User role assignment planning
When planning to assign roles and permissions to users, consider the following factors depending on whether you're assigning UI user roles, API user roles, or creating custom user roles.
Apply the principle of least privilege: grant users only the roles and permissions required to perform their job functions. Start with the minimum level of access required and expand permissions only when a valid business requirement exists.
Planning questions for UI user roles
UI user roles define permissions for human users who interact with Veracode product UIs, such as the Veracode Platform.
- Team assignment needed? Does the user need to be assigned to specific teams, or should they have organization-wide access?
- Most team-level roles require team assignment to function.
- Organization-wide roles like Security Lead, Executive, and Administrator don't require team assignment.
- Role combinations? What other roles must accompany this role for complete workflows?
- Sandbox Administrator can only manage development sandboxes and policy scans. Combine with Creator, Submitter, and Reviewer if creating application profiles, submitting scans, and reviewing scan results is needed. Alternatively, combine with Security Lead.
- Sandbox User plus Creator or Submitter if promotion to policy scans is needed.
- Policy Administrator plus Creator or Security Lead for policy assignment to specific application profiles.
- Compliance or audit requirements? Are there specific compliance or audit requirements this user must meet?
- Some roles have broader access that might need to be documented for compliance audits.
- Verify the role assignment aligns with your organization's security policies.
- Admin scope? Can Team Admin manage this user, or does it require organization Administrator?
- Team Admin can't edit Administrator, Executive, Policy Administrator, Security Lead, Team Admin, or Workspace Administrator roles.
To learn more about role assignments, see UI user roles by job and UI user roles by task.
Planning questions for API user roles
API user roles define permissions for non-human users, such as automations, that use the Veracode APIs and integrations.
- Team assignment approach? How should team access be controlled?
- API users with NO team assignment: Organization-wide access to all applications (no restrictions).
- API users with team assignments: Team-restricted access only.
- This is the opposite of UI user behavior — plan accordingly.
- API user account or UI user account? Is this for a CI/CD pipeline, integration, or individual developer?
- API user accounts have different credential and lifecycle management needs.
- UI user accounts are tied to individuals and their specific workflows.
- Scan type restrictions? Should the role be limited to specific scan types?
- Upload and Scan API and Upload API - Submit Only support scan type restrictions.
- Restricted roles can only perform actions for their specified scan types.
- Token rotation? Establish a credential rotation and revocation plan before assignment.
Planning questions for custom user roles
Custom user roles allow you to create custom roles that meet the specific needs of your organization with the Identity API.
- Permission types and scope? Which permission type qualifiers will control access scope?
retrieve,retrieveTeamOnly,retrieveOrgdetermine whether access is organization-wide or team-restricted.- Using
Org-scoped types (likeretrieveOrg) grants organization-wide access regardless of team assignment.
- Replicating or extending? Does this role replicate an existing predefined role, or combine permissions from multiple roles?
- Start by identifying which predefined roles come closest to your needs.
- Add or remove specific permissions rather than building from scratch.
- Role combinations? What other roles should be paired with this custom role?
- Avoid creating custom roles that don't work well with any predefined roles.
- Test combinations before rolling out to production users.
- License impact? If this custom role includes eLearning or Security Labs permissions, will it consume seats?
- Custom roles with eLearning or Security Labs permissions follow the same seat consumption as predefined roles.