Skip to content

Developer program

Roles and permissions

Control who can connect projects, run scans, triage findings and administer policy.

The console has role-aware navigation for Developer, Security Analyst, DevOps Engineer, Admin, Test and Org Admin. The exact access assigned by an organization remains authoritative.

  • Developers, analysts and DevOps users receive the project capabilities their organization enables.
  • Org Admins can view organization-wide developer analytics and member data.
  • Test-only DAST and test-performance surfaces are limited to eligible roles.
  • Administrative user and model controls are restricted to administrators.

Effective access also depends on the source provider. A Cortex role does not grant access to a GitHub, GitLab, Bitbucket or Azure repository the identity cannot access.

Use least privilege, review memberships periodically, and preserve the acting identity for scans, finding decisions, policy changes and exports.