User Management

DefectDojo’s user management surface is different in each edition. Pick the section that matches your installation.

DefectDojo Open-Source

Open-source DefectDojo uses the Authorized Users model: a user is given access to a Product or a Product Type by being added to that record’s Authorized Users list. Superusers and staff can see everything.

Authentication on open-source DefectDojo is local username/password plus the password-reset flow.

DefectDojo Pro

DefectDojo Pro uses a role-based system with Members, Groups, and Global Roles. Users can also be granted SSO access through SAML or one of the supported OAuth providers.

Migrating between editions

If you’re moving from open-source’s Authorized Users to Pro’s RBAC, or upgrading from a pre-3.0 open-source release that used RBAC into the current Authorized Users model, see the 3.0 upgrade notes. Existing access is preserved automatically.

Action Permission Charts →

All DefectDojo Pro user permissions in detail

Audit Logs →

Access audit logs for DefectDojo objects

Creating a New User →

How to onboard a new user onto your DefectDojo instance

Creating a New User →

How to onboard a new user onto your DefectDojo instance

Open-Source Permissions →

How access to Products and Product Types is granted in open-source DefectDojo

Permissions in DefectDojo →

Summary of all DefectDojo Pro permission options, in detail

Set a User's Permissions →

How to grant Roles & Permissions to a user, as well as superuser status

Set Permissions in Pro →

Overhaul, pro feature

Share Permissions: User Groups →

Share and maintain permissions for many users in DefectDojo Pro