Actions and permissions (Preview) 
Each action that you assign to a role provides permissions to perform specific tasks and access to data.
Note
This feature is supported for hosted customers only and is in preview mode. For access to this feature, contact Contrast support.
On-premises customers manage Contrast access by setting up organization users and access groups.
Organization actions and permissions
This action: | Includes these permissions: | And is part of these built-in roles | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|
View organization | General
Reports
| Organization viewer Organization editor Organization administrator Organization rules administrator App security administrator DevOps administrator | ||||||||||
Edit organization | General
Policies
Security
Reports
| Organization editor Organization administrator Organization rules administrator | ||||||||||
Manage organization rules | General
Policies
Reports
| Organization administrator Organization rules administrator | ||||||||||
Manage organization |
| Organization administrator | ||||||||||
Manage platform organization | Access control
Reports
| Organization administrator DevOps administrator | ||||||||||
View audit logs | Security
| Organization administrator |
Application actions and permissions
This action: | Includes these permissions: | And is part of these built-in roles | ||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
View application |
| Application viewer Application editor Application administrator Application rules administrator App security administrator App security engineer DevOps administrator | ||||||||||||
Edit application |
| Application editor Application administrator Application rules administrator App security administrator | ||||||||||||
Manage application rules |
| Application administrator Application rules administrator App Security administrator | ||||||||||||
Manage application |
| Application administrator |
Project actions and permissions
This action: | Includes these permissions: | And is part of these built-in roles |
---|---|---|
View project | Scan
| Project viewer Project administrator App Security administrator DevOps administrator |
Upload scans | Scan
| Scan uploader Project administrator App security administrator |
View, edit, delete project | Scan
| Project administrator App security administrator |
Create project | Scan
| Project administrator |
Edit project | Scan
| Project administrator App security administrator |
Delete project | Scan
| Project administrator App security administrator |
Protect actions and permissions
This action: | Includes these permissions: | And is part of these built-in resource groups |
---|---|---|
Access Protect | Protect
| Protect viewer Protect policy administrator Organization administrator |
Manage Protect exclusions | Protect
| Protect exclusion administrator Organization administrator |
Manage Protect policies | Protect
| Protect policy administrator |
Manage sensitive data policies | Protect
| Protect sensitive data administrator Organization administrator |
View attack data | Protect
| App security engineer |
SCA projects actions and permissions
This action: | Includes these permissions: | And is part of these built-in roles |
---|---|---|
View SCA projects | Libraries View SCA project details | SCA project group viewer SCA project group administrator |
Create SCA projects | Libraries
| SCA project group administrator |
Delete SCA projects | Libraries
| SCA project group administrator |
Manage SCA projects | Libraries
| SCA project group administrator |
Serverless actions and permissions
This action: | Includes these permissions: | And is part of these built-in roles |
---|---|---|
View Serverless | Serverless
| Serverless user |