs | securityLabs | Individual | Yes | No | Grants access to Security Labs. Each assignment consumes one purchased seat. Plan assignments accordingly. |
Veracode VAST
To use the following permissions, you must have a base Veracode Platform subscription.
| Permission | Permission name | Scope | UI user | API user | Important notes |
|---|---|---|---|---|---|
| Share your results in vendor directory | optIntoVendorDirectory | Individual | Yes | No | Opt-in feature for vendor visibility. |
| View vendor list | viewVendorList | Individual | Yes | No | Third-party scanning must be enabled. |