Skip to main content

UI user roles by task

This section identifies the required UI user roles for performing certain tasks with Veracode products or features.

We also provide the typical UI user roles based on jobs.

Veracode Platform​

The following tables list the roles for general Veracode Platform tasks.

Administer the organization​

TaskAdministratorTeam Admin
Create usersYesYes
Edit usersYesYes
Delete usersYesNo
Reset user passwordsYesYes
Update user rolesYesYes
Add or remove team membershipYesYes
Create teamsYesNo
Edit teamsYesNo
Delete teamsYesNo
Create business unitsYesNo
Edit business unitsYesNo
Delete business unitsYesNo
Manage SAML settingsYesNo
Edit organization settingsYesNo
note

Team Admins can only manage users on their assigned teams and cannot edit roles for Administrator, Executive, Policy Administrator, Security Lead, Team Admin, or Workspace Administrator users. For more information, see Team Admin role details.

Manage application profiles​

TaskAdministratorCreatorDelete ScansSecurity LeadSubmitter
Create application profilesNoYesNoYesNo
Bulk add application profilesNoNoNoYesNo
Assign application profiles to teamsYesYesNoYesNo
Delete any scans for an application profileNoYesYesYesNo

Manage scan results, reports, and analytics​

TaskExecutiveReviewerSecurity LeadSecurity InsightsAnalytics Creator
Publish resultsNoNoYesNoNo
View results and reportsYesYesYesNoNo
Comment on results on the Triage Flaws pageNoNoYesNoNo
Download XML resultsYesYesYesNoNo
View analyticsYesNoYesYesYes
Edit analyticsNoNoNoNoYes
Access Reporting APIYesNoYesYesNo
note

Members of a team assigned to an application profile can accept third-party terms or scan requests. Users with both the Reviewer and Security Insights role can view analytics only for the teams for which they have access.

Manage security policies​

TaskPolicy Administrator
Manage security policiesYes

Manage support consultations​

TaskCreatorSubmitterSecurity Lead
Enable applications for next-day consultationsYesNoYes
Schedule consultations for policy scan resultsYesYesYes
Schedule remediation consultationsYesNoYes
Schedule upload consultationsYesNoYes

Mitigate findings​

TaskMitigation ApproverReviewerSecurity Lead
Propose mitigationsNoYesYes
Approve mitigationsYesNoNo

Use File Exchange​

TaskAdministratorSecurity LeadVendor Manager
Manage File Exchange filesYesYesNo

Veracode Container Security​

TaskSubmitterCreatorSecurity Lead
Submit a container scan and view resultsYesYesYes
Submit an IaC scan and view resultsYesYesYes

Veracode DAST​

TaskAdministratorCreatorSubmitterReviewerSecurity Lead
Request, create, or submit an analysisYesYesYesNoYes
Upload or enter URLsYesYesYesNoYes
Import URLs or API endpointsYesYesYesNoYes
Auto-link results to application profilesYesNoNoNoYes
Manually link results to application profilesYesYesYesNoYes
Assign teamsYesYesYesNoYes
Edit and schedule an analysisYesYesYesNoYes
Edit scan configurationsNoYesYesNoYes
Add or delete scansNoYesYesNoYes
View analysis statusNoYesYesYesYes
View analysis configurationNoYesYesNoYes
Delete an analysisNoYesYesNoYes
View vulnerability summaryNoYesYesYesYes
Generate WAF rulesNoYesYesNoYes

Veracode eLearning​

TaskAdministratorExecutiveeLearning
Manage learnersYesNoNo
Access eLearningNoNoYes
View all eLearning coursesNoYesYes
note

To view all eLearning courses, both the Executive and eLearning roles are required.

Veracode Package Firewall​

TaskAdministratorReviewerSubmitterMitigation ApproverPolicy AdministratorSecurity Lead
Create firewallsNoNoNoNoYesYes
Delete firewallsNoNoNoNoNoYes
Modify policiesNoNoNoNoYesYes
Modify exceptionsNoNoNoYesNoYes
View resultsYesYesYesYesYesYes

Veracode SAST​

TaskCreatorReviewerSubmitterSandbox AdministratorSandbox UserSecurity Lead
Request Manual Penetration Testing (MPT), Static Analysis, or Pipeline ScanYesNoYesNoNoYes
Create sandboxesYesNoNoYesYesYes
Delete sandboxesYesNoNoYesNoYes
Create policy scansYesNoYesNoYesYes
Submit policy scansYesNoNoYesYesYes
Create sandbox scansYesYesNoYesNoYes
Submit sandbox scansYesYesNoYesNoYes

Veracode Security Labs​

TaskAdministratorTeam AdminSecurity Labs AdministratorSecurity Labs ManagerSecurity Labs User
View users and teamsYesYesYesYesNo
Create and manage users, roles, and teamsYesYesNoNoNo
Create and manage campaignsYesYesYesYesNo
Manage reportingYesYesYesYesNo
Manage settings specific to the organizationYesNoYesNoNo
View labs and the leaderboardYesYesYesYesYes
View certificates, if enabledYesYesYesYesYes
View, rotate, or disable API credentialsYesNoYesNoNo
Customize conclusions for lessonsYesNoYesNoNo

Veracode Software Composition Analysis (SCA)​

TaskMitigation ApproverSecurity LeadExecutiveCreatorReviewerSubmitterWorkspace AdministratorWorkspace Editor
View the SCA Portfolio pageNoYesYesYesYesYesYesYes
Create and delete applicationsNoYesNoYesNoNoNoNo
Edit applicationsNoYesNoYesNoNoNoNo
Add teams to applicationsNoYesNoYesNoNoNoNo
View all applicationsNoYesYesNoNoNoNoNo
View specific applicationsNoYesYesYesYesNoNoNo
Request SCA and Static Analysis scansNoYesNoYesNoNoNoNo
View the Workspace Portfolio pageNoYesYesYesYesNoYesYes
Create workspacesNoYesNoYesNoNoNoNo
Delete workspacesNoYesNoYesNoNoYesNo
Edit workspacesNoYesNoYesNoNoYesNo
Add teams to workspacesNoYesNoYesNoNoYesNo
View all workspacesNoYesYesNoNoNoNoNo
View specific workspacesNoYesYesNoYesNoYesYes
Manage projectsNoYesNoNoNoNoYesYes
Link projects to applicationsNoYesNoNoNoNoYesYes
Manage agent-based scan rulesNoYesNoNoNoNoYesYes
Manage integrationsNoYesNoNoNoNoNoNo
Manage agentsNoYesNoNoNoYesYesYes
Ignore and unignore issuesYesNoNoNoNoNoNoNo

Veracode VAST​

TaskAdministratorSecurity LeadVendor Manager
Manage VAST on the Vendors page in the Veracode PlatformNoNoYes