Skip to main content

About user roles and permissions

This section provides details about the permissions available to each role on the Veracode Platform. To see which roles are often relevant to different users in your organization, see Common roles for user accounts.

To grant access to the Veracode APIs, administrators assign the necessary API roles to users with an API user account. To see the roles assigned to your account, select Your Account from the top navigation menu in the Veracode Platform.

Important

Do not share your account credentials for the Veracode Platform with other users.

Administrator

Can manage users, teams, and SAML settings. Administrator access can be granted by Veracode Technical Support or, if your organization uses SSO with IdP data preferred, through a SAML assertion. A user with both the Administrator and eLearning roles is considered an eLearning administrator and can manage Veracode eLearning tasks. Can navigate the Package Firewall UI and copy access tokens, but cannot create or delete firewalls or modify exceptions or policies.

note

You can't assign both the Administrator and Team Admin roles to a user account.

Analytics Creator

Can access Veracode Analytics, where the user can view scan metrics of applications in the user's team portfolio, and create or edit custom reports.

Creator

Can create, edit, and delete workspaces and application profiles, as well as request and delete scans for applications belonging to the user's teams. Can only create workspaces and application profiles for teams the user belongs to. Can assign workspaces and applications to teams. Can allow next-day consultations for an application. Can schedule consultation calls for scan configurations. Can view the list of workspaces and applications they can access. Can also promote a sandbox scan to a policy scan and delete sandbox scans.

The Creator role can be assigned for specific scan types or for all scan types. In addition, if a user account is restricted to specific scan types, they can only request scans of those types.

Delete Scans

Can delete scans.

eLearning

Can access Veracode eLearning courses, assessments, and/or the Knowledge Base.

note

Assigning a role to an eLearning user (learner) consumes one of your purchased Veracode eLearning seats when the learner launches a course. If a learner does not launch a course, you can assign the role to another user. You can only assign as many roles as you have purchased seats.

Executive

Can view Veracode Analytics and reports for all applications. Users with the Executive role must also have the eLearning role to access the Veracode eLearning summary reports. Can view all the applications. Can schedule consultation calls for policy scan results.

Free Trial Admin

Can edit users and teams in their organization. Can create up to nine additional users and four additional teams in the free trial organization. Can submit a support request. Can access DAST in the Veracode Platform. There can only be one free trial administrator in each free trial organization.

Free Trial User

Can edit their user account. Cannot add, edit, or delete users or teams in their organization. Can submit a support request. Can access DAST in the Veracode Platform.

Greenlight IDE User

Can access the Veracode Greenlight plugin in your IDE, perform Greenlight scans, and review Greenlight scan results. This role is only available to organizations that have active Veracode Greenlight subscriptions.

Mitigation Approver

Can approve mitigations for flaws. Can view the list of accessible applications. Can modify exceptions for a Package Firewall.

Policy Administrator

Can access the Policies page to create and edit policies, set default policies and notification rules, and assign policies to applications. When assigned with the Creator or Security Lead role, can change policy assignments for individual applications using the application profile. Can create a Package Firewall and modify its policies.

Reviewer

Can access reports and flaw details for applications that belong to user teams and propose mitigations, but cannot access the review modules page. Can review scan results and scan reports for sandboxes. Can view the list of accessible applications. Can schedule consultation calls for policy scan results. Can navigate the Package Firewall UI and copy access tokens, but cannot create or delete firewalls or modify exceptions or policies. Can access EASM and view results, but cannot start a scan.

Sandbox Administrator

Can create development sandboxes for scanning code in development for applications associated with the user account. For applications which the Sandbox Administrator can access, can edit or delete development sandboxes and propose mitigation comments.

note

You use the Sandbox Administrator role in addition to another role (Creator, Submitter, Reviewer, or Security Lead).

Sandbox User

Can create and edit development sandboxes that enable scanning code in development for applications that belong to the user teams. Can scan code within a development sandbox, delete their scan, review results of a sandbox scan, add comments, and propose mitigations. Can schedule consultation calls for sandbox scan results. You can promote the sandbox scan to a policy scan, which counts toward your policy compliance score, if you:

  • Have the Sandbox User role with the Creator or Submitter role
  • Have All Scan Types or Static Scan selected

Security Insights

Can access Veracode Analytics and Reporting API, where the user can view scan metrics of applications in the user's team portfolio and custom reports. To create or edit dashboards, you must have the Analytics Creator role. This role may be team-restricted, allowing users to access Analytics data only pertaining to the teams they are a part of.

Security Lead

Can create, edit, and delete application profiles. Can view Veracode Analytics, reports, and flaw details for all applications. Can submit applications and approve scan requests made by Creators and Submitters. Can assign applications to teams. Can review all applications and scans and receive all related notifications without restrictions or team assignment limitations. Can approve next-day consultations for an application. Can schedule consultation calls. Can promote a sandbox scan to a policy scan. Can create or delete a Package Firewall and modify its exceptions and policies. Can start an EASM scan.

note

You can assign the Security Lead role for all scan types or only for specific scan types. A scan type restricted assignment limits the type of scans you can create.

Submitter

Can request scans for applications that belong to the user’s teams, access the review modules page, and upload binaries. Can view the list of accessible applications. Cannot create, edit, or delete applications or delete scans. Vendors receiving a third-party scan request must accept it before submitting a scan. Can promote a sandbox scan to a policy scan. Can create, rename, and delete agents and regenerate agent tokens in Veracode Software Composition Analysis (SCA). Can schedule consultation calls for scan configurations. Can navigate the Package Firewall UI and copy access tokens, but can't create or delete firewalls or modify exceptions or policies.

note

You can assign the Submitter role for all scan types, or only for specific scan types. A scan type restricted assignment limits the type of scans you can submit.

Team Admin

Can manage users, including creating new users, resetting passwords, and updating roles. Can only view or manage users who are in the teams that the team admin manages and do not belong to any team that the team admin does not manage. Can add or remove team memberships from a user who is in one of the teams managed by the team admin. Cannot add users to teams that the team admin does not manage. Team admins cannot edit the roles for users who have the Administrator, Executive, Policy Administrator, Security Lead, Team Admin, or Workspace Administrator roles. Cannot create teams or business units, both of which require the Administrator role. When the administrator creates a user with the Team Admin role, the administrator assigns team membership to that user. Team admin for Security Lab users can add or remove learners from their teams.

note

You can't assign both the Administrator and Team Admin roles to a user account.

Vendor Manager

Can view the list of all third-party vendors for the organization. This role may not be available for your account.

VRM Admin

Can create, read, update, and delete dashboards and connectors in Veracode Risk Manager (VRM). Can create tickets in VRM. Does not require team membership to view VRM data.

VRM Guest

Has read-only access to VRM dashboards and connectors. Can view data only for applications assigned to their teams.

VRM Supervisor

Has read-only access to VRM dashboards and connectors. Can create tickets from the Issues and Solutions pages. Does not require team membership to view VRM data.

VRM Team Admin

Can create, read, update, and delete dashboards and connectors in VRM. Can create tickets in VRM. Can view data only for applications assigned to their teams.

Workspace Administrator

Can edit and delete workspaces in Veracode Software Composition Analysis. Can create, edit, and delete agents in a workspace. Can add teams to a workspace and remove them. Can manage rules in a workspace and view workspace reports. Can create and comment on issues. Can manage project settings.

Workspace Editor

Can create, edit, and delete agents in a workspace in Veracode Software Composition Analysis. Can manage rules in a workspace and view workspace reports. Can create and comment on issues. Can manage project settings.

Security Labs roles

These roles are available only if you have an account for Security Labs.

Security Labs Administrator

Can manage all learning activities for Security Labs users in Security Labs. Cannot add or remove users or teams.

Security Labs Manager

Can manage learning activities for users on their teams. Cannot add or remove users or teams.

Security Labs User

Can access Veracode Security Labs interactive training labs.

note

Assigning this role to a Veracode Security Labs user consumes one of your purchased Security Labs seats. To see the number of remaining seats, select the Security Labs User help icon when assigning roles on the Admin page.

Actions by role

The following tables show which actions each role can perform.

ActionAdministratorCreatorDelete ScansSecurity LeadSubmitter
Create Application ProfileNoYesNoYesNo
Bulk Add ApplicationsNoNoNoYesNo
Assign Application to TeamYesYesNoYesNo
Request Manual, Static, or Pipeline ScanNoYesNoYesYes
Delete ScansNoYesYesYesNo

ActionAdministratorCreatorExecutiveReviewerSecurity Lead
Comment on Static ResultsNoNoNoNoYes
View or Delete File Exchange FilesYesNoNoNoYes
Download XML ResultsNoNoYesYesYes

ActionPolicy AdministratorMitigation ApproverReviewerSecurity LeadVendor Manager
Create PoliciesYesNoNoNoNo
Propose MitigationsNoNoYesYesNo
Approve MitigationsNoYesNoNoNo
View Vendors PageNoNoNoNoYes
Publish ResultsNoNoNoYesNo

ActionExecutiveReviewerSecurity LeadSecurity InsightsAnalytics Creator
View AnalyticsYesNoYesYesYes
Edit AnalyticsNoNoNoNoYes
Access Reporting APIYesNoYesYesNo
View ReportsYesYesYesNoNo
Access eLearningYesNoNoNoNo
Important

To be able to access eLearning summary reports, users with the Executive role must also have the eLearning role. Users who are members of the team associated with the application can accept third-party terms or scan requests. Users with both the Reviewer and Security Insights role can view analytics only for the teams for which they have access.

Package Firewall roles

The following table summarizes the Package Firewall permissions available to specific roles on the Veracode Platform.

ActionAdministratorReviewerSubmitterMitigation ApproverPolicy AdministratorSecurity Lead
Create firewallNoNoNoNoYesYes
Delete firewallNoNoNoNoNoYes
Modify policyNoNoNoNoYesYes
Modify exceptionsNoNoNoYesNoYes
View resultsYesYesYesYesYesYes

Dynamic Analysis roles

The following tables summarize the Dynamic Analysis permissions available to certain roles on the Veracode Platform.

ActionAdministratorCreatorSubmitterReviewerSecurity Lead
Request/Create/ Submit AnalysisYesYesYesNoYes
Upload or Enter URLsYesYesYesNoYes
Import URLs From ApplicationsYesYesYesNoYes
Turn on Application Auto-LinkingYesNoNoNoYes
Manually Link Results to ApplicationYesYesYesNoYes
Assign TeamsYesYesYesNoYes

ActionCreatorSubmitterReviewerSecurity Lead
Edit Analysis and ScheduleYesYesNoYes
Edit Scan ConfigurationYesYesNoYes
Add or Delete Scan from Existing AnalysisYesYesNoYes
View ResultsNoNoYesYes
View StatusYesYesYesYes
View Analysis ConfigurationYesYesNoYes
Delete AnalysisYesYesNoYes
View Vulnerability SummaryYesYesYesYes

Sandbox capabilities

The following table summarizes the Sandbox permissions available to each role on the Veracode Platform.

Developers can create sandboxes within existing application profiles, and use them to submit the application code for analysis while still in development. Sandbox scans do not affect the developer's ability to run a formal policy scan of the application, and the results of the sandbox scans do not degrade the policy status or flaw metrics of the production version of the application.

ActionCreatorSubmitterReviewerSandbox AdministratorSandbox UserSecurity Lead
Create Sandbox ProfileYesNoNoYesYesYes
Delete SandboxYesNoNoYesNoYes
Create Policy ScanYesYesNoNoNoYes
Submit Policy ScanYesYesNoNoNoYes
Create Sandbox ScanYesYesNoNoYesYes
Submit Sandbox ScanYesYesNoNoYesYes
Review Scan ResultsNoNoYesNoYesYes
Review Scan ReportsNoNoYesNoYesYes

Veracode Software Composition Analysis roles

ActionMitigation ApproverSecurity LeadExecutiveCreatorReviewerSubmitterWorkspace AdministratorWorkspace Editor
View the SCA Portfolio PageNoYesYesYesYesYesYesYes
Create and Delete ApplicationsNoYesNoYesNoNoNoNo
Edit ApplicationsNoYesNoYesNoNoNoNo
Add Teams to ApplicationsNoYesNoYesNoNoNoNo
View All ApplicationsNoYesYesNoNoNoNoNo
View Specific ApplicationsNoYesYesYesYesNoNoNo
Request SCA (Static) ScansNoYesNoYesNoNoNoNo
Propose MitigationsNoYesNoNoYesNoNoNo
Approve MitigationsYesNoNoNoNoNoNoNo
View the Workspace Portfolio PageNoYesYesYesYesNoYesYes
Create WorkspacesNoYesNoYesNoNoNoNo
Delete WorkspacesNoYesNoYesNoNoYesNo
Edit WorkspacesNoYesNoYesNoNoYesNo
Add Teams to WorkspacesNoYesNoYesNoNoYesNo
View All WorkspacesNoYesYesNoNoNoNoNo
View Specific WorkspacesNoYesYesNoYesNoYesYes
Manage ProjectsNoYesNoNoNoNoYesYes
Link Projects to ApplicationsNoYesNoNoNoNoYesYes
Manage Agent-Based Scan RulesNoYesNoNoNoNoYesYes
Manage IntegrationsNoYesNoNoNoNoNoNo
Manage AgentsNoYesNoNoNoYesYesYes
Ignore and Unignore IssuesYesNoNoNoNoNoNoNo

Container and IaC Analysis

The following table summarizes the Container and IaC analysis permissions available to each role on the Veracode Platform.

ActionSubmitterReviewerDelete ScansCreatorSecurity Lead
Submit Container Scan and view ResultsNoNoNoNoYes
Submit IaC scan and view resultsNoNoNoNoYes
Review Container scan resultsNoYesNoNoYes
Review IaC scan resultsNoYesNoNoYes
Delete Container scansNoNoNoNoNo
Delete IaC scansNoNoNoNoNo

Security Labs roles

ActionAdministratorTeam AdminSecurity Labs AdministratorSecurity Labs ManagerSecurity Labs User
View users and teamsYesYesYesYesNo
Create and manage users, roles, and teamsYesYesNoNoNo
Create and manage campaignsYesYesYesYesNo
Manage reportingYesYesYesYesNo
Manage settings specific to the organizationYesNoYesNoNo
View labs and leaderboardYesYesYesYesYes
View certificates, if enabledYesYesYesYesYes
View, rotate, or disable API credentialsYesNoYesNoNo
Customize conclusions for lessonsYesNoYesNoNo

Custom roles

You can create custom roles that are specific to your organization. Custom roles define specific permissions assigned to users. For example, you can assign a custom role with specific permissions, such as managing application profiles, submitting scans, and managing teams, and apply it to selected user accounts.

If you have the Administrator role, you create custom roles with the Identity REST API. After you create a custom role, you assign it to users in the same way you assign standard Veracode roles.

Use APIs with a user account

The Upload Using the Veracode Plugins permission is available to the Submitter role on the Veracode Platform.

The Create Application Using the Veracode Plugins permission is available to the Creator role on the Veracode Platform.

Permissions

Roles are comprised of different permissions that allow users to perform specific Veracode tasks. To view the permissions associated with specific roles, use the Identity REST API.

The following table lists the Veracode permissions, their types, if applicable, and whether they apply to UI user accounts or API user accounts. Some roles have permission types. In some cases there are seemingly similar permissions types: retrieve, retrieveTeamOnly, and retrieveOrg, for example. Individuals would have retrieve, a Team Admin would have retrieveTeamOnly, and an Administrator would have retrieveOrg.

PermissionPermission namePermission type 1UI userAPI user
Access Admin APIadminApiNoYes
Application portfolioappPortfolioYesYes
Approve Dynamic scansapproveDynamicScansYesNo
Approve Dynamic scans for ISMapproveDynamicScansforVsaYesNo
Approve or reject proposed mitigationsapproveMitigationsYesYes
Run Archer reportsarcherReportsYesYes
Assign application to any teamassignAppToAnyTeamYesYes
Assign application to teamassignAppToTeamYesYes
Change application assurance levelchangeAppAssuranceLevelYesYes
Change the Archer name of an applicationchangeArcherNameYesYes
Create a new applicationcreateApplicationProfileYesYes
Create a collectioncreateCollectionYesYes
Create an eLearning curriculumcreateCurriculumYesYes
Create a login accountcreateLoginAccountYesYes
Create a policy scan for an applicationcreatePolicyScanYesYes
Create a sandbox in an applicationcreateSandboxYesYes
Create a sandbox scan for an applicationcreateSandboxScanYesYes
Create a teamcreateTeamYesYes
Create user for teamcreateUserForTeamYesNo
Custom reportcustomReportYesNo
DashboarddashboardYesNo
Delete an applicationdeleteApplicationProfileYesYes
Delete collectiondeleteCollectionYesYes
Delete a Dynamic AnalysisdeleteDynamicAnalysisYesNo
Delete login accountdeleteLoginAccountYesYes
Delete module scan resultsdeleteModuleScanYesNo
Delete a policy scandeletePolicyScanYesYes
Delete a sandbox in an applicationdeleteSandboxYesYes
Delete a sandbox scandeleteSandboxScanYesYes
Delete a teamdeleteTeamYesYes
Delete a user for teamdeleteUserForTeamYesNo
Download scan reportsdownloadScanReportYesNo
Download scan report as XMLdownloadScanReportXMLYesNo
Download crawl and login scriptdownloadScriptYesNo
Download the site list for the scandownloadSiteListYesNo
Dynamic Analysis result importdynamicAnalysisResultImportYesYes
Change application-related options for Dynamic Analysis auto-linkingeditDynamicAnalysisAutoLinkAppOptionsYesNo
Edit login accounteditLoginAccountYesYes
Edit ISM gatewayeditMVSAGatewayYesNo
Edit account SAML settingseditsamlsettingsYesNo
Edit teameditTeamYesYes
Access eLearning mentor contenteLearningMentorYesNo
Access eLearning professor contenteLearningProfessorYesNo
Enable applications for next-day consultations for creation and updateenableNextDayConsultationYesYes
Allow user to schedule remediation consultationsenableRemediationConsultationYesNo
Allow user to schedule upload consultationsenableUploadConsultationYesNo
Expire another user's API credentialsexpireApiCredentialsYesNo
Expire another user's API credentials if on a managed teamexpireApiCredentialsForTeamYesNo
Export custom dataexportCustomDataYesYes
Access file exchangefileExchangeYesNo
Generate WAF rulesgenerateWafRulesYesNo
Import application profilesimportApplicationProfilesYesNo
Link to applicationlinkAppYesNo
Analytics creatorlookerAnalyticsCreatorYesNo
Analytics viewerlookerAnalyticsViewerYesNo
Maintain Dynamic applicationmaintainDynamicApplicationYesNo
Manage API credentialsManageApiCredentialsgenerate, retrieve, retrieveOrg, retrieveTeamOnly, revoke, revokeOrg, revokeTeamOnlyYesYes
Manage business unitsManageBusinessUnitcreate, retrieve, update, deleteYesYes
Change mitigation behavior for flaws mitigated by custom cleansermanageCustomCleanserManagementYesNo
Manage account-level eLearningmanageElearningYesYes
Manage organizationsManageOrganizationretrieve, updateYesYes
Manage SCA component blacklist for policymanageScaBlacklistYesNo
Manage teamsManageTeamcreate, retrieve, retrieveTeamOnly, update, updateTeamOnly, deleteYesYes
Manage usersManageUsercreate, createTeamOnly, retrieve, retrieveOrg, retrieveTeamOnly, update, updateOrg, updateTeamOnly, delete, deleteTeamOnlyYesYes
Manage vendor contact requestsmanageVendorContactYesNo
Navigation for external AdministratornavExternalAdminYesNo
Navigation for external eLearningnavExternalELearnYesNo
Navigation for external ExecutivenavExternalExecutiveYesNo
Navigation for Security Insight onlynavSecurityInsightOnlyYesNo
Share your results in vendor directoryoptIntoVendorDirectoryYesNo
Manage policiespolicyManagementYesYes
Retrieve cross-profile flaw identifiers in XML reportsportableScopeResultsAggregationYesYes
Promote scan to policy sandboxpromoteScansYesYes
Publish applications with mitigationspublishMitigatedRatingsYesNo
Publish results to enterprisepublishResultsEnterpriseYesNo
Read collectionsreadCollectionYesYes
Enable the Reporting APIreportingApiYesYes
Request a Dynamic AnalysisrequestDynamicAnalysisYesYes
Access Results APIresultsApiNoYes
View another user's API ID and status if on a managed teamretrieveApiCredentialsForTeamYesNo
Retrieve a team as Team AdminretrieveTeamAsTeamAdminYesNo
Retrieve a user for teamretrieveUserForTeamYesNo
Scan with GreenlightscanWithGreenlightYesYes
Access Security LabssecurityLabsYesNo
Set allow dependencies as top-level modulessetAllowDepAsTopLevelModulesYesNo
Navigate to all workspaces in SCA Agent-based ScansrcclrAccessAllWorkspacesYesNo
Create workspace in SCA Agent-based ScansrcclrCreateWorkspaceYesNo
View portfolio list page in SCA Agent-based ScansrcclrListPortfolioPageYesNo
Manage agents in SCA Agent-based Scan workspacesrcclrManageAgentsYesNo
Manage integration, agents, usage, and library catalog in SCA Agent-based ScansrcclrManageOrgYesNo
Manage SCA Agent-based Scan workspacessrcclrManageWorkspacesYesNo
Comment on issues in SCA Agent-based Scan workspacesrcclrWorkspaceCommentIssuesYesNo
Create third-party issues in SCA Agent-based Scan workspacesrcclrWorkspaceCreateThirdPartyIssueYesNo
Ignore and unignore issues in SCA Agent-based Scan workspacesrcclrWorkspaceIssuesVisibilityYesNo
Manage project settings in SCA Agent-based Scan workspacesrcclrWorkspaceManageProjectSettingsYesNo
Manage rules in SCA Agent-based Scan workspacesrcclrWorkspaceManageRulesYesNo
Manage workspace settings in SCA Agent-based ScansrcclrWorkspaceManageWebhooksYesNo
View projects in SCA Agent-based Scan workspacesrcclrWorkspaceViewProjectsYesNo
View issues, vulnerabilities, libraries, and licenses in an SCA Agent-based Scan workspacesrcclrWorkspaceViewReportsYesNo
View teams in SCA Agent-based Scan workspacesrcclrWorkspaceViewTeamsYesNo
Submit a manual policy scansubmitPolicyManualScanYesYes
Submit a static policy scansubmitPolicyStaticScanYesYes
Submit a manual sandbox scansubmitSandboxManualScanYesYes
Submit a static sandbox scansubmitSandboxStaticScanYesYes
Update resultsupdateResultsYesYes
Update team as Team AdminupdateTeamAsTeamAdminYesNo
Update user for teamupdateUserForTeamYesNo
View details for an accountviewAccountDetailsYesNo
View asset inventory resultsviewAssetInventoryResultsYesNo
View policy custom severity settingviewCustomSeverityYesNo
View application-related options for Dynamic Analysis auto-linkingviewDynamicAnalysisAutoLinkAppOptionsYesNo
View Dynamic Analysis resultsviewDynamicAnalysisResultYesNo
View Dynamic Analysis statusviewDynamicAnalysisStatusYesNo
View Dynamic Analysis URL configurationviewDynamicAnalysisURLConfigurationYesNo
View ISM gatewayviewMVSAGatewayYesNo
View open sourceviewOpenSourceYesNo
View reportsviewReportsYesYes
View resultsviewResultsYesYes
View the list of sandboxes in an applicationviewSandboxYesYes
View portfolio for third-party componentsviewScaPortfolioYesNo
Enable SCA Agent-based ScanviewSourceClearScaYesNo
View details for Third-Party tabviewThirdPartyDetailsYesNo
View vendor listviewVendorListYesNo
Submit container scan and view resultssubmitContainerScanYesNo
Submit IaC scan and view resultssubmitIaCScanYesNo
Review container scan resultsviewContainerResultsYesNo
Review IaC scan resultsviewIaCResultsYesNo
Create and manage Security Labs learning for all Security Labs userssecurityLabsAdminYesYes
Create and manage Security Labs learning for users on their teamsecurityLabsManagerYesYes
Generate custom PDF reportsviewReports or viewResultsYesYes

Footnotes

  1. Permission types allow you to perform specific tasks as part of certain permissions. For custom roles, you must specify the types when assigning those permissions to a role.