Action permission charts (Pro)

DefectDojo Pro feature. The Members / Groups / Global Roles RBAC system described on this page is part of DefectDojo Pro. Open-source DefectDojo uses the Authorized Users model — see that page for open-source access control, and the 3.0 upgrade notes if you’re moving between editions.

Role Permission Chart

This chart is intended to list all permissions related to an Asset or Organization, as well as which permissions are available to each role.

The five roles below are DefectDojo Pro’s built-in roles. They are locked presets: their permissions are the same on every instance and cannot be changed. If you have built your own roles, this chart describes the built-ins they were cloned from rather than the roles themselves. For the full catalog of permissions a role can be given, see Custom RBAC Roles.

SectionPermissionReaderWriterMaintainerOwnerAPI Importer
Asset / Organization AccessView assigned Asset or Organization ¹☑️☑️☑️☑️☑️
View nested Assets, Engagements, Tests, Findings, Endpoints☑️☑️☑️☑️☑️
Add new Assets (within assigned Organization) ²☑️☑️
Delete assigned Assets or Organizations☑️
Asset / Organization MembershipAdd Users as Members (excluding Owner Role)☑️☑️
Edit member Roles (excluding Owner Role)☑️☑️
Edit member Roles (including Owner Role)☑️
Remove self from Asset / Organization membership☑️☑️☑️☑️
Add an Owner Role to another User☑️
Edit an associated Asset/Organization Membership within a Group³☑️
Delete an associated Asset/Organization Membership within a Group³
Engagements (Within an Asset)Add, Edit Engagements☑️☑️☑️☑️
View Risk Acceptances ⁴☑️☑️☑️
Add, Edit Risk Acceptances☑️☑️☑️
Delete Engagements☑️☑️
Tests (Within an Asset)Add Tests☑️☑️☑️
Edit Tests☑️☑️☑️☑️
Delete Tests☑️☑️
Findings (Within an Asset)Add Findings☑️☑️☑️
Edit Findings☑️☑️☑️
Import, Reimport Scan Results☑️☑️☑️☑️
Delete Findings☑️☑️
Add, Edit, Delete Finding Groups☑️☑️☑️
Other Data (Within an Asset)Add, Edit Endpoints☑️☑️☑️
Delete Endpoints☑️☑️
Edit Benchmarks☑️☑️☑️
Delete Benchmarks☑️☑️
View Note History☑️☑️☑️☑️
Add, Edit, Delete Own Notes☑️☑️☑️☑️☑️
Edit Other Notes☑️☑️☑️☑️
Delete Other Notes☑️☑️
  1. A user who is assigned permissions at the Asset level only cannot view the Organization it is contained in.
  2. When a new Asset is added underneath an Organization, all Organization-level Users will be added as Members of the new Asset with their Organization-level Role.
  3. The user who wishes to make changes to a Group must also have Edit Group Configuration Permissions, and a Maintainer or Owner Group Configuration Role in the Group they wish to edit.
  4. Risk Acceptance visibility is gated by a distinct minimum permission from Finding visibility — a Reader on the Asset can view the underlying Findings but cannot view Risk Acceptances those Findings belong to. For details on Risk Acceptance permissions, expiration-date behavior, and reinstate workflows, see Risk Acceptances (Pro).

Configuration Permission Chart

Each Configuration Permission refers to a particular function in the software, and has an associated set of actions a user can perform related to this function.

The majority of Configuration Permissions give users access to certain pages in the UI.

Configuration PermissionView ☑️Add ☑️Edit ☑️Delete ☑️
Credential ManagerAccess the ⚙️Configuration > Credential Manager pageAdd new entries to the Credential ManagerEdit Credential Manager entriesDelete Credential Manager entries
Development Environmentsn/aAdd new Development Environments to the 🗓️Engagements > Environments listEdit Development Environments in the 🗓️Engagements > Environments listDelete Development Environments from the 🗓️Engagements > Environments list
Finding Templates¹Access the Findings > Finding Templates pageAdd a Finding TemplateEdit a Finding TemplateDelete a Finding Template
GroupsAccess the 👤Users > Groups pageAdd a new User GroupSuperuser onlySuperuser only
Jira InstancesAccess the ⚙️Configuration > JIRA pageAdd a new JIRA ConfigurationEdit an existing JIRA ConfigurationDelete a JIRA Configuration
Language Types
Login Bannern/an/aEdit the login banner, located under ⚙️Configuration > Login Bannern/a
Announcementsn/an/aConfigure Announcements, located under ⚙️Configuration > Announcementsn/a
Note TypesAccess the ⚙️Configuration > Note Types pageAdd a Note TypeEdit a Note TypeDelete a Note Type
Prioritization EnginesAccess the Prioritization Engine configuration pageAdd a new Prioritization EngineEdit an existing Prioritization EngineDelete a Prioritization Engine
Organizationsn/aAdd a new Organization (under Assets > Organization)n/an/a
QuestionnairesAccess the Questionnaires > All Questionnaires pageAdd a new QuestionnaireEdit an existing QuestionnaireDelete a Questionnaire
QuestionsAccess the Questionnaires > Questions pageAdd a new QuestionEdit an existing Questionn/a
Regulationsn/aAdd a Regulation to the ⚙️Configuration > Regulations pageEdit an existing RegulationDelete a Regulation
Rules EngineAccess the Triage Engine sidebar section and everything under it (All Rules, Runs, and Deliveries)Create a rule, including converting one from the original Rules EngineChange, enable, schedule, run, replay, or take ownership of an existing ruleDelete a rule
Scheduling Service ScheduleAccess the Scheduling pageSuperuser onlyEdit an existing Schedule (change trigger, enable/disable)Delete a Schedule
SLA ConfigurationAccess the ⚙️Configuration > SLA Configuration pageAdd a new SLA ConfigurationEdit an existing SLA ConfigurationDelete an SLA Configuration
Test Typesn/aAdd a new Test Type (under Engagements > Test Types)Edit an existing Test Typen/a
Tool ConfigurationAccess the ⚙️Configuration > Tool Configuration pageAdd a new Tool ConfigurationEdit an existing Tool ConfigurationDelete a Tool Configuration
Tool TypesAccess the ⚙️Configuration > Tool Types pageAdd a new Tool TypeEdit an existing Tool TypeDelete a Tool Type
UsersAccess the 👤Users > Users pageAdd a new User to DefectDojoEdit an existing UserDelete a User
  1. Access to the Finding Templates page also requires the Writer, Maintainer or Owner Global Role for this user.

Group Configuration Permissions

Configuration PermissionReaderMaintainerOwner
View Group☑️☑️☑️
Remove self from Group☑️☑️☑️
Edit a Member’s role in a Group☑️☑️
Edit or Delete an Asset or Organization Membership from a Group¹☑️☑️
Change a Group Member’s role to Owner☑️
Delete Group☑️
  1. This also requires the User to have at least a Maintainer Role on the Asset or Organization which they wish to edit.